VS Code·Cursor·Open VSX·v0.1.0
DevVault
Secure credential storage, right where you code.
Local-only password vault for development logins — AES-256 encrypted, stored on your machine, ready to paste into the IDE browser.
// browser autofill
> VS Code and Cursor do not expose an API to autofill the built-in browser. DevVault copies credentials to the clipboard (with auto-clear) so you can paste them into login forms.
// Features
~/vault · Local secrets for day-to-day login flows
Local vault
No cloud sync — credential data never leaves your machine.
Master password
AES-256-GCM encryption with PBKDF2 key derivation.
OS SecretStorage
Encrypted payload stored through VS Code’s secure storage and OS keychain.
Sidebar vault
Browse, add, edit, and delete entries from the activity bar.
Quick fill
Match credentials by URL or domain, then copy username or password.
Password generator
Cryptographically strong passwords with configurable length and symbols.
Clipboard auto-clear
Secrets are wiped from the clipboard after a configurable delay.
Idle lock
Vault locks automatically after inactivity.
// Install in Cursor
Sideload from Open VSX until marketplace verification lands
// why search misses it
> Cursor uses Open VSX under the hood, but marketplace search favors downloads and formal verification. Newly published extensions often do not show up in Cursor’s search — a known limitation.
> Until DevVault is verified and searchable, install it by sideloading the .vsix from Open VSX.
Download the package
Open the DevVault page on the Open VSX Registry and click Download to get the .vsix file.
Open Extensions in Cursor
Launch Cursor and open the Extensions view with Ctrl+Shift+X (Cmd+Shift+X on Mac).
Install from VSIX…
Click the … (More Actions) menu at the top of the Extensions sidebar and choose Install from VSIX…
Select the file
Pick the .vsix you downloaded. Reload Cursor when prompted to activate the extension.
// From source
Prefer a local VSIX? Build and install from the repo.
# clone & package
$ npm install && npm run package && npm run vsix
Install devvault-0.1.0.vsix via Extensions → Install from VSIX…
// Security model
- > Metadata (name, URL, username, tags) lives in VS Code globalState — not passwords.
- > Passwords and notes are encrypted with AES-256-GCM and stored via SecretStorage.
- > The master password stays in memory while unlocked; optional remember window uses SecretStorage.
- > Locking or deactivating clears in-memory secrets. There are no network calls related to the vault.
Keep a strong master password. Losing it means you cannot decrypt the vault. License: MIT. Publisher: AsyncOwl.
Related pages
More open-source work and ways to get in touch.