Account and encrypted sync

Sign in to Ravelon Cloud or your own server, keep your vault in sync end to end encrypted and share vaults with a team.

Choose where your vault lives#

Open Settings → Account & sync and pick a Storage location:

  • This device: no sync. This mode needs no Ravelon account and does not contact a sync server.
  • Ravelon Cloud: sync through Ravelon Cloud. This needs Ravelon Pro, a one-time purchase without subscription. You can start a free trial here without payment details. When the trial ends, sync pauses and your local data stays as it is.
  • Own server: sync with a server you run yourself. The server software is free and open source, see https://github.com/ravelon-app/ravelon-sync.

Sign in#

Sign in with your account e-mail and password. That is the whole setup: there is no separate sync passphrase. If your account uses two-factor authentication, Ravelon asks for the code in a second step and accepts an authenticator code or a recovery code. Accounts that use Google, GitHub or Discord can choose Sign in with browser instead. Ravelon then asks for your account password once, locally, to open your encryption key.

What is encrypted#

Every record is encrypted on your device before it is uploaded. The key that protects your data is random and reaches the server only in a sealed envelope that your account password opens. A second device signs in with the same password and gets the same key.

If you change the password under Change the account password, your other devices ask for it at their next sign-in.

What syncs#

Hosts, groups, snippets, tunnels and settings sync as soon as you sign in. Changes are uploaded after a short delay and appear on your other devices. Offline changes wait in the encrypted vault until the connection returns.

These stay on the device:

  • Identities with their passwords, key passphrases and imported private keys, unless you turn on Sync keys & identities.
  • Trusted host keys, command history, AI provider profiles and AI agent definitions.

Team vaults#

Use the vault switcher at the top of the sidebar to create a Team vault. In Vault settings you invite members by e-mail and give them a team role and a vault role (Viewer, Editor or Admin). The team vault has a separate sharing key. Send it to members through a trusted channel, separately from the invitation. When you copy it, Ravelon clears it from the clipboard after 30 seconds.

Note: Organizations can turn off sync or allow only a specific server by policy. The setting then shows a Managed badge.

Last updated 30 September 2026