SolidPass is a personal vault for everything you need to keep private — passwords, two-factor (2FA) codes, payment cards, identity documents, bank accounts, crypto wallets, Wi-Fi credentials, secure notes and more. It runs entirely on your device.
The core promise
100% offline. There is no account, no server, and no cloud. The app has no internet permission at all — your data physically cannot leave your device over the network.
Zero analytics & tracking. No logs, no trackers, no ads, no telemetry.
Strong encryption. Your master password derives a key with Argon2id — a memory-hard algorithm built to resist GPU and specialized-hardware attacks — which unlocks a random 256-bit vault key. Every item is individually encrypted with AES-256-GCM, including its title, type, tags and attachment names.
Nothing stored in plain text. The decrypted key lives only in memory while the vault is unlocked and is wiped the moment it locks.
Because SolidPass has no cloud, you are in full control — and fully responsible. If you forget your master password and lose your recovery codes, no one (including us) can recover your data. Please read Section 2 carefully and keep a backup (Section 12).
What you'll need
A master password you can remember (minimum 8 characters — longer is stronger).
A safe place to store your 3 recovery codes (write them down or print them).
Optionally, Face ID / Touch ID / fingerprint set up on your device for quick unlock.
Section 2
Getting started — creating your vault
The first time you open SolidPass, a short setup walks you through three steps. (If you already have a backup file from another device, tap Restore from Backup on the welcome screen instead — see Section 12.)
Welcome. Review the "100% Offline" and "Zero Analytics & Tracking" principles, then tap Get Started.
Set your Master Password. Enter a password (minimum 8 characters) and confirm it. A live strength meter (Weak → Moderate → Strong) helps you choose a good one. Tap Continue.
Save your Emergency Recovery Kit. SolidPass generates 3 recovery codes in the form SP-XXXX-XXXX. Tap Save Recovery Codes (.txt) to export them, then store them somewhere safe. Tap Complete Setup & Initialize.
Enable biometric unlock (optional). If your device supports Face ID / Touch ID / fingerprint, choose Yes, Enable or Skip.
You're all set. A confirmation screen summarises your protection. Tap Enter the Vault.
Faster setup: While you're reading and saving your recovery codes, SolidPass is already building your encrypted vault in the background — you'll see a "Preparing encrypted vault… %" indicator turn into "Encryption ready". By the time you tap Complete Setup, it finishes almost instantly. This uses the exact same strong encryption; it just does the heavy work while you read.
About the 3 recovery codes: you need any 2 of the 3 to recover your vault if you forget your master password. Keep them separate from your device, and don't store the only copy inside SolidPass itself.
Section 3
Locking & unlocking
Unlocking your vault
With biometrics (if enabled): the Face ID / fingerprint prompt appears automatically. You can also tap Tap to Scan Biometrics.
With your master password: type it and tap Unlock.
If you forget your master password
On the lock screen, tap Forgot Password? Recover Vault.
Enter any 2 of your 3 recovery codes, then tap Verify Codes & Decrypt.
Set a new master password and confirm it, then tap Save & Open Vault.
How auto-locking works
SolidPass locks automatically after a period of inactivity (default 5 minutes — configurable in Settings: 1m / 5m / 15m / Never).
Optionally, Lock on Minimise locks the vault the instant you switch away from the app.
You can lock immediately any time with the Lock Vault button at the top of Settings.
Your biometrics are never stored by SolidPass. Enabling biometric unlock saves your vault key inside your device's secure hardware (Keychain / Keystore), released only after a successful Face ID / fingerprint check by the operating system.
Section 4
The Vault — adding & organising items
The Vault tab is your home screen: a searchable list of everything you've saved.
Finding things
Search bar — type to match titles, tags, usernames, websites, note content, and 2FA issuer/account names.
Category filters — tap a pill to show only a type: All Items, Favorites, Passwords, Authenticators (2FA), Cards, Notes, Bank Accounts, Crypto Wallets, Identities, Wi-Fi, Licenses, API Keys, SSH Keys, Recovery Codes, Contacts, or Custom Items.
Favorites — tap the star on any item to pin it to the Favorites filter.
2FA at a glance: Authenticator items show a live 6-digit code and a countdown right in the list. The countdown turns red in the last 5 seconds before it refreshes.
Adding an item
Tap the floating + button.
Choose an item type from the grid.
For Payment Card and Identity, you'll be asked Enter Manually or Scan & Autofill (see Section 7).
Fill in the fields. Every item has a Title (required), an Add to Favorites toggle, a Tags section, and a General Notes field.
