BlockWillGuides

Vault keys

The ways to unlock a vault, and why you should always have more than one.

A vault key opens the encrypted vault. It is not the same as the passkey you sign in with: signing in proves who you are, a vault key decrypts what you own. Someone who gets into your account still cannot read the vault without one.

The kinds of key

KindWhat it isWhere it works
BlockWill SecretA 16-character passphrase you chooseAny device
BiometricTouch ID, Face ID, or Windows Hello on one machineThat device only
Hardware keyA physical security key such as a YubiKeyAnywhere you can plug it in
Phone keyYour phone, paired by scanning a QR codeAnywhere, with the phone

Your first vault is created with a BlockWill Secret, because it is the only method that works before you have registered anything else. The other kinds are added afterwards.

Adding a key

Adding a biometric vault key (0:34)

Unlock the vault, then click Manage Vault.

Under Access & Security Methods, click Add Method and choose the kind of key.

Give it a name you will recognise later, like "MacBook Touch ID". You will be looking at this list in a year trying to remember which key is which.

Confirm with a method you already have. BlockWill needs to open the vault before it can hand a copy of the key to the new method.

Once a vault has more than one key, unlocking it asks Select Your Security Method first. That is expected.

Seeing your options

Choosing how to unlock (0:21)

Once a vault has more than one key, unlocking asks which to use. A passphrase and a biometric key are equal citizens here: either opens the vault.

Adding a BlockWill Secret to an existing vault

Adding a passphrase as a second method (0:36)

A passphrase is the method that works from any device, so it is the sensible companion to a biometric key tied to one laptop.

The "Save to Secret Manager" box is ticked by default and uploads the passphrase to BlockWill's storage. Untick it if you want the passphrase to exist only where you put it.

Changing a passphrase

Updating a BlockWill Secret (0:35)

You confirm your identity, enter the current passphrase, then set the new one.

Naming keys

Labelling a key as you add it (0:33)

Name a key when you create it. "MacBook Touch ID" means something in a year; "Key 2" does not.

Naming only happens at creation. There is currently no way to rename a key afterwards, so it is worth a moment's thought.

Removing a key

Removing a key, and the one you cannot remove (0:31)

You confirm by typing the key's name, then verify your identity. The app will not let you remove your last remaining key: something has to open the vault.

Why more than one

Each key holds its own wrapped copy of the same underlying vault key. Losing one device costs you nothing as long as another method still exists. Losing every method means the contents cannot be recovered by anyone, including BlockWill. That is a design decision, not a limitation, and it is the reason the app keeps asking you to add a second key.

Register your second key while you still have the first. There is no recovery path once you are locked out.

On this page