Skip to content
HN On Hacker News ↗

Sesame: Open Source Passwords, 2FA and Recovery

▲ 65 points 85 comments by d0mkaaa 1w ago HN discussion ↗

Pangram verdict · v3.3

We believe that this entire text is AI.

100 %

AI likelihood · overall

AI
0% human-written 100% AI-generated
SEGMENTS · HUMAN 0 of 1
SEGMENTS · AI 1 of 1
WORD COUNT 430
PEAK AI % 100% · §1
Analyzed
Aug 28
backend: pangram/v3.3
Segments scanned
1 windows
avg 430 words each
Distribution
0 / 100%
human / AI fraction
Verdict
AI
Pangram v3.3

Article text · 430 words · 1 segments analyzed

Human AI-generated
§1 AI · 100%

Your passwords.Your computer. Import your vault and keep passwords, 2FA codes, and recovery details together. Sesame never sees your vault, and the whole app is open source. Sesame vaultFictional test data.Click to view full size. Sesame vaultFictional test data Everything important in one place. Passwords, 2FA codes, recovery details, and backups. Move your vault. Import 15 formats. Review every change before saving. Security checkupEach result links back to the affected login. Test data shown.Click to view full size. Security checkupFictional test data One login, all the sign-in detailsUsername, password, 2FA, website and optional recovery details stay together.Click to view full size. One login, all the sign-in detailsFictional test data Sign in from one view. Copy passwords, read 2FA codes, and find recovery details. Browser extension: packaged for Chrome, Edge, and Firefox, not submitted to the stores yet. BetaReady to testVault, imports, 2FA, checks, Windows Hello and PIN unlock, document attachments, backup, and export. GatedBuilt, not yet shippedBrowser extension, in-app updates, and Sync. PlannedComing laterMobile, passkeys, sharing, and emergency access. Read it, build it, run it yourself. All of it is AGPL-3.0-or-later. A password manager asks for real trust, so you get all of the code. 147 commits in the last 30 days, as of 22 August 2026. sesame-desktop The Windows app and its Rust vault core. Rust 78 commitssesame-server The vault-blind Go API, account portal, and admin interface. Go 34 commitssesame-website This site. Static, and it reads nothing you cannot see here. CSS 11 commitssesame-browser-extension The Chrome, Edge, and Firefox extension. TypeScript 24 commits Build the app yourself The desktop app builds from source with Node, Rust, and the Windows WebView2 runtime. A vault from your own build opens like any other. Host the server yourself The API, account portal, and admin interface come from one repository with PostgreSQL. The desktop app works fine without them. Nothing to opt out of No analytics, no ads, and no third-party scripts. The Content-Security-Policy is in the source too. Your vault never reaches our servers. Encryption, checks, 2FA, and backups run in the Windows app. Vault fileYour device Master password or unlock secretYour device Imported password-manager exportYour device Website account email and password hashSesame website Product and release informationSesame website Public beta. Anyone can download Sesame for Windows. The independent review is still pending, so keep a separate backup of anything you cannot afford to lose. It is free during the beta. Public downloadAvailable Supported platformWindows Website accountOptional Sesame SyncNot available Account registrationOpen Browser extensionPackaged, not submitted A website account covers beta access, signed downloads, licences, connected-device management. It never holds a vault.