Seeking clarity on sharing a vault ???

pomme4moi
pomme4moi
Community Member

I've read this section of the 1P user guide (https://guides.agilebits.com/1password-mac/5/en/topic/share-a-vault), but still don't quite get it. So let me try to clarify here.

I am in an all-Apple environment. I have 1P running on one iMac. I sync 1P using 1P's WiFi Sync from the iMac to three different iOS devices. I do not use Dropbox or iCloud for 1P syncing. I have about 300 login items defined in my 1P vault. I would like my daughter to be able to access about 50 of these items.

Let's say I create a secondary vault (a Family Vault), and I move the 50 items from my primary vault to the secondary vault. Now, when my daughter uses the iMac or one of the three iOS devices, how does she open only the secondary vault to access the 50 items? Thx

Comments

  • Lars
    Lars
    1Password Alumni
    edited May 2015

    Thanks for your question, @pomme4moi!

    Unfortunately, at this time, only Dropbox and folder sync can be used to share vaults selectively. There is currently no way to actively sync a vault between different users without one of those two methods. However, if you don't want to use Dropbox, you can certainly create a folder in a shared location accessible from any account and both you and your daughter can use that vault from your respective user accounts on the iMac. Here's what you'd do:

    • Create the secondary vault and give it a password that's different from your primary vault's Master Password, and that you don't mind sharing with your daughter
    • In a shared location such as inside /Users/Shared, create a new folder and call it something like "Shared 1Password vault."
    • In 1Password Preferences => Sync and choose to sync with Folder from the drop-down menu
    • Navigate to the folder you created inside /Users/Shared and select it.

    1Password will then write out an agilekeychain to that location, and your daughter will be able to log into her account on the iMac and navigate in Finder to that folder. Double-clicking on the agilekeychain inside will prompt her for the vault password you used when you created the vault (not your own Master Password), and she should be able to view and edit all the items inside from that point forward.

    Regarding the iOS devices, that's a bit more tricky: since iPhones and iPads are designed primarily to be single-user devices, there's no mechanism in iOS for multiple individual accounts on a single device like there is in OS X. Accordingly, there's no way to display only certain vaults to certain users, as your iOS device doesn't have a concept of who's using it. If you each have your own iOS devices, then it's simply a matter of you syncing your vaults (including the shared vault) via wi-fi from your account on the iMac, and your daughter doing the same with her iOS devices from her account on the iMac.

  • pomme4moi
    pomme4moi
    Community Member

    Thanks for the response. I understand what you are saying, but it sounds a bit clunky. Maybe I'll wait for the feature to be available with Wifi Sync, or maybe move to Dropbox sync. Thanks again though!

  • Vee_AG
    Vee_AG
    1Password Alumni

    Hi @pomme4moi,

    If I understand your original post correctly, you're not actually describing "vault sharing" as we define it, but rather just using multiple vaults. Does this describe your use case: on a shared computer, you want to be able to access the primary and secondary vault, but you want your daughter to only have access to the secondary vault? This is absolutely doable.

    • While you are logged into the primary vault, you can create a secondary vault and set a new (different) Master Password and hint for that vault.
    • From the primary vault, you can share items to the secondary vault. ("Copy" will retain the item in the primary vault and add it to the secondary vault; "move" will remove it from the primary vault and add it to the secondary.)
    • When you unlock the primary vault, you will also unlock all secondary vaults.
    • When your daughter wants to access the secondary vault, she can open the application, and from the lock screen select 1Password > Switch to Vault and select the secondary one, then enter the password for the secondary vault. This will only give her access to the selected vault, not the primary.

    So if this is what you're aiming to do, you won't need to change your sync settings at all. However, if you are considering using Dropbox or iCloud sync, I think you'd like it. You set it up once, and from then on, it automatically keeps the data synced across all connected devices. It's pretty cool, if I say so myself. :) And syncing with Dropbox gives you the added bonus of being able to use 1PasswordAnywhere, to access your secure data from computers that don't have the 1Password app installed.

    I hope this helps!

This discussion has been closed.