Documentation

The Walilock user guide

Everything for using Walilock day to day: the desktop app, the browser extension for Chrome and Edge, the wali command-line tool, passkeys, family and business vaults, and your web account.

New here? Start with Getting started — it covers the one decision that matters most before you type a single password in.

Start here

Getting started

Walilock is local-first: your vault lives on your device, encrypted, and it works fully offline. An account only exists to sync that encrypted vault between your devices and to unlock paid features — it never lets Walilock read what's inside.

The first screen you'll see

On a brand-new install, the app asks you to choose one of three paths:

  • Activate a plan code — you already paid on the website and have an activation code from your email or the checkout page.
  • Sign in — you have a Walilock account already, registered on another device or on the website, and you're adding this device to it.
  • Start free — a new, local-only vault with no account at all.

If the app already has an account on this device, you won't see this screen — you'll go straight to unlock.

Starting free — no account required

Free is a real, complete local vault: unlimited use, ten vault items, no credit card, no email, nothing synced anywhere. You set a master password and you're in. Upgrade later from inside the app whenever you want sync, unlimited items, or the AI features — nothing about your existing items changes when you do.

Adding a second device to an existing account

There's no "add device" action to run on a new device by itself — you sign in to it, the same way you'd sign in anywhere. On the new device's first-run screen, choose Sign in and enter your account email and sign-in password. Already have Walilock running on this machine under a different account? Use the account switcher on the unlock screen, then Add account → Sign in to an existing account. Either path logs in for real and pulls down your vault key — your data starts syncing immediately, nothing gets overwritten.

Start here

Account password vs. master password — the one thing to get right

Walilock deliberately uses two different passwords for two different jobs. Confusing them is the single most common support question, so read this once before you set either.

Sign-in password (account password)
What you type to log in on the web or a new device. It's proven with a protocol called OPAQUE, which means Walilock's servers verify you know it without the password ever being sent to them — but if you forget it, it's recoverable by email, the same as most accounts you use online.
Master password
Set only inside the app. It unlocks your vault on this device and encrypts every secret you store. It never leaves your device, Walilock never sees it, and there is no "forgot master password" flow that gets your data back — because the whole point is that nobody but you can decrypt it, including us.

There is no recovery-contact or "recover my master password" feature. If you lose it and don't have your emergency kit or a device that's already unlocked, that vault's contents are gone. This isn't a missing feature — it's what "we cannot see your data" actually means in practice.

Start here

Your emergency kit — and what it actually does

Offered as the last step of setting your master password, and available again from Settings → Security any time after. Get very clear on what it is for, because it is easy to assume it does more than it does — and that assumption is exactly what turns into a support ticket at the worst possible moment.

The emergency kit is a device-recovery tool, not a forgotten-password tool. It works together with a master password you still remember, to restore your vault onto a new device after this one is lost, stolen, or wiped. It cannot open your vault for you if the master password itself is the thing you've forgotten — nothing can, on purpose. See why.

What it's for: replacing a lost or wiped device

This is the scenario the kit solves. Your laptop is stolen, or its drive dies, or you're setting up a new machine. You still remember your master password — you just no longer have the device your vault lived on. On the new install, when Walilock asks for your vault, you supply the emergency kit's recovery code together with your master password, and your vault comes back.

What it's not for: a forgotten master password

If the master password itself is gone from your memory, the kit is powerless — it isn't a second factor that substitutes for the password, it's a companion to it. This is the exact tradeoff "we cannot see your data" requires: a recovery path that worked without the master password would be a way for Walilock (or anyone who stole the kit) to open your vault too.

Generating and storing it

  1. Generate the kit from Settings → Security — during initial master-password setup it's offered automatically as the final step, and you can regenerate it there any time afterward.
  2. Save it somewhere that isn't this device. A password manager can't be its own backup location — a fireproof safe, a bank box, or a printed copy with a trusted family member are all reasonable. Cloud storage synced automatically to the same device defeats the point.
  3. Treat it like a spare house key, not a password: on its own it opens nothing. Combined with your master password, it opens everything. Keep the two apart if you can — the kit in a safe, the password in your memory.

