Some notes are nobody's business. MojoPad encrypts at two levels, both with AES-256-GCM and scrypt key derivation — modern, audited primitives.
A password is always typed into a window of MojoPad's own — a small panel in front of your wiki, never a box inside the page you were reading. That is deliberate, and it is the one thing about encryption you can actually see, so it is worth a paragraph.
A page in a wiki can carry a script, and you can choose to let it run. Code you have allowed runs inside the window you are reading in — which used to mean it shared a room with the box you typed your password into. Refusing to let code press buttons does not help here: reading a box is not pressing anything. And a password you typed once was kept in that same room for the rest of the session, so your edits could be sealed again each time you saved.
Both of those have moved out. The panel that asks is its own window, which a document's code cannot see into; and what you type goes straight to the part of MojoPad that does the encrypting, so the window you are reading in never holds your password at all — not while you type it, and not afterwards. A wrong password is refused in the panel, beside the box, so you can try again without losing your place.
What you will notice: a locked page shows an Unlock button rather than a box, and Encrypt Page and Set Document Password ask in the panel. Unlocking a page you already opened earlier in the same session does not ask again. Everything else is as it was.
Edit ▸ Encrypt Page… (⇧⌘E). Choose a password (and an optional hint).
From then on the page's content exists on disk only as ciphertext. Locked pages show a
lock screen in the editor and a 🔒 in the page list, and they are excluded from
search, linking, exports, AI indexing, the web server, and Static Publishing —
no leaks through side doors. Unlock with the password; the page stays unlocked until
the document closes (or the re-lock timer fires).
Its saved versions are deleted at that moment, and this cannot be undone. Every earlier draft of that page was sitting on disk as plain text — encrypting the page while leaving its history beside it would protect nothing at all, so the history goes. MojoPad says so when it happens. If some earlier draft matters more than the secrecy does, copy it out before you encrypt. (A password on the whole document behaves differently — see below — because there it can encrypt the history rather than destroy it.)
File ▸ Set Document Password… protects the whole document: every page's name and content is encrypted at rest, and the document demands the password when opened. Change or remove the password from the same menu (you'll need the current one). There is no recovery — MojoPad never stores your password; a forgotten password means the content is gone. That's the point.
If you keep the wiki on more than one Mac, set, change or remove its password only while the wiki is closed on the others. The other Macs pick up the change the next time they open it. Changed while the wiki is open on two Macs at once, a page saved on one of them in the moment the change is still arriving can end up locked with a password neither Mac holds any more (see On a shared or synced drive).
What's covered, precisely. Page names and page content, of course — but also everything about your writing that is just as telling. The rule is now the other way round from where it started: a page keeps nothing readable except the machinery needed to list and unlock it, and anything new is covered by default rather than having to be remembered. So that means your text and titles, aliases and tags, the notes and synopsis you keep beside a page, the names of files you attached, the path of any file a page mirrors, the text pulled out of your PDFs and books, your reading highlights, video transcripts, page icons and cover pictures — and, in the document as a whole, your folder tree and every page title in it, your belief stamps (the sentences you wrote about changing your mind), your task areas, projects, goals and labels, your territory names, the paths of folders the document follows, which pages you pinned, and the links you drew between pages by hand.
And your history, which is the part people forget. MojoPad keeps saved versions of your pages, and a saved version is a complete copy of a page as it was earlier. Setting a password takes all of them too, along with your saved conversations, the meaning index, the text pulled from your books, and the earlier looks kept for your page styles (MojoPad keeps the look each save replaced) — including versions of pages you have since deleted, which is exactly the history somebody would want. It used to be that locking a document protected the pages and left the history beside them readable, so a wiki you had kept for months was sealed at the front and open at the back. Now the lock takes everything, in one go, at the moment you set the password. If any of it can't be taken, MojoPad tells you how much, and what kind — a saved conversation, an earlier look kept for your page styles, saved versions of your pages, or the search text built from them. For a conversation, for saved versions and for the search text, setting the password again tries once more. A look is different, and MojoPad says so at the time: while the password is on it leaves any unlocked look alone, because it cannot tell one of yours from one somebody else put there — so setting the password again will not reach it, and removing the password and setting it once more is what does. A conversation is the one whose absence you would notice: it is not lost, but if you have just changed the password it stays under the old one and will not appear in your conversations until this succeeds, and if you have just set a password it is still readable without it. MojoPad will not report a document as protected while part of it is still readable.
What deliberately stays readable is the machinery a locked document needs in order to be unlocked: which version of the format it is, when it was created and last changed, how many pages it has, and the scrambling data the password is checked against. Someone with the file and no password can see that a MojoPad document exists and roughly how big it is. They cannot read a word you wrote, or what any page is called.
What is not covered, and this matters: whole files you brought in. A PDF you attached, a snapshot of a web page you clipped, an audio or video recording — the page about them is encrypted, but the file itself sits inside the document package unencrypted, and its own name is taken from the title it arrived with. Someone with the document and no password cannot read your notes on a paper, but they can open the paper, and they can see from the name what a snapshot was of.
So a document password is not the right tool on its own for a file that is itself the secret. For that, use FileVault, which every Mac has, so the whole disk is encrypted when it is off or locked — and keep in mind that a document password protects what you wrote, which is a different thing from what you collected. Encrypting the attachments themselves is coming; until it does, this page would rather tell you than leave you to assume.
Opening one of those files in another app. The app that opens a file keeps copies of its own on your Mac — its autosaves and its list of recent files — and MojoPad cannot reach them to clean them up. So in a wiki with a password, or on a page with a password of its own, MojoPad asks every time before it hands a file to another app, and nothing is handed over until you say yes. Edit Page in External Editor asks too, before it writes anything: your editor needs a readable copy of the page while you work. That copy is kept in your Mac’s temporary folder, readable only by you, and MojoPad deletes it when you close the window or quit.
Documents you locked with an earlier version of MojoPad are brought up to this the first time you unlock them — no action needed, and the password doesn't change.
Settings ▸ Security ▸ Re-lock encrypted content: after 1, 5, 15, or 60 idle minutes, unlocked encrypted pages lock themselves (their plaintext is dropped from memory) and password-protected documents close — except one with changes waiting on the bar that says it was changed on another device, which is covered by its lock screen instead and stays open behind it, so those changes can still be saved (see On a shared or synced drive). A wiki whose password was set on another Mac while it was open here, and not yet unlocked here, is covered by its lock screen too (see Two Macs and a password). Off by default; recommended on a shared Mac.
With the wiki open in more than one window — a second window, or a reference card — each window keeps its own time, and a page locks in a window once that window has been idle. It stays open in any other window you are still using there, so the one you are writing in never loses what you type to a window you left alone; once every window has gone idle, the page is locked everywhere and the next read asks for its password again.
If a page ever is locked before your latest change to it could be saved, MojoPad says so at once and shows the page locked, rather than letting you keep typing into a page that cannot keep it.