A vault protects stored information
A vault is for reusable sensitive information. Unlocking it makes that information available for the permitted work; it is not the same as logging in to OmniTerm or authenticating to an SSH server.
A saved host profile can exist without a saved password. An account can be signed in while its vault remains locked. A private key may also have a passphrase independent of the vault password.
Set up and use a vault
- Open Keys & Security or the vault setup shown when saving a reusable secret.
- Check whether you are using local credential storage or a hosted workspace. There is no universal storage-mode selector in this screen; use the setup and enrollment steps offered by your installation.
- Use a long, unique passphrase and retain the recovery material offered by that workflow.
- Unlock the correct vault before saving or using credentials.
- Lock it when you finish, especially on a shared or unattended device.
Native persistent credential storage also relies on operating-system secure storage being available. If the keyring is locked or unavailable, resolve that problem rather than placing private material in ordinary settings or text files.
Device unlock and recovery are different
Biometric or passkey-assisted options depend on the actual platform and enrollment. A convenient device unlock method is not a substitute for a tested recovery path. Device-bound material may not be exportable or usable on a replacement device.
Account recovery alone does not necessarily decrypt a vault. Keep the account secret, recovery kit or other material required by your specific vault workflow separate from the device it protects.
See backup and recovery before you need it, and cloud and offline storage before changing residency. Encryption at rest does not protect usable secrets from every threat while the client or endpoint is compromised and unlocked.