Skip to main content

Unlocking Your Wallet

Your mwen.io wallet locks automatically when your browser closes, or after a period of inactivity. Unlocking it gives your browser session access to your identity so you can sign in to apps.


Two ways to unlock

Biometric unlock (primary)

If you set up biometric unlock — either during initial setup or later via the Enable biometric unlock link — the wallet popup will show a Use biometrics button when you click the toolbar icon.

  • Touch the fingerprint sensor or look at the camera when prompted.
  • Unlock takes under a second.
  • The wallet uses your device's secure enclave (WebAuthn) — the biometric data never leaves your device.

This is the recommended method. No password typing required.

Password unlock (fallback)

If biometrics are not set up, or you choose to use your password instead, enter your wallet password in the popup to unlock.

Your password is processed locally using PBKDF2 (600,000 iterations) to derive the decryption key for your identity. The password is not sent anywhere.


Enabling biometric unlock after setup

If you skipped biometric setup during registration or recovery, you can enable it at any time while your wallet is unlocked:

  1. Click the mwen.io toolbar icon — your wallet is unlocked.
  2. Click Enable biometric unlock (shown below your DID when no biometrics are configured and your device supports them).
  3. The sidebar opens at the biometric setup flow.
  4. Enter your wallet password to confirm your identity.
  5. Follow your device's prompts (fingerprint, face scan, etc.).
  6. Done — the next time you click the toolbar icon, the Use biometrics button will appear.

If the Enable biometric unlock link is not shown, either biometrics are already configured or your browser/device does not support the WebAuthn platform authenticator.


What "unlocked" means

When your wallet is unlocked:

  • Your wallet can derive the per-app keys needed to sign in.
  • The actual master seed is held in browser memory only for the duration of the session.
  • When your browser closes, the in-memory seed is discarded. Only the encrypted form persists on disk.

Session length

Your wallet stays unlocked for the duration of your browser session. There is no fixed timeout — but the session ends when:

  • You close the browser or the browser tab containing the wallet.
  • You click Lock Wallet in the wallet settings.
  • Your operating system suspends or logs out.

You will need to unlock again the next time you open the wallet or sign in to an app.


Forgot your password?

Your password is not stored or recoverable by mwen.io. If you forget your password:

  1. If you have a .mwen backup file: Import it. You will be asked to set a new local password during import. See Backup & Restore.
  2. If you have your 24-word phrase: Use the recovery flow to re-derive your identity and set a new password. See Recovering Your Identity.
  3. If you have neither: The identity on this device cannot be accessed. This is intentional — no third party holds a copy.