Guides · Vaults and teams
Vaults: Personal, Team and Cloud
Every host you save lives in your Personal Vault, encrypted on your device. To share hosts with other people or devices, you add them to a Team Vault, a Self Hosting Vault or Cloud Vault. This page explains what each one is and how to pick.
- All editions
- Cloud Vault: Internet edition
- About 10 minutes to read
The four vaults at a glance
Personal Vault is always on. The other three are opt-in, and a host is only ever sent to one of them if you add it there. Self Hosting Vault and Cloud Vault are the same system: the only difference is who runs the server.
| Personal Vault | Team Vault | Self Hosting Vault | Cloud Vault | |
|---|---|---|---|---|
| For | Your own hosts on this device | A small team that already shares a folder | Teams that want sync through their own server | The same, without running a server |
| Setup | None, on by default | A shared folder (Syncthing, Dropbox, OneDrive, NFS) or a WebDAV/HTTP URL | Deploy the vault server with Docker | Sign in with your email |
| Encryption | AES-256-GCM. Key in the OS keychain, or derived from your master password | AES-256-GCM. Key from a shared team passphrase, or sealed to each approved device | AES-256-GCM, end to end. The vault key is sealed to each approved device | Same as Self Hosting Vault |
| Who gets in | You | Anyone with the passphrase, or devices an admin approves | Devices an admin approves, or that join through SSO | Same as Self Hosting Vault |
| Permissions | Not applicable | Passphrase: everyone equal. Keypairs: admins, plus members who are read-only until granted edit | Admin, Editor or Operator per device, plus per-host restrictions | Same as Self Hosting Vault |
| Saved passwords | Stay in this device's keychain | Travel with each host you share | Only when Sync passwords is on | Same as Self Hosting Vault |
| Removing someone | Not applicable | Keypairs: revoke re-keys the team automatically. Passphrase: no per-person revoke | Revoke takes effect on the server at once. Rotating the vault key afterwards is recommended | Same as Self Hosting Vault |
| Edition | Both | Both | Both | Internet edition only |
All four are managed in Settings → Vault, which has one tab each: Encrypted Vault, Team Vault, Self Hosting Vault and Cloud Vault. The Encrypted Vault menu on the Dashboard is a shortcut to the same pages.
Personal Vault
MangoSSH encrypts your host list from the first save. By default the key is a random AES-256 key held in your operating system's keychain, so there is nothing to type and nothing to remember. The Encrypted Vault tab shows this as Encrypted (automatic), with a Vault View of every host and which shared vaults it is in.
This protects against someone copying your data files, a backup or a stray synced folder. It does not stop a program already running as your OS user, which can read the same keychain. If you want a password between that program and your hosts, add a master password.
Add a master password
Open Settings → Vault → Encrypted Vault and click Manage password protection….
Enter a New master password of at least 8 characters, confirm it, and click Add Password Protection.
Choose Auto-lock after inactivity: Never, 5, 15, 30 or 60 minutes without mouse or keyboard activity. The default is 15 minutes.
From then on MangoSSH starts on a MangoSSH is locked screen and asks for the password. The derived key is held in memory only and is cleared when the app closes or locks. The same dialog has Change Master Password… and Remove Password (Keep Automatic Encryption), which returns you to keychain-only encryption.
For a second factor, turn on Enable Two-Factor Unlock under Settings → Authentication. It asks for a code from an authenticator app at unlock, and gives you ten single-use recovery codes. It only applies when you use a master password.
There is no recovery path for the master password. If you lose it, the hosts on that device cannot be decrypted. Keep it in a password manager, and consider keeping a copy of your hosts in a Team, Self Hosting or Cloud Vault.
Moving to another computer
Because the automatic key lives in this computer's keychain, copying MangoSSH's data folder to another machine is not enough. Use Settings → Cloud Sync instead. It carries your hosts, SSH keys, macros, scripts and saved passwords between your own devices through a shared folder or a URL (S3, WebDAV, R2), encrypted with a Sync Passphrase you enter on every device. With a shared folder, Sync automatically pushes on every change and checks for the other machine's changes about once a minute. With a URL you push and pull by hand. Cloud Sync is for one person's devices; use a shared vault for other people.
Admin or User: who can create a shared vault
Each device is set to User or Admin. Users can join a Team Vault or Self Hosting Vault that already exists. Only Admin devices can create a new one or recover one with a recovery code. A new install starts as User.
To switch, open Settings → Vault → Encrypted Vault → Account Type and click Admin. This setting only decides who can create a vault. Once you are inside one, what you can do is set by your role in that vault.
