> For the complete documentation index, see [llms.txt](https://docs.redacted.money/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.redacted.money/using-redacted/sessions.md).

# Sign-in and Sessions

Redacted replaces the usual routine of signing every action with a simpler one. You unlock once, act freely, and the session locks itself.

## Unlock Private Mode

Connect your wallet, tap the ghost icon and choose **Sign to Unlock**. Your wallet signs a message (on Keplr mobile there are two quick approvals with a **Continue** in between). That signature deterministically derives your private keys, right in your browser, and nothing is sent anywhere or recorded on-chain.

While a session is unlocked, every supported action, from a swap to a withdrawal, runs on browser-generated proofs and your wallet stays silent. The one time it speaks again is when you fund the Reserve from your public balance, because that transfer is your public wallet acting.

## How sessions work

Your session survives a reload in the same tab, so an accidental refresh doesn't log you out. After 15 minutes without activity, private access locks itself. Scrolling, typing and tapping count as activity, and background price feeds don't. When a session expires you get a clear **Sign in again** prompt, and nothing happens without you, since there is no silent fallback to your public wallet and no signature is requested until you ask.

Locking is instant and free because your keys only ever lived in your browser's memory. There is no server session to revoke, because no server holds your keys.

## Passkeys

A passkey is the sign-in method that your device or password manager already offers on many sites. You confirm it with the check that unlocks your device, or with a hardware key. Redacted can use one as an extra lock on a single device.

There are two settings, both optional and both off until you turn them on. To find them, open the account menu while you are unlocked and choose **Privacy on this device**. Each setting belongs to the account you have open and to the device you are using. On a new device, sign in with your wallet once and turn the settings on there.

{% hint style="info" %}
**Coming soon.** Passkeys arrive with the launch, and this section describes how they will work.
{% endhint %}

### Passkey for withdrawals and sends

Turn on **Passkey for withdrawals and sends** and the app asks for your passkey before your account sends money out and before it makes a recovery backup, because a backup carries your account's key.

| Action                                                                                   | Asks for your passkey |
| ---------------------------------------------------------------------------------------- | --------------------- |
| Withdraw from the Reserve to a public address                                            | Yes                   |
| Send from Spending to another address, including a swap that pays out to another address | Yes                   |
| Export a recovery backup                                                                 | Yes                   |
| Swaps, orders, lending and staking that stay inside your account                         | No                    |
| Move funds between the Reserve and Spending                                              | No                    |

It asks every time, including before each part of a split withdrawal. If you don't confirm, the action stops and nothing leaves your account. Turning the setting off asks for your passkey first.

### Passkey at unlock

**Passkey at unlock** decides what opens Private Mode on this device.

| Choice              | What opens Private Mode on this device             |
| ------------------- | -------------------------------------------------- |
| Off                 | Your wallet's signature, as always                 |
| Unlock with passkey | Your passkey, in place of a wallet popup           |
| Passkey and wallet  | Your wallet's signature and your passkey, together |

Choosing **Unlock with passkey** saves you the wallet popup each time you reopen Private Mode on this device. The sign-in window then shows **Unlock with passkey** next to **Sign to Unlock**, and your wallet only has to stay connected. The device keeps your account's key sealed so that only your passkey opens it, which means anyone who can use your passkey on this device can open your account on it. That puts the protection at about the same level as your device's own lock. Your wallet's signature still opens the account as it always did. If you rely on a hardware wallet's confirmation at every unlock, **Passkey and wallet** keeps it.

Choosing **Passkey and wallet** adds a second factor. Unlocking asks for your wallet's signature and your passkey, which helps when someone else uses your browser and can approve your wallet. The device keeps no key for this choice. After your wallet has signed, the app shows **Confirm passkey**, and your passkey prompt follows your tap.

### What a passkey protects

A passkey protects the session on this device, for example when someone else uses your unlocked browser, and it adds no key on the chain. Your passkey stays with your device or password manager. The app keeps a sealed record in this browser, and nothing about it goes to a server or onto the chain. Your account itself is still opened by your wallet's signature or your recovery backup on any device, so a lost passkey never costs you your account.

A passkey guards the session against people at your device. Code that runs inside your browser, such as a harmful extension, can still reach an unlocked session, so a clean browser stays part of the routine (see [Use a clean browser](/using-redacted/stay-safe.md#use-a-clean-browser)).

### If you lose a passkey

Your wallet's signature and your recovery backup still open your account, and the steps below take you back in.

* Lock Private Mode, then choose **Lost your passkey? Unlock with your wallet and turn passkeys off** in the sign-in window. Your wallet signs and your account opens, and both passkey settings of that account then switch off on this device. You can make a new passkey afterwards.
* If only a backup opens your account, restore it in another browser, where the passkey settings start off.

### Turning passkeys on

Choose a setting and the app asks you to make a passkey. Setup usually asks you to confirm twice, once when the passkey is made and once when the app tries it. Changing or turning off a setting asks for its passkey first. Each setting makes its own passkey, so you may see two Redacted passkeys in your password manager.

Passkeys work here when they support a feature called PRF. Recent versions of Safari and Chrome have it. It works with passkeys in the Google Password Manager and iCloud Keychain, and with many other password managers and hardware keys. The in-app browsers of wallet apps often can't use passkeys. The settings are greyed out there with a short explanation, and a regular browser that supports passkeys works.

## Under the hood

Key derivation is scoped to your wallet, the chain and the deployment, and the app verifies that your wallet signs deterministically before trusting the result. The reload cache keeps session material encrypted in browser storage, bound to your wallet and provider.

Passkey settings use the PRF extension of WebAuthn, the standard behind passkeys. Your passkey gives the app a secret that stays on your device, and the app turns it into an encryption key with HKDF-SHA256 and AES-256-GCM. A setting seals what it protects under that key, bound to your account and your passkey, and browser storage keeps the sealed bytes with the passkey's id and a salt. The secret itself is never stored, and because each setting has its own passkey, what one setting sealed opens for no other.

A session is only a convenience. Your [recovery backup](/using-redacted/backup-and-recovery.md) is what guarantees access, and once you have saved it, no browser, wallet or device is a single point of failure.