Password Help — what "Forgot master password?" actually does

The unlock screen has a link that reads "Forgot master password?" — a fair question to ask, and the panel it opens gives an honest answer rather than pretending there's a reset button. Below is the real panel, reproduced exactly, so you know before you ever need it.

Walilock — Password Help
Password Help

Interactive — click a choice below, exactly as it works in the app.

"I can't sign in to my account"

This is the flow to use for a forgotten sign-in (account) password. It emails you a reset link, the same as any normal account. It has no effect whatsoever on your vault or your master password.

"I can't unlock my vault"

Choosing this is honest about what happens next: the app tells you plainly that the master password cannot be reset or recovered by anyone. If this device has a working biometric unlock (fingerprint or Windows Hello) enabled, the panel tells you so explicitly and gives you one genuinely useful piece of advice: close this dialog, unlock with biometrics while it still works, and export a backup from Settings → Security immediately. That window closes the moment biometric enrollment is lost too — a new device, a removed fingerprint, an OS reset — so it's worth acting on the same day you see this message, not filing it away.

If no unlock method works on this device at all, the panel says so directly: that vault's items cannot be recovered, and your options are starting a new vault or adding an account you still have access to. This is stated plainly rather than softened, because a forgotten master password with no biometric fallback and no emergency-kit-plus-remembered-password is, genuinely, unrecoverable.

Desktop app — full walkthrough

First launch, step by step

Everything below reproduces the app's own screens using its own copy, its own colors, and its own decision order — read straight from the component source rather than described from memory, so what you see here is what you'll actually see. It is an interactive walkthrough, not a photograph of the app: click through it the same way you'd click through the real thing.

Screen 1 — the welcome choice

This is the very first thing a brand-new install shows you — and only a brand-new install. If this device already has an account, you'll never see it; you'll land straight on unlock instead.

Walilock
Welcome to Walilock
How would you like to get started?

Click any card — the outcome shown matches exactly what happens next in the real app.

The order is deliberate: Activate a Plan Code is listed first and visually primary because most first launches are a customer who just paid. Sign In exists specifically because, before it was added, a returning user reinstalling the app had no way back to their existing account from this screen at all — they could only ever create a fresh one. Start Free needs nothing from you but a master password.

Adding a second device the correct way

There's no separate "enroll this device" step to run from the new device, and that's intentional — signing in already does everything required. Two doors lead to the same real login:

  • A brand-new install — the welcome screen's Sign In card, shown above.
  • This machine already runs Walilock under a different account — the account switcher on the unlock screen, then Add account → Sign in to an existing account.

Both run a real OPAQUE login against your account and then pull down your actual vault key — not a placeholder, not a re-registration. Your data begins syncing immediately and nothing on either device is overwritten. (An earlier version of this exact screen did something different and dangerous — it ran a raw account registration against whatever was typed in, silently overwriting the real account's password if you made a typo. That path no longer exists; sign-in is the only way in now, for exactly this reason.)

Desktop app — full walkthrough

Setting your master password

Whichever welcome path you chose — Start Free, a fresh plan-code activation, or the very first account setup — you'll reach this screen exactly once per device. It is the single most consequential thing you'll type into Walilock, so the app is deliberately blunt about the stakes before it lets you proceed.

Walilock — Set up your vault
Create your master password
This unlocks your vault on this device.
Because we never receive it, there is no "reset password" email that can bring your vault back. If you forget it, your encrypted data can't be decrypted. Store it somewhere you trust, and save an emergency kit — the kit gets you back in if this device is lost or wiped, but nothing gets you back in if the password itself is forgotten.

Interactive — the checkbox really does gate the button, exactly like the real screen.

Why the consent checkbox exists

This is the same warning box and the same checkbox text used at signup on walilock.com — Walilock deliberately says the identical thing whether you set this up in the app or the account team hears about it on the web, so there's exactly one honest story about what this password does. The Continue button stays disabled until you check the box. That's not friction for its own sake — the app would rather you close this window and think about it than click through a sentence you didn't read.

