Your vault is safe — it lives on the server, encrypted. Nothing on this device is lost by repairing the app.
HVault
Your vault, everywhere
If your browser filled this in for you, clear it (X) and type your master password by hand.
Username + master password is all you need. Your master password never leaves this device.
HVault
No entries.
Entry
New entry
Type
Site
Credentials
Notes
Account
Secret
Camera permission is only requested when you tap Scan. You can always type the Base32 secret by hand.
Settings
Auto-lock
Lock the vault after this much inactivity.
Install
Add HVault to your home screen for a full-screen, offline-capable app. (On iPhone use Share, then "Add to Home Screen".)
Sync
—
Biometric unlock (Face ID / fingerprint)
Checking…
Read this before enabling. Anyone who can unlock this device with
Face ID, Touch ID, a fingerprint or the device PIN will be able to open
your entire vault without knowing your master password. Only turn
this on if you are the only person enrolled on this device.
Your master password keeps working either way.
This device
—
—
Encrypted backup
Downloads the encrypted vault exactly as the server stores it, plus the
public KDF parameters (salt + iteration count) needed to derive the key again.
No entry is ever exported in plaintext.
This file is useless if you forget your master password — there is no
recovery, no reset and no support channel that can decrypt it. It is safe to
store anywhere, and worthless to a thief without your password.
—
Master password
Changing the master password is not available in this app.
The sync server refuses to overwrite an existing KDF salt
(PUT /v1/kdf only fills a salt that is still empty).
A password change would therefore leave the server advertising the OLD salt
while the stored blob was encrypted under a NEW key — every device, including
this one, would then fail to decrypt a vault that is otherwise intact.
Rather than risk that, the change flow is disabled. Use the extension
(or ask for the server-side change endpoint) instead.
Account
—
“Sign out & clear” does NOT delete your vault.
Removed from this browser only: the saved username, the device id, the
auto-lock preference and any wrapped biometric key. Kept, untouched: your encrypted vault on the server — every password,
every 2FA code, every version in history.
You get everything back by signing in again with your username + master
password. Nothing here is irreversible as long as you know those two.
About
HVault PWA. No analytics, no third-party requests — the only host contacted is hvault.fii.one.