Self-hosted service
flythenimbus/bramble avatar
flythenimbus/bramble

Bramble: a local-first password manager with a private P2P mesh

Local-first, encrypted password manager with private P2P mesh. Passkeys. Create and sign in with passkeys, stored as ordinary vault entries so they sync between your devices with everything else.

395 stars19 forksTypeScriptGPL-3.0

At a glance

What is it?
Bramble keeps the vault on your own devices and syncs it directly between them, with a single Rust crypto core behind the browser extension, desktop app and mobile apps. Here is how the pieces fit, what the README leaves open, and who should stay away.
Who is it for?
Adopt Bramble if you accept that you are the backup plan: the README is explicit that nobody else holds a copy of your vault, so the export to an encrypted .bramble file and the peer-to-peer sync group are your safety net, and the desktop app is the only client the README says can run a backup schedule while the vault is locked.
Can I use it commercially?
Yes, with conditions. GPL-3.0 is a copyleft licence: if you distribute software that includes it, you must release that software's source code under the same licence. Running it internally without distributing it does not trigger that obligation.
Is it still maintained?
Yes. The repository last received commits 7 days ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 25, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The problem Bramble solves, and who it is built for

Most password managers ask you to trust a company. You create an account, the vendor holds an encrypted copy of your vault, and the security story ends with their breach disclosure. Bramble inverts that. The README states there is "no account, no server holding your vault, no company to get breached and leak everything." The vault lives in the browser's private extension storage, in ordinary files on your own disk in the desktop app, and in app-private encrypted storage on mobile.

The audience follows from that design. Bramble suits people who already run their own storage or are willing to, and who treat a password manager as a file they own rather than a service they subscribe to. It also suits multi-device users who dislike the idea of a relay: the README says devices sync directly, peer-to-peer, end-to-end encrypted, with no cloud in the middle. If you need a vault you can open from any borrowed computer through a web login, this is the wrong shape of tool, because there is no web vault to log into.

One Rust crypto core, four clients, no server in between

Everything cryptographic happens inside a single Rust core, compiled to WebAssembly in the browser and to a native library on iOS and Android. Key derivation, encryption and decryption run there, and the README says derived keys are wiped from memory after use. That shared core is why the extension, the desktop app and the two mobile apps can read the same vault format.

The desktop app is where the architecture gets interesting. It is built with Tauri, so the UI is the same React that runs in the extension while the vault and every cryptographic operation live in a Rust process. The README is specific about the boundary: the Vault Key never enters the webview at all. The desktop app also acts as a sync hub. Peer-to-peer sync needs two devices awake at the same moment, and the README points out that two phones rarely are, while a computer in the tray usually is. Pairing the desktop app with the extension is optional and one-directional: the README says pairing only adds to the extension, which stays standalone and never needs the app installed.

Backups are the other half of the mechanism. Explicit exports produce an encrypted .bramble file that stays ciphertext, so a stolen backup still needs the master password. Scheduled backups upload that same ciphertext to Dropbox, any S3-compatible bucket (the README names Backblaze B2, Cloudflare R2, Storj, Wasabi and MinIO), or a self-hosted WebDAV server such as Nextcloud, ownCloud or Fastmail. Each destination has its own cadence, daily, weekly or monthly, and Bramble keeps the most recent snapshots and prunes the rest.

Installing Bramble and taking the first real backup

There is no build step for ordinary users. The README points at the Chrome Web Store and Firefox Add-ons for the extension, bramble.sh for the macOS and Linux desktop app, the GitHub releases page for Android, and the App Store for iOS. Those are the supported install paths; the repository is a pnpm monorepo whose root scripts build the clients, not something a user is expected to run.

If you do want to build from source, the root package.json pins the toolchain and exposes per-platform scripts. The desktop targets are separate, which matters because a macOS build behaves differently when unsigned:

bash
pnpm build
pnpm build:macos
pnpm build:linux

The .env.example explains why the signing identity is not cosmetic: macOS ties a keychain item's ACL to the reading binary's code signature, so an unsigned desktop build prompts for the login password every launch and browser pairing looks broken. `security find-identity -v -p codesigning` lists available identities.

For testing the backup path without a cloud account, the repository ships a docker-compose.yml with throwaway Nextcloud and MinIO containers. The comments in that file give the exact WebDAV coordinates to enter in Bramble:

bash
docker compose up -d
yaml
# WebDAV provider settings for the local Nextcloud container
Server URL: http://localhost:8080/remote.php/dav/files/admin/
Username:   admin
Password:   Bramble-test-123

Backups land in a "bramble/" folder under that user's files. The file notes that Nextcloud's first boot takes roughly 30 to 90 seconds to install, and that the extension popup can reach http://localhost because host permissions bypass CORS and localhost is exempt from mixed-content blocking. The same file documents the integration suite: `BRAMBLE_IT=1 pnpm --filter @vault/core exec vitest run providers.integration`.

