Raycast Export Explorer1
A web front-end tool that allows users to upload and decrypt their exported Raycast settings (.rayconfig file). The data is decrypted and parsed 100% client-side by the browser and allows you to explore any Raycast Notes included in the export. Notes can be downloaded individually as Markdown and/or bulk-downloaded as a zipped archive.
- 100% Client-Side: Decryption and processing happen entirely in your browser. Your data never leaves your device and is not sent to any external server.
- Raycast Notes Export: Specifically designed to extract and convert the internal Raycast notes database into standard Markdown files.
- Secure: Uses the Web Crypto API for secure, local AES-256-CBC decryption.
- 🔐 Decrypt .rayconfig files: Unlock your exported settings using your Raycast export password.
- 💾 Export to zip: Download all your notes at once as a zipped archive of Markdown files.
- 📝
Preview Notes: View your notes directly in the browser with proper formatting#TODO. - 📱 Responsive UI: Clean, modern interface built with Svelte and Tailwind CSS.
- Node.js (Latest LTS recommended)
- pnpm
-
Clone the repository:
git clone <repository-url> cd raycast-db
-
Install dependencies:
pnpm install
-
Start the development server:
pnpm dev
-
Open your browser to
http://localhost:5173
pnpm buildThe built files will be in the dist/ directory.
pnpm test- Export from Raycast: From the launcher, type "export" and select "Export Settings & Data".
- Upload: Open Raycast Export Explorer and select your
.rayconfigfile. - Decrypt: Enter the password you chose during export.
- Explorer: Browse your notes and download them individually or as a ZIP package.
src/lib/decrypt.ts: Handles the AES-256-CBC decryption and key derivation (PBKDF2-like double hashing).src/lib/utils.ts: Converts the Raycast AST (Abstract Syntax Tree) format into standard Markdown.src/App.svelte: The main application logic and UI.
The tool implements the specific encryption scheme used by Raycast. Thanks to this Gist for the original analysis:
- Key Derivation:
Hash1 = SHA256(Passphrase)Hash2 = SHA256(Hash1 + Passphrase)Key= First 32 bytes ofHash1IV= First 16 bytes ofHash2
- Decryption: AES-256-CBC.
- Decompression: The decrypted stream is a Gzipped JSON payload.
My original shell script MVP decrypt_rayconfig.sh is included that allows for decrypting a *.rayconfig file to its JSON representation using openssl and gunzip.
./decrypt_rayconfig.sh <path-to-rayconfig> <password>Footnotes
-
I spent about as much time creating the logo in Blender as I did everything else 🤫 ↩
