Unlock your saved work

3 minute read · Cloud & Sync

Unlock the Vault to use protected saved resources and encrypted workspace sync. Its password and recovery material are separate from the ordinary login session.

Set up once, keep the recovery information

Follow the Vault setup screen for the signed-in account. Choose the requested unlock method and save recovery material somewhere you can still reach if this computer is unavailable. Later, unlock the existing Vault instead of creating a new identity for the same saved work.

Saved credentials are protected records. The privileged local tools resolve the secrets when you authorize a connection or operation; the server does not decrypt customer credentials to manage cloud storage.

If unlock fails

Check that you are in the right Vortex account and using its Vault recovery path. Older accounts can have migration behavior related to the login password. Read the actual prompt rather than assuming a new account’s setup applies.

An unavailable OS keychain or unreadable existing master key needs recovery. Do not silently regenerate the key, delete the profile or replace the encrypted database: those actions can strand the data you are trying to recover.

Record the error and preserve existing files while seeking help. Never send a Vault password, recovery code or key in a bug report. Continue with account recovery and another computer.

Set up the Vault without losing the recovery boundary

  1. Confirm the signed-in account before creating a Vault. Existing encrypted cloud records belong to that account.
  2. Follow the setup screen and choose the requested Vault password. Keep the generated recovery material in a private place outside the app.
  3. Unlock the Vault and open a saved resource or let workspace sync finish. A successful account login alone does not demonstrate successful decryption.
  4. Close and reopen Vortex, then verify that you can unlock and read the same resource. This is a useful first recovery rehearsal before relying on cloud history.

A password manager is a suitable place for private recovery material. An agent prompt, shared repository, public issue or screenshot is not. Do not delete an existing keychain entry as a troubleshooting shortcut; an unreadable master key must not be replaced with a new unrelated key.

Understand what the Vault protects

Saved credentials are resolved by the privileged desktop process when you connect. Resource lists and agent discovery should expose useful names and IDs without the saved secret. Once you deliberately execute a query or request, its result can still contain private information. Inspect captured output before sharing it with an agent or exporting it.

Local workspace records use encrypted payloads in the desktop's SQLite storage. Cloud workspace envelopes are encrypted before upload. Resource ownership metadata, cloud mail and Signals have separate handling; unlocking the Vault does not make every server pipeline end-to-end encrypted.

If old data will not unlock

Check that the account, existing Vault password and OS keychain are available. Older accounts may pass through a supported password-based Vault migration. Follow that flow instead of deleting local storage. Preserve the profile and recovery files before asking support to investigate. A normal login password reset should not be described as recovering a missing encryption key. Read sync on another device before moving work between computers.

Updated Sep 13, 2026 · Need a hand?