What it is
Passwords is Octoolo's password manager. It keeps logins, payment cards, secure notes and Wi-Fi passwords in one encrypted vault file on the PC, opened with a master password that only you know. It has three tools: the Password manager (the vault itself, with one-time codes, a password generator, a health check, import, export and backups), the Account manager (the same logins seen as accounts: which email or phone each uses, how you sign in, two-step sign-in, recovery codes, the accounts to close) and the Password leak check (is one password in a known data breach?). It replaces apps like KeePass, Bitwarden, 1Password, LastPass or the passwords a browser keeps. The vault never leaves the PC: there is no Octoolo account for passwords, no cloud copy and no sync.
Opening it and what it costs
- Passwords needs Octoolo Cloud (the subscription) or its free trial; see Prices and limits for prices, the trial and the free apps. Without an active subscription the app does not open; the vault file stays on the PC, still encrypted, and opens again once the subscription is active.
- On Octoolo's home screen Passwords is in the Every day group. The home screen's quick action Keep your passwords opens the password manager; search finds it by "password", "vault", "2fa", "bitwarden" and its tools' names.
- Inside, the list down the left is Passwords and accounts: Password manager, Account manager, Password leak check.
- Addresses:
#/app/passwords,#/app/passwords/password-manager,#/app/passwords/account-manager,#/app/passwords/password-check.
Tasks
- Password manager (
password-manager): make the vault, then keep logins, cards, secure notes and Wi-Fi passwords in it; copy them past Windows' clipboard history; one-time codes; a generator; the Health tab (leaked, weak, reused, old passwords, accounts without two-step sign-in); Import & export (CSV from browsers and other managers, encrypted backups, CSV export); Settings (auto-lock, clipboard clearing, the master password). - Account manager (
account-manager): the vault's logins as accounts, grouped by the email or phone number each uses, with how you sign in, whether two-step sign-in is on, which recovery codes you kept and the accounts to close. - Password leak check (
password-check): type or paste one password and Check it against Have I Been Pwned's list of leaked passwords, without sending the password. It does not need the vault.
All three tasks work. None is "coming".
How to make the vault the first time
The first time the Passwords Password manager or Account manager opens, it shows Make your vault.
- Type a Master password. The dice (Suggest one) fills in six random words with a digit; the eye shows it.
- The meter must reach Strong and the password must have at least 10 characters. Otherwise it says "Use at least 10 characters that are hard to guess, rated Strong. Six random words work well: try the dice."
- Type it again in The master password again ("The two are not the same yet." until they match).
- Tick I have written it down somewhere safe. If I forget it, the passwords in this vault are gone.
- Press Make my vault. Making the key takes about half a second on purpose.
The page says the vault is "Encrypted with XChaCha20-Poly1305 under a key that Argon2id makes from your master password." There is one vault per Windows user on the PC; the password manager and the account manager share it.
The master password cannot be recovered
If the master password is forgotten, this is what matters most:
- Octoolo never had a copy of it. The vault is encrypted with a key made from it, so nobody (not Octoolo, not support, not Getiket Technologies) can open the vault, reset the password or recover the passwords without it. There is no recovery email, no recovery key and no reset through the subscription.
- If it is truly forgotten, the passwords in that vault are lost. The only ways back are remembering it, or a backup or an exported CSV made before.
- Things worth trying first: Caps Lock, the keyboard layout (another language's layout moves letters and symbols), an older password, a master password changed recently (backups made before the change open with the old one).
- To start again: on the lock screen click Forgot the master password?. It says "It cannot be recovered." and "The vault is encrypted with it, and Octoolo never had a copy. You can start a new, empty vault: the old one is put aside, not deleted, in case you remember it later." Tick Put my vault aside and start a new one and press Start a new vault. The old vault is renamed
vault-forgotten-<date>-<time>.octooloin the vault's folder (itsvault.bakcopy is deleted), and Make your vault appears. - If the old password comes back later: open the new vault, go to Import & export, Bring in a backup, Choose a backup, pick the
vault-forgotten-….octoolofile and type the old master password. Its entries are added to the new vault.
The vault: what it holds
In the Passwords Password manager, New adds an entry; for a new entry, the kind is one of Login, Card, Secure note and Wi-Fi.
- Login: Name, Website, User name, Password (with the dice Make a new password), One-time code secret, then The account: Email it uses, Phone it uses, How you sign in, Two-step sign-in, Recovery codes, Status; and Notes. A login without a name takes its website's name ("github.com").
