Trusted Devices
Trusted devices let you move encrypted account access to a new browser or device with help from a device you already trust.
Add a device
Section titled “Add a device”Start the device approval flow on the new device with Unlock with Another Device, then approve it from an existing trusted device in account security. The approving device creates an encrypted envelope that only the requesting device can consume.
The new device shows a verification code while it waits. On the trusted device, open account security, refresh pending device approvals, and approve only the request with the same code.
Approvals expire. If a request is old or unexpected, deny it and start again from a device you control.
A trusted device is an unlock path for encrypted account material. It is not just a remember-me checkbox. Only approve a browser or device that you control, and use a name you will recognize later.
Locked-key state
Section titled “Locked-key state”After signing in on a new browser, the account may be authenticated but key locked. In that state, ordinary account access can work, but zero-knowledge applications cannot receive a client app key yet.
Trusted-device approval moves the new browser from key locked to key unlocked by transferring an encrypted envelope. If no trusted device is available, use another configured unlock method, such as password-derived unlock, passkey PRF, or a recovery key.
If a browser was signed in with federation or an authentication-only passkey, it may still need this approval step before a zero-knowledge app can open encrypted data.
Manage devices
Section titled “Manage devices”Review trusted devices from account security. Revoke devices that are lost, shared, retired, or no longer yours.
Revoking a trusted device prevents future use of that device envelope. It does not erase data already copied out of a compromised browser or device, so revoke quickly when access is in doubt.
What others can see
Section titled “What others can see”Admins and the DarkAuth backend can see trusted-device metadata and approval state. They cannot see plaintext account keys, trusted-device envelope keys, recovery keys, or client app keys.