Clavimit is a browser extension for encrypting and decrypting Gmail messages using client-side cryptography.
It uses hybrid encryption with AES-256-GCM and RSA-OAEP with SHA-256. Encryption and decryption are performed locally in the browser using the Web Crypto API.
Clavimit does not require an account or a Clavimit server.
- π Encrypt Gmail messages
- π Decrypt Clavimit messages directly from Gmail
- βοΈ Secure compose mode keeps plaintext out of Gmail's compose field
- π€ Optional sender-side decryption for messages in Sent
- π Use your own RSA keys or generate a key pair locally
- π Available for Chrome and Firefox
- π« No Clavimit account or backend required
- π§© Built using the browser-native Web Crypto API
Clavimit is available on the Chrome Web Store. Install Clavimit from the Chrome Web Store
Clavimit is available on the Firefox Add-Ons. Install Clavimit from Firefox Add-Ons
Contributors are welcome β including first-time open-source contributors.
Clavimit is a small project that touches several interesting areas:
- browser extension development
- JavaScript
- Gmail/DOM integration
- Web Crypto
- testing
- privacy and security
- UI/UX
UI improvements, tests, documentation, validation, browser compatibility, and Gmail integration are all valuable areas to work on.
If this is your first contribution, these are good places to start:
- #16 β Improve README.md and CONTRIBUTING.md files
- #1 β Keep package and manifest versions synchronized
- See all good first issues
For larger tasks, see the open issues.
Read CONTRIBUTING.md for development setup, testing, contribution guidelines, and pull-request instructions.
If you're unsure whether an issue is suitable for you, leave a comment on it. I'm happy to point you toward the relevant parts of the codebase.
When encrypting a message:
- Open Clavimit.
- Open the encryption section.
- Provide the recipient's RSA public key by:
- pasting the key, or
- selecting a public-key file.
- Choose a compose mode:
- Gmail compose - encrypt the message currently written in Gmail.
- Secure compose - write the plaintext message directly inside Clavimit. Clavimit opens a Gmail compose window automatically and inserts only the encrypted message.
- Optionally enable Keep a decryptable copy for the sender and provide the sender's RSA public key.
- Click Encrypt.
Clavimit generates a new AES-256 key for each message and encrypts the email content using AES-GCM.
The AES key is encrypted using the recipient's RSA public key with RSA-OAEP. If Keep a decryptable copy for the sender is enabled, the same AES key is also encrypted using the sender's RSA public key. Encrypting the AES key separately for the recipient and sender allows either party to decrypt the same encrypted message using their own RSA private key.
The encrypted email contains the information required for the recipient to decrypt it, including:
- the encrypted AES key
- the encrypted AES key for the sender, when enabled
- the initialization vector (IV)
- the encrypted message
- the algorithm identifiers
- the Clavimit message-format version
Encrypted messages are wrapped in a Clavimit message block:
-----BEGIN CLAVIMIT MAIL-----
...
-----END CLAVIMIT MAIL-----
To decrypt a Clavimit message:
-
Open the encrypted email in Gmail.
-
Open Clavimit.
-
Provide your RSA private key by:
- pasting the key, or
- selecting a private-key file.
-
Click Decrypt.
Clavimit attempts to decrypt the message AES key using the provided RSA private key. If the message contains both recipient and sender encrypted-key copies, Clavimit automatically uses the one that can be decrypted with the supplied private key.
The recovered AES key is then used to decrypt the email content.
The resulting plaintext is displayed by the extension.
The Keep a decryptable copy for the sender feature allows the senders to decrypt their own messages from Gmail's Sent section.
Clavimit can optionally generate an RSA key pair for you. This is not required; you can also use your existing compatible RSA keys.
Clavimit currently uses:
- AES-256-GCM for message encryption
- RSA-OAEP with SHA-256 for encrypting the AES key
- a newly generated AES key for every encrypted message
- a new random initialization vector for every encryption operation
- the browser's native Web Crypto API
Clavimit does not implement cryptographic primitives itself.
For encryption, Clavimit requires the recipient's public key. The sender may optionally provide their own public key to keep a decryptable copy of the message.
For decryption, Clavimit requires a private key corresponding to one of the public keys used during encryption.
Users remain responsible for storing, backing up, exchanging, and verifying their own RSA keys. Keys can be generated independently or optionally generated locally using Clavimit.
