Security and recovery

Passkeys authenticate service access. WebAuthn PRF derives the key that opens an encrypted vault in your browser. The service cannot decrypt your EOA keys. It can observe credential associations, ciphertext sizes and request timing.

Recover a wallet

Save each wallet's private key before using it. On another device, use an available passkey with working PRF support. If that is unavailable, import the saved private key into a new vault or an external wallet. This restores the same EOA address and its assets. It does not recover the old vault's labels or other unsaved keys.

There is no email recovery, administrator reset, recovery-code login or automatic cross-provider passkey transfer in this release. Losing all usable passkeys and all saved EOA keys loses access. A newly created wallet needs its own saved private key.

Limits

Storage and operations

Each registered tenant has separate transactional storage. Anonymous account lookup is unavailable. Authentication challenges expire after two minutes and are consumed once. Sessions last ten minutes. APIs use no-store responses and do not use shared caches. Expired provisional enrollment records are removed after one day; operation receipts remain for seven days. Routine logs must exclude request bodies, authentication material and wallet identifiers.

Report a problem

Contact the Thetanuts team through its established support channel with a short description and the affected site/version. Do not send private keys, passkey output, recovery material or authorization headers. There is no public upload endpoint for secrets.