Status
Enrollment
Ordinary backup registration
Register the ordinary backup before continuing. It remains the first fallback when the primary is unavailable and is not Recovery-passkey material.
Recovery-passkey setup
Each slot must be a distinct, user-verifying, single-device, non-backed-up credential. The server selects the next slot. Both slots are recovery-only and cannot authenticate an ordinary session.
Authentication
Authenticate with a normal primary or backup passkey. If either works, use this ordinary path instead of Recovery-passkey. Successful normal authentication cancels a pending recovery attempt. Reloading clears the memory-only CSRF token.
Total-loss credential recovery
Use this only to declare that every normal primary and backup passkey is unavailable. The service cannot prove physical loss. A usable backup must be used through ordinary authentication instead.
Initiation and completion each require fresh assertions from both dedicated Recovery-passkeys. A valid initiation starts a fixed 72-hour notice interval and expires after 168 hours. Normal authentication, an explicit veto, or another authenticated POST cancels the attempt.
Inbound message
Outbound message
This client only receives and acknowledges outbound messages that already exist. It never creates an Enki reply.