The authenticator wraps the vault key
Inside a non-exportable keystore, PBKDF2-SHA256 and AES-GCM wrap the vault key so that unlocking can be authorised by the platform authenticator.
Product / Unlock and recovery
Biometrics and hardware keys can stand in for the master password. They only remove friction: the vault key still derives from master password plus secret key, and a 24-word recovery kit stays available.
Unlock can be delegated to the hardware you already carry. Windows Hello, Touch ID, Face ID, Android biometrics or a FIDO2 key such as YubiKey can satisfy the authentication step, so you do not type a long master password every morning.
Recovery is a separate path entirely. A 24-word BIP-39 recovery phrase can unlock and reset the vault if the master password and the device are both gone, and the emergency kit that carries it is written to a file you control rather than to a vendor.
A password hint exists for the in-between case, stored in plaintext on purpose so it can actually remind you — which is why the product warns you not to put the password itself in it.
Inside a non-exportable keystore, PBKDF2-SHA256 and AES-GCM wrap the vault key so that unlocking can be authorised by the platform authenticator.
Vault access always derives from master password plus secret key through Argon2id. Hardware binding is a layer on top, never the foundation.
A lost or replaced authenticator does not affect the vault file, its backups, or any record inside it.
Master password, account secret key and the emergency kit are collected once, at setup, on your own device — there is no server-side account to recover them from.
Hardware unlock means anyone who can authenticate on the device, or who holds your security key, can open the vault — that is the point, and it is why device and key security matter. The password hint is stored in plaintext precisely so it can be read back to you, so it must never contain the password itself. A recovery phrase should be written down and kept offline: anyone who reads it can reset your vault.
The platform authenticator is TPM-backed on Windows, and the wrapping key material does not leave that boundary.
On macOS the platform authenticator output is sealed by the Secure Enclave.
A 24-word recovery phrase can unlock and reset the vault when the password and the device are both unavailable.
It changes who can open the vault, not how it is encrypted. The records stay encrypted with the same keys, and access still derives from your master password and secret key.
You fall back to the master password, and if you have lost that too, the recovery kit. The vault itself is unaffected — only the convenience factor is gone.
Offline, physically, somewhere you would still find it in several years. It is a master key: whoever reads it can reset your vault.