Encrypted SSH vault and recovery
The SSH vault is optional and available on Supporter, Patron, and Legend. It keeps saved hosts, portable private keys, and command snippets consistent across your signed-in devices.
Your device creates a random vault key and encrypts the whole snapshot before upload. Your vault password protects that key locally. The recovery code can reset a forgotten password. tokenstat.ai stores only ciphertext, revision metadata, salts, and opaque encrypted key material. It cannot read a hostname, password, private key, or snippet.
Create or restore
Choose Create new on the first device and set a vault password. tokenstat then shows a one-line recovery code once. Store it in a password manager or on paper and complete the confirmation before closing the screen.
Unlock the same account vault on another signed-in device with its password. If you forget the password, enter the recovery code locally and choose a new one. Neither the password nor the recovery code is uploaded in usable form.
The recovery limit is deliberate
The recovery code is the password-reset path. There is no operator-recovery path. If every device able to open the vault, the password, and the recovery code are lost, the vault is permanently inaccessible. Support cannot override this boundary because tokenstat never has a decryption key.
An unlocked device can issue a new recovery code. The former code stops working after the encrypted rotation is accepted.
After a plan downgrade, new synchronized changes pause, but downloading, restoring, exporting, or deleting an existing encrypted vault remains available.
More in Desktop app