Why the Emergency Kit step is separate, not optional-and-skippable

It's presented as its own full screen, right after the password is set, while the stakes are freshest in your mind. See Your emergency kit above for exactly what it does and doesn't recover — the short version repeated here because it matters: it restores your vault onto a new device using a master password you still remember, it does not recover a master password you've forgotten.

Desktop app — full walkthrough

Unlocking the app

Every launch after the first drops you here. It's deliberately the smallest screen in the app.

Walilock — Locked
Welcome back
you@example.com

The biometric button only appears if you've enabled it — and its label matches your OS ("Use Windows Hello", "Use Touch ID", "Use fingerprint").

The account switcher

Running more than one Walilock account on this machine? A switcher lives on this screen too, letting you move between accounts without signing out — each is fully isolated from the others, with its own vault, its own key, its own master password.

"Forgot master password?"

Clicking it opens the exact Password Help panel documented above — jump to it if you haven't read that part yet. The short version: it never resets your master password, because nothing can. What it does do is get you to the biometric-unlock-and-export escape hatch before you accidentally spend a reset that wouldn't have helped anyway.

Desktop app

The vault

Everything you store lives in one encrypted vault, organized by category.

Item types

  • Login — username, password, URL, and notes.
  • Secure note — free-form encrypted text.
  • Credit card — card number, expiry, CVV, billing details.
  • Identity — reusable name/address/contact info for filling forms.
  • API credential — the developer-oriented item type the CLI reads by category/item/field, e.g. an OpenAI key.

Adding, editing, deleting

Add an item from the vault list; every field is encrypted before it's written to disk. Deleting an item is recoverable by default — it moves to a "recently deleted" state you can restore from, the same pattern the CLI's wali rm / wali restore use. Free accounts are capped at 10 items; every paid tier is unlimited.

Desktop app

Password generator

Available from the toolbar and inline whenever you're filling a password field. Configure length and character classes (uppercase, lowercase, digits, symbols) and optionally exclude ambiguous characters like Il1 or 0O. The same generator logic backs wali generate on the command line, so a password generated one way behaves identically to one generated the other.

Desktop app

Import & export

Reachable from the vault's import/export panel.

Importing

Bring items in from another password manager's export file. Review what will be imported before it's committed to your vault — nothing is written silently.

Exporting

Export your vault for backup or migration. An export file is unencrypted by nature — it exists specifically so another tool can read it — so treat it like the plaintext secrets it contains: delete it once you've used it, and never store it somewhere synced or shared.

Desktop app

Two-factor codes (TOTP)

Store a site's TOTP secret alongside its login and Walilock generates the rotating 6-digit code for you, the same way an authenticator app does — one less app to keep unlocked.

Adding a TOTP secret

Two ways in, side by side — typing stays a first-class option because plenty of sites only ever show you the raw base32 key:

  • Type it manually — paste or type the base32 secret a site gives you.
  • Scan the QR code — on Android, this opens your camera live, since holding the phone up to your desktop screen is the natural motion. On desktop, it defaults to importing an image (a saved screenshot, or drag-and-drop) rather than a webcam, since the QR is already on the screen you're using. Either platform can reach the other method if you need it.
Desktop app

Passkeys

Walilock can create, store, and use passkeys — the passwordless sign-in standard built on public-key cryptography — right alongside your regular logins, in the same vault, under the same master password.

Using a passkey

When a site asks for a passkey, Walilock offers the matching one from your vault. Manage everything you've created from the passkey section: see which site each one belongs to, when it was created, and remove ones you no longer need.

Moving passkeys to a new device

Transferring a passkey between two Walilock installs uses a paired device flow with a real safety check: after the two devices connect, you're shown a 6-digit code on both and asked to confirm they match before anything transfers. This isn't a formality — the transfer is refused unless you confirm, and if the codes don't match, the session is abandoned outright rather than offered a retry, because a mismatch means the device on the other end isn't the one you intended to pair with.

