iWarden
Web vault Privacy GitHub

Password manager · Apple platforms

A password manager that stays yours, end to end.

Most password managers ask you to trust their cloud with your most sensitive data. iWarden removes that requirement: a fully native Bitwarden® and Vaultwarden client for iPhone, iPad, Mac, and Apple Watch that syncs only with the server you choose, end-to-end encrypted, with keys that never leave your device.

iOSiPadOSmacOSwatchOS
Download for Mac on the App Store iPhone, iPad & Apple Watch: in App Review

How it works

Your keys, your server, no middleman.

iWarden has no backend of its own. That is by design, not omission. It speaks the standard Bitwarden protocol directly to the server you choose: Bitwarden US or EU, or a self-hosted Vaultwarden instance you run.

Your master password derives your encryption keys on-device, and only encrypted data is ever synced, and only to your server. This architecture mitigates the largest risk a password manager can carry, a provider-side breach, by removing the provider entirely: the developer has no servers to receive your vault and no way to read it.

iWardenon your Apple devices
Your serverholds only encrypted data

Keys are derived and held on your device, so the server you choose (Bitwarden's cloud, or a Vaultwarden instance you host) only ever stores data it can't read.

What's inside

A complete vault, native to every device.

Native to Apple

  • System AutoFill for apps and sites, including passkeys
  • A real three-column Mac app
  • Apple Watch verification codes
  • Home Screen widgets
  • Share extension to save logins anywhere

Everything a vault holds

  • Logins, cards, identities, notes
  • SSH keys and passkeys
  • Password & passphrase generator, TOTP verification codes
  • Attachments, folders, tags, organizations, and Send
  • Import from Bitwarden, 1Password, LastPass, Apple Passwords

Locked down

  • Face ID / Touch ID / Optic ID and PIN unlock, with auto-lock
  • On-screen privacy shield
  • Security report with a vault health score - weak and reused passwords flagged on-device, breach checks opt-in
  • Emergency access & key rotation
  • Open source, AGPL-3.0-licensed

Power tools on the Mac

  • Built-in ssh-agent - ssh and git sign through the vault, Touch ID per signature
  • The iwarden CLI scripts your vault from the terminal
  • Auto-type credentials into what AutoFill can't reach - RDP, VMs, terminals
  • Menu bar quick access - search and copy without opening the app
  • Keyboard shortcuts to copy a username, password, or code

Privacy

Private by architecture, not by policy.

There's no telemetry to turn off and no account to trust, because there's nothing on the other end. The privacy policy documents exactly what the app does; the source is public, so you can verify every claim.

Read the privacy policy