The Walilock user guide
Everything for using Walilock day to day: the desktop app, the browser extension for Chrome and Edge, the wali command-line tool, passkeys, family and business vaults, and your web account.
New here? Start with Getting started — it covers the one decision that matters most before you type a single password in.
Getting started
Walilock is local-first: your vault lives on your device, encrypted, and it works fully offline. An account only exists to sync that encrypted vault between your devices and to unlock paid features — it never lets Walilock read what's inside.
The first screen you'll see
On a brand-new install, the app asks you to choose one of three paths:
- Activate a plan code — you already paid on the website and have an activation code from your email or the checkout page.
- Sign in — you have a Walilock account already, registered on another device or on the website, and you're adding this device to it.
- Start free — a new, local-only vault with no account at all.
If the app already has an account on this device, you won't see this screen — you'll go straight to unlock.
Starting free — no account required
Free is a real, complete local vault: unlimited use, ten vault items, no credit card, no email, nothing synced anywhere. You set a master password and you're in. Upgrade later from inside the app whenever you want sync, unlimited items, or the AI features — nothing about your existing items changes when you do.
Adding a second device to an existing account
There's no "add device" action to run on a new device by itself — you sign in to it, the same way you'd sign in anywhere. On the new device's first-run screen, choose Sign in and enter your account email and sign-in password. Already have Walilock running on this machine under a different account? Use the account switcher on the unlock screen, then Add account → Sign in to an existing account. Either path logs in for real and pulls down your vault key — your data starts syncing immediately, nothing gets overwritten.
Account password vs. master password — the one thing to get right
Walilock deliberately uses two different passwords for two different jobs. Confusing them is the single most common support question, so read this once before you set either.
- Sign-in password (account password)
- What you type to log in on the web or a new device. It's proven with a protocol called OPAQUE, which means Walilock's servers verify you know it without the password ever being sent to them — but if you forget it, it's recoverable by email, the same as most accounts you use online.
- Master password
- Set only inside the app. It unlocks your vault on this device and encrypts every secret you store. It never leaves your device, Walilock never sees it, and there is no "forgot master password" flow that gets your data back — because the whole point is that nobody but you can decrypt it, including us.
There is no recovery-contact or "recover my master password" feature. If you lose it and don't have your emergency kit or a device that's already unlocked, that vault's contents are gone. This isn't a missing feature — it's what "we cannot see your data" actually means in practice.
Your emergency kit — and what it actually does
Offered as the last step of setting your master password, and available again from Settings → Security any time after. Get very clear on what it is for, because it is easy to assume it does more than it does — and that assumption is exactly what turns into a support ticket at the worst possible moment.
The emergency kit is a device-recovery tool, not a forgotten-password tool. It works together with a master password you still remember, to restore your vault onto a new device after this one is lost, stolen, or wiped. It cannot open your vault for you if the master password itself is the thing you've forgotten — nothing can, on purpose. See why.
What it's for: replacing a lost or wiped device
This is the scenario the kit solves. Your laptop is stolen, or its drive dies, or you're setting up a new machine. You still remember your master password — you just no longer have the device your vault lived on. On the new install, when Walilock asks for your vault, you supply the emergency kit's recovery code together with your master password, and your vault comes back.
What it's not for: a forgotten master password
If the master password itself is gone from your memory, the kit is powerless — it isn't a second factor that substitutes for the password, it's a companion to it. This is the exact tradeoff "we cannot see your data" requires: a recovery path that worked without the master password would be a way for Walilock (or anyone who stole the kit) to open your vault too.
Generating and storing it
- Generate the kit from Settings → Security — during initial master-password setup it's offered automatically as the final step, and you can regenerate it there any time afterward.
- Save it somewhere that isn't this device. A password manager can't be its own backup location — a fireproof safe, a bank box, or a printed copy with a trusted family member are all reasonable. Cloud storage synced automatically to the same device defeats the point.