Importing and exporting with other password managers

Walilock supports the industry Credential Exchange Format for moving passkeys to and from other compatible password managers, for the cases where a paired-device transfer isn't the right fit — for example, a one-time migration off another product.

Business and Enterprise admins can additionally set an org-wide passkey policy from the admin console, governing whether members are required, permitted, or blocked from creating them.

Desktop app

AI features Personal+ and above

Three AI-assisted tools, all reading your already-decrypted, in-memory vault locally rather than sending it anywhere:

Vault assistant

A chat interface for asking questions about your own vault — "what's my WiFi password", "which logins reuse this password" — and getting an answer with the specific item cited as its source, streamed as it's generated.

Security audit

Scans your stored items for reused, weak, or aging passwords and gives you a prioritized list of what to change first.

Phishing scanner

Checks a page or link against patterns associated with credential-phishing attempts before you type a password into it.

Breach monitor

Flags vault items whose email or password has shown up in a known data breach, so you know what to rotate.

Desktop app

Sync & devices Personal+ and above

On a paid plan, every change encrypts locally first, then syncs as ciphertext — the relay servers move encrypted blobs between your devices and never hold a key that could open them. A sync status indicator in the app shows you're current; if you're offline, changes queue and catch up the moment you're back online.

Free accounts are local-only by design — nothing about a free vault ever leaves the device it's on, which is also why free has no multi-device sync.

Sharing

Family vault — the complete guide Family

One shared vault, owned by whoever created it, with other family members invited in to see and use what's shared there. Everyone keeps their own personal vault entirely separate — the family vault is an addition sitting alongside it, never a replacement. This is the single most-requested-for-detail feature in this guide, so it gets the longest section: every screen, every button, every error message you might see, reproduced from the app's own source rather than summarized.

Creating your family vault

Only the account holding an active Family plan sees this option, and only until a vault exists — after that, the same sidebar entry opens the vault instead. Creation is two short steps.

Walilock — Family Vault
What should we call your family vault?
You can change this later.

Interactive — type a name, click Create, and the real step 2 appears.

Step 2's "Skip for now" is a genuine skip, not a soft nag — your vault exists the moment step 1 finishes, whether or not you invite anyone that same minute. You land straight in the vault either way, ready to add your first shared password.

Inviting members — and every message you might see

Invites are sent by email, and the person you invite needs a Walilock account — free is enough — to accept one. Below is the real invite dialog, plus every error message the app can show for it, written verbatim from the source rather than paraphrased, because the exact wording is what you'll actually see and search for if something goes sideways.

Invite to your family vault

They'll need a free Walilock account to join.

What you'll seeWhat it means
"…is already in your family vault."Nothing to do — they're already a member.
"…already has a pending invite — they just need to accept it."You already invited them; no need to resend unless it's been a while (see FAQ).
"Your family vault is full. You'd need to remove someone first."You've hit the plan's member cap.
"Your family plan has ended. Renew to add new people."The plan lapsed — existing members keep access, but no new invites until you renew.
"They need to open Walilock and sign in once before you can add them."Their account exists but has never published an encryption key from this app — normal for a brand-new signup that hasn't opened the app yet. Resolves itself the moment they sign in once; try the invite again after.
"We couldn't find an Walilock account for that email. Ask them to sign up first."No account at all exists for that address yet.
"You've sent a lot of invites recently. Try again a bit later."Rate-limited — the relay caps invites per vault per day. Not an error with the invite itself, just a pause.

The security-code check — a real safety mechanism, not a glitch

Occasionally an invite triggers a very different screen instead of the usual confirmation. If you ever see this, read it — it exists specifically to stop a real attack.

Invite to your family vault
The encryption key published for alex@example.com has changed since this device last saw it. Nothing has been sent.

This usually means they reset or reinstalled their account. It can also mean someone is trying to intercept what you share — so check with them before continuing.

Ask alex@example.com to open Settings → Security on their device and read out "My Security Code." It should match the one below — confirm it over a call or in person, not over chat.

