The vault and your secrets
How your passwords, API keys and tokens are protected, and how to manage them.
How the vault protects you
Your secrets are encrypted in your browser with a key that only your passphrase or your recovery key can open. Account:dir stores only the encrypted form. We cannot read your secrets, and we cannot recover them for you.
Locking and unlocking
Your vault unlocks when you enter your master passphrase, and stays unlocked while you move around the app. It locks again when you reload the page, open Account:dir in a new tab, or log out.
To unlock with your recovery key instead, select "Use recovery key instead" on the unlock screen. Capital letters, spaces and hyphens do not matter when you type it.
On a shared computer, log out when you finish.
Adding a secret
Open an account and find the Secrets panel. Choose a type (password, api_key, token or other), add an optional label and an optional expiry date, enter the value and select "Add secret".
Using a secret
Each secret is hidden as dots. Select "Reveal" to show it, "Hide" to hide it again, and "Copy" to copy it to your clipboard. You can also edit a secret, or delete it and confirm with "Delete secret".
The expiry date is shown next to the secret as a reminder. Account:dir does not send expiry notices.
Changing your passphrase
Open your account menu and select "Change passphrase". Enter your current passphrase, or your recovery key, then your new passphrase twice, select "Change passphrase" and confirm with "Yes, change it". Your saved data and your recovery key stay the same.
Replacing your recovery key
Unlock your vault, open Command Center, then Security, and select "Replace recovery key". You need your current passphrase. Your old recovery key stops working immediately, and the new key is shown only once, so write it down or copy it before you leave the page.
If you lose your passphrase
Use your recovery key to unlock, then set a new passphrase.
Important: if you lose both your passphrase and your recovery key, your secrets cannot be recovered by anyone, including us. Resetting your sign-in password does not change your vault.