Ants Projects Hub ← All projects

Live

Rolodex

LiveWINMACLNXLatest: v1.3.0

Rolodex

A safe, simple place to keep your passwords, keys, and private notes — on your own computer.

Rolodex tucks all your logins, API keys, and secret notes inside a single encrypted file. One master password unlocks it. There's no cloud, no account to sign up for, and no tracking — your data never leaves your machine. It runs on Linux, Windows, and macOS.

Rolodex application icon.

Read the full guideShow less

What it does

  • Everything stays encrypted. Your whole vault is scrambled with strong, industry-standard encryption and can only be opened with your master password. (For the technically curious: AES via Fernet, with the key derived from your password using PBKDF2-HMAC-SHA256 at 600,000 rounds and a random per-vault salt.)
  • Organise into categories. Group entries (Email, Banking, Games…), collapse the sections you're not using, and drag entries from one category to another.
  • Find anything fast. Search as you type across names, fields, and notes.
  • Secrets stay hidden. Passwords and keys are masked behind dots and reveal only when you ask. Rolodex recognises sensitive-looking fields on its own.
  • Built-in password generator. Create a strong random password in a click, with control over its length and which kinds of characters to include.
  • Live 2FA codes. Store an authenticator secret (a otpauth:// link or the plain setup key) and Rolodex shows the rotating 6-digit login code right on the card, with a countdown ring and one-click copy — no separate phone app needed.
  • Safer copying. Copy a password with one click — and Rolodex wipes it from the clipboard a few seconds later, so it doesn't sit there for other apps to read.
  • Auto-locks when you step away. After a stretch of inactivity (or instantly with the Lock button or Ctrl+L), Rolodex re-locks and forgets your master password until you unlock again.
  • Import your existing list from a plain text file, with a preview and a skip-duplicates step.
  • Backup & restore, plus a plain-text export if you ever want to move your data elsewhere.
  • Change your master password whenever you like.
  • Easy to scan. Different kinds of fields — logins, keys, web addresses, dates — each get their own colour accent so a card reads at a glance.

Download & run

Ready-to-run downloads for Linux, Windows, and macOS are on the Releases page. Each is a single file with everything bundled inside — there's nothing else to install.

Your system Download How to start it
Linux (x86-64) rolodex-linux-x86_64 Make it runnable — chmod +x rolodex-linux-x86_64 — then run it. Works on most current Linux systems.
Windows (64-bit) rolodex-windows-x86_64.exe Double-click it. It isn't signed yet, so Windows may show a blue "protected your PC" box — click More info → Run anyway.
macOS (Apple Silicon) rolodex-macos-arm64 It isn't signed yet, so the first time right-click → Open, then confirm. After that it opens normally.

Your vault is saved in your personal data folder (~/.local/share/Rolodex on Linux, ~/Library/Application Support/Rolodex on macOS, %APPDATA%\Rolodex on Windows), not next to the download.

First launch

The first time you open Rolodex, you'll create your master password (at least 8 characters). This one password protects everything.

⚠️ There is no way to recover a forgotten master password. It is never saved anywhere — it's the only key to your data. If you lose it, the data is gone for good. Make a backup you can restore from (menu → Backup vault…) and keep your master password somewhere safe.

Run from source instead (optional)

Prefer to run the code directly? You'll need a few things first:

  • Python 3.10 or newer
  • GTK 4 and libadwaita — the desktop toolkit Rolodex is built with — via PyGObject
  • The Python cryptography package

Install the toolkit from your system's package manager:

# openSUSE
sudo zypper install python3-gobject gtk4 libadwaita python3-cryptography

# Debian / Ubuntu
sudo apt install python3-gi gir1.2-gtk-4.0 gir1.2-adw-1 python3-cryptography

# Fedora
sudo dnf install python3-gobject gtk4 libadwaita python3-cryptography

The desktop toolkit has to come from your system (it isn't on PyPI). The one remaining piece, cryptography, can also be installed with pip — always the latest version:

pip install -U -r requirements.txt

Then start it:

python3 rolodex.py

Add it to your app menu (Linux)

