module

Secrets::Recovery

Paper recovery: export the age private key as a passphrase-encrypted blob (printable ASCII). Used at init (to print and store at the physical safe) and at master-key import after losing the Mac.

Flow:

init: identity <- MasterKey.generate! passphrase <- Diceware.generate (proposed, accepted) paper <- Recovery.export(identity, passphrase) print(paper, passphrase) ← user records both

import (new Mac): paper <- user retypes from physical paper passphrase <- user retypes Diceware identity <- Recovery.import(paper, passphrase) MasterKey.install!(identity)

Instance methods

export(identity : String, passphrase : String) : String

Encrypt the age private key (AGE-SECRET-KEY-1...) with the passphrase. Returns ASCII text (PEM-like markers + base64).

Source
import(paper : String, passphrase : String) : String

Decrypt a paper blob into the original age private key. Validates that the result looks like an AGE-SECRET-KEY-1....

Source