Unlocking, Device Factor and Recovery

This guide teaches you how to open your vault quickly and safely every day, and how to make sure you are never permanently locked out. By the end you will be able to unlock with a device gesture instead of retyping your master password, change your master password with confidence, and recover with your recovery kit if you ever forget it.

Unlocking and What Re-Locks the Vault

After this section you will understand the lock model. You open the vault by entering your master password on the Unlock your secrets screen, which decrypts it locally on your device. A wrong password fails on your own device, never on the server, so there is nowhere for an attacker to sit and guess. The vault re-locks when you would want it to: after an idle period, when you choose Lock secrets, when you sign out, when you switch to another organization, and if the session is revoked. Locking is local: a locked vault holds no readable key in memory.

Unlocking can ask for a fresh second-factor confirmation when you have not confirmed one recently, the same check sensitive account changes use. If you use the Backbuild browser extension, the app and the extension stay in step: unlocking the vault in the app unlocks the extension at once, and locking in either one locks both (see The Vault in the Browser Extension).

Unlock Faster with a Device Factor

After this section you will reopen the vault with a fingerprint, face, or PIN instead of your full master password. After your first master-password unlock on a device, you can enroll a device factor, also called instant unlock. It uses your device's built-in platform authenticator, the same kind behind Touch ID, Windows Hello, and hardware security keys, so that later unlocks on that device take a quick verifying gesture rather than the full master password. You enroll a device through the Backbuild desktop app today; the iOS and Android apps will offer the same when they ship.

It is important to understand what this is and is not. It is re-authentication with a cheaper gesture, not the removal of authentication. Your master password stays the primary way to bootstrap a device, a fresh verifying gesture is required every single time you unlock, and nothing that could silently open the vault is stored at rest. On the Backbuild desktop app, your operating system's secure hardware store is the custodian of the device key. If a device has no compatible authenticator, you simply keep using your master password, which stays fast.

The device second-factor card in Backbuild settings, shown here in the web app. Callout 1 marks the card, titled This device as a second factor. Its text explains that you open Backbuild in the desktop or mobile app to register this device with its built-in security chip, so it can automatically satisfy the extra security check when you unlock your vault here.
The device second-factor card in Security settings. On the web it points you to the Backbuild desktop app, where you register the device so it satisfies the vault step-up automatically (the iOS and Android apps will do the same once they ship). The master password remains the bootstrap and the fallback.

Change Your Master Password

After this section you will be able to rotate your master password without disrupting your team. With the vault unlocked, choose the Change master password control in the Secrets header, enter the new password twice, and choose Change password. The new password must meet the same rules as the first one: at least fourteen characters, with an upper-case letter, a lower-case letter, a digit, and a symbol. The app may ask you to confirm your second factor first.

Your keys are re-sealed under the new password on your device, so every vault stays accessible and nothing has to be re-shared: vault keys are wrapped to your public keys, not to the password itself, so your access and everyone else's continues uninterrupted. The recovery kit you saved at setup stays valid after the change; it is not replaced. Keep it as safe as the password itself.

If You Forget Your Master Password

After this section you will know that forgetting is recoverable, and exactly how. Backbuild cannot reset your master password, because it never holds it and cannot read the vault it protects. That is the guarantee that keeps everyone else out too. Recovery therefore comes from something you saved in advance, your recovery kit, and from nothing else.

Save your recovery kit at setup

When you first set up the vault, Backbuild generates a strong, machine-made recovery secret and shows it to you exactly once. The setup screen calls it your recovery kit or your Emergency Kit; it is the same thing. The secret starts masked, with controls to reveal it and to copy it. Store it somewhere safe and offline, such as a printout in a locked drawer or an entry in a separate, trusted password manager, then confirm that you saved it. It is never shown again, and no one can show it to you later.

The Save your Emergency Kit card shown once during vault setup. Callout 1 marks the card: a masked recovery secret with reveal and copy buttons, the explanation that this recovery secret is the only way back into your secrets if you forget your master password, and a warning to store it in a password manager or print it because this is the last time it will be shown. Callout 2 marks the I've saved my recovery secret button.
The one-time recovery kit at setup: (1) the masked recovery secret, with reveal and copy, and (2) the confirmation that you saved it. After this screen, the secret is never shown again.

