Settings

Tokens instead of passwords, keys instead of accounts. Everything here is the only copy — we store hashes.

Access tokens

Your token is the account. Anyone holding it holds everything.
Shown masked by default. Reveal only on a private screen — shoulder-surfers are a real threat model.
There is no recovery. We store only a hash of your token — we cannot reset what we never knew. Lose every token and the account, its services and its credit are gone. Keep the primary token offline and use sub-tokens for daily work.
LabelTokenScopeCreatedLast used

Security

Two-factor and active sessions.

Sessions

Devices currently holding your token in storage.

SSH keys

Injected automatically on deploy and rebuild. Password auth stays disabled.
NameFingerprintKeyAdded
Paste the .pub contents — never the private key. Fingerprint is computed locally as SHA256.

Preferences

Defaults that pre-fill the Deploy form.

Danger zone

Irreversible. By design, there is no "contact support to undo".
Delete this account

All services are wiped immediately. Token hashes are erased at once; the payment ledger (txid + amount only) is purged after a 30-day dispute window. Remaining credit is forfeited — it cannot be sent anywhere without a destination only you could have set in advance.