Master Password
Choose how your encryption key is protected.
Your encryption key can be protected in one of two ways. The choice also determines whether the workspace can move to another device.
Auto-unlock
A device key is generated and kept on the device. This is a local-only mode. It does not create the recovery material required by the current cloud sync path, and it cannot open the workspace on a new device.
Master password
Your key is wrapped under a master password. You must enter it to unlock, and an encrypted recovery blob lets another signed-in device restore the workspace. The server never receives the master password or an unwrapped data key.
Setting or changing
Set a master password from an extension's security settings or the mobile app. It is required before mobile cloud sync can start. Key derivation is intentionally slow, so unlocking may take a moment.
On mobile, a master-password workspace locks when the app leaves the active AppState. The app does not currently provide biometric unlock or a configurable idle timer.