Their code now
7F2A-91C4-BE08-3D6E

This fires when the key on file for the person you're inviting doesn't match what this device last trusted for them — almost always because they reset or reinstalled their account, which is completely ordinary. It is treated as a security event rather than waved through, because the other explanation is someone intercepting the invite. Nothing is sent while this is showing. Call or message the person some other way, have them read their Security Code out loud from their own Settings → Security, compare it to what's shown here, and only click "Codes match" once you've actually verified it — not just because the screen is annoying and you want it gone.

The member roster and roles

Family vault has exactly two roles — owner and member — nothing more granular. The owner is whoever created the vault; everyone else who accepts an invite is a member.

Walilock — The Rodriguez Family
The Rodriguez Family
End-to-end encrypted
MR
Maria Rodriguez
Joined Jan 3, 2026
Owner
JR
Jake Rodriguez
Joined Feb 14, 2026

Click a member row — the owner sees a "Remove from vault" action on anyone but themself.

Only the owner can invite or remove people — the app's own first-time banner says this outright: "Everyone in your family vault can see and use these passwords together. Only you, who started the vault, can invite or remove people." A member has full read/use access to every shared item but cannot manage who else is in the vault.

Sharing and unsharing passwords

Any member — not just the owner — can add an item to the shared list, via the Add button next to "Shared passwords." Sharing an item moves it out of your personal vault into the family vault (not a copy sitting in both) — everyone in the family, including you, then sees it in the shared list instead of your personal one.

If you've just created a vault and haven't invited anyone yet, the app shows this instead of an empty list: "It's just you in here so far. Family vaults are better shared." — with a one-click Invite someone button right there.

If a device hasn't yet received this vault's decryption key — brand new install, or waiting on the first sync — it shows a calm, specific message rather than an empty vault or an error: "This vault isn't set up on this device yet. Its passwords are safe — this device just doesn't have the key to open them. Unlock [vault name] on the device you already use it on while online, and it'll appear here shortly after." Nothing is lost; this device just hasn't caught up yet.

Removing a member — what actually happens (read this before you rely on it)

This is the part of Family Vault most likely to be assumed rather than known, and getting it wrong has real consequences — so here is the removal confirmation dialog's exact text, unedited:

Remove from vault

Remove Jake Rodriguez from your family vault?

They'll lose access through the app — right away if they're online, or within a day if their device isn't. Passwords already saved on their device can stay readable there, so change any you don't want them to keep. Everything stays safe for the rest of your family.

Break that down into the three concrete facts it's telling you, because each one matters:

  1. Enforcement isn't instant for an offline device. A removed member's own app is what enforces the removal — if their device is offline, it can keep working with the vault it already has for up to a 24-hour grace window before it learns it's been revoked.
  2. The vault's encryption key is never rotated on removal. Whatever was already synced to the removed member's device before you removed them remains decryptable by that device, indefinitely — removal stops new access, it does not retroactively re-lock what already went out.
  3. The one action that actually protects a specific password is changing it. If you're removing someone specifically because you don't trust them with certain passwords anymore, removal alone is not that protection — rotating those passwords is.

None of this means removal is broken or pointless — for the ordinary case (a family member moving out, no longer needing shared access, nothing adversarial) it does exactly what you'd expect. It matters specifically for the harder case: removing someone you no longer trust, where "did this actually lock them out" is the question you're really asking. In that case, the honest answer is: mostly, eventually, and change anything sensitive yourself regardless.

Family vault FAQ

How many members can a family vault have?

Up to 5 members, per the Family plan's published limit (see Pricing). If you're at the cap, inviting someone new fails with "Your family vault is full" until you free a spot.

I sent an invite and nothing happened — did it work?

A successful invite shows a green confirmation toast and adds a "pending" row to your outbound invitations, which the owner can see, cancel, or resend from the same screen. If you saw neither a toast nor an error, check the pending-invitations list before resending — a resend that half-fails is explicitly surfaced as its own error rather than silently leaving a stale row, so trust what the screen says over an assumption.

Can a member remove themselves, or invite others?

No to both — only the owner can invite or remove anyone, including the option to leave. If a member wants out, ask the owner to remove them.

What happens to shared passwords if I cancel my Family plan?

