# Klef

> Zero-knowledge .env sync.

End-to-end-encrypted .env sync you can host yourself. A React SPA does AES-256-GCM encryption in the browser under an Argon2id-wrapped data key. The Hono Worker and its D1 database only ever hold ciphertext.

- Role: Solo. Crypto design, app, Worker.
- Year: 2026
- Status: Live, open source
- Stack: React, Hono, Cloudflare Workers, D1
- Live: https://klef.sh
- Source: https://github.com/BenyD/klef
- Listed under: Projects

## What I built

- AES-256-GCM encryption in the browser
- An Argon2id-wrapped data key
- A server that only ever stores ciphertext
- Self-hosting on Cloudflare

## Further reading

- [Where the key lives](https://beny.one/where-the-key-lives): Encrypting a secret is the easy part. The harder question is what happens to the decrypted key afterwards, and how long you let it exist.

A project by [Beny Dishon](https://beny.one), software engineer in Chennai, India.
