Doriath
A zero-knowledge encrypted secrets manager for . A personal vault for every user, secret sharing for teams, and a write-without-read credential store for applications.
A vault that lives where your team already works.
Doriath leverages Nextcloud's own users, groups, notifications and unified search instead of rebuilding them — so sharing a secret is as natural as sharing a file.
Zero-knowledge encryption.
RSA-4096 encrypts every secret; AES-256 protects the private key behind your master password, which is never stored. A private Certificate Authority (root + intermediate) signs every user and application certificate and renews itself automatically.
Personal vault, folders, unified search.
Every user gets a private vault organised in folders, with fuzzy search and a copy-to-clipboard list view. Secrets surface in Nextcloud's unified search bar without ever exposing a decrypted value.
Sharing built for teams.
Share a secret with a user or a Nextcloud group, with sync-on-update and one-click revocation. Send a password-protected link with a usage limit, or a write-without-read request link so a colleague can submit a credential you can never read. Temporary ownership delegation covers the case where an owner is unavailable.
Application credentials, not just passwords.
Applications register through CSR-based onboarding, receive an admin approval queue, and get write-without-read secrets they can push but never read back in plaintext. Registered applications exchange a signed JWT assertion (RFC 7523) for a short-lived Bearer token to call the API.
Partners shipping Doriath
Implementation, hosting, and integration partners that deliver Doriath to their customers. Pick the partner you already work with, or one whose stack matches yours.