Skip to content
All guides

TECHNICAL GUIDE

Online Services

Device authentication, connection authorization, encrypted backup transfers, and recovery sessions.

Service architecture

Online Services authorizes account operations, connects devices, and stores encrypted backups. Clients encrypt and decrypt vault contents locally. Local vaults and manual backups do not require an Online Services account.

ConnectionPurpose and data
Client ↔ account APIAuthentication, device permissions, backup metadata, and temporary storage access.
Client ↔ signaling servicePeer presence and connection negotiation for authorized device pairs.
Client ↔ linked clientLive encrypted synchronization over WebRTC, directly or through a TURN relay.
Client ↔ backup storageEncrypted snapshot uploads and downloads using signed URLs issued by the API.

Linked devices exchange encrypted changes and merge them into their local vaults. The servers help establish the connection but do not apply those changes. Managed backups preserve vault contents at the time of upload for later restoration. Devices do not use them to catch up on missed synchronization.

How the account session works

Each enrolled device has an ECDSA P-256 signing key pair. Its private key is stored inside the encrypted vault; the service holds the public key. To authenticate, the API sends a random challenge that can be used only once. The client signs that challenge with its private key using ECDSA with SHA-256 as the hash function. The API verifies the signature against the registered public key, proving that the client holds the corresponding private key. It then issues a short-lived access token and a rotating refresh token.

The master password unlocks the local vault, making the device's private signing key available to the client. Online Services authenticates the device through its signature, without receiving the master password or private key. This account signing key is separate from the post-quantum keys used for device synchronization.

Refreshing a session replaces the refresh token. Reuse of a consumed token revokes that device's sessions. Access also depends on an active server-side session and current device permissions, not just the token's signature and expiry. Logout revokes the current session; removing a device revokes its sessions.

The web app keeps the session in its unlocked application state. The extension service worker owns its session and injects authorization only for allowed API routes. Locking or a 30-minute system idle event clears the extension session and attempts remote revocation.

Managed synchronization services

Managed signaling introduces linked devices and authorizes their presence channel. STUN assists direct connectivity. The API issues short-lived TURN credentials when relay is needed. Once connected, the clients perform their own signed, end-to-end encrypted synchronization protocol. Both vaults must be unlocked and online at the same time; a background window can participate while its client remains running.

The service can observe account/device identifiers, connection timing, addresses and traffic volume needed to operate these network services. Only the linked devices hold the session keys needed to decrypt synchronization traffic. Signaling servers and TURN relays do not receive those keys and cannot read the vault contents exchanged between devices.

The synchronization protocol covers key establishment, message protection, and merging in detail.

Device management and root access

Device registration associates a signing identity with an account. A pairwise link separately authorizes two devices to discover and synchronize with one another. Managed signaling checks both the saved relationship and the account's device-linking entitlement.

A root device has account administration permissions (not operating-system root access). The first registered device is a root device; newly linked devices start without root access. Root permissions govern device enrollment, removal, permission changes, and backup settings. At least one device must retain root access. Demotion revokes the device's existing sessions so subsequent requests use its new permissions.

Unlinking removes a pairwise relationship but keeps both account registrations. Removing a device also removes its account sync relationships. Neither operation remotely erases the device's local vault.

See Manage devices and links for the map, connection statuses, and saved-link cleanup.

Encrypted backup lifecycle

The client creates a .cryx snapshot and encrypts it before transfer. Managed backup copies omit linked-device and sync configuration but retain the encrypted Online Services device binding needed after restore.

  1. Create an upload intent

    The client submits the ciphertext byte length, SHA-256 checksum, and an idempotency key. The API reserves quota for a pending snapshot and returns a temporary signed upload URL.

  2. Transfer ciphertext

    The client uploads directly to storage. Retrying the same snapshot reuses its encrypted bytes and idempotency key rather than creating another backup.

  3. Complete the snapshot

    The API checks the stored object's size and checksum metadata before marking the snapshot ready. Incomplete intents expire; a pending upload is not a restore point.

  4. Download and verify

    After authorization, the API issues a temporary download URL. The client checks the downloaded byte length and SHA-256 checksum before local decryption. These transfer checks do not replace authenticated encryption.

Automatic backup runs only while the vault is open and unlocked. Successful changes are grouped for 30 seconds. Transient failures retry during that unlocked session. Lock gives a final attempt up to five seconds; closing the browser or losing power cannot guarantee a final upload.

Root devices can list and download the account's ready snapshots; non-root devices can access their own snapshots. Enabling managed backups requires an eligible entitlement and an existing Online Services Recovery Kit. The backup user guide covers setup, downloads, and restoration.

Recovery authorization and decryption

The Online Services Recovery Kit contains an account ID and recovery phrase. It authorizes account recovery; it cannot decrypt a vault. Fresh-device backup recovery exchanges these credentials for a short-lived recovery session that can list and download backups from current root devices.

The service checks that an eligible backup exists before consuming the Kit. Successful session creation invalidates that Kit. Retries using the same client-generated session token can resume the session after a lost response. If no eligible backup exists, the Kit remains valid. Rotating the recovery package invalidates earlier Kits and active backup recovery sessions.

The downloaded snapshot still needs local decryption with its master password and any additional key protection, or its vault recovery code. The encrypted account binding in the snapshot lets the restored root device authenticate again, provided that registration is still valid. After unlock, the client requests a replacement Recovery Kit. See the recovery guide for this flow and account recovery from an existing vault.

Quota, request limits, and pruning

RuleCurrent service behavior
Per backupAt most 10 MB of ciphertext for one backup.
Account quota150 MB total ciphertext, including pending uploads.
Pending uploadsAt most 5 upload intents can remain pending.
Upload intentsAt most 120 per UTC day.
First 24 hoursAll ready snapshots remain eligible for routine retention.
Through 30 daysThe newest snapshot for each day is retained.
Through 366 daysThe newest snapshot for each month is retained.

The newest completed backup from each current root device is protected from routine pruning. Storage is limited by total size; there is no fixed maximum number of completed backups. Each backup must also fit within the 10 MB per-backup limit and the account's 150 MB total allowance.

Entitlement loss and deletion

Pause backups
Stops automatic uploads. Existing restore points remain available and continue under normal retention rules.
Cancel subscription
Paid access continues to the end of the paid period. After entitlement ends, new uploads stop.
After entitlement
Remaining snapshots can be downloaded or deleted for 90 days, subject to normal pruning, then they are queued for deletion.
Delete account
Deletes active account records and queues hosted backups for deletion, without the 90-day grace period.

Hosted backup deletion is asynchronous. Queued cleanup removes stored objects and retries failures. Ending Online Services does not erase local vaults or downloaded backups.

Public client implementation

These links pin the client revision used for this guide. They document client behavior and request contracts, not the private service implementation.