Everyone keeps seeing what's already shared — the app's own copy is explicit: "Everyone can still see your saved passwords — adding new ones is paused until you renew." Renewing lifts the pause; nothing is deleted while it's lapsed.

I got the "encryption key has changed" warning when inviting someone I trust. Is my vault compromised?

Almost always no — this fires whenever the invitee's published key differs from what your device last saw for them, and the overwhelmingly common cause is a normal account reset or reinstall on their end. Confirm with them by voice or in person using the security-code comparison shown in the dialog (see above) before proceeding either way.

Still stuck?

Email support@walilock.com with what you were trying to do and what you saw instead — screenshots help.

Sharing

Business & admin console Business / Enterprise

Business tenants have two distinct surfaces, and they're kept deliberately separate.

The Business panel — every member

Where an ordinary member reaches the shared credentials and collections they've been granted access to. It's a viewing and using surface, not a management one.

The admin console — admins only

Everything that changes who can access what lives here and only here: inviting and removing members, assigning roles, seat management, creating or deleting collections, granting keys, IP allowlisting, activity/audit logs, and — for Enterprise — SSO configuration. If you're a member looking for admin actions and don't see them in your panel, that's by design; ask your tenant's admin.

Browser extension

Installing the extension (Chrome & Edge)

Walilock comes in two parts. The app on your computer holds your passwords. The add-on in your browser fills them into websites. The add-on never keeps its own copy of anything — it asks the app each time, and the app only answers once you have unlocked it. That is why the app has to be installed first: otherwise there is nothing for the add-on to ask.

Setting it up, step by step

  1. Install the desktop app first. Get it from the Download page and run the installer. Open it once and set up your vault with a master password, then add a login or two — you will want something real to test with.
  2. Add Walilock to your browser. In Chrome, open the Walilock listing in the Chrome Web Store, linked from the Download page, and click Add to Chrome, then Add extension. In Edge, open the listing in Microsoft Edge Add-ons and click Get, then Add extension. Use whichever browser you actually browse in — you can add it to both, and each keeps its own connection to the app.
  3. Pin it so you can see it. Both browsers hide new add-ons behind an icon at the top right. Click the puzzle piece in Chrome, or the Extensions icon in Edge, find Walilock in the list, and click the pin beside it — in Edge it is labelled Show in toolbar. The Walilock icon then stays in your toolbar, which is how you check the connection and unlock.
  4. Unlock, and check they are talking. Click the Walilock icon and enter your master password — the same one you set in the app. It should say Connected & Unlocked and show your saved items.
  5. Try it on a real login. Go to a site you saved a password for and click into the username or password box. Walilock offers the matching login; click it and both fields fill in. When you sign in somewhere new, Walilock offers to save it, so your vault fills up as you go rather than all at once.

About the permission warning. Your browser will say Walilock can "read and change your data on all websites". That is how every password manager works: to offer your login on a site, the add-on has to be able to see that you are on a sign-in page. Chrome and Edge show the same warning for every extension of this kind. Walilock reads pages to spot sign-in boxes — it does not send your browsing anywhere.

If it will not accept your master password, read this before assuming you typed it wrong. When the add-on cannot reach the app, it still shows a normal-looking password box and only complains after you type something — so a connection problem looks exactly like a wrong password. Close the browser completely, every window, then open it again and try once more. Chrome and Edge only look for the app when they start up.

Chrome and Edge each assign the extension its own store identity, and native messaging is scoped to that identity per browser. This is normal browser behaviour, not a Walilock quirk — installing from each store's official listing handles it automatically.

Browser extension

Using the extension

Click the Walilock icon in your toolbar to open the popup — search your vault, copy a value, or open a login directly from there. On a page with a recognized login form, Walilock offers to fill it; on a page that supports passkeys, it can offer your saved passkey the same way your OS's built-in prompt would.

Browser extension

Troubleshooting the extension

"Walilock was updated or reloaded. Reload this page and try again."

Normal after the extension updates itself, or after you manually reload it — any tab that was already open loses its connection to the new copy. Reload that tab and it reconnects.

