Log inGet Vautir

Search the help center, features, guides and more.

Signing in with a key connector

For companies that want no master passwords: what a Vautir key connector is, how members sign in with one, and what running one involves.

With single sign-on, members still have a master password. A company that wants its people to have none can run a key connector: a small service on its own servers that keeps a key for each member, and hands it over only to someone the company’s identity provider vouches for. The member’s apps use that key where the master password would go.

Signing in

On the log-in screen, choose Sign in with my organization’s key connector, and enter your email address, the connector’s address and your Secret Key. Your browser opens your company’s sign-in page, and then a page that asks you to allow the login, with the code your app shows.

It works in the browser extension, the desktop app, and the iPhone, Mac and Android apps. The web vault can’t reach a connector.

What holds what

  • The connector holds a key for each member.
  • Your devices hold your Secret Key, as always.
  • Our server holds nothing new: only ciphertext.

Every key of your account still comes from two things together: what the connector keeps, and the Secret Key on your devices. The connector alone opens nothing, and neither does our server.

For whoever runs it

  • It runs on your own servers, behind a reverse proxy that speaks https, with an OpenID Connect application at your identity provider.
  • An admin names its address in the console, under Policies, Single sign-on.
  • Back up its database and its key file together, and keep both private. A member whose connector key is lost is locked out as surely as one who forgot a master password. A recovery code, or trusted contacts, is the way back.
  • Whoever runs the connector, with one of a member’s devices, has that member’s vault. That’s the trade a company makes for no master passwords.
  • A new device still needs the member’s Secret Key: typed, or handed over by a device that’s logged in.

Last updated October 4, 2026