Vault Creation

How a Nythera vault is created

Vault creation has two jobs: protect the secret and define who can recover it later.

Nythera keeps those jobs separate. The website manages the vault workflow. The extension handles plaintext and encryption.

Creation flow

Step-by-step

The website guides the user through naming the vault, choosing trusted contacts, and signing the required wallet transactions. The secret itself is entered in the extension.

Step 1

1. Start vault

User chooses what to protect and names the vault.

Step 2

2. Enter in extension

Seed phrase, key, password, or note is typed in the extension popup.

Step 3

3. Allocate CDR vault

Website creates the vault and access policy through Story CDR.

Step 4

4. Encrypt

Extension encrypts with Story CDR threshold encryption.

Step 5

5. Store ciphertext

Website writes encrypted data only.

Encryption

How encryption works

For text secrets, the extension fetches the Story DKG public key, derives the CDR label from the vault UUID, and performs TDH2 encryption.

After encryption succeeds, the extension clears the pending plaintext and returns ciphertext to the website.

Technical encryption sequence

1. Website allocates a vault and receives a numeric UUID.

2. Website asks the extension to encrypt for that UUID.

3. Extension fetches the Story DKG public key.

4. Extension derives the encryption label from the UUID.

5. Extension TDH2-encrypts the plaintext.

6. Extension returns hex ciphertext.

7. Website writes ciphertext to CDR.

Files

File vault transparency

File vaults have a different trust boundary in the current build. Text secrets are encrypted inside the extension. Files are currently encrypted inside the browser page before storage.

Nythera shows this distinction in the product so users and reviewers understand the current security model.