Autofill isn't offering to fill a login

Confirm the desktop app is open and unlocked — the extension has no vault of its own to fall back to. If it was open, try unlocking it again; a locked vault can't be searched for a match.

wali — the command line

Install & initialize

wali is Walilock's CLI — built for scripts, CI, and AI-agent workflows that need a secret without ever writing it to disk, shell history, or the process list another user on the machine can read.

The desktop installer adds wali to your PATH automatically. If a step failed, or you copied the binary by hand, run it yourself:

wali path add

Create a vault (or point at your desktop app's existing one — the CLI reads the same vault file by default):

wali init

--vault-path works on every command to point at a specific vault file. Left unset, the CLI uses the desktop app's active account.

wali — the command line

Everyday commands

Every secret is addressed the same way everywhere in the CLI: category/item/field.

wali list                                    # everything in the vault
wali add --name "AWS Master" --category login
wali get <item-id>                           # full decrypted item
wali read login/prod-db/password             # one value, to stdout only
wali edit login/prod-db/password             # prompts for the new value
wali rm "GitHub"                             # recoverable
wali rm "GitHub" --permanent                 # not recoverable
wali restore "GitHub"                        # undo the soft delete
wali generate --length 24 --exclude-ambiguous

wali edit prompts for the new value by default rather than taking it as an argument — a secret typed on the command line lands in shell history and is visible to every other user's ps on the machine, which is exactly what the CLI exists to avoid. Pass the value explicitly only from a script that has already solved that problem, or pipe it in with --stdin.

wali read is built for command substitution — it writes nothing but the raw value to stdout, with every prompt and warning going to stderr instead, so the captured value is never polluted:

export DB_PASS=$(wali read login/prod-db/password)
wali — the command line

Injecting secrets: run, inject & broker

wali run — secrets as environment variables

Runs a child process with secrets injected into its environment — nothing touches shell history or a file on disk.

wali run --env STAGING_DB_PASSWORD=login/aws-master/password -- ./deploy.sh

wali inject — rendering a template file

For tools that insist on a real file, not an environment variable. References use {{ wali://category/item/field }} — braces are required because item names can contain spaces.

wali inject --file .env.tpl > .env

Redirecting inject to a file writes real plaintext secrets to disk — the exact thing run exists to avoid. Prefer run wherever the target program can take environment variables.

wali broker — for when even the environment is too much

run puts the secret in the child's environment, where anything running as that child — including an AI agent — can read it back. broker doesn't: the child gets a local loopback URL instead, requests arrive with no credential attached, and Walilock attaches one on the way out, only to the single upstream a signed manifest allows.

wali broker --name openai -- python train.py
# child process receives: AEGIS_BROKER_OPENAI=http://127.0.0.1:PORT
wali — the command line

Machine tokens

A token is a scoped, revocable credential for non-interactive access — CI pipelines, servers, scheduled jobs — that can only ever reach the specific paths it was minted for. Unlike your master password, a leaked token costs exactly those secrets and nothing else, and it can be revoked without touching anything else.

wali token mint --name "ci-deploy" --path login/prod-db/password --expires-in-days 30
wali token list
wali token revoke <token-id>
wali token refresh    # re-reads current values into every existing token

A token's values are a snapshot from mint time — rotating the underlying secret leaves issued tokens serving the old value until you run wali token refresh.

wali — the command line

Project manifests

A manifest constrains what can be pulled from the vault while working inside a project directory — the guardrail that keeps an AI coding agent steered by a prompt injection from reaching secrets the project doesn't need.

wali manifest sign      # requires the vault unlocked — that's the point
wali manifest verify    # checks the signature, no master password needed
wali manifest unregister

Signing requires the vault to be unlocked because the signing key is itself wrapped under the vault key — an agent running as you cannot produce a valid signature, so it cannot widen its own access by editing the manifest. Enforcement fails closed: once a project is registered, a missing or invalid manifest is refused rather than silently ignored, which is why unregister exists as an explicit, deliberate way out.

