User Guide
Secret Vault
Enrol, unlock and recover a private encrypted operational vault.
Secret Vault stores encrypted recovery records, notes, documents and certificates. It is not a credential-injection API, SSH agent or general password-manager integration.
Enrol and unlock
Open Security > Secret Vault. Confirm the Kaya password and fresh TOTP, or complete a configured OIDC MFA step-up. Choose a PIN meeting the Admin minimum (default eight digits) or a passphrase of at least 12 characters. Save the one-time recovery kit and confirm it before normal use.
A normal Kaya login never unlocks the vault. An unlocked session is bound to the current application session, auto-locks after inactivity, has an eight-hour absolute limit and is revoked by manual lock, logout or recovery. Protected values are withheld from HTML until Reveal; Highly Sensitive fields require fresh PIN/passphrase and one-use MFA approval.
Backup and recovery
Use Backup and Recovery to create a passphrase-encrypted .kayavault export. Kaya verifies it by decrypting it immediately. Keep this alongside a full Kaya backup, not instead of one. If the PIN is lost, use the recovery key plus current Kaya password or fresh verified OIDC MFA; recovery issues a replacement key and revokes existing vault sessions.
Current limitations include no completed collection-membership UI, emergency access, key rotation, malware scanning or organisation escrow. Related: Module Settings, Backing Up Kaya.