- Card: Title, Name on card, Number, Expires, Security code, PIN, Notes. Lists show only the last four digits.
- Wi-Fi: Title, Network name, Security (WPA3, WPA2, WPA, WEP, Open), Password, Notes.
- Secure note: Title and Notes (for a passport number, a licence key and the like).
- How you sign in: Not noted, Password, Sign in with Google, Sign in with Apple, Sign in with Microsoft, Log in with Facebook, Sign in with GitHub, A link or code by email, Another way. The Password field shows for Not noted, Password, or when a password is kept.
- Two-step sign-in: Not noted, Off, Authenticator app, Text message, Email code, Security key or passkey (a note only: the vault cannot hold passkeys).
- Status: In use, To close, Closed (dated when closed).
Showing and copying:
- Secrets show as dots until the eye (Show) is pressed. Most fields have a copy button.
- Open the website opens a login's site in the default browser (only http and https addresses).
- The star adds an entry to favorites (they sort first, and the ★ filter shows them).
- Edit, then Save, Cancel, or Delete followed by Delete for good. Deleting cannot be undone (except from a backup).
- When a password changes, the old one goes to Earlier passwords (the last 10 are kept, each with when it stopped being used).
- The list searches names, websites, user names, emails, phones, network names and card holders, and filters All, Logins, Cards, Notes, Wi-Fi. A colored dot marks an entry with a problem (red for leaked or weak, amber for reused or old).
Copying passwords and the clipboard
When the Passwords app copies a secret (a password, a code, a card number, recovery codes), Octoolo puts it on the clipboard itself and tells Windows to keep it out of the clipboard history (Win+V) and out of the cloud clipboard. A line at the bottom says what was copied, for example "Password copied, cleared in 30 s". After that time (Clear a copied password from the clipboard after: 15 s, 30 s (the default), 90 s, Never) the clipboard is emptied, but only if it still holds that secret. Locking the vault also clears the last copied secret. Pasting is done with Ctrl V as usual.
One-time codes (two-step sign-in)
The Passwords app makes the 6-digit codes that authenticator apps (Google Authenticator, Microsoft Authenticator, Authy) make, for sites that use time-based codes (TOTP).
- On the site, turn on two-step sign-in with an authenticator app. When it shows a QR code, choose the option to see the code as text (the "secret", or "can't scan it?").
- In the login's Edit, paste it into One-time code secret: the base32 secret (letters A to Z and digits 2 to 7, spaces allowed, like "JBSW Y3DP EHPK 3PXP") or the whole
otpauth://totp/…address. - Under the field it shows "Code now:" with the current code. Type that code on the site to finish, then Save.
The login then shows One-time code with the code, a ring for the seconds left and a copy button. Codes of 6 to 10 digits, periods of 1 to 300 seconds and SHA-1, SHA-256 or SHA-512 are read from the address. It cannot scan a QR code from the screen or a picture, and it does not do counter-based codes ("Only time-based codes (TOTP) are supported."). Codes are made from the PC's clock: if Windows' time is wrong, sites refuse them.
The password generator
In the Passwords editor, the dice next to Password (Make a new password) opens the generator:
- Characters: 8 to 64 characters, with A–Z, a–z, 0–9 and !#$ (the symbols
!#$%&*+-=?@^_~); at least one of each kind chosen; look-alike characters (O, 0, I, l, 1, |) are never used. - Words: 3 to 10 words from a list of short common English words, each with a capital, joined by dashes, with a digit at the end ("Maple-Otter-Quartz-Lemon-Harbor-7").
- It shows the strength in bits. Another one, Copy (copied the careful way, past the clipboard history) and Use it. The choices are remembered.
- Every character or word is picked evenly with cryptographic random numbers.
How strong a password is
The Passwords app rates passwords with zxcvbn (Dropbox's estimator, run on the PC): Very weak, Weak, Fair, Strong, Very strong, how long cracking it would take (for a thief holding the file of a well-protected site), and the number of guesses, with a tip when it is weak. It knows common passwords, names, words, dates, keyboard patterns and l33t, and counts the entry's own name, site and user name against the password.
The health check
The Passwords Password manager's Health tab (shown as "Health · N" when N entries have a problem) looks at the passwords of logins and Wi-Fi networks:
- Leaked: in Have I Been Pwned's list of leaked passwords ("Seen N times in data leaks: change it").
- Weak: rated Very weak, Weak or Fair.
- Reused: the same password on another entry ("Also used by N other entries").
- Old: not changed for more than a year.
- No two-step: logins whose Two-step sign-in is set to Off (not those left Not noted, and not closed accounts).
