Overview
Your master password is the key to your encrypted vault. Change it if you think it’s been compromised, or to upgrade to a stronger password.
When to Change Your Master Password
Consider changing if:
- You suspect someone may know it
- You’ve used it on an untrusted device
- It doesn’t meet current security recommendations
- You’ve shared it (even with someone you trust)
- It’s been a long time since you last changed it
Steps to Change
- Log in to the web vault at vault.heimlane.io
- Click your profile icon in the top right
- Select Account Settings
- Under Master Password, click Change Master Password
- Enter your current master password
- Enter your new master password
- Re-enter the new password to confirm
- (Optional) Update your master password hint
- Click Change Master Password
What Happens When You Change It
- Your vault is decrypted with the old password
- New encryption keys are derived from your new password
- Your vault is re-encrypted with the new keys
- The new encrypted vault syncs to all devices
Important: Other logged-in sessions will be logged out and need to use the new password.
Choosing a New Master Password
Requirements:
- Minimum 12 characters (we recommend 14+)
- Should be unique - never used anywhere else
Tips for a strong password:
- Use a passphrase:
correct-horse-battery-staple - Mix words with numbers and symbols
- Make it memorable but not guessable
- Avoid personal information (names, dates, etc.)
After Changing
- All devices will need to log in with the new password
- Update your password hint if needed
- Write down the new password and store securely (temporarily)
- Practice typing it a few times to memorize
Troubleshooting
Problem: Forgot new password immediately
Solutions:
- Use the password hint you set
- Try any passwords you commonly use
- If 2FA is enabled, you’ll still need the master password
- Contact support only as last resort (limited help due to zero-knowledge)
Problem: Can’t log in after changing
Solutions:
- Clear browser cache and cookies
- Try the web vault directly (not extension)
- Ensure you’re using the new password
- Check caps lock
Problem: Old sessions still work
Solutions:
- Sessions remain valid until they time out
- You can log out all sessions in Account Settings
- Change password again if concerned about security
Tips
- Never share your master password with anyone
- Don’t store it in plain text on your computer
- Consider a physical backup in a secure location
- Set a memorable but secure password hint
