Vault keys
The ways to unlock a vault, and why you should always have more than one.
A vault key opens the encrypted vault. It is not the same as the passkey you sign in with: signing in proves who you are, a vault key decrypts what you own. Someone who gets into your account still cannot read the vault without one.
The kinds of key
| Kind | What it is | Where it works |
|---|---|---|
| BlockWill Secret | A 16-character passphrase you choose | Any device |
| Biometric | Touch ID, Face ID, or Windows Hello on one machine | That device only |
| Hardware key | A physical security key such as a YubiKey | Anywhere you can plug it in |
| Phone key | Your phone, paired by scanning a QR code | Anywhere, with the phone |
Your first vault is created with a BlockWill Secret, because it is the only method that works before you have registered anything else. The other kinds are added afterwards.
Adding a key
Unlock the vault, then click Manage Vault.
Under Access & Security Methods, click Add Method and choose the kind of key.
Give it a name you will recognise later, like "MacBook Touch ID". You will be looking at this list in a year trying to remember which key is which.
Confirm with a method you already have. BlockWill needs to open the vault before it can hand a copy of the key to the new method.
Once a vault has more than one key, unlocking it asks Select Your Security Method first. That is expected.
Seeing your options
Once a vault has more than one key, unlocking asks which to use. A passphrase and a biometric key are equal citizens here: either opens the vault.
Adding a BlockWill Secret to an existing vault
A passphrase is the method that works from any device, so it is the sensible companion to a biometric key tied to one laptop.
The "Save to Secret Manager" box is ticked by default and uploads the passphrase to BlockWill's storage. Untick it if you want the passphrase to exist only where you put it.
Changing a passphrase
You confirm your identity, enter the current passphrase, then set the new one.
Naming keys
Name a key when you create it. "MacBook Touch ID" means something in a year; "Key 2" does not.
Naming only happens at creation. There is currently no way to rename a key afterwards, so it is worth a moment's thought.
Removing a key
You confirm by typing the key's name, then verify your identity. The app will not let you remove your last remaining key: something has to open the vault.
Why more than one
Each key holds its own wrapped copy of the same underlying vault key. Losing one device costs you nothing as long as another method still exists. Losing every method means the contents cannot be recovered by anyone, including BlockWill. That is a design decision, not a limitation, and it is the reason the app keeps asking you to add a second key.
Register your second key while you still have the first. There is no recovery path once you are locked out.