- Treat it like a spare house key, not a password: on its own it opens nothing. Combined with your master password, it opens everything. Keep the two apart if you can — the kit in a safe, the password in your memory.
Password Help — what "Forgot master password?" actually does
The unlock screen has a link that reads "Forgot master password?" — a fair question to ask, and the panel it opens gives an honest answer rather than pretending there's a reset button. Below is the real panel, reproduced exactly, so you know before you ever need it.
Interactive — click a choice below, exactly as it works in the app.
"I can't sign in to my account"
This is the flow to use for a forgotten sign-in (account) password. It emails you a reset link, the same as any normal account. It has no effect whatsoever on your vault or your master password.
"I can't unlock my vault"
Choosing this is honest about what happens next: the app tells you plainly that the master password cannot be reset or recovered by anyone. If this device has a working biometric unlock (fingerprint or Windows Hello) enabled, the panel tells you so explicitly and gives you one genuinely useful piece of advice: close this dialog, unlock with biometrics while it still works, and export a backup from Settings → Security immediately. That window closes the moment biometric enrollment is lost too — a new device, a removed fingerprint, an OS reset — so it's worth acting on the same day you see this message, not filing it away.
If no unlock method works on this device at all, the panel says so directly: that vault's items cannot be recovered, and your options are starting a new vault or adding an account you still have access to. This is stated plainly rather than softened, because a forgotten master password with no biometric fallback and no emergency-kit-plus-remembered-password is, genuinely, unrecoverable.
First launch, step by step
Everything below reproduces the app's own screens using its own copy, its own colors, and its own decision order — read straight from the component source rather than described from memory, so what you see here is what you'll actually see. It is an interactive walkthrough, not a photograph of the app: click through it the same way you'd click through the real thing.
Screen 1 — the welcome choice
This is the very first thing a brand-new install shows you — and only a brand-new install. If this device already has an account, you'll never see it; you'll land straight on unlock instead.
Click any card — the outcome shown matches exactly what happens next in the real app.
The order is deliberate: Activate a Plan Code is listed first and visually primary because most first launches are a customer who just paid. Sign In exists specifically because, before it was added, a returning user reinstalling the app had no way back to their existing account from this screen at all — they could only ever create a fresh one. Start Free needs nothing from you but a master password.
Adding a second device the correct way
There's no separate "enroll this device" step to run from the new device, and that's intentional — signing in already does everything required. Two doors lead to the same real login:
- A brand-new install — the welcome screen's Sign In card, shown above.
- This machine already runs Walilock under a different account — the account switcher on the unlock screen, then Add account → Sign in to an existing account.
Both run a real OPAQUE login against your account and then pull down your actual vault key — not a placeholder, not a re-registration. Your data begins syncing immediately and nothing on either device is overwritten. (An earlier version of this exact screen did something different and dangerous — it ran a raw account registration against whatever was typed in, silently overwriting the real account's password if you made a typo. That path no longer exists; sign-in is the only way in now, for exactly this reason.)
Setting your master password
Whichever welcome path you chose — Start Free, a fresh plan-code activation, or the very first account setup — you'll reach this screen exactly once per device. It is the single most consequential thing you'll type into Walilock, so the app is deliberately blunt about the stakes before it lets you proceed.
Interactive — the checkbox really does gate the button, exactly like the real screen.
Why the consent checkbox exists
This is the same warning box and the same checkbox text used at signup on walilock.com — Walilock deliberately says the identical thing whether you set this up in the app or the account team hears about it on the web, so there's exactly one honest story about what this password does. The Continue button stays disabled until you check the box. That's not friction for its own sake — the app would rather you close this window and think about it than click through a sentence you didn't read.
Why the Emergency Kit step is separate, not optional-and-skippable
It's presented as its own full screen, right after the password is set, while the stakes are freshest in your mind. See Your emergency kit above for exactly what it does and doesn't recover — the short version repeated here because it matters: it restores your vault onto a new device using a master password you still remember, it does not recover a master password you've forgotten.
