Dashlane

<< Click to Display Table of Contents >>

Navigation:  Using SyncBackPro > Basic Operation > Secrets Manager >

Dashlane

 

warning

The Dashlane steps on this page are a summary, and Dashlane may change them at any time. The definitive instructions are the ones on the Dashlane CLI web site: https://cli.dashlane.com/personal/devices

 

SyncBackPro can retrieve logins, passwords, secure notes and secrets from Dashlane. Dashlane has no web API for the contents of a vault, because a vault is only ever decrypted on your own devices. SyncBackPro therefore uses the Dashlane CLI (dcli.exe), a free and open source program from Dashlane, and signs in with it as a non-interactive device.

 

 

What You Need

 

•A Dashlane account that is used only by SyncBackPro. Dashlane recommends a separate account for non-interactive devices. Share with it just the items that SyncBackPro needs. The account must have a master password: passwordless accounts, and accounts that use single sign-on (SSO), cannot be used. It must also not be set to ask for a one-time password at every login.

•The Dashlane CLI for Windows, version 6.2412.0 or later, from the Dashlane CLI releases page.

•The Microsoft Visual C++ Redistributable for Visual Studio 2015-2022 (x64). The Dashlane CLI will not start without it.

•64-bit Windows. The Dashlane CLI is only available for 64-bit Windows.

•Internet access to Dashlane from the computer running SyncBackPro.

 

 

Step 1: Install the Dashlane CLI

 

Download dcli-win-x64-signed.exe from the releases page, rename it to dcli.exe and save it somewhere every user account that runs your profiles can read, e.g. C:\Program Files\Dashlane CLI\dcli.exe. To check that it works, open a command prompt and run:

 

 "C:\Program Files\Dashlane CLI\dcli.exe" --version

 

It should print a version number. If it says The specified module could not be found then install the Visual C++ Redistributable and try again.

 

 

Step 2: Register a Device for SyncBack

 

In the same command prompt run:

 

 dcli devices register "SyncBack"

 

You are then taken through these steps:

 

1.Enter the email address of the Dashlane account.

2.The command shows a web address. Open it in a web browser, and the page gives you a token, a long code made of letters, digits and dashes. Enter it at the prompt Please enter the token given in the browser.

3.Dashlane then emails a 6-digit code to the account. Enter it at the next prompt. If the account uses an authenticator app for two-factor authentication, enter the code from the app instead.

4.Enter the master password of the account.

 

The command then prints a line like this:

 

 DASHLANE_SERVICE_DEVICE_KEYS=dls_...

 

Copy everything from dls_ to the end of the line. These are the device keys. They are shown only once, and they contain the master password of the account, so treat them as you would the master password itself.

 

If you later change the master password of the account then the device keys stop working, and you must register a new device.

 

 

Step 3: Create the Connection

 

In SyncBackPro, go to the Secrets Manager (via the main burger menu), go to the Connections page, click Create and choose Dashlane. You are then asked for:

 

 Name: The name you want to give to the connection. This is for your reference.

 Path to dcli.exe: Where you saved the Dashlane CLI in step 1. If you leave it blank then SyncBackPro looks for dcli.exe on the path.

 Device Keys: The device keys from step 2, starting with dls_.

 

SyncBackPro connects immediately and lists the items in the vault, so you will know straight away if any of the details are wrong. The first time can take a little longer as the vault is downloaded. You then create secrets that use the connection in the usual way, as described in Secrets Manager.

 

 

Which Items Can Be Used

 

•Logins: you choose whether the secret is the login, email or password of the item.

•Secure Notes and Secrets: the whole text is used. For example, an SFTP private key can be kept in a secure note. Secrets are only available in Dashlane's business plans (Password Management and Credential Protection); logins and secure notes are available in every plan.

 

Items are listed by their title, and a login without a title is listed by its web site address. The title must match exactly, including upper and lower case. Give each item a unique title. If items of different kinds have the same title, a login is used before a secure note, and a secure note before a secret. Two items of the same kind with the same title, for example two logins, are refused with an error rather than guessed at, because the username and password could otherwise come from different items.

 

Renaming an item breaks the profiles that use it. SyncBackPro remembers a Dashlane item by its title and nothing else. If you rename the item in Dashlane, every profile that uses that secret fails with Secret does not exist until you modify the secret in the Secrets Manager and select the item under its new title. The same happens if the item is deleted, or is no longer shared with the account.

