Settings
Tokens instead of passwords, keys instead of accounts. Everything here is the only copy — we store hashes.
Access tokens
Your token is the account. Anyone holding it holds everything.
Shown masked by default. Reveal only on a private screen — shoulder-surfers are a real threat model.
There is no recovery. We store only a hash of your token — we cannot reset what we never knew. Lose every token and the account, its services and its credit are gone. Keep the primary token offline and use sub-tokens for daily work.
| Label | Token | Scope | Created | Last used |
|---|
Security
Two-factor and active sessions.
Sessions
Devices currently holding your token in storage.
SSH keys
Injected automatically on deploy and rebuild. Password auth stays disabled.
| Name | Fingerprint | Key | Added |
|---|
Paste the .pub contents — never the private key. Fingerprint is computed locally as SHA256.
Preferences
Defaults that pre-fill the Deploy form.
Danger zone
Irreversible. By design, there is no "contact support to undo".
Delete this account
All services are wiped immediately. Token hashes are erased at once; the payment ledger (txid + amount only) is purged after a 30-day dispute window. Remaining credit is forfeited — it cannot be sent anywhere without a destination only you could have set in advance.