standard-passkey / manage

Passkeys

DeviceTypeAddedLast usedState

Enrol on every device you would be upset to be locked out from. Revoking is refused when only one passkey remains — that would leave you with no way back in.

Recovery key

Shown once and never again. Only a scrypt hash is stored, so this cannot be looked up later. Put it in Keychain now: security add-generic-password -a "$USER" -s WEBAUTHN_PASSKEY_ATSIGN -w

Generating replaces any existing key immediately and resets the lockout counter. Rotate after any use, and after typing it on a machine you do not control.

Invites

An invited address may enrol once, using the shared join secret. Both are needed: the secret alone opens nothing.

Join secret

Shared with everyone you invite. Rotating it does not affect your recovery key, and does not revoke anyone who has already enrolled.

Shown once and never again. Only a scrypt hash is stored, so this cannot be looked up later. Share it with the people you invite — it is useless without an invite naming their address.

Protected sites

HostnameModeState

This list is a registry, not a switch. A site is gated because it imports the verifier; adding a row here records the intent and writes an audit entry, but changes no behaviour. monitor is a note to your future self until something consumes it.

Recent activity

WhenEventResultFromDetail