Recover and set a new master password

  1. Open Backbuild Secrets. On the Unlock your secrets screen, choose Forgot your master password?
  2. Enter your recovery secret in the Recover with your Emergency Kit dialog.
  3. Choose a new master password and confirm it. It must meet the usual rules.
  4. Choose Recover & set new password. The app may ask you to confirm your second factor. Your keys are re-sealed under the new password and the vault unlocks; every vault, item, and share is exactly as you left it.
The Recover with your Emergency Kit dialog over the locked Secrets screen. Callout 1 marks the Recovery secret field. Callout 2 marks the New master password field, above Confirm new password. Callout 3 marks the Start over (erase this identity) button, below a note that starting over permanently deletes your secrets identity and every vault on this account and cannot be undone. Cancel and Recover and set new password buttons sit at the bottom.
Recovering: (1) your recovery secret, (2) a new master password, then Recover & set new password. (3) Start over is the last resort when the kit is lost too.

If the recovery kit is lost too

If you have neither your master password nor your recovery kit, the same dialog offers Start over (erase this identity). It permanently deletes your secrets identity and the vaults on your account, and it cannot be undone; the app asks you to confirm before it erases anything. You then set up a fresh vault with a new master password. Vaults that were shared with other people stay available to their other members, who can share them with you again once your new vault is set up. This is why a shared team vault should always have a second owner (see Sharing Vaults with Your Team).

There is no administrator recovery path

Your recovery kit is the only way back in. No one in your organization, administrators included, can open, reset, or replace your secrets identity, and so no one can read your vaults on your behalf. No one at Backbuild can either. Settings, then Secrets, states this on its Recovery card, so the policy is written down where an organization's secrets settings live.

Settings, Secrets for the Northwind Labs organization. Above it, the Master-password policy card lists the minimum requirements: at least 14 characters, a lowercase letter, an uppercase letter, a number, and a symbol. Callout 1 marks the Recovery card, which explains that each member recovers their own secrets with the recovery kit they saved, that there is no administrator recovery path, and that a member who loses both their master password and their recovery kit cannot recover their personal vaults while shared vaults stay available to their other members.
Settings, Secrets: the master-password policy every member's password must meet, and (1) the Recovery card stating that members recover with their own recovery kit and that there is no administrator recovery path.

This is the honest answer to the recovery paradox. A vault an administrator or a provider can reset is a vault they can open: whoever can replace your keys can become you. Backbuild Secrets closes that door entirely, so the responsibility moves to two habits that cost almost nothing: keep your recovery kit somewhere safe and offline, and give every shared vault a second owner so a team is never stranded by one person's lost password.

Everyday access Your master password, which never leaves your device or a device factor: a quick gesture on a trusted device Forgot the password? Your recovery kit Enter the recovery secret you saved at setup and choose a new master password. Every vault stays as it was. Kit lost too? Start over Erases your secrets identity and your vaults. Vaults shared with others stay with them, and they can share them again. No administrator, and no one at Backbuild, can open, reset, or replace your secrets identity.
Everyday access is your master password or a device gesture. If you forget the password, your recovery kit restores access with every vault intact. Only if the kit is lost too do you start over.

What happens if I forget my master password? Am I locked out forever?
No, if you saved your recovery kit. On the unlock screen choose Forgot your master password?, enter the recovery secret, and set a new master password; every vault stays as it was. What is impossible is a reset by anyone else, because that would mean someone else could open your vault.

Can my organization's administrator reset my vault or recover it for me?
No. There is no administrator recovery path: no one in your organization, administrators included, can open, reset, or replace your secrets identity, and no one at Backbuild can either. Your recovery kit is the only way back in. What an administrator can do is make sure the team is not stranded, by keeping a second owner on every shared vault.

I lost both my master password and my recovery kit. What now?
Choose Start over (erase this identity) in the recovery dialog. It permanently deletes your secrets identity and your vaults, then lets you set up a fresh vault. Vaults shared with other people stay with their other members, who can share them with you again.

If I change my master password, do I have to re-share all my vaults, or save a new kit?
Neither. Vault keys are wrapped to your keys, not to your password, so changing the password leaves all your sharing intact, and the recovery kit you saved at setup keeps working.

Is instant unlock less secure than my master password?
It is re-authentication with a cheaper gesture, not the absence of it. A fresh verifying gesture is required every unlock, the master password remains the bootstrap and fallback, and nothing that could silently open the vault is stored at rest.

Next Steps