Set up this phone as a signer
The AWS secret key will live only on this phone, inside one encrypted vault. Every signature costs one tap.
Fresh device — no vault here yet. Keys stay on the device that creates them; setting up here will not pull a vault from another phone or laptop. If you already have a vault elsewhere, that device keeps it.
Once set up, this phone can
- approve signatures — one tap per AWS request
- hold the vault — hosts (laptops) borrow the capability, never the key
- pair & verify hosts — link a laptop, confirm it by QR or safety words
- show where it stands — its role, the keys it holds, and an activity ledger
Vault custody
Biometric-gated. Preferred.
No passkey support? Use a passphrase (weaker)
amber custody: no hardware gating.
Enclave custody unavailable
This vault is enclave-wrapped (passkey PRF) but the authenticator did not return a PRF result. Refusing to downgrade to a weaker unlock. Nothing was signed.
identity fingerprint (R2 word list — 32 words)
This phone's own fingerprint. A host that pairs with you shows the same words (secret phone identity) — compare to confirm you're talking to the right phone.
raw 256-bit fingerprint (hex)
Pending requests 0
No pending requests. A request that arrives over the relay pops here for one-tap approval. Nothing is signed without your biometric.
What you can be asked to approve
Every kind of approval this device answers. One tap each — never batch-approved.
Off-network request
On an air-gapped / library PC the host shows a request QR instead of using the relay.
Verify a host
Scan the host's identity QR. This phone byte-compares it to the host you paired with and shows one verdict — you read no fingerprint.
Keys
Alias names and secret keys live inside the encrypted vault; unlocking requires your custody factor. The key never leaves this phone.
Add a key
Grants
What each key is allowed to do — deny-all by default, you add the one verb it needs.
Grants are enforced where the key is used (keel-secret / secretd), not on the phone. There is nothing to configure here yet.
Coming soon: per-key allow rows synced from your vault.
Activity 0
Local audit ledger — every approve / deny / pair / verify, newest first. Stored on this phone only; survives reload. Never leaves the device.
Pair a host
Show this QR to the host machine (it pastes the decoded JSON). It contains only public data.
…or copy the payload text and paste it into secret phone pair <name> '<payload>':
Paired hosts
Link a device
Link another keel device (a phone, a Pi) as a co-custodian. Show this code to the other device and scan theirs. Both of you compare the safety words before linking — a device that isn't safety-confirmed can never outrank yours.
Linked devices
Custody
Recovery & transfer
Move or replicate custody to another device; back up with Shamir shares or a recovery passphrase.
Coming soon — no backend on this phone yet. Secure defaults mean most keys never need this.