Your key never leaves your device
How a keypair is generated in your browser and sealed with your PIN.
Step 1 of 5
What is generated, and where
When you create an identity, your browser generates an Ed25519 keypair — a standard digital-signature key pair — using the Web Crypto stack. The private key is 32 bytes of randomness that has never existed anywhere else.
Your PIN is run through PBKDF2 with 600,000 iterations to derive an AES-GCM encryption key, and the private key is sealed with it inside your browser’s IndexedDB. Unlocking it later requires the same PIN. There is no copy anywhere else — not on our servers, not in any backup.
What the service receives
Only the public key. Your address — xity1 followed by 40 hexadecimal characters — is derived from it by double-SHA-256. The platform records the public key, your address, and anchors the registration to XityChain.
The private key cannot be reset or recovered by anyone, including you, because no one holds it. Recovery (step 5) exists for exactly this reason.