The score is the share of passwords that are strong, unique and not known to be leaked ("12 of 15 passwords are strong, unique and not known to be leaked."). Check for leaks checks every login and Wi-Fi password and reports "Checked N passwords: none found in data breaches." or "… K found in data breaches."; it adds "N passwords not checked for leaks yet." until then. A password's leak result is cleared when it changes. Clicking an entry in a list opens it.
The account manager
The Passwords Account manager shows the vault's logins as accounts (cards, notes and Wi-Fi are not shown there).
- Top: Accounts (with how many emails and phones), With two-step sign-in (a percentage), Without two-step and To close.
- Your emails and phone numbers: one card per email or phone the accounts use (taken from Email it uses, or a user name that is an email, or Phone it uses), with how many accounts and how many have two-step sign-in; accounts with none go under "No email noted". Clicking a card filters the list.
- The list filter: All, No two-step, Two-step not noted, No recovery codes, Password at risk, To close, Closed. Search accounts searches as the password manager does.
- Add an account adds a login with How you sign in set to Password; its form shows the account part first, then Signing in.
- Status marks an account To close or Closed: closed accounts leave All and show under Closed with when they were closed.
The password leak check
The Passwords Password leak check checks one password without opening the vault. Type or paste it into Password to check (its strength shows as you type) and press Check it.
- "Leaked N times": it is in Have I Been Pwned's list ("Criminals try leaked passwords first. Stop using it, everywhere, and give each site its own password.").
- "Not found in any known leak" ("That is good, but it does not make a weak password strong.").
- To check every password you keep, use Check for leaks in the password manager's Health tab.
How it stays private: Octoolo makes the password's SHA-1 fingerprint on the PC and sends only its first 5 characters to Have I Been Pwned (api.pwnedpasswords.com). The answer lists every leaked fingerprint that starts the same way (padded so its size says nothing), and the match is made on the PC. The password, and even its whole fingerprint, never leave the computer. It needs the internet.
How to bring in passwords from a browser or another manager
In the Passwords Password manager, open the Import & export tab:
- In the other app, export the passwords as a CSV file: Chrome, Edge, Firefox, Safari, Bitwarden, 1Password, LastPass, Dashlane or KeePass (KeePassXC's CSV layout).
- Under Bring in passwords, drop the CSV on Drop the exported CSV here, or press Choose a file. It is read on the PC.
- It says how many entries and where they seem to come from (for example "152 entries from Chrome or Edge"), how many empty rows were left out, and shows the first 50 rows (passwords as dots).
- Press Add N entries. The result says "N entries added, K duplicates skipped." and "Now delete the CSV file and empty the Recycle Bin: it holds your passwords in plain text."
What is read: columns are found by their names (name or title, url or website, username or login, password, email, notes or extra or comments, totp/otp/otpauth, favorite), with commas, semicolons or tabs between them. It recognises Octoolo's own CSV, Bitwarden, Firefox, LastPass, 1Password, Safari, Dashlane, KeePass and Chrome or Edge; other files with such columns are read as "a CSV file". Rows typed as cards or notes become cards or secure notes; LastPass's secure notes become notes; Firefox's password-changed dates are kept; passwords are kept exactly, spaces included. An entry already in the vault (the same site, user name, password and name; the same card number; the same network and password; the same note) is skipped, so importing the same file twice adds nothing.
Not read: encrypted or JSON exports (for example Bitwarden's .json or 1Password's .1pux), KeePass database files (.kdbx), and passkeys. KeePass 2's own "KeePass CSV (1.x)" layout (Account, Login Name, Web Site, Comments) loses the entry names and user names: export it with KeePassXC's layout (Group, Title, Username, Password, URL, Notes) instead.
Backups, export and moving to a new PC
In the Passwords Password manager, Import & export, Take them out:
- Save an encrypted backup saves the vault's file as it is, still encrypted, through a Save dialog, named
Octoolo vault <date>.octoolo. It opens only with the master password the vault had when the backup was made. Keep one on a USB stick or in a cloud drive. - Export as CSV (after ticking I understand the CSV is not encrypted, and I will delete it after use) saves
Octoolo passwords <date>.csv: every entry and every secret in plain text, UTF-8 with a byte order mark so Excel reads accents, with the columns kind, title, url, username, password, otp, email, phone, sign_in, two_factor, recovery_codes, status, holder, number, expiry, cvc, pin, ssid, security, notes. Anyone who opens it sees every password. Octoolo can read it back with Bring in passwords. Favorites, password history, dates and leak results are not in it.