A rolodex.desktop launcher is included. Point it at your copy of the repo and install it:

# from the folder where you cloned this repo:
sed -i "s|/path/to/rolodex|$PWD|g" rolodex.desktop   # point it at this copy
cp rolodex.desktop ~/.local/share/applications/

Where your things are kept

File What it is
rolodex.py The whole application (it's a single file).
contacts.vault Your encrypted vault — created on first run. Never shared or committed.
.rolodex.conf Window size plus a couple of non-secret settings (see below). Plain text, no secrets.
Backups/, rolodex_export_*.txt Backups and exports you create.
requirements.txt The single pip dependency (cryptography).
rolodex.desktop The app-menu launcher (edit its paths — see above).
rolodex.png The app icon.

Security & privacy

  • Your vault is protected with well-established encryption, but its real strength is your master password — pick a strong one.
  • The vault file can be read only by your own user account, and your master password is never written to disk.
  • Two safety timers can be tuned in .rolodex.conf (plain text, no secrets): how long before it auto-locks (idle_lock_seconds, default 300 seconds; set 0 to turn off) and how soon a copied password is wiped from the clipboard (clipboard_clear_seconds, default 20; 0 to turn off).
  • This is a personal-use tool, not audited security software. It's one readable file — feel free to look before trusting it with anything critical. The nuts-and-bolts of the vault format are documented in docs/specs/vault-format-and-crypto.md.

Contributing

Contributions are welcome — see CONTRIBUTING.md for the ground rules (one-file app, minimal dependencies) and SECURITY.md for reporting security issues privately.

License

MIT © 2026 Anthony Schemel

Added

  • Generate TOTP 2FA codes from stored authenticator secrets. (ROLO-0006) Store an otpauth:// URI or a 2FA-labelled base32 setup key and Rolodex renders the rotating RFC 6238 code inline with a countdown ring and one-click copy. Pure-stdlib TOTP — no new dependency.

  • Password health checkup: flag weak and reused secrets (ROLO-0008) A new "Password health..." menu item opens a read-only report that scores every stored secret on length and character-class variety (Weak/Fair/Good/Strong) and flags any secret reused across entries, worst first. All analysis runs in-process over the decrypted vault — nothing leaves the app.

  • GitHub Actions CI: ruff lint + pytest on every push/PR (ROLO-0020) New .github/workflows/ci.yml runs ruff and the pytest suite on push and PR to main, installing the system GTK stack from apt so import rolodex resolves. Pinned actions/checkout@v7.

  • Keyboard shortcuts for common actions (ROLO-0007) Ctrl+F focuses search, Ctrl+N adds an entry, Ctrl+Shift+C copies the selected entry's password/secret (plain Ctrl+C still copies selected text), Ctrl+L locks the vault, Escape clears the search box, and Ctrl+? opens a keyboard-shortcuts reference.

  • Unsaved-changes guard (ROLO-0022) — closing the add/edit dialog with edits in flight now confirms before discarding them.

  • Duplicate-name warning (ROLO-0023) — saving an entry whose name matches another (case-insensitive) now asks for confirmation first.

  • Show/hide (eye) toggle on sensitive fields in the add/edit editor (ROLO-0021) — peek at a masked value while editing, view-only so it never changes whether the field is stored as a secret.

Changed

  • Extract shared helpers: single 0600 file-write, container-clear, dialog scaffold (ROLO-0019) Internal refactor, no behaviour change. The owner-only (0600) write now lives in one write_private_file() used by both the vault save and the plaintext export; a clear_container() replaces three hand-rolled "remove all rows" loops; and make_dialog_scaffold() collapses the ToolbarView+HeaderBar+Clamp boilerplate repeated across all six dialogs. Net 53 fewer lines.

  • Debounced sidebar search (ROLO-0018) — the list rebuilds once typing pauses (~150ms) instead of on every keystroke.

All releases on GitHub →