Enki Progenitor

Same-origin local client for enrollment, ordinary authentication, one-shot total-loss credential replacement, communication, and bounded control. Session and continuation cookies are HTTP-only. CSRF stays in memory. This page makes no recoverability claim.

Status

Enrollment

Credential-loss disposition

Choose exactly one. No option is selected by default and no choice is inferred. Selecting permanent lockout is an explicit waiver of post-loss credential replacement.

If recovery-capable setup expires before backup completion, permanent single-passkey lockout is recorded. If it expires after backup completion but before both recovery slots verify, the ordinary backup remains, every partial recovery slot is unusable, and total-loss recovery is unavailable.

Two registrations and authenticator metadata do not prove separate physical custody. Keep the two Recovery-passkeys in separate custody. This client makes no recoverability claim.

After one successful recovery, only the replacement primary remains. No backup can be registered, no Recovery-passkey remains, and any later total normal-credential loss permanently ends communication.

Authentication

Authenticate with a normal primary or backup passkey. If either works, use this ordinary path instead of Recovery-passkey. Successful normal authentication cancels a pending recovery attempt. Reloading clears the memory-only CSRF token.

Total-loss credential recovery

Use this only to declare that every normal primary and backup passkey is unavailable. The service cannot prove physical loss. A usable backup must be used through ordinary authentication instead.

Initiation and completion each require fresh assertions from both dedicated Recovery-passkeys. A valid initiation starts a fixed 72-hour notice interval and expires after 168 hours. Normal authentication, an explicit veto, or another authenticated POST cancels the attempt.

Inbound message

Outbound message

This client only receives and acknowledges outbound messages that already exist. It never creates an Enki reply.


        
        
        

Control