Amarkal keeps logins, passkeys and API keys on your Mac — encrypted so that only you can open them — next to the services, subscriptions and money they belong to.
Logins, one-time codes and API keys live in one encrypted vault, filled in across macOS — in Safari, Chrome and anywhere else the system asks. Passkeys are created and used by Amarkal itself, and never leave it in readable form.
Only this Mac, a folder you already sync, your own S3 or WebDAV server, or Amarkal Sync. Change your mind later and move between them in a couple of clicks — the vault, its history and its keys travel together. Everything is encrypted before it leaves your Mac, and we never hold the key: we cannot read your vault, list what is in it, or recover it for you. Keep it in your own storage and your Mac makes no requests to us at all.
Every secret belongs to a service, and every service to a project. What it costs, when it renews, whether it is up, what it earns — read with your own keys, from the services that expose it, and kept beside the credentials that run them.
A group can live in a folder or on a server you own — our servers are not involved at all. Invite by link, see who has access, remove someone when the time comes. If you remove them because a secret may have been exposed, Amarkal hands you the list of what that person could see, with a checkbox against each item, so you can change those secrets at the services themselves and keep track of what is done.
A recovery phrase of 24 words opens your vault on a new Mac, years from now, with no server involved. Deleted items wait in the Trash for as long as you choose; nothing is destroyed automatically.