Unlocking the app
Every launch after the first drops you here. It's deliberately the smallest screen in the app.
The biometric button only appears if you've enabled it — and its label matches your OS ("Use Windows Hello", "Use Touch ID", "Use fingerprint").
The account switcher
Running more than one Walilock account on this machine? A switcher lives on this screen too, letting you move between accounts without signing out — each is fully isolated from the others, with its own vault, its own key, its own master password.
"Forgot master password?"
Clicking it opens the exact Password Help panel documented above — jump to it if you haven't read that part yet. The short version: it never resets your master password, because nothing can. What it does do is get you to the biometric-unlock-and-export escape hatch before you accidentally spend a reset that wouldn't have helped anyway.
Guided tour: every section of the app
Once unlocked, everything in Walilock is reachable from one sidebar. Below is the real navigation, in its real order, with its real labels and tooltips — click any item to see what it does.
Click through the sidebar exactly as you would in the app — every section's real tooltip appears below it.
Vault
All Items browses your entire vault, unfiltered. Vault Chat opens the AI assistant (Personal+ and above) — see AI features.
Categories
This group only appears once you actually have items in a given category — Logins, Secure Notes, Credit Cards, Identities, API Credentials each get their own entry, with a live count badge, the moment the first item of that type exists. An empty vault shows no Categories group at all; it isn't hidden, there's simply nothing to list yet.
Passkeys
Four entries: My Passkeys (view and manage), Import Passkeys (from a CXF file), Export Passkeys (to a CXF file), and Device Transfer — the paired-device flow with the 6-digit confirmation code described in Passkeys below.
Security
AI Security Audit, Phishing Scan, and Breach Monitor are all Personal+ and above and locked with an upgrade prompt below that tier. Password Policy lets you configure organization-wide password strength requirements. Generator is the standalone password generator, always available on every tier.
Data
Import and Export — see Import & export.
Sharing
Family Vault — the entire next section of this guide is devoted to it. Add Device is not an action at all; it's a guide screen explaining that adding a device happens by signing in on that device (see Adding a second device above) — this entry exists so people looking for "add device" find the explanation rather than a dead end.
Company Business tenants only
Company Vault — the shared credentials your business has granted you. Only visible if your account belongs to a business tenant; see Business & admin console.
Admin Admins only
Admin Console — seats, vault, and audit logs. Only visible to accounts with the admin role on a business or enterprise tenant.
The vault
Everything you store lives in one encrypted vault, organized by category.
Item types
- Login — username, password, URL, and notes.
- Secure note — free-form encrypted text.
- Credit card — card number, expiry, CVV, billing details.
- Identity — reusable name/address/contact info for filling forms.
- API credential — the developer-oriented item type the CLI reads by category/item/field, e.g. an OpenAI key.
Adding, editing, deleting
Add an item from the vault list; every field is encrypted before it's written to disk. Deleting an item is recoverable by default — it moves to a "recently deleted" state you can restore from, the same pattern the CLI's wali rm / wali restore use. Free accounts are capped at 10 items; every paid tier is unlimited.
Password generator
Available from the toolbar and inline whenever you're filling a password field. Configure length and character classes (uppercase, lowercase, digits, symbols) and optionally exclude ambiguous characters like Il1 or 0O. The same generator logic backs wali generate on the command line, so a password generated one way behaves identically to one generated the other.
Import & export
Reachable from the vault's import/export panel.
Importing
Bring items in from another password manager's export file. Review what will be imported before it's committed to your vault — nothing is written silently.
Exporting
Export your vault for backup or migration. An export file is unencrypted by nature — it exists specifically so another tool can read it — so treat it like the plaintext secrets it contains: delete it once you've used it, and never store it somewhere synced or shared.
Two-factor codes (TOTP)
Store a site's TOTP secret alongside its login and Walilock generates the rotating 6-digit code for you, the same way an authenticator app does — one less app to keep unlocked.
Adding a TOTP secret
Two ways in, side by side — typing stays a first-class option because plenty of sites only ever show you the raw base32 key:
- Type it manually — paste or type the base32 secret a site gives you.
