This browser can’t open ZK Vault
What works
- Chrome or Edge on a desktop computer (Windows, macOS or Linux) with a USB security key such as a YubiKey 5.
- Firefox 139 or later on a desktop computer with a USB security key.
What doesn’t work
- Safari on macOS, and every browser on iPhone and iPad (they all run on Apple’s WebKit engine): security keys can return a wrong PRF secret, which ZK Vault can’t tell apart from a wrong Vault PIN, so each try could cost one of your key’s 3 strikes.
- Security keys over NFC on Android.
- Passkeys synced through a phone, password manager or cloud account. Only hardware keys are accepted.
The page must be opened over HTTPS (or on localhost) at the address the vault was set up for.
Unlock your vault
Enter your Vault PIN, then use one of your security keys.
All three keys are needed
- Key A:Needed
- Key B:Needed
- Key C:Needed
- Enter your Vault PIN and press Unlock.
- Insert any of your keys when the browser asks.
- Enter that key’s own key PIN if the browser asks for it.
- Touch the key.
The two PINs and the 3-strike rule
Vault PIN is the PIN you chose for this vault. It is never sent to the server; your key turns it into a secret that only works with that key.
Key PIN is the security key’s own FIDO2 PIN. The browser asks for it; the key itself blocks after too many wrong key PINs.
Each key allows 3 wrong Vault PINs in a row; a correct Vault PIN resets the count. In a Tangem vault the third destroys that key’s copy of the vault key on the server, for good, and your other keys keep working. In a Shamir vault, or on the last key that still opens a Tangem vault, the third destroys the whole vault and every file in it. Before a key’s last attempt the page asks you to confirm it. There is no recovery: nobody, including whoever runs this server, can open a vault without a working key and its Vault PIN.
If the browser lists several ZK Vault entries on one key, pick the one that starts with your vault’s tag, such as “ZK Vault 1a2b3c4d”. The tag is shown at the top of your vault, and its Keys panel shows each key’s entry.
No vault yet?
Create a new vault
- Mode
- Vault PIN
- Keys
- Verify
Enroll your three keys one at a time. You’ll touch each key twice: once to create its credential, once to seal its copy of the vault key.
Last check before the vault is created: insert Key A once more and press Verify.
Key A derives its secret again, and this browser checks that it opens what was sealed a moment ago. A key that couldn’t unlock the vault is caught now, before anything is stored in it.
Enter Key A’s key PIN if the browser asks, then touch the key.
Your three keys are enrolled and Key A is verified, but the vault wasn’t created yet. Nothing has to be enrolled again: try creating it once more.
Your vault is ready
- Mode
- Vault ID
Picking the right key entry
When you unlock, your browser may list the entries stored on a key. This vault’s entries are named:
If you use several vaults on this server with the same keys, pick the entry that starts with “”. Picking another vault’s entry counts as a wrong Vault PIN on that vault, or opens that vault if it has the same Vault PIN.
How it works from now on
Needs your attention
Add files
Files can’t be added while a key change is in progress.
While files upload or download, auto-lock (15 minutes without activity, or 5 minutes with this tab in the background) waits until they finish. Pressing Lock cancels uploads and downloads that haven’t finished.
Files
Keys
Key changes are paused while files are uploading.
Vault ID