Help Center
Find answers to common questions and learn how to use PasswordOwl.
Getting Started
How do I create an account?
- Go to the registration page
- Enter your email address
- Choose a strong master password (at least 12 characters recommended)
- Verify your email by clicking the link we send you
- Important: Save your Secret Key securely - you'll need it to log in on new devices
What is the Secret Key and why is it important?
Your Secret Key is a 128-bit random key generated during registration. It looks like this:
A3-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXXIt serves two critical purposes:
- Extra security: Even if someone guesses your password, they can't access your vault without the Secret Key
- Server breach protection: If our servers are compromised, attackers still can't decrypt your data
Warning: If you lose either your master password OR your Secret Key, your data cannot be recovered. This is by design.
How do I save my Secret Key safely?
We recommend multiple backup methods:
- Download the Emergency Kit - A PDF you can print and store in a safe place
- Write it down - Store in a secure location (safe, safety deposit box)
- Remember this device - Check "Remember this device" to save the key locally (you'll only need your password)
How do I create my first vault?
- Log in to your account
- Click the "+ New Vault" button
- Give your vault a name (e.g., "Personal", "Work")
- Click inside the vault to add your first password
Security
What is zero-knowledge encryption?
Zero-knowledge means your data is encrypted on your device before it's sent to our servers. We never see:
- Your master password
- Your Secret Key
- Your vault names
- Your stored passwords, usernames, or notes
What encryption does PasswordOwl use?
AES-256-GCM
Military-grade encryption for all your vault data
Argon2id
Memory-hard key derivation (64MB, 3 iterations) that resists brute-force attacks
PBKDF2 Authentication
Your password is verified using PBKDF2 (100K iterations) — only a salted hash is stored
What happens if PasswordOwl gets hacked?
Even in the worst-case scenario where our servers are completely compromised, attackers would only obtain:
- Your email address
- Encrypted data that looks like random gibberish
- Cryptographic records that cannot reveal your password
Without your master password AND Secret Key, your data is computationally impossible to decrypt.
Tips for a strong master password
- Use at least 12 characters (16+ is better)
- Mix uppercase, lowercase, numbers, and symbols
- Consider a passphrase:
correct-horse-battery-staple - Never reuse your master password anywhere else
- Don't use personal information (birthdays, pet names, etc.)
Using PasswordOwl
How do I log in on a new device?
On a new device, you'll need:
- Your email address
- Your master password
- Your Secret Key
After logging in, you can check "Remember this device" so you won't need to enter the Secret Key again on that device.
Can I use PasswordOwl on multiple devices?
Yes! Your encrypted vault syncs automatically. Just log in on any device with your email, password, and Secret Key. All changes sync in real-time.
How do I generate a secure password?
When adding a new item to your vault:
- Click on the password field
- Click the "Generate" button
- Adjust length and character options if needed
- The generated password is automatically filled in
Troubleshooting
"Decryption failed" error
This error means your Secret Key doesn't match. Common causes:
- Typo in the Secret Key - double-check each character
- Missing or extra dashes
- Confusing similar characters (0 vs O, 1 vs I)
The Secret Key format is: A3-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX-XXXXXX
I forgot my master password
Due to zero-knowledge encryption, we cannot reset your password or recover your data. This is by design for your security.
If you've completely lost your master password and cannot remember it, you'll need to create a new account. Your old encrypted data cannot be recovered.
I lost my Secret Key
If you're still logged in on another device:
- Go to Settings
- Look for "View Secret Key" or export your Emergency Kit
If you're logged out everywhere and don't have a backup, you'll need the Secret Key to log in. Without it, your data cannot be decrypted.
Email verification link expired
Verification links expire after 1 hour. If yours has expired, return to the registration page and click "Resend verification email" to get a new link.
I'm not receiving verification emails
- Check your spam/junk folder
- Make sure you entered the correct email address
- Add
noreply@passwordowl.comto your contacts - Wait a few minutes - emails can sometimes be delayed
- Try requesting a new verification email
Chrome Extension
How do I install the Chrome extension?
- Visit the Chrome Web Store
- Click "Add to Chrome"
- Confirm by clicking "Add extension"
- Click the extension icon and sign in with your PasswordOwl account
How does autofill work?
The autofill feature detects login forms automatically:
- Visit any website with a login form
- Click on the username or password field
- A dropdown appears with matching credentials for that site
- Click on the credential you want to use
- Both username and password are filled automatically
Does the extension save new passwords automatically?
Yes! When you log in to a website or create a new account, the extension will detect the form submission and prompt you to save the credentials. You can choose to save them to any of your vaults.
Desktop Chrome only
The Chrome extension is available for desktop browsers only. On mobile devices, use the PasswordOwl web app to access your vault and copy credentials manually.
The extension doesn't offer autofill on some websites
If autofill doesn't appear on a specific website, try these steps:
- Make sure you're signed in to the extension (click the icon to check)
- Refresh the page after signing in
- Check that you have credentials saved for this specific domain
- Some sites use custom login forms that may not be detected - you can use the extension popup to copy and paste credentials manually
Is the extension secure?
Yes! The extension uses the same zero-knowledge encryption as the web app. Your vault key is stored securely in the browser and all decryption happens locally on your device. We never have access to your passwords.
Google Drive Storage
What is Google Drive storage?
Instead of storing your encrypted vault on our servers, you can choose to store it in your own Google Drive account. PasswordOwl uses the appDataFolder, a hidden folder that only PasswordOwl can access. Your encrypted data lives in your Google account, giving you full ownership.
How does it work?
- Go to Settings > Storage in your vault
- Click "Connect Google Drive" and authorize PasswordOwl
- Choose to migrate your existing data or start fresh
- Your vault is now stored on your Google Drive
You can switch back to our servers at any time from the same settings page.
Is it still zero-knowledge?
Yes. Your data is encrypted with AES-256-GCM before it leaves your browser, regardless of where it's stored. Google Drive only receives encrypted data that neither Google nor PasswordOwl can read. The same zero-knowledge guarantees apply.
How do I switch between our servers and Google Drive?
You can switch at any time:
- Go to Settings > Storage
- Select your preferred storage provider
- Choose to migrate your data to the new provider
- Your vault continues to work seamlessly
Still Need Help?
Can't find the answer you're looking for? We're here to help.
We typically respond within 24-48 hours.