Bank Name, Account Holder, Account Number, Routing Number, SWIFT/BIC, IBAN
Crypto Wallet
Wallet Type/Network, Wallet Address, "Watch-only" toggle; if not watch-only: Seed Phrase (+ optional passphrase), Derivation Path
Identity
Full Name, Document Type, Document Number, Expiration & Issue dates, Issuing Authority, plus photo/PDF attachments
Wi-Fi Password
Scan Wi-Fi QR, SSID, Password, Security Type (WPA3/WPA2/WEP/None)
Software License
License Key, Publisher, Version, Purchase Date
API Key
API Key, Endpoint URL, Header Name, Environment (Dev/Staging/Prod)
SSH Key
Private Key, Public Key, Passphrase, Key Fingerprint
Recovery Codes
Service Name + a list of one-time backup codes
Contact
First/Last Name, Company, and lists of Phones, Emails, Addresses
Custom Item
Any number of Label + Value fields, each with an optional "hide value" toggle
Attachments (Cards & Identities): add a scanned document, a photo, an image from your gallery, or a PDF (Identities). Limit 3 MB per file; images and PDFs only. Photos taken in-app are not saved to your device's camera roll.
Section 6
Viewing an item
Tap any item to open its details.
Reveal secrets. Passwords, CVVs, PINs, API keys, SSH private keys, seed phrases, recovery codes and 2FA secrets are hidden behind an eye icon — tap to reveal.
Copy fields. Every field has a copy button. Copied secrets are automatically cleared from the clipboard after 45 seconds.
Live 2FA codes. Authenticator items show a large rotating code with a progress bar, a "seconds remaining" readout and a Copy Authentication Code button.
Attachments. Cards and Identities display their images/PDFs — tap to preview full-screen or share.
Favorite / Edit / Delete. Toggle the star, tap Edit Item to change fields, or Delete Item (with confirmation) to remove it.
Section 7
Scanning — cards, IDs, QR codes & attachments
SolidPass reads documents entirely on-device (offline OCR). Nothing is uploaded.
Scanning a payment card
Add a Payment Card and choose Scan & Autofill (or tap Scan Payment Card inside the form).
Align the card within the guide. SolidPass captures at full quality and reads the number, expiry and name.
The card number is checked with the Luhn checksum and the network (Visa, Mastercard, Amex, …) is detected. If a digit looks wrong, you'll be warned so you can fix it.
Review the fields and tap Create Item.
Scanning an identity document (passport / ID card)
Add an Identity and choose Scan & Autofill.
Capture the document so the machine-readable zone (the two or three <<< lines) is clearly visible.
SolidPass parses the MRZ following the ICAO 9303 standard and validates the check digits — when they verify, you'll see "The machine-readable zone was verified", which means the document number, dates and name were read reliably.
Review and save. Some fields (like the issue date) aren't in the MRZ, so add those by hand if needed.
For the most reliable scans: use good, even lighting; lay the card/document flat on a dark surface; avoid glare; and fill the frame with the document. For IDs, the MRZ lines at the bottom are what make reading accurate — make sure they're sharp.
Other scanners
2FA QR codes — Authenticator items can scan an otpauth:// QR, including Google Authenticator "export" QRs (multiple accounts at once). See Section 13.
Wi-Fi QR codes — Wi-Fi items can scan the standard Wi-Fi QR to fill SSID, password and security type.
Section 8
Document Scanner
The Scanner tab is a document store, separate from vault items — ideal for multi-page paperwork you want kept encrypted and exportable as a PDF.
Tap + to create a new document, or open an existing one to edit.
Give it a Title, then add pages with Scan Page / Take Photo or Import from Photo Gallery (multi-select).
Reorder pages up/down or remove them. Pages are optimised for size and encrypted on save.
From the list or the full-screen preview, tap share / export to compile all pages into a single PDF.
Also reachable from Settings → Tools & Utilities → Solid Document Scanner.
Section 9
Password Generator
The Generator tab creates strong, random secrets. Tap the copy icon to use one (auto-cleared from the clipboard after 45 seconds); tap Regenerate for a new value.
Password
Length 8–64 (default 16)
Toggle uppercase, lowercase, numbers, symbols
"Exclude Ambiguous" removes 0 1 O l I
Guarantees at least one of each selected type
Passphrase
3–10 words (default 4) from a curated list
Separator: -_./
Easy to type, hard to crack
PIN
4–16 digits (default 6)
Secure random number generation
Tip
Inside a Password item, tap the refresh icon next to the password field to drop in a fresh 16-character password without leaving the form.
Section 10
Security Health
The Health tab audits your vault entirely on-device and gives you a Vault Score out of 100 (Excellent ≥ 80, Needs Work ≥ 50, otherwise Critical). Expand any section to see the affected items and jump straight to them.
Check
What it flags
Weak Passwords
Under 8 characters, or fewer than 3 character types
Reused Passwords
The same password used on more than one entry
Old Passwords
Not changed in over 180 days
Missing URLs
Password entries with no website (harder to autofill/verify)
Expiring Documents
Cards & IDs already expired or expiring within 3 months
Wallets Without Backup
Non-watch-only crypto wallets with no saved seed phrase
The Health check only ever reads your decrypted data in memory. Nothing is sent anywhere.