 

Also, if you give a different item the old title, SyncBackPro will use that item from then on, without any warning. So once an item is used by a profile, do not rename it, and do not reuse its old title for anything else.

 

 

Elevated, Scheduled and Administrator Protection

 

SyncBackPro does not use any Dashlane login stored in your Windows profile. Each time it connects it gives the Dashlane CLI its own temporary folder, which is deleted afterwards, and nothing is stored in Windows Credential Manager. A Dashlane connection therefore works in the same way when SyncBackPro is run normally, run elevated, run under Administrator Protection, or run from a scheduled task, including one that runs whether or not the user is logged on. The account the profile runs as must be able to reach Dashlane over the Internet.

 

 

Security

 

•The device keys are stored, encrypted, in the SyncBackPro settings. The value of a secret is never stored locally nor shown to the user.

•The device keys contain the master password of the Dashlane account, which is one reason to use an account that holds only the items SyncBackPro needs.

•To stop SyncBackPro retrieving secrets, remove its device from the Dashlane account, e.g. with dcli devices list and dcli devices remove.

•While a profile runs, an encrypted copy of the vault is kept in a temporary folder, so that all the Dashlane secrets the profile uses can share one connection. It is deleted when the profile finishes.

•Do not also use the same Dashlane account with the Dashlane CLI yourself, under the same Windows account. SyncBackPro removes the Credential Manager entry that the Dashlane CLI keeps for that account.

 

 

Limitations

 

•SyncBackPro only reads from Dashlane. It never creates, changes or deletes items.

•Every profile run that uses a Dashlane secret signs in to Dashlane and downloads the vault, which takes several seconds and needs Internet access. This happens once per run for each connection, not once per secret, as the secrets of a run share one connection.

•The Dashlane CLI cannot use a proxy server. It ignores the Windows proxy settings and the HTTPS_PROXY environment variable, so the computer, and the account the profile runs as, need direct HTTPS access (port 443) to *.dashlane.com.

•Passwordless accounts, accounts that use single sign-on (SSO), and accounts that ask for a one-time password at every login cannot be used.

•Other item types, e.g. passkeys, payments, IDs and attachments, cannot be used.

•Items are found by their title only, so renaming an item in Dashlane breaks every profile that uses it until the secret is selected again. See Which Items Can Be Used above.

 

 

Troubleshooting

 

The specified module could not be found: the Visual C++ Redistributable (x64) is not installed.

 

The Dashlane CLI (dcli.exe) was not found: the path in the connection is wrong, or it is blank and dcli.exe is not on the path. If SyncBackPro is run as another user, e.g. from a scheduled task, check that user can read the file.

 

The Dashlane CLI is version ...: the Dashlane CLI is too old to use device keys. Download the latest version.

 

... is not the Dashlane CLI as signed by Dashlane: the device keys unlock your whole vault, so SyncBackPro only gives them to a dcli.exe that carries Dashlane's own digital signature. The file is the unsigned download (dcli-win-x64.exe), has been changed or damaged, or is a different program. Download dcli-win-x64-signed.exe again. While a profile is using the Dashlane CLI, dcli.exe cannot be replaced, so update it when no profiles are running.

 

The Dashlane CLI needs 64-bit Windows: Dashlane does not provide the CLI for 32-bit Windows, so Dashlane cannot be used on this computer.

 

Error while verifying the master password: the device keys are wrong, the device has been removed from the account, or the master password has changed since the device was registered. Register a new device and modify the connection to use its keys. If the message ends with a network code, such as ECONNREFUSED, ETIMEDOUT or ENOTFOUND, the keys are not the problem: the Dashlane CLI could not reach Dashlane (see below).

 

The Dashlane CLI did not finish within 120 seconds: the computer, or the account the profile runs as, cannot reach Dashlane. Check the Internet connection and the firewall. The Dashlane CLI cannot use a proxy server, so a network that only allows Internet access through a proxy must allow direct HTTPS access to *.dashlane.com.

 

More than one Dashlane login is called ...: two items of the same kind have the same title. Rename one of them so that every title is unique, then, if needed, modify the secret in the Secrets Manager and select the item again.

 

Secret does not exist: the item has been renamed or deleted in Dashlane, or is no longer shared with the account. Modify the secret in the Secrets Manager and select the item again.

 

No secrets are listed: the account has no logins, secure notes or secrets. Check that the items have been shared with the account.

 

See also: Secrets Manager

 

 

 

All Content: 2BrightSparks Pte Ltd © 2003-2026