wali — the command line

Full command reference

CommandDoes
wali initCreate a new vault with a master password.
wali unlockOpen an interactive Walilock shell.
wali list [--deleted]Show every item, or everything soft-deleted.
wali get <id> [--show-full]Show one item's full decrypted content.
wali add --name <n> --category <c>Add an item interactively.
wali edit <path> [value] [--stdin]Change one field. Prompts if value is omitted.
wali rm <item> [--permanent] [-y]Delete (recoverable, unless --permanent).
wali restore <item>Undo a soft delete.
wali generate [flags]Generate a strong random password.
wali read <path> [-n]Print one value to stdout, nothing else.
wali inject [--file <f>]Render a template, replacing secret references.
wali run --env <VAR=path> -- <cmd>Run a command with secrets as env vars.
wali broker --name <n> -- <cmd>Run a command against a local credential-issuing proxy.
wali manifest sign|verify|unregisterManage this project's signed access manifest.
wali token mint|list|revoke|refreshManage scoped machine tokens.
wali path add|removeAdd/remove this binary from your PATH.
wali log [--verify] [--tail N]Show the access ledger — who read what, when. Never secret values.

Every command supports --help for its full flag list, and every subcommand's help text is written to be read, not just glanced at — wali edit --help, for instance, explains the shell-history reasoning above in full.

Account

Web account & billing

Sign in at walilock.com/login to reach your account portal — it manages your plan and billing, and nothing else. It cannot see your vault, your passwords, your notes, your files, your sign-in password, or your master password; your sign-in password is proven with OPAQUE and never transmitted, and your vault and master password never leave your own devices.

Changing your plan

From your account page, Change plan lets you move between tiers without leaving your session or re-entering your email — the account you're changing is the one you're already signed into. Already on a paid plan? Changing plan or cancelling routes to Stripe's billing portal, the one place a change prorates correctly.

After a purchase

Right after checkout you'll see an activation code — it's also emailed to you and kept on your account page afterward as a record, even though it's already been used to activate your plan automatically.

Account

Supported platforms

One vault, wherever you use it:

Windows
Desktop app
macOS
Desktop app
Android
Mobile app
iOS
Mobile app
Chrome
Browser extension
Edge
Browser extension
CLI
Windows / macOS / Linux

See Download for the current release on each platform.

Account

FAQ & troubleshooting

I forgot my sign-in password. Can I get back in?

Yes — it's recoverable by email from the login page. This resets the credential you use to sign in; it has no effect on your master password or your vault's contents.

I forgot my master password. Can I get back in?

Only if this device — or another device signed into the same vault — is already unlocked, or you have working biometric unlock available right now. Your emergency kit does not help here: it restores your vault onto a new device using a master password you still remember, it cannot substitute for a forgotten one. If neither of those applies, that vault's contents genuinely can't be recovered — see why, and see Password Help for the exact panel the app shows you.

What does the "Forgot master password?" link on the unlock screen actually do?

It opens a panel that asks which problem you actually have — a forgotten sign-in password (recoverable by email) or a forgotten master password (not recoverable, by design). Choosing the master-password path never offers a reset, because none exists; instead, if biometric unlock is available on this device, it tells you to use it now and export a backup immediately, before that window closes too. See the full reproduction in Password Help.

Why does the CLI need me to unlock the desktop app / set a vault path?

The CLI reads the same encrypted vault the desktop app uses. By default it looks for the vault tied to your active desktop account; use --vault-path to point it at a different file.

Can I use Walilock without ever creating an account?

Yes — the free tier is a genuine local-only vault with no account, no email, and nothing ever sent anywhere. Multi-device sync and the paid features do require an account, since syncing needs somewhere to sync to.

Something here doesn't match what I'm seeing

This guide is written from the app's own source, not from memory — but software changes. If a screen looks different from what's shown here, tell us at support@walilock.com and we'll fix the guide or the app, whichever is wrong.

How do I reach support for anything not covered here?

Every contact path on this site reaches the same place: email support@walilock.com directly, or use the contact form — it now genuinely delivers to that address rather than only showing a confirmation.