Section 11
Settings
Security
Biometric Unlock — enable/disable Face ID / Touch ID / fingerprint (enabling requires a biometric confirmation).
Lock on Minimise — lock instantly when you leave the app.
Auto-Lock Timeout — 1m / 5m / 15m / Never.
Change Master Password — enter current + new password; your vault key is re-encrypted and the vault re-locks.
Backup & Imports
Export Encrypted Vault (.solidpass) and Restore Vault from .solidpass — see Section 12.
Import from CSV (Bitwarden, 1Password, Chrome) and Import from Google Authenticator — see Section 13.
Emergency Kit
Download Emergency Kit — re-export your 3 recovery codes as a .txt file.
Support & Information → Frequently Asked Questions, Contact Us.
Appearance follows your device's light/dark setting automatically.
Danger Zone — Reset Vault & Wipe All Data. This permanently deletes your database, credentials, recovery codes and settings from the device. You must type wipe all data to confirm. There is no undo — export a backup first if you might want your data later.
Section 12
Backup, restore & moving to a new device
Uninstalling the app deletes everything. Because SolidPass keeps no cloud copy, always export a backup before uninstalling, resetting, or switching phones.
Creating a backup
Go to Settings → Export Encrypted Vault (.solidpass).
Choose where to save/share the file. Keep it somewhere durable that survives an uninstall (e.g. Files / a folder you control).
The .solidpass file is a complete, fully encrypted copy of your vault — all items, their file attachments, and your Scanner-tab documents — and can only be opened with the master password that created it (or that vault's recovery codes). It carries a checksum to detect corruption.
Restoring a backup
On a fresh install: tap Restore from Backup on the welcome screen, pick your .solidpass file, and enter that backup's master password.
Into an existing vault (Settings → Restore Vault from .solidpass): choose either —
Merge — decrypts the backup and adds its items, attachments and scanned documents to your current vault (keeps what you already have).
Replace & Import — destructive: wipes the current vault and replaces it with the backup. You'll then unlock with the backup's master password.
Moving to a new phone: Export on the old device → transfer the .solidpass file → install SolidPass on the new device → Restore from Backup.
Section 13
Importing from other apps
From a password manager (CSV)
Export a CSV from Bitwarden, 1Password, or Chrome.
In SolidPass: Settings → Import from CSV, then pick the matching format.
Logins are imported (Bitwarden also brings in secure notes) and tagged with the source name.
Delete the plaintext CSV afterwards. Exported CSV files are unencrypted — remove them from your device once the import succeeds.
From Google Authenticator
In Google Authenticator, choose Transfer accounts → Export to show a QR code.
In SolidPass: Settings → Import from Google Authenticator and scan the QR.
One Authenticator item is created per account. (Older HOTP entries are skipped.)
Section 14
Autofill
Open Settings → Autofill for step-by-step instructions to set SolidPass as your device's autofill provider.
iOS: Settings → General → AutoFill & Passwords.
Android: System autofill service picker.
The screen includes an Open Autofill Settings shortcut that jumps to the right system page.
Autofill is being rolled out; the in-app screen always shows the current status and exact steps for your platform.
Section 15
FAQ & troubleshooting
I forgot my master password. What now?
Use Forgot Password? Recover Vault on the lock screen with any 2 of your 3 recovery codes, then set a new password. Without the password and without 2 recovery codes, the data cannot be recovered — this is by design.
The camera scan didn't read my card / ID correctly.
Improve lighting, remove glare, lay the item flat on a dark surface and fill the frame. For IDs, keep the bottom <<< lines sharp — that's what SolidPass validates. You can always correct any field by hand before saving; a card number that fails its checksum will be flagged.
Why does the app lock when I switch apps?
If Lock on Minimise is on, SolidPass locks the moment it goes to the background for safety. Turn it off in Settings if you prefer, and adjust the Auto-Lock timeout.
Can I take a screenshot?
No — screenshots and screen recording are blocked app-wide, and the app preview is blanked in the task switcher, to keep your secrets off the screen.
Is there a subscription or ads?
No ads, ever, and no tracking. All functionality is available.
Does anything leave my device?
No. There is no network access at all. Backups only leave your device if you explicitly export and share a file.
Section 16
Security best practices
Use a strong, unique master password — this is the one key to everything. A long passphrase is ideal.
Store your recovery codes offline — printed or written, kept somewhere separate from your phone. You need 2 of 3.
Back up regularly — export a .solidpass file after major changes and before uninstalling or switching devices.
Enable biometrics + a short auto-lock — convenient and safe on a device only you can unlock.
Turn on Lock on Minimise if you share your device or work in public.
Delete plaintext exports (CSV from other apps) as soon as you've imported them.
Run Security Health periodically and fix weak, reused or old passwords.
Keep your backup file's password safe too — a backup can only be opened with the master password that created it.
SolidPass — Security Without Compromise Offline & zero-knowledge · Air Microservices LLC Support: solidpass@airmicroservices.com