- Scan the QR code — on Android, this opens your camera live, since holding the phone up to your desktop screen is the natural motion. On desktop, it defaults to importing an image (a saved screenshot, or drag-and-drop) rather than a webcam, since the QR is already on the screen you're using. Either platform can reach the other method if you need it.
Passkeys
Walilock can create, store, and use passkeys — the passwordless sign-in standard built on public-key cryptography — right alongside your regular logins, in the same vault, under the same master password.
Using a passkey
When a site asks for a passkey, Walilock offers the matching one from your vault. Manage everything you've created from the passkey section: see which site each one belongs to, when it was created, and remove ones you no longer need.
Moving passkeys to a new device
Transferring a passkey between two Walilock installs uses a paired device flow with a real safety check: after the two devices connect, you're shown a 6-digit code on both and asked to confirm they match before anything transfers. This isn't a formality — the transfer is refused unless you confirm, and if the codes don't match, the session is abandoned outright rather than offered a retry, because a mismatch means the device on the other end isn't the one you intended to pair with.
Importing and exporting with other password managers
Walilock supports the industry Credential Exchange Format for moving passkeys to and from other compatible password managers, for the cases where a paired-device transfer isn't the right fit — for example, a one-time migration off another product.
Business and Enterprise admins can additionally set an org-wide passkey policy from the admin console, governing whether members are required, permitted, or blocked from creating them.
AI features Personal+ and above
Three AI-assisted tools, all reading your already-decrypted, in-memory vault locally rather than sending it anywhere:
Vault assistant
A chat interface for asking questions about your own vault — "what's my WiFi password", "which logins reuse this password" — and getting an answer with the specific item cited as its source, streamed as it's generated.
Security audit
Scans your stored items for reused, weak, or aging passwords and gives you a prioritized list of what to change first.
Phishing scanner
Checks a page or link against patterns associated with credential-phishing attempts before you type a password into it.
Breach monitor
Flags vault items whose email or password has shown up in a known data breach, so you know what to rotate.
Sync & devices Personal+ and above
On a paid plan, every change encrypts locally first, then syncs as ciphertext — the relay servers move encrypted blobs between your devices and never hold a key that could open them. A sync status indicator in the app shows you're current; if you're offline, changes queue and catch up the moment you're back online.
Free accounts are local-only by design — nothing about a free vault ever leaves the device it's on, which is also why free has no multi-device sync.
Family vault — the complete guide Family
One shared vault, owned by whoever created it, with other family members invited in to see and use what's shared there. Everyone keeps their own personal vault entirely separate — the family vault is an addition sitting alongside it, never a replacement. This is the single most-requested-for-detail feature in this guide, so it gets the longest section: every screen, every button, every error message you might see, reproduced from the app's own source rather than summarized.
Creating your family vault
Only the account holding an active Family plan sees this option, and only until a vault exists — after that, the same sidebar entry opens the vault instead. Creation is two short steps.
Interactive — type a name, click Create, and the real step 2 appears.
Step 2's "Skip for now" is a genuine skip, not a soft nag — your vault exists the moment step 1 finishes, whether or not you invite anyone that same minute. You land straight in the vault either way, ready to add your first shared password.
Inviting members — and every message you might see
Invites are sent by email, and the person you invite needs a Walilock account — free is enough — to accept one. Below is the real invite dialog, plus every error message the app can show for it, written verbatim from the source rather than paraphrased, because the exact wording is what you'll actually see and search for if something goes sideways.
