Firefox stores saved website logins in a browser profile. A Primary Password adds an extra layer around those locally saved credentials and prompts when Firefox needs them in a session. Mozilla warns that without it, someone who can copy the relevant profile files may read stored logins. It is especially useful on a shared computer, but it is not a replacement for separate operating-system accounts, disk encryption or a screen lock. Forgetting it can cost the saved passwords.
Before you start
Inventory important accounts and ensure each has a verified recovery route. If the browser holds the only copy of a unique password, consider a secure independent backup plan before turning on a new vault dependency. Use a long, memorable unique Primary Password and do not store its only copy inside Firefox itself.Do it step by step
- Open Firefox Settings, Privacy & Security, then the password area and enable Use a Primary Password. Enter the new secret in Firefox's native dialog, not a popup from an unrelated webpage.
- Close and reopen Firefox to test the prompt. Try to access a saved login and confirm the Primary Password is required when Firefox needs stored credentials.
- Check the separate OS user account. Everyone who shares the computer should have their own locked login; a Firefox Primary Password cannot stop another user from reading files already downloaded or an open website session.
- If you use Firefox Sync, verify your Mozilla account's own sign-in and recovery independently. The Primary Password can affect when Sync accesses locally stored credentials but is not the Mozilla account password.
- Record the Primary Password in a secure offline or independent password-manager location. Test that you can retrieve that record without opening the same Firefox profile.
- Periodically sign out of sensitive websites and lock the OS session when leaving. An unlocked browser with an active website session can expose account data even if stored passwords are protected.