Recovery
Recovery happens inside the extension
Nythera recovery is designed around the same principle as creation: the website should coordinate the process, not receive the secret.
An approved wallet can start recovery. Story CDR handles access-controlled recovery. The extension collects and decrypts the result.
Recovery flow
What happens when someone clicks Recover
The website checks whether the connected wallet is allowed to recover the vault. If access is approved, the extension prepares recovery key material and the wallet submits a CDR read transaction.
Step 1
1. Verify access
Website checks whether the wallet can recover this vault.
Step 2
2. Prepare key
Extension creates the recovery keypair.
Step 3
3. Read from CDR
Wallet submits the read request.
Step 4
4. Validators respond
Extension collects recovery partials.
Step 5
5. Display in extension
Recovered content opens in the recovery page.
Display model
The recovery page is temporary by design
Recovered content is not immediately shown. The recovery page first presents a locked state. The user must explicitly reveal the secret.
A visible 60-second timer starts when recovered content arrives. The user can clear immediately, or the page clears automatically.
Website response
What the website receives during recovery
The website receives recovery status only. It can show whether recovery succeeded or failed, but it does not receive the recovered secret.
Allowed and forbidden recovery responses
Allowed: { ok: true } or { error: "..." }.
Forbidden: secret, plaintext, decryptedData, fileBytes, AES key, or recovered file bytes.