FREE · IN THE BROWSER · NOTHING UPLOADED
An encrypted paper backup of your vault, codes or keys
A paper backup survives a dead disk, a lost phone and a locked account. The usual advice is to print the export as text, which puts every password on a sheet anyone can read. Kionel prints the file as encrypted QR codes instead, and any phone with a browser turns the pages back into the file.
Written by Taha Bayar, a biologist working on data handover between devices.
What fits
| What | Typical size | Pages |
|---|---|---|
| 2FA recovery codes (a text file) | under 1 KB | 1 |
| SSH or GPG private key | 1–7 KB | 1 |
| KeePass or KeePassXC database (.kdbx) | tens of KB | 2–5 dense |
| Password manager export (JSON) of a few hundred entries | roughly 100–300 KB | plain JSON compresses well: often 3–5 dense; a password-protected export hardly compresses: 10–25 dense |
The free personal edition prints and reads up to 5 pages: about 19 KB on standard pages and 57 KB on dense ones, after compression. Plain text shrinks a lot; an already-encrypted file, such as a .kdbx or a password-protected export, hardly shrinks at all. Kionel refuses a file that does not fit before anything prints, and says whether Dense would fit it.
How to make one
- Export the file. In Bitwarden: Tools → Export vault. For the strongest backup choose .json (Encrypted) with Password protected; it needs more pages because encrypted data does not compress, so a large vault may need a business licence. A plain .json export fits in far fewer pages and is then protected by Kionel's code alone. In KeePassXC there is nothing to export: the .kdbx database is already encrypted, so print that file. For 2FA recovery codes, save them in a text file.
- Print it with Kionel. Open Kionel, choose the file, pick Print on paper, choose Dense if it helps it fit, and print. The offline package works on a computer you keep off the network.
- Keep the code apart from the pages. Kionel shows a 12-character code. Without it the pages cannot be read. Store it where you would keep a spare key, not in the same envelope.
- Delete the unencrypted export from the computer, including the Downloads folder and the recycle bin.
- Test the restore once. On your phone: Receive → Printed pages, enter the code, point the camera at the pages. A backup you have never restored is a hope, not a backup.
Why two layers of encryption
The code protects the pages with a key derived from 12 characters (60 bits), and every guess costs 600,000 rounds of PBKDF2. That stops someone who finds the envelope. For secrets that must stay safe for decades against a well-funded attacker, print an export that is already password-protected, as above: the paper then holds a file that is encrypted twice, and the inner password never leaves your head.
What the printer sees
Only the encrypted codes. Office and network printers often keep recent jobs in memory or on a disk, and a print spooler can leave a copy on the computer. With Kionel that copy is the same unreadable codes as the paper, unless you choose to print the code on the pages.
Compared with other paper backup tools
| Tool | Runs on | Restore with | Notes |
|---|---|---|---|
| paperkey | command line | typing or OCR, then GnuPG | Made for GPG secret keys only; prints the key as text, very compact. |
| qr-backup | Linux command line | a webcam or scanner and its tools | Fits more per page at its densest setting; optional password. |
| PaperCrypt | command line | its own tool | Printable encrypted documents with instructions on the page. |
| Kionel | any browser, including a phone | any phone camera, pages in any order | Nothing to install; spare codes chosen so a smudged or torn code does not lose the file. |
Keep it readable
- Print on a laser printer if you can; inkjet ink can run if the paper gets wet.
- Store the pages flat and dry, away from sunlight. A plastic sleeve helps.
- Print a new set when the file changes, and destroy the old one. Old pages still open with their old code.