Docs / Vaultlight
Find and deliver a field without leaving your task.
Vaultlight is the Windows and macOS command palette for unlocked vaults. It is not available on iOS or Android.
Desktop availability
Vaultlight runs only in the Windows and macOS desktop apps. Use the main 9Secure app for recovery-key unlock, attachments, full item editing, and non-Login item creation.
iOS uses the main app and Password AutoFill. The remaining sections describe the desktop Vaultlight feature and do not imply an iOS equivalent.
Unlock boundaries
Vaultlight can use only vaults available through the current unlocked keyring. If no keyring exists, it directs you to set one up in 9Secure.
- A locked session shows Keyring is Locked and a keyring-password field.
- Windows can offer Unlock with Windows Hello.
- macOS can attempt device unlock when it is configured.
- Recovery-key entry and keyring archiving stay in the main app.
Vaultlight closes and clears its armed item when the keyring locks.
On macOS, Vaultlight is also unavailable while sensitive Keyring, Settings, item-edit, or item-create surfaces require the main app's focus.
Open Vaultlight
Use the configured global hotkey or choose Open Vaultlight from the system tray or menu bar. The default hotkey is Control+;.
The system tray menu also opens Vaultlight. In search, use Ctrl+N for New Login, Ctrl+O to open 9Secure, and Ctrl+L to lock.
The menu bar extra can also open Vaultlight. In search, use Command+N for New Login, Command+O to open 9Secure, and Command+L to lock. Control variants also work for these search commands.
Search the index
Vaultlight Search searches item titles, item types, field labels, and non-secret field values in the unlocked index. It does not decrypt concealed field values to make them searchable.
- Type to filter up to the available result limit.
- Use the arrow keys to change selection and Enter to activate it.
- Use Escape to clear a nonempty query. Press it again when the query is empty to close.
created:andmodified:filters accept a UTC day. Normal searches also use fuzzy subsequence matching.
No results means no indexed item matched, not that every concealed value was searched.
Create a quick Login
- Open the New Login command.
- Choose a Vault and enter the Item name and Username.
- Review or generate the password.
- Add one or more Website values.
- If a website uses
http://, review the Sentinel warning and explicitly enable Allow HTTP for this website only when required. - Select Create.
The compact creator always creates a Login. It does not add attachments or arbitrary custom fields. Use the main app for those tasks.
Arm an item
Activate a result to arm up to ten copyable fields. Vaultlight decrypts the selected item's concealed payload only when needed to build its actions. The reference card maps fields to the number shortcuts and shows a countdown.
For a Login with Authenticator configured, Vaultlight places the current rotating code immediately after the password, shows its remaining lifetime, and refreshes it at the next period boundary.
For an SSH Key, saved commands appear as Run Command actions. Activating one executes the complete command through the desktop shell instead of copying or delivering the command text. See SSH command security before using it.
- Attachments are not exposed. The card says Open in app to access.
- Overflow fields require the main app.
- Add Website can update a supported armed item.
- Open the item in the main app when you need complete details or editing.
Deliver a field
Press Control+1 through Control+0 for the action shown beside that shortcut. Field actions deliver the value, including the currently displayed Authenticator code. An SSH command action runs the saved command instead. Either action restarts the armed-session countdown.
- Paste copies the field, then sends the platform paste shortcut to the previously focused app.
- Type Out sends Unicode input and does not place the field on the clipboard.
- Copy Only copies the field without sending input.
Confirm the target field before delivery. Type Out can behave differently in applications that transform keystrokes, and Paste depends on the target still accepting input.
Clipboard and session behavior
When Vaultlight copies a value, it clears that clipboard entry after the configured session timeout only if 9Secure still owns the same clipboard content. Replacing the clipboard prevents 9Secure from deleting your newer content.
Clipboard-history exclusion is enabled by default. It marks Vaultlight copies as sensitive or non-roaming where the platform supports it. This reduces exposure but cannot control third-party clipboard managers or another process that already read the value.
Escape hides an armed card, then closes or clears it when pressed again. Locking the keyring immediately clears the armed state.
Configure Vaultlight
Open Settings to configure:
- Vaultlight on or off.
- Vaultlight hotkey: Control ;, Control \, or a supported custom shortcut.
- Vaultlight session timeout: 15 seconds through 5 minutes.
- Vaultlight delivery: Paste, Type Out, or Copy Only.
- Exclude copies from clipboard history.
Grant Vaultlight Accessibility for global Escape fallback, Paste, and Type Out. Without it, Paste copies the value but cannot paste into another app, and Type Out cannot type.
Windows has no Vaultlight Accessibility setting. Hotkey registration and input injection use Windows facilities. Delivery cannot cross into an app running at a higher administrator integrity level.
Handle failures safely
- No Keyring: open 9Secure and complete keyring setup.
- Keyring is Locked: unlock with the password or configured device authentication.
- No results: shorten the query and search indexed titles, field labels, or non-secret values.
- Hotkey failure: choose another shortcut in Settings. Operating systems and other apps can reserve global shortcuts.
- Paste failure: the value may still be on the clipboard even when input delivery fails. Check the visible error before retrying.
- Type Out failure: the value is not copied, but part of it may already have been typed. Inspect and clear the target before retrying.
- Attachments or missing fields: open the item in the main app.