Every USERNAME.md handle is backed by an Ed25519 keypair that signs your profile,
your did:web document, and your verifiable claims.
BYOK decides who holds that key — from "generated it myself" to
"it never leaves my hardware" to "my cloud, my KMS, my kill switch."
Start where you are. Each level strictly reduces what we can do with your keys.
Generate your Ed25519 keypair on your own machine and import it from the Panel or the API. We encrypt it at rest under the platform key-encryption key and sign with it on your behalf — your key, our custody. If you lose your copy, we can still recover your account.
Included with Pro · $49/yrYour private key never touches our infrastructure. Register the public key, sign your profile artifacts offline — laptop, CI job, HSM — and publish the signed artifact. We verify against your registered key and serve it. We provably cannot sign as you, and we cannot recover a lost key. That's the point.
EnterpriseClassic enterprise BYOK: your tenant's data is encrypted under an AWS KMS key that lives in your account, reached by cross-account grant. Revoke the grant and the data is cryptographically shredded — your compliance team's favorite sentence in this paragraph.
Enterprise add-onWhat each level means when things go right — and when they don't.
| Key Import | Zero-Custody | Customer KMS | |
|---|---|---|---|
| who generates the key | You | You | You (in your AWS account) |
| who can sign with it | Us, for you | Only you | Us, until you revoke |
| where it lives | Encrypted in our database | Wherever you keep it | Your KMS, never exported |
| lost-key recovery | We can recover you | Nobody can — by design | Your KMS backup policy |
| instant kill switch | Revoke in Panel | Stop publishing | Revoke the KMS grant |
Credentials, Keybase proofs, and ATProto binds signed with your old key stop
chaining to your published key the moment you import. You'll re-issue them under the new key. That's not a bug:
it's what "the key changed" is supposed to mean in a system where signatures are the product. The Panel makes you
confirm this in writing, and the API requires the literal phrase replace-signing-key.
Coming for Enterprise: Split-Key Signatures — your agent and you each hold half the signing power, so neither can act alone. Ask about the design-partner program.
Key Import ships with Pro today. Zero-custody and customer-managed KMS are onboarding a small group of design partners now — compliance-driven teams get priority.