Where Bramble puts the burden on you

The honest limitation is stated in the README itself: "Nobody else holds a copy of your vault, so keeping a backup is up to you." A forgotten master password is not a support ticket, it is data loss. Exporting a .bramble file is a manual habit, and the README tells you to do it "now and then, especially before any big change," which is exactly the kind of instruction people skip.

Peer-to-peer sync has a timing constraint that is easy to underestimate. Two devices must be awake at the same moment to exchange data, and the README concedes that two phones rarely are. The mitigation is leaving the desktop app running in the tray as a sync hub, which means the design quietly assumes you own a computer that stays on. A phone-only user has the weakest version of the sync story.

Scheduled backups have their own gap. The README says the desktop app is the one that can keep a schedule while the vault is locked, because it is already sitting in the tray. So the automatic path depends on the desktop app running, and Dropbox sign-in is extension-only "for now." Finally, the desktop app targets macOS and Linux. There is a build:windows script in the root package.json, but the README's supported desktop platforms are macOS and Linux, so a Windows user should not assume a first-class client.

How Bramble differs from Bitwarden and 1Password

Bitwarden and 1Password both offer self-hosting or local storage in some form, but their default architecture is a vendor-operated sync service. You register, the service stores your encrypted vault, and syncing is a client-server conversation. Bramble removes that server from the sync path entirely: devices talk to each other, and the only third parties that ever receive bytes are the backup destinations you configure, which see ciphertext.

The trade-off is what you give up in exchange. A hosted manager gives you a web vault, an organisation account, and a password reset flow backed by a company. Bramble gives you none of those, because there is no account to reset. It also means Bramble's availability is your devices' availability. If every device is offline or broken and you never exported a backup, the vault is gone, and no vendor can help. That is the deal the README describes, and it should be the deciding factor rather than any feature list.

Maintenance, releases and the GPL-3.0 licence

The repository is not archived, and the last push was on 2026-08-29, which is recent. Release tags are split per platform: 1.22.0-chromium for the Chromium extension on 2026-08-29, 0.17.1-android on 2026-08-28, and 1.21.0-chromium two days earlier. The README confirms that the iOS and Android apps are versioned and released independently of the extension, so you should expect client versions to drift apart rather than move in lockstep.

Upgrade cost is low for users, since the extension updates through the browser store and the mobile apps through their stores. It is higher if you build the desktop app yourself, because macOS code signing and notarisation are part of a working build, and the .env.example lists the Apple credentials and the R2 and Cloudflare variables used for APT releases. Bramble is GPL-3.0. If you only run it, that changes nothing. If you plan to redistribute a modified client or embed the code in another product, read the licence text and the SECURITY.md and CONTRIBUTING.md files in the repository rather than relying on a summary; this is a description of the licence, not legal advice.

Editorial conclusion

Adopt Bramble if you accept that you are the backup plan: the README is explicit that nobody else holds a copy of your vault, so the export to an encrypted .bramble file and the peer-to-peer sync group are your safety net, and the desktop app is the only client the README says can run a backup schedule while the vault is locked. Skip it if you want a hosted web vault you can open from any borrowed machine, or if you need a Windows desktop build, since the desktop targets macOS and Linux only. Before trusting it with a real vault, verify three things yourself: that a second device actually pairs and holds the data, that an exported .bramble file restores onto a wiped client, and that your chosen backup destination (Dropbox, an S3-compatible bucket or your own WebDAV server) accepts the upload on the cadence you set.

Frequently asked questions

Does Bramble store my vault on a server?

No. The README states there is no account and no server holding your vault, and that the vault lives in the browser's private extension storage, in files on your own disk in the desktop app, and in app-private encrypted storage on mobile. Devices sync directly with each other, peer-to-peer, with no cloud in the middle.

How do I back up a Bramble vault?

The README describes three routes: export the whole vault to an encrypted .bramble file from Settings in the extension or desktop app, rely on peer-to-peer sync so every paired device holds a live copy, or configure scheduled cloud backups to Dropbox, an S3-compatible bucket or your own WebDAV server. The exported file stays ciphertext and still needs your master password to open.

Which platforms does Bramble run on?

The README lists a browser extension for Chromium browsers, a desktop app for macOS and Linux, an iOS app, and an Android app. The extension is also published on Firefox Add-ons.

What happens if I lose my master password?

The README does not document a recovery path, and it says nobody else holds a copy of your vault, so keeping a backup is up to you. Treat the master password and the exported backup as the only ways back in.

Can Bramble create and store passkeys?

Yes. The README says passkeys are created and used for sign-in, and that they are stored as ordinary vault entries so they sync between your devices with everything else.

Official sources

  1. Official documentation
  2. Official README
  3. Project repository
  4. Release notes
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/flythenimbus-bramble.svg)](https://hysenlabs.com/projects/flythenimbus-bramble)