Password Vault is a place for passwords and other private information - things you should not keep in Notes. Everything in it is encrypted in your browser before it reaches Magpie. Magpie stores the encrypted result and cannot read your Password Vault, including from the database.

Setting up Password Vault

The first time you open Password Vault, you choose a Password Vault password. This is separate from your Magpie account password - Magpie cannot recover it, and it does not need to match your login password. Changing your account password later does not affect Password Vault.

You are then shown a one-time recovery key. It is the only other way into your Password Vault if you forget your Password Vault password, and Magpie does not keep a copy. Save or download it before continuing; there is a confirmation step so this cannot be skipped by accident.

Unlocking and locking

Enter your Password Vault password to unlock it for the browser tab. Password Vault locks itself again after 15 minutes without activity, or immediately if you click the lock button. Locking clears the unlocked keys from memory - it does not delete anything.

If you forget your Password Vault password, use Forgot your Password Vault password? Use your recovery key on the locked screen. Entering the recovery key lets you set a new Password Vault password without losing any saved items. If you lose both your Password Vault password and your recovery key, Magpie cannot recover your Password Vault.

Items

Password Vault currently supports five item types: logins, secure notes, API credentials, recovery codes, and custom items with your own fields. Each custom field can be marked concealed, which hides it behind Reveal the same way a password is hidden. Items can be tagged, marked as favorites, and searched - search runs against the items already decrypted in your browser, so nothing you type is sent to Magpie.

Git repository access tokens can be sent from the token page to Password Vault in another browser tab. Unlock Password Vault, review the pre-filled API credential, and save it.

Deleting an item moves it to Trash rather than removing it immediately. Restore it from the Trash filter, or delete it permanently from there.

To select items for a bulk action, click anywhere on a row or use its checkbox. Click the item title to open it. Selected rows remain highlighted until you clear the selection, change filters, or complete an action.

Password generator

When editing a password field, Generate password opens a generator with adjustable length and character options. It uses your browser's secure random number generator, not an ordinary random function.

Importing

Import passwords, in the bar at the top of the Password Vault list, reads a CSV export from another password manager - Generic CSV, Google/Chrome Password Manager, Bitwarden, or 1Password - entirely in your browser. The file is never uploaded to Magpie. You review the parsed items before anything is saved; rows that look like something already in your Password Vault (same domain and username, or the same title) are flagged and unchecked by default, and you can select or deselect any row before importing.

Exporting

The export button in the bar at the top of Password Vault downloads an encrypted backup (.magpievault). It contains the same ciphertext Magpie stores, plus what your Password Vault password or recovery key needs to decrypt it - it is not a plaintext file.

What Magpie can and cannot see

Magpie can see that a Password Vault item exists, its size, and when it changed. Magpie cannot see an item's title, type, or any field inside it - all of that is encrypted before it leaves your browser. For a problem with Password Vault, Contact support.