Bring in a backup (same tab): Choose a backup, pick an .octoolo file (from this PC or another), type The backup's master password, Bring it in. New entries are added; an entry that is in both is kept as it was changed last; duplicates are skipped. It merges into the open vault, so a vault must exist and be unlocked first. The backup's password and the vault's may be different.
Moving to a new PC:
- On the old PC: Save an encrypted backup and copy the file to the new PC.
- On the new PC: install Octoolo, open Password manager, Make your vault (any strong master password, the old one or a new one).
- Import & export, Bring in a backup, choose the file, type the old vault's master password, Bring it in.
Alternatively, before making a vault on the new PC, copy the old vault.octoolo into the vault folder (below; make the vault folder if it is not there yet); the new PC then shows Your vault is locked and opens with the old master password.
Locking
- The Passwords vault locks itself after it sits unused: Lock the vault after it sits unused for 1 min, 5 min, 15 min (the default), 1 hour or Never (the Settings tab, Locking). Clicking, typing or scrolling in the password manager or the account manager counts as use; using other Octoolo apps does not.
- Lock (top right, next to "N entries, encrypted on this PC") locks it at once.
- Quitting Octoolo locks it (the key exists only in Octoolo's memory while the vault is open). Closing the window while Octoolo stays in the tray for Productivity's reminders does not lock it: it then locks after the auto-lock time, or never with Never.
- Unlocking: Your vault is locked, type the Master password, Unlock.
- There is no unlocking with Windows Hello, a PIN or a fingerprint.
Changing the master password
In the Passwords Password manager, Settings, Master password: type the Current master password, the New master password (it must rate Strong and have at least 10 characters) and New master password again, then Change master password ("Master password changed"). The vault is encrypted again under the new password. Backups saved before still open with the old password only.
Files it opens and saves
- Opens: CSV exports of other password managers and browsers (.csv), Octoolo vault backups (.octoolo).
- Saves: encrypted backups (.octoolo) and CSV (.csv), each through a Save dialog.
- The vault file format: JSON with
format"octoolo-vault",version1, the key settings (Argon2id, 64 MiB of memory, 3 passes, 4 lanes, a random 16-byte salt), the cipher "xchacha20poly1305", a random 24-byte nonce and the encrypted entries. The header is authenticated with the data, so it cannot be altered without the vault refusing to open.
Options and settings
All in the Passwords Password manager's Settings tab (they are kept inside the encrypted vault): Lock the vault after it sits unused for, Clear a copied password from the clipboard after ("Copied secrets never go into Windows' clipboard history (Win+V) or its cloud clipboard."), Show the vault's file (opens File Explorer at it), and Master password. The generator remembers its last choices.
Keyboard shortcuts
| Keys | Does |
|---|---|
| Enter | On the lock screen: unlock; in a form: Add or Save |
| Ctrl V | Paste what was copied (Windows' own) |
The Passwords app has no shortcuts of its own beyond these.
Where it keeps things
- The vault:
%LOCALAPPDATA%\com.octoolo.app\vault\vault.octoolo. - Beside it:
vault.bak, the vault as it was before the last change (same master password; there is none right after the master password was changed or a new vault was started); a vault put aside with Start a new vault asvault-forgotten-<date>-<time>.octoolo. - Show the vault's file in Settings opens that folder.
- Uninstalling Octoolo keeps the vault unless "Delete the application data" is ticked on the uninstaller's first page. Ticking it deletes the vault: save a backup first.
- The vault is on this PC only. Nothing about it is on octoolo.com or in the Octoolo Cloud account.
Downloads it needs
None. The Passwords app needs no download. Only Check for leaks and the Password leak check use the internet.
Privacy
- The vault, the master password and every secret stay on the PC. The master password is never stored, only used to make the key, and the key is kept in Octoolo's memory only while the vault is open and wiped when it locks.
- The page shows lists without secrets; a secret is read only when you open, show, edit or copy it.
- Leak checks send only the first 5 characters of each password's SHA-1 fingerprint to Have I Been Pwned. Nothing else leaves the PC because of Passwords.
- Octoolo's usage statistics say that the Passwords tools were opened, never what is in the vault.
Troubleshooting
"That is not the master password."
The Passwords app could not open the vault with what was typed. Check Caps Lock and the keyboard layout (the language shown in Windows' taskbar), and try any recently changed master password. The same message shows if the vault file itself was changed or damaged, because an altered file cannot be told from a wrong password.
