> For the complete documentation index, see [llms.txt](https://docs.sectoral.xyz/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.sectoral.xyz/privacy-and-cryptography/keys-and-recovery.md).

# Keys and Account Recovery

On Sectoral, self-custody is built into the architecture, not offered as a promise. Your keys are generated on your own device and never leave it. Sectoral's servers keep no copy and never see them unencrypted. You own the account, in the literal sense.

***

## Two keypairs, two jobs

| Keypair            | What it does                                                                                                                              |
| ------------------ | ----------------------------------------------------------------------------------------------------------------------------------------- |
| **Signing key**    | A standard EVM (secp256k1) key that controls your smart account and signs its transactions, the same kind of key any Ethereum wallet uses |
| **Decryption key** | Opens your confidential token balance so you can see your own amounts and transaction history                                             |

Both are derived from one secret created on your hardware when you sign up, and Sectoral never receives either of them in unencrypted form.

***

## Passkey-derived keys

Instead of asking you to write down a recovery phrase, onboarding is built on WebAuthn. You keep full custody without a slip of paper to lose.

1. You sign up using an email address plus a passkey on your device: Face ID, Touch ID, Windows Hello, or a hardware security key.
2. A key derivation function runs over that passkey on your device and produces your Sectoral keypair locally.
3. The private key material is then encrypted and stored in the secure enclave, or whatever your platform provides in its place.
4. All Sectoral ever sees is a public key and the transactions you sign.

This removes the failure that most often breaks self-custody in the real world (a seed phrase noted somewhere and later lost), and it costs you nothing, since you can still export the key whenever you like.

***

## Exporting your key

You can export at any time from **Settings → Security → Export Key**. The result works in any standard EVM wallet, such as MetaMask, Rabby, or Rainbow, because your Sectoral smart account is controlled by an ordinary Ethereum-style key and Robinhood Chain is fully EVM-compatible. You are never locked in.

Keeping that exported key safe is your responsibility. Anyone who has it controls the account.

***

## When a device goes missing

* **Synced passkeys:** if your passkey lives on a second device or with a syncing provider like iCloud Keychain or Google Password Manager, signing in on another device restores access right away.
* **Social recovery (post-beta):** choose trusted contacts who, acting together, can approve a recovery.
* **Exported backup:** a key you exported and kept somewhere safe brings the account back on any device.

Every recovery path requires your key material, by design. Sectoral has no reset button and no way to let you back in, because it never had what that would take.

***

## How this ties into privacy

The decryption key is also what lets you disclose or export data without relying on a middleman. Since only you hold it, only you can view your history or prove what a payment contained to someone else. The same key in the same enclave gives you both control and confidentiality. Read more in [Showing Proof of a Payment](/privacy-and-cryptography/proving-a-payment.md).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.sectoral.xyz/privacy-and-cryptography/keys-and-recovery.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
