Where Does LastPass Cache Its Vault Locally?
Where the LastPass browser extension caches its encrypted vault copy on Windows, macOS, and Linux.
Last updated
LastPass keeps the real vault on its servers; the browser extension holds an encrypted local cache for offline use. Chrome era paths point at extension storage for ID hdokiejnpimakedhajhdlcegeplioahd, Firefox at profile storage plus a .lastpass folder on Linux.
Those paths shift across browser and extension versions, from legacy SQLite databases files to IndexedDB trees. Never depend on a fixed path: the vault syncs from login, so the account plus master password is the backup. Local files matter to forensics, not to recovery.
Where LastPass stores this, by platform
%LOCALAPPDATA%\Google\Chrome\User Data\Default (extension storage)
Extension cache under the Chrome profile (databases/ legacy, IndexedDB modern) plus %LOCALAPPDATA%/../LocalLow/LastPass for the binary component era. Clear browsing data wipes the cache and forces a fresh sync on next login.
~/.config/google-chrome/Default (extension storage)
Same profile relative extension storage as Windows. Firefox builds keep vault data in the profile folder instead. Linux Firefox also used ~/.lastpass historically; check both spots on old installs.
Frequently asked questions
how do i back up my lastpass vault locally
Nowhere portable. The local copy is an encrypted cache of the server vault, keyed to the browser profile and master password. New machines sign in and sync; there is no file import. Treat any local file as a forensic artifact, not a backup.
where is the lastpass chrome extension data
In the extension storage for ID hdokiejnpimakedhajhdlcegeplioahd: legacy Chrome builds used a databases/ SQLite file, modern builds use IndexedDB/LevelDB under the profile. Firefox keeps its own profile storage plus ~/.lastpass on Linux. Paths move across versions, so confirm against the running browser.
does lastpass store my master password locally
Only with Remember Password enabled, which keeps a decryptable token in the local database. Security guidance says leave it off on shared machines. The 2022 breach showed why local copies deserve the same paranoia as servers.
Notice an outdated path? Let us know.