Independent by design. Apple at heart.

Your secrets.
Your devices.
Your choice.

A native password manager with a developer’s soul. Keep logins and API keys together, sync through your iCloud, and put secrets to work from the command line.

macOS 15+ · iOS & iPadOS 18+ · MIT licensed

2ndPass: a titanium vault door on an indigo app icon
your next workflow
# References in your project. Secrets in your vault.
$ 2ndpass run --env-file app.env -- npm run dev

# Same vault. Native app. Your iCloud.
Native apps & AutoFillSecure Enclave device keysYour iCloud for syncMIT licensed open source

One vault. Both sides of your day.

From signing in
to shipping code.

The password you need in Safari. The token your script needs in Terminal. 2ndPass brings them into one native application, without a separate password-manager service.

01 / EVERYDAY ACCESS

At home on your devices.

Native Mac, iPhone, and iPad interfaces. Fill passwords and verification codes through Apple’s AutoFill system.

Set up AutoFill ↗
02 / DEVELOPER WORKFLOWS

Secrets, ready to run.

Read a field, inject a configuration template, or launch a command with credentials resolved into its environment.

Meet the CLI ↗
03 / YOUR INFRASTRUCTURE

Bring your own iCloud.

Encrypted vaults travel through CloudKit. There’s no 2ndPass account or separate sync server to operate.

Understand the boundary ↗
04 / A PRACTICAL MOVE

Bring your passwords with you.

Import supported exports from 1Password, Bitwarden, Apple Passwords, Chrome, and LastPass. Review warnings before committing.

Plan your move ↗
05 / MORE THAN LOGINS

A place for the other secrets.

Store API credentials, notes, SSH key text, cards, identities, and encrypted attachments. Organize with vaults, tags, and favorites.

Organize your vault ↗
06 / OPEN BY INTENTION

Software you can inspect.

Read the source. Build it yourself. Change it to suit you. 2ndPass is MIT-licensed, with its architecture and limitations documented.

Why open source matters ↗

Built to replace a real workflow

Keep the convenience.
Choose the tool.

2ndPass began with a developer who wanted to leave 1Password but still needed the everyday utility of op. The familiar read, run, and inject pattern lives here, alongside a native password manager.

Move a workflow from op ↗
app.env
APP_ENV=development
PGUSER=secondpass://${APP_ENV}/db/user
PGPASSWORD=secondpass://${APP_ENV}/db/password
Terminal
$ 2ndpass run --env-file app.env -- npm run dev
Resolve first. Launch only when every lookup succeeds.

Protection with a clear explanation

Synced through the cloud.
Rooted in your hardware.

Each enrolled device has its own Secure Enclave keys. Your secrets are encrypted before they reach iCloud, and signed updates help detect unauthorized changes.

Hardware protects the device keys; passwords still enter app memory when you use them. Good security starts with an honest description of what is protected.

Read the security model ↗
1

Your device

Authenticate to use hardware-bound private keys.

2

Encrypted vault

Separate encryption keys for individual secrets.

3

Your iCloud

Store and sync ciphertext to enrolled devices.

Your Apple Account is also part of device enrollment and must be protected.

A second pass at passwords

Built out of
a decision to leave.

“I needed a replacement for op. So I built one.”

The starting point for 2ndPass.

A values-driven decision became a practical tool. Read why the project exists, what it aims to do, and what it doesn’t promise.

Read the origin story ↗