Team Vault
Team Vault needs no server. Every member points MangoSSH at the same shared folder, and whatever already syncs that folder (Syncthing, Dropbox, OneDrive, a mounted NFS share) moves the encrypted files between machines. A WebDAV or plain HTTP URL works too. Besides hosts, Team Vault carries shared scripts and a team audit log. The team audit log needs the shared-folder method.
You pick one of two sign-in modes when you set it up, and you cannot switch later without starting over:
- Team passphrase. Everyone types the same passphrase. Simple, but everyone has identical full access and there is no way to cut one person off.
- Device keypairs. Each device has its own key pair, kept in the OS keychain. An admin approves each new device, can make members admins, and decides per member whether they can edit the shared vault. New members are read-only until granted edit. Revoking a device re-encrypts the vault under a new key that the revoked device never receives. Creating the team shows a recovery code once; it restores admin control if every admin device is lost.
Open Settings → Vault → Team Vault.
Choose the Authentication mode and the Action: Create new team, Join existing team or Recover with a code.
Choose the Sync method and enter the shared folder or URL. Every member must use the same location. URL credentials are stored in the OS keychain.
Enter Your device label (teammates see it when they approve you) and, in passphrase mode, the Team passphrase. Click Set Up / Unlock.
To share a host, right-click it and choose Share with team, or use Sync → Share SSH Host with Team on the Dashboard. The host's saved password goes with it. Shared hosts appear in every member's host list with a team badge, and Copy makes your own editable local copy.
Self Hosting Vault and Cloud Vault
These use a vault server that stores only ciphertext and enforces who may read or write each record. Self-hosting the vault server walks through deploying one, creating the vault and adding teammates. Cloud Vault is the MangoSSH-hosted version: you sign in with your email and a six-digit code instead of entering a server URL, and it is a paid feature during the beta. A device connects to one Self Hosting Vault or Cloud Vault at a time.
Roles
An admin sets each member's role in the vault's Members tab.
| Role | Can do |
|---|---|
| Admin | Everything: approve and revoke devices, change roles, restrict hosts, rotate the recovery code and vault key, delete the vault. Admins see every host, including restricted ones. |
| Editor | Add, change and remove shared hosts, except hosts restricted to other members. |
| Operator | Connect to shared hosts and use their stored credentials, but not add or change them. Shown as Viewer in the SSO group mapping. |
The server enforces these roles. A change a role is not allowed to make is rejected and reported as a Not synced notice, while the rest of the sync still goes through.
Per-host restrictions
By default every member sees every shared host, within their role. An admin can click Restrict next to a host in the Hosts tab and pick which members may see it. The server then hides that host from everyone else, and admins still see it. Clearing every name removes the restriction.
Sync passwords
Off by default. With it off, saved passwords and key passphrases never leave the device's keychain, and teammates type their own. With it on, this device includes its saved credentials when it pushes its hosts, still end-to-end encrypted. It is a per-device choice and only affects the hosts this device pushes. For credentials people should use without ever seeing them, use the PAM Broker.
Shared hosts
Only hosts you add are sent to the server. In the Hosts tab, tick hosts in the grid and click Save & Sync. The grid only adds; it never removes a host that is already shared. The Synced via Self Hosting Vault list below it shows what is currently shared, with Unshare buttons. Unsharing stops this device updating the host. Deleting a host from your device deletes it from the vault too. A background sync runs about once a minute while the app is open.
Choose where a new host is stored
The Vault tab of the Add or Edit host form has a Choose Vault list. It is an action applied when you save, not a setting: it always starts on Personal Vault, and choosing another vault adds the host there in addition to your Personal Vault.
| Choice | What happens on save |
|---|---|
| Personal Vault | Nothing extra. The host is encrypted locally. |
| Team Vault | Shared with the whole team. Team Vault has no private mode. |
| Self Hosting Vault | Added to your Self Hosting Vault restricted to this device, so other members don't see it (admins still do). You must be an admin of that vault; otherwise it stays in Personal Vault only. |
| Cloud Vault | Added to the vault this device is connected to, visible to every member according to their role. |
If the vault you pick is not set up on this device, MangoSSH tells you and keeps the host in Personal Vault only.
Troubleshooting
| Symptom | Likely cause |
|---|---|
| No Create option for a Team or Self Hosting Vault | This device is set to User. Switch Account Type to Admin. |
| “Your role here is Operator” | An admin gave you the Operator role. You can connect, but ask an admin for Editor to add or change hosts. |
| A Team Vault member can't share or remove hosts | In keypair mode new members are read-only. An admin grants edit access in the Team Vault's member list. |
| A teammate sees the host but has to type the password | Sync passwords is off on the device that shared it. |
| “This device's access … was revoked” | An admin revoked this device. Ask them to approve a new join request. |
| Hosts missing after copying the data folder to a new PC | The automatic key stays in the old PC's keychain. Use Cloud Sync or a shared vault to move hosts. |