They'll need a free Walilock account to join.
| What you'll see | What it means |
|---|---|
| "…is already in your family vault." | Nothing to do — they're already a member. |
| "…already has a pending invite — they just need to accept it." | You already invited them; no need to resend unless it's been a while (see FAQ). |
| "Your family vault is full. You'd need to remove someone first." | You've hit the plan's member cap. |
| "Your family plan has ended. Renew to add new people." | The plan lapsed — existing members keep access, but no new invites until you renew. |
| "They need to open Walilock and sign in once before you can add them." | Their account exists but has never published an encryption key from this app — normal for a brand-new signup that hasn't opened the app yet. Resolves itself the moment they sign in once; try the invite again after. |
| "We couldn't find an Walilock account for that email. Ask them to sign up first." | No account at all exists for that address yet. |
| "You've sent a lot of invites recently. Try again a bit later." | Rate-limited — the relay caps invites per vault per day. Not an error with the invite itself, just a pause. |
The security-code check — a real safety mechanism, not a glitch
Occasionally an invite triggers a very different screen instead of the usual confirmation. If you ever see this, read it — it exists specifically to stop a real attack.
This usually means they reset or reinstalled their account. It can also mean someone is trying to intercept what you share — so check with them before continuing.
Ask alex@example.com to open Settings → Security on their device and read out "My Security Code." It should match the one below — confirm it over a call or in person, not over chat.
This fires when the key on file for the person you're inviting doesn't match what this device last trusted for them — almost always because they reset or reinstalled their account, which is completely ordinary. It is treated as a security event rather than waved through, because the other explanation is someone intercepting the invite. Nothing is sent while this is showing. Call or message the person some other way, have them read their Security Code out loud from their own Settings → Security, compare it to what's shown here, and only click "Codes match" once you've actually verified it — not just because the screen is annoying and you want it gone.
The member roster and roles
Family vault has exactly two roles — owner and member — nothing more granular. The owner is whoever created the vault; everyone else who accepts an invite is a member.
Click a member row — the owner sees a "Remove from vault" action on anyone but themself.
Only the owner can invite or remove people — the app's own first-time banner says this outright: "Everyone in your family vault can see and use these passwords together. Only you, who started the vault, can invite or remove people." A member has full read/use access to every shared item but cannot manage who else is in the vault.
Removing a member — what actually happens (read this before you rely on it)
This is the part of Family Vault most likely to be assumed rather than known, and getting it wrong has real consequences — so here is the removal confirmation dialog's exact text, unedited:
Remove Jake Rodriguez from your family vault?
They'll lose access through the app — right away if they're online, or within a day if their device isn't. Passwords already saved on their device can stay readable there, so change any you don't want them to keep. Everything stays safe for the rest of your family.
Break that down into the three concrete facts it's telling you, because each one matters:
- Enforcement isn't instant for an offline device. A removed member's own app is what enforces the removal — if their device is offline, it can keep working with the vault it already has for up to a 24-hour grace window before it learns it's been revoked.
- The vault's encryption key is never rotated on removal. Whatever was already synced to the removed member's device before you removed them remains decryptable by that device, indefinitely — removal stops new access, it does not retroactively re-lock what already went out.
- The one action that actually protects a specific password is changing it. If you're removing someone specifically because you don't trust them with certain passwords anymore, removal alone is not that protection — rotating those passwords is.
None of this means removal is broken or pointless — for the ordinary case (a family member moving out, no longer needing shared access, nothing adversarial) it does exactly what you'd expect. It matters specifically for the harder case: removing someone you no longer trust, where "did this actually lock them out" is the question you're really asking. In that case, the honest answer is: mostly, eventually, and change anything sensitive yourself regardless.
Family vault FAQ
How many members can a family vault have?
Up to 5 members, per the Family plan's published limit (see Pricing). If you're at the cap, inviting someone new fails with "Your family vault is full" until you free a spot.
I sent an invite and nothing happened — did it work?
A successful invite shows a green confirmation toast and adds a "pending" row to your outbound invitations, which the owner can see, cancel, or resend from the same screen. If you saw neither a toast nor an error, check the pending-invitations list before resending — a resend that half-fails is explicitly surfaced as its own error rather than silently leaving a stale row, so trust what the screen says over an assumption.
Can a member remove themselves, or invite others?
No to both — only the owner can invite or remove anyone, including the option to leave. If a member wants out, ask the owner to remove them.
