Emergency Vault: Phone-Free Document Recovery

Zero-knowledge AES-256-GCM. Ciphertext only ever leaves this page.

⚠ Warning: Secondary emergency backup tool. Keep physical copies safe. The Worker never receives your passphrase or plaintext.

API Endpoint

Step 1 · New Vault

1. Account Registration & Master Passphrase

Generate a 5-word UPPERCASE passphrase (each word ends with a random digit 0–9). A local AES key and PBKDF2 verifier are derived on this device. Then register the Account ID with POST /api/register — the Worker receives only the verifier hash and salt, never the passphrase.

No passphrase generated yet.
No vault initialized on this device yet.
Step 2 · Daily Use

2. Unlock Vault

Tap your passphrase on the keys below (A–Z, 0–9, and SPACE). Physical typing is disabled. Input is masked on screen. Unlock derives the local AES key, then authenticates with POST /api/login. On a new device, enter your existing Account ID above — no local registration session is required.

Step 3 · Emergency Only

3. Emergency Account Recovery

Lost your passphrase? Generate a new passphrase above, then click 'Reset Vault' to wipe local memory and re-register your Account ID with a fresh master verifier.