identitykeysLet's Encrypt account

Let's Encrypt account

acme-account·5-of-15·ECDSA-secp256r1 (CGGMP24)·key:kms:le:account
Both recovery paths configured.
Off-Grid seedconfigured

A 24-word seed encrypted to a key we never see. If you lose every device, the seed alone can recover this key.

Social recovery5 guardians · 3-of-5

3 of 5 guardians acting together can rotate the primary DID after a 30-day veto window.

Manage guardians
If you ever need to recover
  1. From a recovery device, click “I’ve lost access”. The wizard offers two paths.
  2. Seed path: enter your 24 words → submit on-chain → wait ~5 min for finality → new pubkey, fresh cert auto-issued.
  3. Social path: notify guardians → each opens a recovery URL on their device → 3 sign → on-chain initiate → 30-day veto starts.
  4. During the veto window, any of your existing devices can cancel the rotation. After the window expires, the new device controls the key.
  5. Re-issue caps. Old capabilities are automatically revoked at rotation. Issue new ones for your services.