What happens to shared passwords if I cancel my Family plan?
Everyone keeps seeing what's already shared — the app's own copy is explicit: "Everyone can still see your saved passwords — adding new ones is paused until you renew." Renewing lifts the pause; nothing is deleted while it's lapsed.
I got the "encryption key has changed" warning when inviting someone I trust. Is my vault compromised?
Almost always no — this fires whenever the invitee's published key differs from what your device last saw for them, and the overwhelmingly common cause is a normal account reset or reinstall on their end. Confirm with them by voice or in person using the security-code comparison shown in the dialog (see above) before proceeding either way.
Still stuck?
Email support@walilock.com with what you were trying to do and what you saw instead — screenshots help.
Business & admin console Business / Enterprise
Business tenants have two distinct surfaces, and they're kept deliberately separate.
The Business panel — every member
Where an ordinary member reaches the shared credentials and collections they've been granted access to. It's a viewing and using surface, not a management one.
The admin console — admins only
Everything that changes who can access what lives here and only here: inviting and removing members, assigning roles, seat management, creating or deleting collections, granting keys, IP allowlisting, activity/audit logs, and — for Enterprise — SSO configuration. If you're a member looking for admin actions and don't see them in your panel, that's by design; ask your tenant's admin.
Installing the extension (Chrome & Edge)
Walilock comes in two parts. The app on your computer holds your passwords. The add-on in your browser fills them into websites. The add-on never keeps its own copy of anything — it asks the app each time, and the app only answers once you have unlocked it. That is why the app has to be installed first: otherwise there is nothing for the add-on to ask.
Setting it up, step by step
- Install the desktop app first. Get it from the Download page and run the installer. Open it once and set up your vault with a master password, then add a login or two — you will want something real to test with.
- Add Walilock to your browser. In Chrome, open the Walilock listing in the Chrome Web Store, linked from the Download page, and click Add to Chrome, then Add extension. In Edge, open the listing in Microsoft Edge Add-ons and click Get, then Add extension. Use whichever browser you actually browse in — you can add it to both, and each keeps its own connection to the app.
- Pin it so you can see it. Both browsers hide new add-ons behind an icon at the top right. Click the puzzle piece in Chrome, or the Extensions icon in Edge, find Walilock in the list, and click the pin beside it — in Edge it is labelled Show in toolbar. The Walilock icon then stays in your toolbar, which is how you check the connection and unlock.
- Unlock, and check they are talking. Click the Walilock icon and enter your master password — the same one you set in the app. It should say Connected & Unlocked and show your saved items.
- Try it on a real login. Go to a site you saved a password for and click into the username or password box. Walilock offers the matching login; click it and both fields fill in. When you sign in somewhere new, Walilock offers to save it, so your vault fills up as you go rather than all at once.
About the permission warning. Your browser will say Walilock can "read and change your data on all websites". That is how every password manager works: to offer your login on a site, the add-on has to be able to see that you are on a sign-in page. Chrome and Edge show the same warning for every extension of this kind. Walilock reads pages to spot sign-in boxes — it does not send your browsing anywhere.
If it will not accept your master password, read this before assuming you typed it wrong. When the add-on cannot reach the app, it still shows a normal-looking password box and only complains after you type something — so a connection problem looks exactly like a wrong password. Close the browser completely, every window, then open it again and try once more. Chrome and Edge only look for the app when they start up.
Chrome and Edge each assign the extension its own store identity, and native messaging is scoped to that identity per browser. This is normal browser behaviour, not a Walilock quirk — installing from each store's official listing handles it automatically.
Using the extension
Click the Walilock icon in your toolbar to open the popup — search your vault, copy a value, or open a login directly from there. On a page with a recognized login form, Walilock offers to fill it; on a page that supports passkeys, it can offer your saved passkey the same way your OS's built-in prompt would.
Troubleshooting the extension
"Walilock was updated or reloaded. Reload this page and try again."