Keys are provided to Clavimit only when they are needed, either by pasting them into the extension or selecting a key file.
Clavimit does not intentionally:
- upload keys to a server
- synchronize keys between devices
- permanently store private keys in the browser
- provide key recovery
- distribute public keys
- verify that a public key belongs to a particular person
Key ownership and key distribution remain under the user's control.
Encryption and decryption are performed locally in the browser.
Clavimit does not require a backend service for message encryption or decryption.
The email content and cryptographic keys are processed by the extension only when required to perform the requested operation.
For more details, see Privacy Policy.
When using Gmail compose, Clavimit encrypts the message after it has already been written in Gmail's compose window.
Gmail may automatically save the plaintext message as a draft before Clavimit applies encryption. Therefore, Gmail compose mode does not protect the plaintext message from Gmail while it is being composed.
Therefore, the current version of Clavimit does not protect the plaintext message from Gmail itself while the message is being composed.
When using Secure compose, the plaintext is written inside Clavimit instead. Clavimit encrypts the message locally, opens a Gmail compose window if necessary, and inserts only the encrypted message into Gmail.
Clavimit is currently an experimental project and has not been independently security audited.
It should not currently be relied upon for highly sensitive or production-critical communication.
Clavimit also does not currently provide:
- public-key identity verification
- digital signatures
- sender authentication
- automatic public-key discovery
- protection against a malicious or compromised browser
- protection against a compromised device
- protection against plaintext drafts created by Gmail before encryption
Users should independently verify that a public key really belongs to the intended recipient before using it.
Clavimit is under active development.
The current implementation supports:
- Gmail message encryption
- Gmail message decryption
- Gmail and secure compose modes
- Optional sender-side decryption by encrypting the AES key for both recipient and sender
- RSA public keys provided as pasted text or files
- RSA private keys provided as pasted text or files
- AES-256-GCM message encryption
- RSA-OAEP key encryption
- Clavimit-formatted encrypted email messages
- local browser-based cryptographic operations
Clavimit is intended to provide a simple encryption layer for Gmail while keeping cryptographic key ownership in the hands of the user.
The project deliberately does not aim to become a full cryptographic key-management system.
Future versions may improve usability around public keys and identity verification without requiring Clavimit to take ownership of users' private keys.
The next planned improvements focus on extending the current email workflow and improving privacy:
- Attachment encryption β encrypt email attachments together with the message content.
- Formatted decrypted messages β correctly display decrypted HTML and structured message content instead of showing the raw representation.
- Symmetric encryption mode β optionally allow encryption using a user-provided symmetric key for situations where both parties already share a secret.
Longer-term features that may be explored include:
- public-key fingerprint display
- digital signatures
- signature verification using user-provided public keys
- support for additional cryptographic algorithms
Clavimit will continue to leave key ownership, distribution, and identity verification to the user rather than acting as a key-management or identity service.
Contributions are welcome.
See CONTRIBUTING.md for development setup, contribution guidelines, issue reporting, and current areas for contribution.
To install the development version manually:
- Clone or download this repository.
- Check out the develop branch:
git checkout develop- Install the project dependencies:
npm installThe extension build requires:
- Node.js
- npm
- No external or web-based build tools
package-lock.json is included to reproduce dependency versions.
The build script copies the extension source files, selects the browser-specific implementation, and generates the final manifest.json by combining the common manifest with the browser-specific manifest.
Run
npm run build:chromeThe generated Chrome extension is written to: dist/chrome
To load it manually:
- Open Chrome.
- Navigate to
chrome://extensions. - Enable Developer mode.
- Click Load unpacked.
- Select the
dist/chromedirectory. - Open Gmail.
- Open Clavimit from Chrome and use the side panel to encrypt or decrypt messages.
Run
npm run build:firefoxThe generated Firefox extension is written to: dist/firefox
To load it manually:
- Open Firefox.
- Navigate to
about:debugging. - Select This Firefox.
- Click Load Temporary Add-on.
5.Select the
dist/firefox/manifest.jsonfile. - Open Gmail.
- Open Clavimit from Chrome and use the side panel to encrypt or decrypt messages.
Extensions loaded through about:debugging are temporary and must be loaded again after restarting Firefox.
Clavimit is licensed under the GNU General Public License v3.0.
See the LICENSE file for details.




