Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Invitations, users and devices

Administration is a terminal wizard that runs inside the server container. It has no web interface and no HTTP surface, so there is nothing to expose.

docker compose exec server node dist/admin/cli.js

An administrator can issue invitations and revoke devices. An administrator cannot read anyone’s vault: the server never has the keys.

What the menu does

EntryWhat it does
Invite someoneCreates a single-use registration token. You choose how long it stays valid (1 hour, 24 hours or 7 days) and which capabilities the new account gets. The token is shown as text and as a QR code.
List users and devicesShows every account and the devices enrolled on it.
List outstanding invitationsShows tokens that have been issued and not yet used or expired.
Revoke a userRevokes every device on the account and spends its outstanding device-join tokens.
View audit logShows the security event history.
Prune audit logDeletes audit entries older than a number of days you choose. Retention is manual.
Recover a locked-out accountPresent but does nothing. See below.

Capabilities

Accounts can carry capabilities that describe what an administrator may do: manage invitations, manage devices, view the audit log. They are granular, not all-or-nothing.

The audit log

The log records registrations and enrolments (including refusals), device revocations, master password changes and invitations issued. It never records a credential, token or key. Source IP addresses are recorded only for refused registrations and enrolments, so abuse can be traced.

Locked out? There is no recovery

If someone forgets their master password, nobody can recover their vault. The server holds no copy of the key and there is deliberately no escrow. The “Recover a locked-out account” entry exists so that its absence is not mistaken for a missing feature. The only way out is an encrypted backup plus the password that opens it.

Revoking a single device

Users can revoke their own devices from the app: the device list in Settings on Android, and in the extension’s Settings.