Skip to main content

Security

Your configuration can hold things you'd rather others didn't read: text that actions type, paths, script code. A password encrypts the files that hold them, so someone who copies or opens the files sees nothing useful without the password.

Protection is a deterrent against casual reading, not a vault: while Input.Observer runs, it has your configuration open, and anything an action does is visible on screen as usual.

There is no way to recover a forgotten password. Nobody, including you and the makers of Input.Observer, can decrypt a protected file without it. Read If you forget the password before you set one.

Changes on the Security page take effect at once. They don't wait for Apply, and Discard doesn't undo them.

What the password protects​

One password protects three files, all kept together in your configuration folder (The configuration file):

FileHolds
Configuration (config.toml)Everything you set up: groups, actions, gestures, settings
License (license.dat)Your license email and key
Console (console.toml)The console's script editor text and window position

All three are protected or none is; there is no password per file. A file that doesn't exist yet (for example, the license file before you activate a license) is protected as soon as it is created.

These are not protected:

  • which gesture profile is active;
  • values scripts store between runs (the Storage builtins);
  • macro recordings, in the Recordings folder;
  • plugin settings, such as the Styles plugin's settings file, and style purchase files;
  • exported files: an export is always plain text, and the export dialog warns you when your configuration is protected (Import and export).

When you turn protection on, the plain-text backups of your configuration in its Backup folder are deleted, so an older copy can't give away what you just protected. Backups made from then on are encrypted (Backups).

The Security page​

Input.ObserverSimpleAdvanced
AUTOMATION
Actions
Text expansion
Snippets
Sandbox
App groups
Ignore groups
Gestures
SETUP
General
Appearance
Security
Help
About
Security
Password protection for your configuration, license and console. Changes here apply immediately.
Protection status
Configuration (config.toml)
Not protected
License (license.dat)
Not protected
Console (console.toml)
Not created yet
Remember password for
How long a correctly-typed password is remembered before you're asked again. 0 asks every time.
60
Password
Set password…

Protection status shows each file as Password protected, Not protected, or Not created yet.

Setting a password​

  1. On the Security page, choose Set password… ①.
  2. Type the password in New password and again in Confirm password, and choose OK.

The three files are encrypted at once. The tray menu's Set Password... does the same.

Changing or removing the password​

Once a password is set, the button reads Change or remove password… (the tray menu's item reads Change Password...).

Change or remove password
Current password
••••••••
New password
Confirm password
Leave New password blank to remove protection instead.
OKCancel
  • To change it, type the current password, then the new one twice.
  • To remove protection, type the current password and leave New password ① and Confirm password blank. All three files are decrypted.

If the current password is wrong, nothing is changed and the page says so.

When you are asked for the password​

  • Every time Input.Observer starts. It can't read your configuration without it. Cancelling closes Input.Observer.
  • When you open the configuration window, unless the password is still remembered (below).
  • When you open the console, unless it is still remembered.
  • When something saves a protected file and the password isn't remembered, for example the tray menu's Global Actions switch.

Remember password for​

Remember password for ② sets how long a correctly typed password is remembered, so you aren't asked several times in a row — at startup, for example, the configuration, the license and the console settings may all need it within seconds.

SettingDefaultRange
Remember password for60 s0–300 s; 0 asks every time

While the configuration window or the console is open, the remembered password doesn't run out; the time starts again when you close the window. A remembered password is held encrypted in memory and is always checked against the file again before it is used.

Changing this setting while your configuration is protected saves the configuration, which needs the password. If none is at hand, the page says so: open Change or remove password… once to confirm the password, then try again.

When the files don't match​

If some of the three files are protected and others aren't (for example, a file was restored from an old copy), the Security page shows "Your protected files are not all in the same state", with Protect all three… and Remove protection from all three…. Input.Observer also asks at every start until it is fixed, with three choices: Encrypt all three files (recommended), Remove protection from all three files, or Leave the files as they are.

If you forget the password​

There is no reset and no recovery code. What you can do depends on the file:

  • Configuration. After three wrong passwords at startup (or when opening the console), Input.Observer offers Browse for a configuration file, Start fresh with a new default configuration or Close Input.Observer (Recovery). Browsing or starting fresh renames the protected file aside, still encrypted, rather than deleting it, so it can still be opened if you remember the password later. An exported file you kept is plain text and can be imported into the fresh configuration (Import and export). Backups in the Backup folder are encrypted with the password that was in use when each was made.
  • License. If you cancel the license password prompt at startup, Input.Observer says it can't read your license file and then asks you to activate, as if no license were there. Enter your license email and key again (About and license).
  • Console. The console won't open without the password. Its file only holds the console's script editor text and window position; deleting console.toml from your configuration folder lets the console open again, empty. If Input.Observer then reports that the protected files aren't all in the same state, choose to protect all three.