Ji-ho Lee132 downloadsA secure, lightweight, and high-performance KeePass integration plugin for Obsidian, featuring WebAssembly Argon2 decryption, masked inline chips, and interactive credential tables.
📖 Full documentation: https://search5.github.io/safe-passage/
SafePassage is a secure, lightweight, and high-performance KeePass integration plugin for Obsidian. It allows you to link your local KeePass databases (.kdbx) to render masked credential chips and structured tables directly inside your notes, while keeping your master passwords secure.
`{{sp:profile/path#field}}` tags into elegant circular masking chips. Click to copy the secret value, with configurable clipboard auto-clear timeouts.Group/Path, so renaming or moving an entry never breaks a token that points to it. Path-based tokens keep working unchanged.Insert Secret modal, directly while typing {{sp: in a note, and inside safe-passage code blocks — including a one-click unlock when the target profile is locked.Insert Secret command modal.npm run build and copy main.js, manifest.json, and styles.css into your vault's .obsidian/plugins/safe-passage/ directory.work-db)..kdbx file, relative to this vault (e.g., Secrets/vault.kdbx)..key or .keyx file, relative to this vault.Insert credential tokens anywhere in your note wrapped in backticks:
My twitter password is `{{sp:work-db/SNS/Twitter#Password}}` and the username is `{{sp:work-db/SNS/Twitter#UserName}}`.
work-db: Twitter#Password (🔒). Click to open the password unlock modal.Finance/API/Stripe (Password). Click to copy the value to your clipboard.Note: The
work-dbsegment is the profile's internal ID, not its display name — SafePassage inserts it automatically when you save a secret (see below), so you never type it by hand. Because it's the ID rather than the name, renaming a profile later won't break tokens that were already inserted.
The part after the profile can be either a path (Group/SubGroup/Title) or a KeePass entry's UUID, prefixed with uuid::
{{sp:work-db/uuid:Yhz3AjkUmk+HQu5+w2xdWQ==#Password}}
A UUID never changes even when the entry is renamed or moved to another group, so a UUID reference survives database reorganization where a path reference would break. Existing path-based tokens keep working exactly as before — nothing needs to be migrated.
Since nobody types a UUID by hand, SafePassage suggests entries wherever a reference is entered:
{{sp: directly in a note triggers a chained autocomplete: profile → entry → field, automatically inserting the next separator as you go. If the target profile is locked, the suggestion list offers a one-click unlock instead of coming up empty.profile: field and entries: list items inside safe-passage code blocks.Use the safe-passage markdown code blocks to render structured tables:
```safe-passage
title: "Production Servers Access Control"
profile: work-db
fields: [UserName, Password, URL]
entries:
- SSH-Prod/[Prod] bastion
- uuid:Yhz3AjkUmk+HQu5+w2xdWQ==
This renders a sleek table displaying columns for each field and copy buttons for every entry. Entries can freely mix path and UUID references.
### 5. Inserting New Credentials (Write Support)
1. Open the Command Palette (`Cmd + P` or `Ctrl + P`).
2. Search and execute **`SafePassage: Insert Secret`**.
3. Choose a profile, type the entry path (e.g., `Database/MySQL`), and input the credentials. You can use the **[Generate]** button to instantly create a strong 16-character password.
4. Click **[Save]**. The credentials will be written directly to your physical `.kdbx` file, and the token `` `{{sp:work-db/Database/MySQL#Password}}` `` will be auto-inserted at your cursor location, using a UUID reference for that entry.
---
## 🔒 Security Design
- **Zero Plain-Text Storage**: Master passwords and database buffers are never saved to disk in plain text.
- **Memory Safety**: Decrypted database instances are stored in transient JavaScript heaps and cleaned up immediately upon session timeout.
- **Clipboard Sanitation**: Copied secrets are automatically cleared from your system clipboard after the duration configured in your settings.
- **Read-Only Mode**: Protect crucial databases by toggling "Read-Only" in the profile settings to block any write operations.
---
## 🛠 Developer Commands
For building and testing the codebase locally:
```bash
# Install dependencies
npm install
# Run build compilation
npm run build
This project is licensed under the MIT License.