Recovery kit
Last updated: 28 Jun 2026
A recovery kit (`.nt2recovery`) for device loss—not a substitute for `.nt2backup` full vault export.
Who this is for
Vault owners who use threshold Shamir key material and want a path to unlock on a new browser or after device loss—without NT² resetting your password.
What you need
| Tier | Free |
| Vault state | Unlocked (to export); locked or cold device (to use) |
| Network | Offline-capable |
| Feature toggle | Threshold vault (default for new vaults) |
Steps
Export a recovery kit
- Unlock your vault.
- Open Settings → Recovery → Recovery kit (
https://se.nt2.me/settings/recovery/recoveryKit). - Export the
.nt2recoveryfile to storage you control (encrypted drive, offline media). - Store it separately from your master password and alongside—not inside—your vault.
Custody: The kit file holds a recovery share (one of three unlock factors) in a form that is not encrypted as a sealed blob. Anyone who obtains the file holds that share. Combined with your master password—or an enrolled device—they could reconstruct vault access. Treat the file like a spare hardware key: keep it offline on media you control; do not email or chat it as a casual attachment; move browser downloads out of a shared Downloads folder.
Use a recovery kit on a cold device
- On the unlock screen, select your vault by display name.
- When prompted, provide your master password or use Reset password with this device + recovery kit (see unlock-screen flows).
- You need two factors among your master password, this device, and your recovery kit—not all three every time.
After changing your master password
- Complete Settings → Recovery → Change master password when available.
- Export a new
.nt2recoverywhen prompted. - Destroy or securely archive old recovery kits—they no longer match the new password factor.
Tips and common mistakes
- Recovery kit does not replace regular
.nt2backupexports for item data—export both. - NT² cannot recover your vault if you lose password, device, and kit with no backup.
- Never email or message recovery kits; store them separately from your master password (the kit itself is not passphrase-wrapped ciphertext for Share_rec).
- After a password change, export a new kit and destroy or securely archive old ones.