Skip to content
MFICORE
Create your site

Password vault

The vault keeps passwords and other secrets for you and the people you share them with. It is end-to-end encrypted: everything is locked and unlocked on your own device, and what reaches our servers is unreadable to us.

Where to find it

A vault belongs to you, not to one of your sites. You buy one from the Store on your own dashboard, and it then appears as Password Vault in the sidebar — and in the app, from the menu behind the ☰ button.

If your vault used to be under a site: it has moved to your own dashboard, with everything in it untouched. The one thing that changed is who else can reach it. People who could open it because they help run that site can't any more — share it with them directly (below) if they still need it.

Your master password

Setting up a vault asks for a master password. This is deliberately not your account password.

Your account password reaches our servers when you sign in — that is how signing in works. Your master password never does. That difference is the whole reason the vault is private: even with full access to the database, there is nothing there that can be turned back into your secrets.

The cost of that is real and worth understanding before you start:

Your recovery key

Because nobody can reset your master password, setting up a vault also gives you a recovery key — a long string shown to you exactly once.

Write it down or print it, and keep it somewhere separate from your password. It is not stored on our servers in a form we can read, and it cannot be shown to you again.

Using it later unlocks your vault without the master password. Doing so sends you a message and is recorded, because from the outside there is no way to tell you using your recovery key apart from somebody else who has found it.

You can decline a recovery key. If you do, forgetting your master password means losing everything in that vault permanently.

Vaults and sharing

A vault is a group of entries with its own key. You start with your own, and you can create more.

Choose Sharing to see who can open a vault and to add someone. Search for them by name, the same way you would address a message. They must have set up their own vault first — otherwise there is no key of theirs to lock yours to; if they haven't, the panel says so by name rather than quietly skipping them.

If someone can't be found by name, they can read their own user id off their own Sharing panel and send it to you.

Taking access back. Revoke on the Sharing list removes someone and changes the vault's key, re-locking every entry so nothing written from then on is within their reach. Two honest limits:

Only the person who created a vault can share it or take access back. Someone you share with gets the vault's contents, not the vault itself.

Importing from Psono

If your passwords live in Psono today, you can bring them across in one go:

  1. In Psono, open Other → Export, choose your datastore and the JSON format, and save the file.
  2. In the vault (on the web dashboard), unlock, pick the vault to import into, and choose Import…. Select the file you just saved.
  3. A preview lists every password found. Untick anything you don't want, then confirm.

The export file is read on your own device and never uploaded — each entry is encrypted right here, exactly like one you typed in, before anything leaves your browser. All the same, the exported file itself is your passwords in readable form: delete it once the import is done.

A few things to know:

Unlocking with Face ID, a fingerprint or Windows Hello

In the app you can unlock the vault with the device's own unlock gesture instead of typing your master password every time — Face ID, Touch ID or a fingerprint on a phone or Mac, Windows Hello on a PC. Your password is kept in the device's own secure storage.

Be clear about what that means: anyone who can unlock that device can then open your vault. If other people can unlock your phone, do not turn this on.

On Windows, "Hello" may mean the PIN. Windows treats a device PIN and a fingerprint as the same unlock gesture, and gives an app no way to insist on the fingerprint. The PIN is tied to that one machine — it is useless to someone who has only stolen the password — but it is still a PIN, and it is usually shorter than a master password. Worth knowing before you turn this on for a shared PC.

Every so often the app asks for your master password anyway. That is on purpose. Nobody can reset it, so a password you never type is one you may not remember when you need it.

You can turn it off at any time from the vault screen, and whoever owns the vault can switch it off for everyone.

Signing in when your connection is down

A vault keeps working during an outage, but you still have to get past sign-in, and the second step you chose decides whether you can.

An authenticator app generates its codes on your own device, so it works with no connection at all. Emailed codes have to reach you, which they cannot do while your connection to us is down.

Whichever you use, keep your recovery codes somewhere you can get at them. They are checked without contacting anyone, so they work when nothing else can reach you.

Locking

The vault locks itself after a period of inactivity — set by whoever owns it, under the vault app's options — and whenever you close or reload the page. Unlocking again needs your master password — nothing is remembered between visits, which is why there is no "stay unlocked" option.

Earlier versions of an entry

Every time you change an entry, the version you replaced is kept. Choose History on an entry to see them, with the date each was replaced.

You will also see a version here if the same entry was changed in two places at once — on your phone and in a browser, say, while one of them was offline. One of those changes wins and the other is kept here rather than thrown away, so nothing you saved is lost quietly.

When entries say they can't be read

Occasionally an entry shows as encrypted with a key your device does not have yet. This is normal and usually brief. It happens just after someone shares a vault with you, or after a vault's key is changed, and it resolves once the new key reaches the device you are on.

Where your vault lives

A vault runs in more than one place at once, so it survives losing a whole location. If your office loses its internet connection, the copy there keeps working for people in the building; if that site goes down entirely, the copies elsewhere still have everything. The copies catch each other up automatically once they can talk again.

If two people change the same entry while the copies are separated, one version wins and the other is kept as earlier history on that entry rather than being thrown away. Nothing you save is discarded silently.

See Premium Apps for how to add or remove a copy, and what each one costs.