> For the complete documentation index, see [llms.txt](https://docs.gotempest.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.gotempest.app/accounts-vaults-and-privacy/accounts-and-vaults.md).

# Accounts, Vaults & Multiple Accounts

Add and switch Tempest Cloud or self-hosted accounts, choose personal and shared vaults, and understand sign-out versus removal from this device.

A Tempest **account** is your identity on a particular Tempest server. A **vault** is the collection of encrypted documents you are using within that account. Switching accounts and switching vaults are separate actions.

You can keep a personal Tempest Cloud account and a work account on a self-hosted server on the same device. Their tokens, encryption keys, server endpoints and local vault files are kept in separate account storage. Adding a second account and switching between accounts require the **multi-account entitlement (Pro)**; the device's account plans determine whether that feature is available.

```mermaid
flowchart TD
    D[This device] --> A[Personal account on Tempest Cloud]
    D --> B[Work account on self-hosted server]
    A --> P[Personal vault]
    A --> T[Shared vaults granted to this account]
    B --> W[Work personal vault]
    B --> S[Work shared vaults]
```

## Add or switch an account

On desktop, open **Settings → Account**. The **Accounts** section lists the accounts on this device, shows each server and marks the current one. Use **Add account…**, select Tempest Cloud or a self-hosted server, and complete sign-in. Use **Switch** beside an existing account to make it current. The account menu in the sidebar footer also provides account selection.

On mobile, open **More** and use the account controls to add or switch accounts. Complete browser sign-in and unlock the account's vault when prompted.

Check the server shown alongside the account, particularly if the same email is used on multiple servers. An identity on Tempest Cloud does not automatically have access to a different self-hosted deployment.

Switching changes the account shown in the app; it does not merge data or import credentials from another account. The native host adjusts foreground syncing to the current accounts. Do not assume all background accounts continue syncing just because they remain in the list.

## Choose a vault

In **Settings → Account → Active vault**, choose the personal vault or a shared vault available to that account. Shared-vault access depends on membership and a key grant; account sign-in alone is insufficient.

Current v3 shared vaults wrap their key for each authorized account's public key. Unlock with your account's **Master Password** when prompted. A legacy v1/v2 shared vault can instead ask for the shared passphrase supplied by its owner; follow the prompt for that vault.

Shared-vault permissions also determine whether you can edit saved connections. The native vault layer checks those writes, including restores from History, rather than relying only on disabled UI buttons. Permission to connect to a saved host does not imply permission to edit its saved credential record. Such restrictions do not prevent a recipient who can decrypt data from copying it outside Tempest.

## Sign out versus remove

| Action                      | Effect                                                                                                                                    |
| --------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| **Switch account**          | Select another account; keep the other account registered on this device.                                                                 |
| **Sign out**                | Remove sign-in tokens and shared-vault access/cache as applicable; keep the account listed and retain its personal data as a local vault. |
| **Remove from this device** | Remove the account registration, its local keys and its local account directory. Data already synced stays on the server.                 |

**Sign out is not a local data wipe.** The personal vault is retained locally and, when possible, re-encrypted under a device-local key. The next sign-in in that account slot can adopt that local data, including when signing in with a different identity. Use **Add account** to keep a second identity separate, and **Remove from this device** when your intention is to discard that account's local data.

Close account-related sessions and let pending edits sync before removal. Shared files still in use by another native process can require cleanup after that process releases them; do not treat sign-out as guaranteed forensic erasure. Copies in clipboard history, exports, recordings and backups are outside these controls.

## Desktop and CLI share account state

On the same computer, the desktop app, CLI and MCP share the native account root. CLI changes to the current account, sign-in or removal can therefore affect the desktop app too.

```bash
tempest account list
tempest account add
tempest account use you@example.com
tempest --account you@example.com ssh list
tempest account logout you@example.com
tempest account remove you@example.com
```

Use an account ID if an email does not uniquely identify the account. `--account` selects an account for that command; `TEMPEST_ACCOUNT` is the environment equivalent. See the [CLI guide](/cli/tempest-cli.md) for endpoint configuration and sign-in.

## Web Mode account isolation

Each browser session has a scoped account list and current account. It cannot automatically access another browser session's accounts or the backend machine's CLI identity. The standalone backend still runs the vault host and is trusted with decrypted data; see [Local Credential Storage](/accounts-vaults-and-privacy/where-tempest-stores-credentials.md#web-mode).

## See also

* [Passwords & Recovery](/accounts-vaults-and-privacy/resetting-password.md)
* [End-to-End Encryption](/accounts-vaults-and-privacy/end-to-end-encryption.md)
* [Vault History](/accounts-vaults-and-privacy/vault-history.md)
