Guide
Set up Ovik, keep your vault safe, and use it alongside Cryptomator.
Parts marked Next update describe features coming in the next App Store update.
Getting started
1. Turn on the Finder extension
Ovik shows unlocked vaults in Finder through a Finder extension. The first time you open Ovik, a short guide Next update takes you through it. If your vault doesn't show up in Finder, check that Ovik is turned on here:
- macOS 15.2 or later: System Settings → General → Login Items & Extensions → File Providers
- macOS 15.0–15.1: an Apple bug hides this setting. Please update macOS to 15.2 or later.
- macOS 14 Sonoma: System Settings → Privacy & Security → Extensions → Added Extensions
2. Create a vault, or open one you already have
New vault: click Create New Vault…, enter a name and click Choose Save Location…. Pick a folder your cloud app syncs, such as one in iCloud Drive or Dropbox, or any folder on your Mac. Ovik creates a new folder with the vault's name there.
Then choose a password. It must be at least 12 characters and strong enough to be hard to guess, and a strength meter shows how you're doing Next update. A few unrelated words make a good password. Before you can create the vault, you confirm that Ovik can't recover the password. Read Your password and key file before you put anything important in it.
Existing vault: click Open Vault… and select the vault folder (the one that contains vault.cryptomator and masterkey.cryptomator). Vaults created with Cryptomator work as they are.
3. Unlock and use it in Finder
Enter the password and click Unlock. The vault appears under Locations in the Finder sidebar, and Reveal in Finder opens it. Use it like any other folder: files you save there are encrypted on your Mac before they're written to the vault folder, and your cloud app syncs only the encrypted files.
On a Mac with Touch ID, later unlocks can use your fingerprint Next update. The first unlock after you open Ovik always asks for the password.
4. Lock when you're done
Click Lock. The vault disappears from Finder, and the decrypted copies of the files you opened are removed from your Mac. You can also lock every vault from the menu bar icon Next update, and have vaults lock on their own when your Mac is idle, its screen locks or it goes to sleep Next update. See Support for the settings.
Quitting Ovik locks all vaults. Closing its window doesn't: Ovik keeps running in the menu bar Next update.
Your password and key file
Opening a vault takes two things: your password, and the vault's key file, masterkey.cryptomator, in the vault folder. The key that encrypts your files is stored in the key file, locked with your password. There is no server and no account, so nobody else holds a copy of either.
| If you lose… | What happens |
|---|---|
| Your password | The files in the vault are lost for good. Nobody can reset or recover the password, including us. |
| The key file (deleted or damaged) | The vault can't be opened, even with the right password, unless you have a backup of the key file. |
| The vault folder | The files are gone, like any other data you lose. Back up the vault folder too: it's encrypted, so the backup can go anywhere. |
Keep your password in a password manager. Ovik doesn't create a recovery key, and there's no "forgot password".
Back up the key file. Click Show Master Key File in Finder on the vault's page and copy the file somewhere else, such as a USB drive or an attachment in your password manager. It only opens with your password, but keep it private: anyone with a copy can try to guess the password.
A key file backup doesn't replace the password. It opens with the password the vault had when you made the backup. After you change the password, make a new backup.
When you change the password, Ovik keeps the old key file next to the new one as masterkey.cryptomator.XXXXXXXX.bkup, and the old password still opens the vault through it. If someone else might know the old password, delete that backup when Ovik offers to. To fully retire an old password, create a new vault and move your files into it.
Using Cryptomator too
Ovik uses the openly documented Cryptomator vault format (version 8). The same vault folder opens in the official Cryptomator apps on Windows, Linux, iPhone, Android and other Macs with the same password, and vaults made in Cryptomator open in Ovik.
- Let syncing finish before you unlock the vault on another device.
- Lock the vault in Ovik before you edit it on another device. When you unlock, Ovik takes a working copy of the vault, so changes your cloud app brings in while it's unlocked don't show up until the next unlock. If you then edit the same file in Ovik, your Ovik version replaces the other one.
- Don't edit the same file on two devices at once. Your cloud app may then keep two copies. Ovik notices these conflict copies and shows how many there are on the vault's page Next update.
- On one Mac, use one app at a time. Don't unlock the same vault in Ovik and Cryptomator at the same time.
- Vaults created in Ovik contain a short
README-Ovik.txt. Cryptomator ignores it.
Getting files back without Ovik
Because the format is open, you never depend on Ovik to reach your files. If Ovik ever can't open a vault, or you stop using it, the official Cryptomator app can:
- Stop saving through Ovik. Lock all vaults and quit Ovik.
- Let your cloud app finish syncing.
- Make a copy of the whole vault folder, for example on an external drive. Work on the copy and leave the original as it is.
- Install the official Cryptomator app from cryptomator.org (free on Mac).
- In Cryptomator, add an existing vault and select
masterkey.cryptomatorin the copied folder. - Unlock with your Ovik password and copy the files you need out of the vault.
If the password doesn't work and you changed it in Ovik, the old password opens the .bkup file next to the key file: in the copy, rename the .bkup file to masterkey.cryptomator (replacing the current one) and try the old password. You can also put a key file backup of your own in its place.
Still stuck? Email [email protected] with your macOS version, Ovik version, cloud service and the error you see. Never send your password, key file, file names or file contents.