rosec is about to gain a Proton Pass provider. I originally built it because my passwords were in Bitwarden and I wanted my Linux desktop to read them from there, and I still think that's the useful bit: keep your secrets where you want them, let the desktop get on with using them.
So, another provider. This one talks directly to Proton's API, decrypts the vault contents locally, and serves them through the same Secret Service that libsecret applications already use. It runs as a WebAssembly plugin, with no Proton CLI process sitting underneath it. You can use Proton's CLI to set things up if you prefer, but rosec doesn't need it running or logged in afterwards.
The nice part, as with the KeePassXC provider, is that passwords are only some of what's in the vault. SSH keys turn up in rosec's agent, with confirmation before signing, and time-based one-time passwords (TOTP) work through the usual rosec totp get. Even the extra TOTP fields on an item come through, each as its own entry. Notes, cards and the other item types are supported too, though I'll leave the field-by-field tour to the docs.
Getting it talking
You'll need a normal personal access token, with access to the vaults you want rosec to read. Viewer permission is enough, because this provider is read-only. You still edit things in Proton Pass.
In the Proton Pass web app, that's Settings → Access tokens → New token. Pick the vaults, set an expiry and leave Use for AI agent off. Proton's guide has the current plan requirements, which are better kept there than copied into a blog post for me to forget about.
Once the separate provider bundle and a matching rosec host are installed, add this to your configuration:
provider
id = "proton"
kind = "protonpass"
offline_cache = true
Then register it:
rosec provider auth proton
That asks for the complete token and a local passphrase of your choosing. The token gets stored encrypted, protected by that passphrase and the installation key; after that, you unlock with the local passphrase. Your Proton account password isn't involved, and the local one never gets sent to Proton. Paste the token into the prompt, not the config file.
From there it's familiar:
rosec sync
rosec search
rosec get ITEM_ID
rosec totp get --stdout ITEM_ID
Use an ID from the search results in those last two commands. There's no separate Proton version of each command to remember.
A few edges
I've kept the experimental label. The live checks cover reading a test vault, checking the generated two-factor codes, signing through the SSH agent, and making sure registration survives a daemon restart. Useful things to have working, but I'm not going to turn that into a claim that every corner of Proton Pass has been exercised.
Existing supported passkeys can also sign through rosec, but that needs a little more qualification: no new passkeys, no counter updates, and no credentials with nonzero stored counters. That part has synthetic protocol tests; live browser testing is still outstanding.
The offline cache is handy when you're away from a connection. It's encrypted locally and expires after ten days, but it does mean a disconnected machine can still have secrets whose token you've since revoked. There isn't a remote-revocation trick that can reach an offline laptop. If you'd rather it didn't keep a copy, set offline_cache = false.
Sync is a full refresh for now, with no push updates. If it fails, the provider locks rather than carrying on with half a vault. Also, the usual Secret Service distinction applies: usernames and URLs are public metadata; passwords, notes and custom field values aren't.
The plugin will ship separately under GPL-3.0-or-later, including its corresponding source and dependency notices. I'm getting it ready to push now, so the packages are still to come. Repo, as ever, on GitHub.