Vault Creation
How a Nythera vault is created
Vault creation has two jobs: protect the secret and define who can recover it later.
Nythera keeps those jobs separate. The website manages the vault workflow. The extension handles plaintext and encryption.
Creation flow
Step-by-step
The website guides the user through naming the vault, choosing trusted contacts, and signing the required wallet transactions. The secret itself is entered in the extension.
Step 1
1. Start vault
User chooses what to protect and names the vault.
Step 2
2. Enter in extension
Seed phrase, key, password, or note is typed in the extension popup.
Step 3
3. Allocate CDR vault
Website creates the vault and access policy through Story CDR.
Step 4
4. Encrypt
Extension encrypts with Story CDR threshold encryption.
Step 5
5. Store ciphertext
Website writes encrypted data only.
Encryption
How encryption works
For text secrets, the extension fetches the Story DKG public key, derives the CDR label from the vault UUID, and performs TDH2 encryption.
After encryption succeeds, the extension clears the pending plaintext and returns ciphertext to the website.
Technical encryption sequence
1. Website allocates a vault and receives a numeric UUID.
2. Website asks the extension to encrypt for that UUID.
3. Extension fetches the Story DKG public key.
4. Extension derives the encryption label from the UUID.
5. Extension TDH2-encrypts the plaintext.
6. Extension returns hex ciphertext.
7. Website writes ciphertext to CDR.
Files
File vault transparency
File vaults have a different trust boundary in the current build. Text secrets are encrypted inside the extension. Files are currently encrypted inside the browser page before storage.
Nythera shows this distinction in the product so users and reviewers understand the current security model.