Encrypted notes for Omarchy. A small GTK window over a single encrypted file, launched in a sandbox with no network. There are no accounts, no sync and no updates. A copy of the file is useless without the code you chose.
Screenshots use made-up notes.
- A list of notes on the left, the editor on the right, search through the full text of every note.
- One code of 8 to 32 digits. argon2id needs a couple of seconds to turn it into a key, so guessing a stolen file is slow.
- Autosave 1.2 s after the last keystroke. A deleted note can be brought back with Undo for 8 seconds.
- The code can be changed at any time; the vault is then encrypted again with a new salt.
- After 5 minutes without input the window saves, wipes the key and closes. Time spent in suspend counts too. The timeout is configurable.
- Text copied from a note is marked as a secret, so clipboard history tools skip it.
- An icon in the Omarchy bar and
SUPER + N. The window floats in the centre and does not show up in screenshots or screen sharing.
- It is not a password manager. No autofill, no browser integration, no fields.
- It does not sync. One file on one machine. If you copy it somewhere, the copy opens with the same code.
- A forgotten code cannot be recovered. There is no reset and no recovery file.
- Nobody outside the project has reviewed it. The cryptography is libsodium, but the format and the code around it have had no outside audit. See SECURITY.md.
Arch and Omarchy:
sudo pacman -S python python-gobject gtk4 libadwaita libsodium bubblewrap jq
git clone https://github.com/stop-loss-enjoyer/kist
cd kist
./install.shThen:
- Add the window rules to your Hyprland config:
omarchy/hyprland.luaon Omarchy,hyprland/window-rules.confon stock Hyprland. - On Omarchy, add the Kist widget to the bar in the settings and run
omarchy restart shell.
Dependencies, other distributions, updating and removal are covered in INSTALL.md.
The window, the container and the sandbox only need GTK 4, libsodium and bubblewrap, so Kist runs in any Wayland session. The Omarchy parts are the bar widget, window rules in the Omarchy style, colours from the current Omarchy theme and the clipboard marking that the Omarchy clipboard history respects. Kist is not part of Omarchy and is not affiliated with it.
On the first start Kist asks for a new code, twice.
| Action | Key |
|---|---|
| open | the bar icon or SUPER + N |
| search in all notes | Ctrl+F, Esc clears it |
| new note | Ctrl+N |
| delete note | Ctrl+Shift+Delete, asks first, 8 s to undo |
| save now | Ctrl+S, it autosaves anyway |
| lock and close | Ctrl+L |
| change the code | the menu, Change code… |
Ctrl+Delete stays with the editor, where it deletes the next word.
The first line of a note is its title in the list, the second line is the preview. Notes are listed newest first.
After three wrong codes in a row Kist offers to open the previous version of
the vault (notes.container.bak). A file cut short by exactly one block looks
the same as a wrong code, and this is the way out of that case.
Settings live in ~/.local/share/kist/config.json:
{ "idle_lock_seconds": 300 }0 turns the idle lock off.
- The file. The key is argon2id over your code, the body is XChaCha20-Poly1305. The 68 byte header, with the salt and the KDF parameters, is authenticated, so editing it to make guessing cheaper breaks the file. The body is padded to 4 KiB blocks, so the file size does not show how much you wrote.
- No network. The launcher runs the app through bubblewrap with
--unshare-netand an empty/run, which also takes away the DNS resolver socket. - Memory. The key sits in
mlocked memory and is wiped on close. Core dumps are off. Python strings cannot be wiped, so the decrypted text lives only as long as the window is open. - Screen and clipboard. The
no_screen_sharewindow rule keeps the window out of screenshots and screen sharing. Copies carry the hint that clipboard history tools respect.
What this does not cover is listed in SECURITY.md. Read it before you put anything important in.
| Path | What it is |
|---|---|
~/.local/share/kist/notes.container |
the notes, encrypted |
~/.local/share/kist/notes.container.bak |
the previous version |
~/.local/share/kist/config.json |
settings |
~/.local/lib/kist/ |
the code |
~/.local/bin/kist |
the launcher: sandbox, one window at a time, focus |
Back up ~/.local/share/kist/ with whatever you already use. The file is
encrypted, so the backup is as safe as your code is long.
python3 tests/test_vault.py # 51 checks, the container
python3 tests/test_ui.py # 23 checks, the windowThe container checks tamper with every header field, feed in damaged and
truncated files and hostile KDF parameters, check the padding and the .bak
rollback, and compare the key byte for byte with openssl kdf ARGON2ID. The
window checks run on an invisible broadway display and never touch a real
screen or a real vault.
MIT, see LICENSE.



