The 1Password Community forums are in read-only mode from Jan 28th - Feb 4th, 2025. Find out more.

Are the Secondary Vault(s) configurable?

wkleem
wkleem
Community Member

I hope I'm not asking the obvious but are the Secondary configurable? What if I don't want any Secondary vaults on my Mac or I want to limit the number of vaults that anybody can access?

Comments

  • littlebobbytables
    littlebobbytables
    1Password Alumni

    Hi @wkleem,

    I suspect I may not fully understand your query. So the following may not be applicable. If that's the case please help correct my understanding.

    If you don't want any secondary vaults then you're under no obligation to create any. Even if you create secondary vaults for your own needs, syncing of each is quite separate. You can set up syncing of a primary vault while a secondary vault isn't synced at all. There are certain limitations, for example you have to sync your primary vault if you want to use Wi-Fi Sync, it isn't possible at the moment to synchronise just a secondary vault.

    As for access, most of the control is with Dropbox which is how we currently support sharing of secondary vaults. If you wish to share a secondary vault between Dropbox accounts you have to explicitly set this up.

    As I say, I've got this feeling that I'm not really understanding the question so please do let me know if that is the case and maybe if you could describe your situation a little more it might help :smile:

  • detjo
    detjo
    Community Member

    Why can't secondary vaults be on icloud too? I don't use dropbox.

  • littlebobbytables
    littlebobbytables
    1Password Alumni

    Hi @detjo,

    The original intent behind secondary vaults was to allow people to share certain passwords with others e.g. a couple with shared accounts or team members in a work environment. As iCloud does not allow any form of sharing the use of iCloud Sync for secondary vaults wasn't considered at the time.

    Now it turns out many people like using secondary vaults as a logical divide between work and personal. For this group the goal isn't sharing of the secondary vault so they would like iCloud Sync to be available. We do have an existing feature request for this but I'm unable to supply even an estimated timeframe for this request - sorry. If you goal is to share a secondary vault with others though iCloud isn't a viable option.

    If you have any follow up questions do please ask away :smile:

    ref: OPM-2895

  • wkleem
    wkleem
    Community Member

    Hi LittleBobbyTables, I suppose that I am confused myself as secondary vaults works differently across platforms. E.g. Secondary vaults take on the Primary vault's password in 1Password for iOS.

    There doesn't appear to be a way of changing the priority of the vault where the Secondary vault becomes Primary or is there?

  • littlebobbytables
    littlebobbytables
    1Password Alumni

    Hi @wkleem,

    Different platforms do currently handle secondary vaults differently it's true.

    On Windows you interact with your vault by directly accessing the .agilekeychain or OPVault folder, just like 1Password 3 did. You can only have a single vault open at a time so they don't feel so much like secondary vaults, more just like multiple vaults. Each vault is only unlocked with its own Master Password.

    On Mac and iOS a different approach was taken, partly because of how iOS works. The encryption keys for your secondary vaults (not to be confused with the Master Password which is different) are stored inside the SQLite database file that stores all of your vaults. The secondary encryption keys are secured by the same encryption that secures your primary vault and can only be accessed via your Master Password. Now you can unlock just a single secondary vault by switching to it and entering its Master Password in 1Password for Mac but as you already know, entering your Master Password for your primary vault unlocks them all as well. We have people that prefer both approaches.

    At the moment there isn't an easy, one click approach to swapping a secondary vault with your existing primary but it is possible to do so. It involves ensuring both vaults exist either as .agilekeychains, possibly because they were already being synchronised or exporting the contents of the two vaults using the 1Password Interchange Format (.1pif). This would allow you to create a new primary and secondary vault and then add the contents so the ordering was swapped. There are a few steps involved and we find it's only something the more passionate users wish to do as a result but it is possible.

    Did that help at all?

  • wkleem
    wkleem
    Community Member

    Thanks Adam, I just need time to soak in all the info, and there are lots of it!

  • Drew_AG
    Drew_AG
    1Password Alumni

    @wkleem, on behalf of littlebobbytables, you're very welcome! You're right, it's certainly a lot of info to absorb. If you have more questions about that, just let us know - we're always happy to help! :)

  • Vee_AG
    Vee_AG
    1Password Alumni

    Hi @wkleem,

    Indeed! There's a lot going on in 1Password, especially when syncing across platforms. Let us know if you have any other questions, and as always, we'll do our best to help make sense of things for you! :)

This discussion has been closed.