Unlock your vault
Set and unlock your vault passphrase in Servor, save your recovery key, understand what "locked" means, and recover access if you forget it.
Your vault is what keeps Servor zero-knowledge: your sensitive data is encrypted in your browser with a passphrase only you know. This page explains how to set that passphrase, unlock the vault each session, save your recovery key, and what to do if you ever forget it.
What the vault is
The first time you sign in, Servor asks you to create a vault passphrase. That passphrase encrypts everything sensitive in your browser before it ever reaches our servers — which means we cannot see it and we cannot reset it for you. This is the whole point: nobody at Servor, and nobody who compromises our servers, can read your data without your passphrase.
Because we can't reset it, you also get a recovery key — a list of 24 words — as a backup way in. Keep both safe.
If you lose both, the data is gone
Losing your passphrase and your recovery key means losing access to your encrypted data for good. There is no support ticket that can bring it back. Save the recovery key the moment you see it.
Set your vault passphrase
You do this once, on your first sign-in.
Choose a strong passphrase
Pick something long and memorable that you don't use anywhere else — a passphrase of several words is stronger and easier to remember than a short complex password. Type it, then confirm it.
Save your recovery key
Servor shows you a 24-word recovery key. Write it down or store it in a password manager. Treat it like the keys to your house — anyone with it can unlock your vault.
Confirm and continue
Confirm you've saved the recovery key. Your vault is now created and unlocked for this session, and you're ready to add a server.
Where to keep the recovery key
A password manager (or a printed copy in a safe) is ideal. Don't store it in the same place as your Servor login, and don't paste it into a chat or email.
What "locked" means
Your vault locks whenever you start a fresh session — for example after you sign in on a new day, on another device, or after clearing your browser. A locked vault means the encryption key isn't loaded in your browser yet, so anything that needs it is paused.
You'll see an unlock screen asking for your passphrase whenever the vault is locked and you try to do something that requires it, such as:
- Opening the web terminal
- Running commands on a server
- Working with the AI copilot
Just enter your passphrase and the vault unlocks for the rest of the session.
Read-only viewers don't need to unlock
If your role is viewer, you can browse monitors, status pages, incidents and command history without ever unlocking a vault — read-only access needs no encryption key. Unlocking is only required to run things. See roles and permissions.
Unlock the vault each session
Open something that needs the vault
Head to a server terminal, the command runner, or the AI copilot — start from your servers. If the vault is locked, the unlock screen appears automatically.
Enter your passphrase
Type the passphrase you set on first sign-in and confirm. The vault unlocks for the current session — you won't be asked again until the session ends.
If you forget your passphrase
Don't panic — this is exactly what the recovery key is for.
Choose "Use recovery key" on the unlock screen
Instead of the passphrase, switch to recovery-key entry.
Enter your 24-word recovery key
Type the words in order. This unlocks the vault without the passphrase.
Set a new passphrase
Once you're back in, set a new passphrase you'll remember. Your recovery key stays valid as your backup.
No passphrase and no recovery key?
Servor genuinely cannot recover encrypted data without one of them — that's the guarantee that keeps your data private. If both are lost, you'll need to start fresh: re-add your servers and re-create anything that was encrypted. Contact your team owner, who may still have access if their own vault is unlocked.
Tips for teams
If you work with a team, a new member's access to encrypted data is granted the first time a teammate with an unlocked vault is online. If you've just been invited and see a "waiting for a teammate to come online" screen, ask someone on the team to unlock their vault — access then unlocks automatically. Details in invite teammates.