If the password is surely right and it still fails:
- First, try
vault.bakbeside the vault (the version before the last change, same master password); the support team can help with this. Do it before anything else: Start a new vault (under Forgot the master password?) deletesvault.bak. - If that does not open either, use an encrypted backup: Forgot the master password? puts the vault aside, make the new vault, then Import & export, Bring in a backup with the backup's master password.
Octoolo cannot recover a forgotten master password (see "The master password cannot be recovered").
"The vault file is damaged: …"
The Passwords vault file is not readable as a vault: "The vault file is damaged: it is not an Octoolo vault.", "… its nonce.", "… its data.", "… its entries could not be read.", "The vault file is damaged (its key settings are out of range).", "The vault file is damaged (its salt)." The file was changed by something else, or the disk failed. First try the vault.bak beside it (the previous version, with the same master password; the support team can help), then an encrypted backup through Forgot the master password?, a new vault and Bring in a backup. Starting a new vault deletes vault.bak, so try it first.
"… made by a newer Octoolo. Update Octoolo to open it."
The Passwords vault (or the backup) was saved by a newer Octoolo than the one running. Update Octoolo (Settings, Updates) and try again.
The vault locked itself, or "The vault is locked."
The Passwords auto-lock time passed without use (15 minutes by default), or Octoolo was quit. Unlock it again. Something done after it locked shows "The vault is locked.". Change the time in Settings, Locking.
A copied password is gone from the clipboard, or not in Win+V
By design in the Passwords app: copied secrets are cleared after the time in Clear a copied password from the clipboard after (30 seconds by default) and are kept out of Windows' clipboard history. Copy it again, or choose 90 s or Never.
The import found nothing or not everything
- "No passwords found in that file. Choose the CSV your browser or password manager exported." The file has no rows with a name, website, user name, password, notes, card number or network: it is not a password CSV, or it is an encrypted or JSON export.
- "N duplicates skipped": those entries are already in the vault.
- Names or user names missing after a KeePass import: use KeePassXC's CSV layout.
- After importing, delete the CSV and empty the Recycle Bin.
"That is not the backup's master password."
Bring in a backup needs the master password the vault had when that backup was saved, which can be different from the current one.
The leak check does not work
The Passwords leak check needs the internet: "Could not reach Have I Been Pwned. Check your internet connection.", "Have I Been Pwned did not answer." or "Have I Been Pwned's answer did not arrive." Check the connection, a firewall or a proxy that blocks api.pwnedpasswords.com, and try again. In the Health tab, "Some could not be checked: …" means part of the check failed.
One-time codes are refused by the site
The codes come from the PC's clock: turn on Set time automatically in Windows' date and time settings. Check that the secret was pasted whole. "That is not a valid secret: it has letters A to Z and digits 2 to 7." means it is not a base32 secret; "Only time-based codes (TOTP) are supported." means the site uses counter-based codes, which Octoolo does not make.
Passwords does not open after the subscription ended
Passwords needs an active Octoolo Cloud subscription or trial; without one the app shows the subscription page instead. The vault stays on the PC, encrypted, and opens again when the subscription is active. Uninstalling without ticking "Delete the application data" keeps it too. Someone who plans to cancel and wants to use the passwords elsewhere meanwhile should use Export as CSV (or note what they need) before the subscription ends: the vault cannot be opened while Octoolo Cloud is off.
Other messages
- "There is a vault already. Unlock it instead." A vault exists for this Windows user.
- "There is no vault yet." The vault file is missing (deleted, or a new Windows user).
- "The current master password is not right." When changing the master password.
- "That entry is no longer in the vault." It was deleted, or the vault was restored meanwhile.
- "That web address is not valid." / "Only web addresses (http and https) can be opened." From Open the website.
- "The clipboard is busy: …" Another program held the clipboard; try the copy again.
Limits and what it cannot do
- It has no browser extension and cannot fill in passwords on websites or in apps: copy and paste them.
- It cannot sync between PCs or with phones, and has no mobile app or web vault. Move it with a backup.
- It cannot recover or reset a forgotten master password, and support cannot either.
- It cannot store passkeys, attachments or files, and cannot share entries with other people.
- It cannot unlock with Windows Hello, a PIN or a fingerprint.
- It cannot scan QR codes for one-time codes, and does not make counter-based (HOTP) or Steam codes.
- It cannot import encrypted or JSON exports, KeePass .kdbx databases, or folders and tags.
- It cannot change passwords on websites for you, or watch for new breaches on its own: run Check for leaks again from time to time.
- There is one vault per Windows user.