Your data

Vault and master password

The vault holds every secret Synapse stores for you. A master password is what stands between it and anyone with access to your computer.

What's in the vault

Open it from the header's ··· menu, or the command palette. It holds:

None of this lives in the host list itself, and none of it ever leaves your device unless you switch on Sync between devices or make an encrypted backup yourself.

Without a master password

If you haven't set one, everything above is stored unencrypted in the app's local storage on this device. Synapse shows Not encrypted next to Master password in Settings as a reminder. Set one as soon as you can.

Setting a master password

Go to Settings (Ctrl ,) → Credentials → Set master password. Use at least 12 characters, typed twice to confirm. A meter under the field gives a rough idea of how hard it is to guess; a passphrase of four or five random words is both strong and easy to remember.

Once set, everything in the vault is encrypted with AES-256-GCM, using a key derived from your master password with Argon2id (64 MiB of memory, 3 passes), which makes guessing passwords slow and expensive even on specialised hardware. Vaults set up with an older version (which used PBKDF2-SHA256) are upgraded to Argon2id automatically the next time you unlock them. A master password shorter than 12 characters from an older version keeps working; Synapse suggests changing it in Settings, but never forces you to. Synapse shows Locked or Unlocked next to Master password depending on whether the vault is open right now.

Nobody can recover a forgotten master password

It's never saved anywhere, and it isn't sent to Maku or anyone else. Forget it, and the vault stays locked - there is no reset link and no support ticket that gets it back. Write it down or, better, keep it in a password manager the moment you set it.

From version 0.2.6, Cloud backup can get you back into a copy of your vault using a 24-word recovery phrase shown once when you set it up - keep that in a password manager too. See Backups and restore. Without the master password and without that phrase, a Cloud backup can't be opened either.

Locking and unlocking

Use Lock now next to Master password to lock the vault immediately - this clears the decrypted credentials from memory. Set Lock automatically to have it lock itself after a period without keyboard or mouse input: never, or after 5, 15, 30, 60 or 240 minutes idle.

While the vault is locked, saved host credentials are hidden (connecting to a host that needs them prompts you to unlock first), but you can still edit everything else about a host.

Changing or removing the master password

Change password asks for your current password and a new one, then re-encrypts the vault. Remove master password decrypts everything and stores it unencrypted on this device again - nothing is deleted, so turn it back on any time.

Managing keys and passwords

Inside the Vault window, switch between SSH key and Password items. For SSH keys you can paste an existing one or generate a new one on the spot. Deleting an item that's still attached to a host as its credential warns you first and shows which hosts use it.

One key, many hosts

Save a key once in the vault and point several hosts at it, instead of pasting the same key into each host's Authentication section.