Bring Your Own Key

Your identity. Your key material.

Every USERNAME.md handle is backed by an Ed25519 keypair that signs your profile, your did:web document, and your verifiable claims. BYOK decides who holds that key — from "generated it myself" to "it never leaves my hardware" to "my cloud, my KMS, my kill switch."

Get Pro — $49/yr Talk to us about Enterprise

Three levels of custody

Start where you are. Each level strictly reduces what we can do with your keys.

LEVEL 1 — AVAILABLE NOW

Key Import

Generate your Ed25519 keypair on your own machine and import it from the Panel or the API. We encrypt it at rest under the platform key-encryption key and sign with it on your behalf — your key, our custody. If you lose your copy, we can still recover your account.

Included with Pro · $49/yr
LEVEL 2 — DESIGN PARTNERS

Zero-Custody Publishing

Your private key never touches our infrastructure. Register the public key, sign your profile artifacts offline — laptop, CI job, HSM — and publish the signed artifact. We verify against your registered key and serve it. We provably cannot sign as you, and we cannot recover a lost key. That's the point.

Enterprise
LEVEL 3 — DESIGN PARTNERS

Customer-Managed Keys

Classic enterprise BYOK: your tenant's data is encrypted under an AWS KMS key that lives in your account, reached by cross-account grant. Revoke the grant and the data is cryptographically shredded — your compliance team's favorite sentence in this paragraph.

Enterprise add-on

The custody matrix

What each level means when things go right — and when they don't.

 Key ImportZero-CustodyCustomer KMS
who generates the keyYouYouYou (in your AWS account)
who can sign with itUs, for youOnly youUs, until you revoke
where it livesEncrypted in our databaseWherever you keep itYour KMS, never exported
lost-key recoveryWe can recover youNobody can — by designYour KMS backup policy
instant kill switchRevoke in PanelStop publishingRevoke the KMS grant
$ curl -X PUT https://username.md/v1/users/you/signing-key \
  -H 'Authorization: Bearer un_…' -H 'Content-Type: application/json' \
  -d '{"private_jwk": {"kty":"OKP","crv":"Ed25519","d":"…"}, "confirm": "replace-signing-key"}'
{"handle": "you", "public_jwk": {"kty":"OKP","crv":"Ed25519","x":"…"}, "warning": "Signing key replaced…"}
# did.json, profile JWS, and future credentials now chain to YOUR key.

Read this before you import

Key replacement breaks signature continuity — on purpose.

Credentials, Keybase proofs, and ATProto binds signed with your old key stop chaining to your published key the moment you import. You'll re-issue them under the new key. That's not a bug: it's what "the key changed" is supposed to mean in a system where signatures are the product. The Panel makes you confirm this in writing, and the API requires the literal phrase replace-signing-key.

Coming for Enterprise: Split-Key Signatures — your agent and you each hold half the signing power, so neither can act alone. Ask about the design-partner program.

Hold your own keys.

Key Import ships with Pro today. Zero-custody and customer-managed KMS are onboarding a small group of design partners now — compliance-driven teams get priority.

Subscribe to Pro — $49/yr Become a design partner See all pricing