Password Vault is a place for passwords and other private information - things you should not keep in Notes. Everything in it is encrypted in your browser before it reaches Magpie. Magpie stores the encrypted result and cannot read your Password Vault, including from the database.

Setting up Password Vault

The first time you open Password Vault, you choose a Password Vault password. This is separate from your Magpie account password - Magpie cannot recover it, and it does not need to match your login password. Changing your account password later does not affect Password Vault.

You are then shown a one-time recovery key. It is the only other way into your Password Vault if you forget your Password Vault password, and Magpie does not keep a copy. Save or download it before continuing; there is a confirmation step so this cannot be skipped by accident.

Unlocking and locking

Enter your Password Vault password to unlock it for the browser tab. The tab stays unlocked when you reload the page or visit another part of Magpie and come back, so you are not asked for the password again each time.

Password Vault locks itself again after 15 minutes without activity. To change this, choose the time in The vault locks after 15 minutes without activity at the top of the Password Vault list: 5, 15 or 30 minutes, or 1 hour. Time spent in other parts of Magpie counts as inactivity. The setting applies in every browser where you use Password Vault on the website.

It also locks immediately when you click Lock or press Ctrl+L, and when you sign out of Magpie. Locking clears the unlocked keys - it does not delete anything. A new browser tab starts locked.

To stay unlocked across a reload, the tab keeps an encrypted copy of its key. Magpie holds the key to that copy only until the vault locks, and never has both at once, so Magpie still cannot open your vault.

If you forget your Password Vault password, use Forgot your vault password? Use your recovery key on the locked screen. Entering the recovery key lets you set a new Password Vault password without losing any saved items. If you lose both your Password Vault password and your recovery key, Magpie cannot recover your Password Vault.

The native app supports setup, recovery, unlock, all five item types, custom fields, tags, favorites, password generation, Trash, restore and permanent deletion. It keeps unwrapped keys in app memory after you leave Password Vault or switch apps. You can return without entering the vault password again while the app process remains open. Lock vault clears the keys. Signing out or closing the app process also requires another unlock. Concealed multi-line fields, such as recovery codes, stay hidden until you choose Show secret fields. The app can also import passwords from a CSV file and export the encrypted backup, as described below.

The website and native app open the same personal Password Vault for your Magpie account. Use the same Password Vault password on both. Encrypted items sync through Magpie; the Password Vault password does not. Team Password Vaults are not available yet, so changing the selected team does not change which vault opens.

Items

Password Vault currently supports five item types: logins, secure notes, API credentials, recovery codes, and custom items with your own fields. Each custom field can be marked concealed, which hides it behind Reveal the same way a password is hidden. Items can be tagged, marked as favorites, and searched - search runs against the items already decrypted in your browser, so nothing you type is sent to Magpie.

In the mobile app, tap a saved password's dotted row to copy it. Choose Show beside the row to display the password without copying it. Choose Edit password to change the saved value. The copied password remains on the device clipboard until the clipboard is replaced or cleared by the device.

Git repository access tokens can be sent from the token page to Password Vault in another browser tab. Unlock Password Vault, review the pre-filled API credential, and save it.

The list shows one row per item: its name, username, website, type and when it last changed. A username or website too long for its column ends in …; choose it to show the whole value. At the end of each row, Copy username and Copy password copy a login's values without opening it; an API credential has Copy API key, and a custom item copies its first concealed field. On a narrower window the Type column, then the Updated column, then the Copy username button are left out. All items, Favorites and Trash switch between views. Search and the type filter narrow the current view, and the sort menu orders it by name, by website, or with the most recently updated first. Click anywhere on a row to open the item; the website link opens the site in a new tab. Going back from an item returns to the same place in the list.

On an item's page, click its title or any value to change it, then press Enter or click elsewhere to save. Notes save with Ctrl+Enter (Cmd+Enter on a Mac) or by clicking elsewhere, and Escape cancels a change. A concealed value stays hidden while you change it unless you choose Reveal first. Each change is encrypted in your browser and saved straight away. For a custom item, Add, rename or remove fields opens a form for changing which fields it has. Items in Trash cannot be changed until they are restored.

Tags

Tags work as folders. Give an item one or more tags in its Tags field, separated by commas. An item with several tags is in each of those folders. When any item has a tag, a Tags row under the search bar lists every tag with the number of items it holds in the current view. Choose a tag to show only its items, Untagged for items without one, or All to show every item again. Each item's tags are also shown in the list's Tags column: the first two, then a count of the rest. Search matches tags too. "Work" and "work" count as the same tag.

To tag many items at once, select them and choose Add tag. Type a new tag and choose Add, or pick an existing tag. Remove tag lists the tags the selected items have. Each item is encrypted and saved again, one at a time. Tags are encrypted with the rest of the item, so Magpie cannot see them.

Deleting an item moves it to Trash rather than removing it immediately. Restore it from the Trash view, or delete it permanently from there.

To act on several items at once, check their boxes, or use the box in the column heading to check every item shown. A bar above the list names how many are selected and offers Move to Trash, or Restore and Delete forever in Trash. Only items shown in the list can be selected; changing the search or filter removes any selected item it hides. Outside Trash the bar also offers Add tag and Remove tag.

Password generator

On a login's page, Generate beside the password opens a generator with adjustable length and character options. Use this password asks before replacing a saved password, then saves the new one; change it on the website too, or the saved password will no longer work. When you create an item, Generate password under the password field fills it in the same way. The generator uses your browser's secure random number generator, not an ordinary random function.

In the mobile app, choose Generate password under a login's password. Set the length from 8 to 64 characters, choose the character types, and choose Use this password. The password is generated on the device with its secure random number generator. It fills the field only; choose Save encrypted item to keep it.

Importing

Import passwords, under More in the bar at the top of the Password Vault list, reads a CSV export from another password manager - Generic CSV, Google/Chrome Password Manager, Bitwarden, or 1Password - entirely in your browser. The file is never uploaded to Magpie. You review the parsed items before anything is saved; rows that look like something already in your Password Vault (same domain and username, or the same title) are flagged and unchecked by default, and you can select or deselect any row before importing.

In the mobile app, unlock the vault and choose Import passwords from its action menu. Choose the password manager the file came from, then the CSV file. The app reads it on your device, removes its own copy straight away, and shows the same review list. It imports up to 1,000 items at a time. Delete the original CSV file when you are finished, because it holds your passwords in plain text.

Exporting

Export encrypted backup, under More in the bar at the top of the Password Vault list, downloads an encrypted backup (.magpievault). It contains the same ciphertext Magpie stores, plus what your Password Vault password or recovery key needs to decrypt it - it is not a plaintext file.

In the mobile app, unlock the vault and choose Export encrypted backup from its action menu, then save or send the file from the share sheet. It is the same file the website downloads, and it does not include items in Trash.

What Magpie can and cannot see

Magpie can see that a Password Vault item exists, its size, and when it changed. Magpie cannot see an item's title, type, or any field inside it - all of that is encrypted before it leaves your browser. For a problem with Password Vault, Contact support.