Guides · Vaults and teams
Password manager
Keep the logins that aren't SSH hosts, such as web consoles, switch admin pages, API keys and notes, in the same encrypted vault as your hosts. It includes a generator, a strength meter, an audit, and an optional Windows Hello or Touch ID prompt before a password is shown.
- Personal Vault
- Biometric gate: Windows and macOS
- About 5 minutes
Where it lives
Open the Dashboard and click Password Manager in the Workspace list on the left.
Logins are stored in their own encrypted file, separate from your hosts, using the same key as your Personal Vault. There is no second master password:
- With automatic encryption (the default), the Password Manager is always available.
- If you added a master password, it is available only while the vault is unlocked. When it is locked the page says so and links to Settings.
Add a login
Click Add Login.
Fill in the General tab. Only Name is required.
Click Save.
| Field | Use it for |
|---|---|
| Name | How the login appears in the list, such as “GitHub” or “core-sw-01 web UI”. |
| Host | Optional IP or hostname. When set, the login gets a Connect via SSH button (see below). |
| Username / email | The account name. |
| Password | The secret. The eye button shows or hides it while you edit, and the dice button (Generate a password) opens the generator. |
| URL | Where you use the login. |
| Folder / tag | Optional grouping, shown as a badge in the list and matched by search. |
| Notes | Free text, such as recovery hints or which team owns the account. |
Generate a password
Click the dice button beside Password to show the generator options, set Length (4 to 128, default 20) and the character sets (A-Z, a-z, 0-9, !@#), then click Generate. Every set you tick appears at least once. Look-alike characters such as O, 0, l and 1 are left out, so a password read off the screen can be typed back correctly.
The four-segment meter under the field rates what you type as Weak, Fair, Good or Strong, from its length and mix of character types. Anything under 8 characters, or starting with a common pattern like password or 123456, counts as Weak.
Use a login
Each row shows the name, username, folder and a masked password, with these buttons:
- Show/hide password unmasks it in the row.
- Copy password puts it on the clipboard.
- Connect via SSH (only when Host is set) opens a terminal to that host on port 22 with the saved username and password, without creating a saved host.
- Edit and Delete. Deleting asks for confirmation and cannot be undone.
Search matches name, username, URL and folder. Every reveal and copy is written to the audit log, as are adds, edits and deletes.
Require Windows Hello or Touch ID
You can make MangoSSH ask for your fingerprint, face or PIN before it reveals or copies a saved password.
Open Settings → Vault → Encrypted Vault and click Manage password protection….
Under Password Manager protection, turn on Require Windows Hello to reveal passwords (on a Mac, Require Touch ID to reveal passwords).
The prompt appears when you click Show/hide password or Copy password in the list, and when you click the eye button on a login opened with Edit. In Edit the saved password stays hidden until you pass the prompt; saving with the field left empty keeps it unchanged, and typing or generating a new password needs no prompt. Hiding a password again never prompts. The setting works with or without a master password.
It covers every way the app shows or copies a saved password: the show and copy buttons in the list, and the eye button in Edit. It is a presence check, not extra encryption: logins are already decrypted by your vault.
The option appears only where it can work. On Linux the section is hidden. On a Windows PC or Mac without Windows Hello or Touch ID set up, the section shows the reason instead of the toggle.
Audit your passwords
Click Audit for a Password Audit. It scans every saved login on your device, with no network access, and lists passwords that are Weak (by the same rules as the strength meter) or Reused across logins. Click the edit button on a finding to fix it.
In the Internet edition, Check for Breaches also checks each password against Have I Been Pwned's Pwned Passwords list. Only the first 5 characters of each password's SHA-1 hash leave your device, never the password or the full hash. It runs only when you click the button.
Share a login
Logins stay on your device unless you share them. Settings → Cloud Sync does not carry them. To share one, open it with Edit, go to the Vault tab, pick a vault under Choose Vault and click Save. Like the same list in the host form, it is an action applied on save and always starts on Personal Vault.
| Choice | What happens |
|---|---|
| Personal Vault | Stays on this device. |
| Self Hosting Vault | Uploaded to your Self Hosting Vault restricted to this device, so other members don't see it (vault admins still do). You must be an admin of the vault. |
| Cloud Vault | Uploaded to the vault this device is connected to, for every member according to their role. |
| Team Vault | Uploaded to your Team Vault's encrypted store. Teammates see it in their Password Manager with a 👥 Team badge while their Team Vault is unlocked. They can show and copy it but not edit it; members with team edit permission can remove it from the Team Vault for everyone. |
Logins shared through a Self Hosting or Cloud Vault appear in other members' Password Manager after their next sync (about once a minute), marked ☁️ Shared. Once a login is shared, a vault admin can use Restrict to Specific Members… on its Vault tab to choose who sees it. See Vaults for roles and restrictions.
The Sync passwords setting only applies to hosts. A login is its password, so anyone who can see a shared login can reveal and copy it, including members with the Operator role.
Troubleshooting
| Symptom | Likely cause |
|---|---|
| “Vault is locked — unlock it in Settings first.” | You use a master password and the vault has locked. Unlock it, then reopen the page. |
| No Windows Hello or Touch ID option in Settings | You are on Linux, or the device has no biometric sign-in set up. Set it up in the OS first. |
| “Could not add privately to Self Hosting Vault” | This device is not an admin of the vault, or is not connected to one. The login stays in Personal Vault. |
| A shared login doesn't appear for a teammate | It is restricted to other members, or their vault is locked. Self Hosting and Cloud Vault logins appear while their Personal Vault is unlocked; Team Vault logins appear while their Team Vault is unlocked too. |
| No Check for Breaches button | You are running MangoSSH Secure, which leaves out every feature that contacts the internet. |