Normal after the extension updates itself, or after you manually reload it — any tab that was already open loses its connection to the new copy. Reload that tab and it reconnects.
Autofill isn't offering to fill a login
Confirm the desktop app is open and unlocked — the extension has no vault of its own to fall back to. If it was open, try unlocking it again; a locked vault can't be searched for a match.
Install & initialize
wali is Walilock's CLI — built for scripts, CI, and AI-agent workflows that need a secret without ever writing it to disk, shell history, or the process list another user on the machine can read.
The desktop installer adds wali to your PATH automatically. If a step failed, or you copied the binary by hand, run it yourself:
wali path add
Create a vault (or point at your desktop app's existing one — the CLI reads the same vault file by default):
wali init
--vault-path works on every command to point at a specific vault file. Left unset, the CLI uses the desktop app's active account.
Everyday commands
Every secret is addressed the same way everywhere in the CLI: category/item/field.
wali list # everything in the vault
wali add --name "AWS Master" --category login
wali get <item-id> # full decrypted item
wali read login/prod-db/password # one value, to stdout only
wali edit login/prod-db/password # prompts for the new value
wali rm "GitHub" # recoverable
wali rm "GitHub" --permanent # not recoverable
wali restore "GitHub" # undo the soft delete
wali generate --length 24 --exclude-ambiguous
wali edit prompts for the new value by default rather than taking it as an argument — a secret typed on the command line lands in shell history and is visible to every other user's ps on the machine, which is exactly what the CLI exists to avoid. Pass the value explicitly only from a script that has already solved that problem, or pipe it in with --stdin.
wali read is built for command substitution — it writes nothing but the raw value to stdout, with every prompt and warning going to stderr instead, so the captured value is never polluted:
export DB_PASS=$(wali read login/prod-db/password)
Injecting secrets: run, inject & broker
wali run — secrets as environment variables
Runs a child process with secrets injected into its environment — nothing touches shell history or a file on disk.
wali run --env STAGING_DB_PASSWORD=login/aws-master/password -- ./deploy.sh
wali inject — rendering a template file
For tools that insist on a real file, not an environment variable. References use {{ wali://category/item/field }} — braces are required because item names can contain spaces.
wali inject --file .env.tpl > .env
Redirecting inject to a file writes real plaintext secrets to disk — the exact thing run exists to avoid. Prefer run wherever the target program can take environment variables.
wali broker — for when even the environment is too much
run puts the secret in the child's environment, where anything running as that child — including an AI agent — can read it back. broker doesn't: the child gets a local loopback URL instead, requests arrive with no credential attached, and Walilock attaches one on the way out, only to the single upstream a signed manifest allows.
wali broker --name openai -- python train.py
# child process receives: AEGIS_BROKER_OPENAI=http://127.0.0.1:PORT
Machine tokens
A token is a scoped, revocable credential for non-interactive access — CI pipelines, servers, scheduled jobs — that can only ever reach the specific paths it was minted for. Unlike your master password, a leaked token costs exactly those secrets and nothing else, and it can be revoked without touching anything else.
wali token mint --name "ci-deploy" --path login/prod-db/password --expires-in-days 30
wali token list
wali token revoke <token-id>
wali token refresh # re-reads current values into every existing token
A token's values are a snapshot from mint time — rotating the underlying secret leaves issued tokens serving the old value until you run wali token refresh.
Project manifests
A manifest constrains what can be pulled from the vault while working inside a project directory — the guardrail that keeps an AI coding agent steered by a prompt injection from reaching secrets the project doesn't need.
wali manifest sign # requires the vault unlocked — that's the point
wali manifest verify # checks the signature, no master password needed
wali manifest unregister
Signing requires the vault to be unlocked because the signing key is itself wrapped under the vault key — an agent running as you cannot produce a valid signature, so it cannot widen its own access by editing the manifest. Enforcement fails closed: once a project is registered, a missing or invalid manifest is refused rather than silently ignored, which is why unregister exists as an explicit, deliberate way out.
