one moment
vault.
Checking your session…
sign in required
Sign in
Sign in with your passkey to reach your vault. You’ll come right back here.
first time
Set up
You’re signed in, but this account has no vault key yet. Register a passkey on your account page — that’s what creates and protects your vault key.
locked
Unlock
Use your passkey to unlock this vault. Nothing is decrypted until you do — not even on the server.
A shared collection has its own key, wrapped for each member. The household’s logins live once and every member sees them; your personal entries stay yours. Removing someone makes a new key and re-encrypts everything, so nothing written afterwards reaches them.
Name someone who can reach your vault if you cannot. They ask; a wait you choose runs; you are mailed and can refuse. Only when the wait has passed does the server hand over your key — wrapped so only their passkey can open it. The server never can.
Your sharing fingerprint: … — read it to someone to prove a share really is to you.
Name an emergency contact
People who can reach my vault
Vaults I can reach
A Send is an encrypted note behind a link — a Wi-Fi password, a door code. The key is after the # in the link, and a browser never sends that part to any server, so ours holds only noise.
Live Sends
Weak and reused passwords are worked out here in the browser. The breach check asks Have I Been Pwned directly: only the first five characters of each password’s SHA-1 hash leave this tab — never the password, never through our server.
Move a Bitwarden or Vaultwarden vault in. Export it from Vaultwarden (Tools → Export vault → .json, the unencrypted one), choose the file here, and it is parsed and encrypted in this tab. The counts before and after are checked against each other.