Full command reference
| Command | Does |
|---|---|
wali init | Create a new vault with a master password. |
wali unlock | Open an interactive Walilock shell. |
wali list [--deleted] | Show every item, or everything soft-deleted. |
wali get <id> [--show-full] | Show one item's full decrypted content. |
wali add --name <n> --category <c> | Add an item interactively. |
wali edit <path> [value] [--stdin] | Change one field. Prompts if value is omitted. |
wali rm <item> [--permanent] [-y] | Delete (recoverable, unless --permanent). |
wali restore <item> | Undo a soft delete. |
wali generate [flags] | Generate a strong random password. |
wali read <path> [-n] | Print one value to stdout, nothing else. |
wali inject [--file <f>] | Render a template, replacing secret references. |
wali run --env <VAR=path> -- <cmd> | Run a command with secrets as env vars. |
wali broker --name <n> -- <cmd> | Run a command against a local credential-issuing proxy. |
wali manifest sign|verify|unregister | Manage this project's signed access manifest. |
wali token mint|list|revoke|refresh | Manage scoped machine tokens. |
wali path add|remove | Add/remove this binary from your PATH. |
wali log [--verify] [--tail N] | Show the access ledger — who read what, when. Never secret values. |
Every command supports --help for its full flag list, and every subcommand's help text is written to be read, not just glanced at — wali edit --help, for instance, explains the shell-history reasoning above in full.
Web account & billing
Sign in at walilock.com/login to reach your account portal — it manages your plan and billing, and nothing else. It cannot see your vault, your passwords, your notes, your files, your sign-in password, or your master password; your sign-in password is proven with OPAQUE and never transmitted, and your vault and master password never leave your own devices.
Changing your plan
From your account page, Change plan lets you move between tiers without leaving your session or re-entering your email — the account you're changing is the one you're already signed into. Already on a paid plan? Changing plan or cancelling routes to Stripe's billing portal, the one place a change prorates correctly.
After a purchase
Right after checkout you'll see an activation code — it's also emailed to you and kept on your account page afterward as a record, even though it's already been used to activate your plan automatically.
Supported platforms
One vault, wherever you use it:
See Download for the current release on each platform.
FAQ & troubleshooting
I forgot my sign-in password. Can I get back in?
Yes — it's recoverable by email from the login page. This resets the credential you use to sign in; it has no effect on your master password or your vault's contents.
I forgot my master password. Can I get back in?
Only if this device — or another device signed into the same vault — is already unlocked, or you have working biometric unlock available right now. Your emergency kit does not help here: it restores your vault onto a new device using a master password you still remember, it cannot substitute for a forgotten one. If neither of those applies, that vault's contents genuinely can't be recovered — see why, and see Password Help for the exact panel the app shows you.
What does the "Forgot master password?" link on the unlock screen actually do?
It opens a panel that asks which problem you actually have — a forgotten sign-in password (recoverable by email) or a forgotten master password (not recoverable, by design). Choosing the master-password path never offers a reset, because none exists; instead, if biometric unlock is available on this device, it tells you to use it now and export a backup immediately, before that window closes too. See the full reproduction in Password Help.
Why does the CLI need me to unlock the desktop app / set a vault path?
The CLI reads the same encrypted vault the desktop app uses. By default it looks for the vault tied to your active desktop account; use --vault-path to point it at a different file.
Can I use Walilock without ever creating an account?
Yes — the free tier is a genuine local-only vault with no account, no email, and nothing ever sent anywhere. Multi-device sync and the paid features do require an account, since syncing needs somewhere to sync to.
Something here doesn't match what I'm seeing
This guide is written from the app's own source, not from memory — but software changes. If a screen looks different from what's shown here, tell us at support@walilock.com and we'll fix the guide or the app, whichever is wrong.
How do I reach support for anything not covered here?
Every contact path on this site reaches the same place: email support@walilock.com directly, or use the contact form — it now genuinely delivers to that address rather than only showing a confirmation.