Rekey
Menu
Request access

Rekey

Hand off control without handing us your secret.

Rekey helps one group pass control of a digital asset to another — with no single person holding the whole key. The secret is created on participant machines; our service never holds clear KEY or clear file payloads.

What Rekey is for

Sometimes control of an account or a sealed package needs to move from the people who set it up to another trusted group. Rekey runs that handoff as a guided ceremony.

  • You keep the secret material on your own computers — each participant runs a small app called the Rekey agent.
  • We only coordinate — invitations, status, and sealed packages. Rekey never holds the controlling secret in the clear, and never receives clear file payloads.
  • No one person holds the whole key alone — enough people from the right group must cooperate.

How a handoff works

A short story of the path from setup to the receiving group. Press play, or step through one scene at a time.

    Scene 1

    Form the two groups

    Where knowledge lives

    Rekey’s cloud service never holds clear KEY, and never receives clear file payloads. Secrets are created on participant machines. Sealed packages stay sealed while they travel through us — the service coordinates; it does not open your sealed mailboxes.

    • On your side — the Rekey agent holds that seat’s keys and opens sealed mail only locally.
    • On our side — ceremony status, who is invited, and sealed deposits we cannot open. For file delivery, we store ciphertext only. For some on-chain deliveries, we store a public account manifest — not a private signing key.
    • In email — join links and install tips, never the controlling secret.

    More on terms like KEY, DKG, and sealed mail is in the FAQ.

    Closed beta

    We’re inviting a small number of organizers to try Rekey. Leave your email and we’ll follow up with access when a seat opens.

    If you already have an invite code, we’ll send install steps with your access email. Enter the code when you create a ceremony.

    FAQ

    Plain answers to terms and ideas that may be new on a first read.

    What is a ceremony?

    A structured handoff with named seats, invitations, and clear stages (setup → seal → hand over → deliver). Everyone follows the same script so control moves on purpose, not by informal key sharing.

    What is the Rekey agent?

    A program you install on your own computer. It holds that seat’s keys, talks to the Rekey service for sealed mail and status, and never uploads your private keys to us.

    What is Group A and Group B?

    Group A sets up the handoff and holds early custody. Group B is the receiving group after the handoff. The organizer is usually on the A side and helps run the process.

    What is a “controlling secret” or KEY?

    The secret that can unlock the delivery (for example decrypt a sealed file, or authorize a change on a blockchain account). That secret is split across people, and Rekey’s cloud service never holds it in the clear.

    What is distributed key generation (DKG)?

    A way for several computers to create a shared secret together so that no one machine ever needs to see the whole secret first. In Rekey’s default path, Group A (plus a special completing piece held by the organizer) creates that secret locally.

    What is the “king” or completing share?

    An extra share the organizer holds so that Group A alone cannot rebuild the full secret. After handoff, the receiving group gets their own completing piece. Think of it as a required co-signature in share form, not a password we store.

    What is cutover / VSR?

    Cutover is the step that moves custody from A toward B. VSR (verifiable secret redistribution) is a method that reshapes the shares for the new group without putting the full secret back together on a single dealer machine along the way.

    What does Rekey’s cloud service actually store?

    Ceremony roster and status, sealed packages, and coordination messages. For file deliveries: ciphertext only — never clear payload bytes. For some blockchain deliveries: a public account manifest — never a clear private signing key.

    Why do I need a beta invite code?

    Creating live ceremonies on our hosted service is invite-only during beta, so we can support participants carefully. Starting a production ceremony needs the invite code we send after approval.

    Where does ceremonies@ceremony.rekey-service.com go?

    That address is used as the from line on automated invite and verification email. It is not a monitored inbox for human replies — use the beta form on this page instead.

    Is this the same as giving Rekey my wallet seed?

    No. The hosted service never holds clear KEY and never receives clear file payloads. You run the agent; sealed material opens on participant machines.

    TRON handoffs

    These apply when the delivery is a TRON Rally account (not a sealed file). A design goal is unlinkability: outsiders should not learn Group B’s real-world identity, or tie those people to who can move Rally.

    What is a Rally account?

    The ceremony creates a new Rally address from the group’s shared public key — not by importing an existing wallet. That address is the on-chain account whose Owner permission is what you hand off. Rekey’s cloud service never holds a Rally private key for the threshold products.

    What does “fund Rally on Shasta at Wrap” do?

    Optional. Leave it off to seal the new Rally address without touching the chain (you can fund later). Turn it on only if the organizer’s machine can pay network fees from an operator funder wallet: Wrap then activates Rally on Shasta, tops it up with a fee reserve (about 100 TRX for a later ownership update), and finishes threshold on-chain setup. That does not import an old account — each ceremony still derives a fresh Rally.

    What is B′ (B-prime), and what happens at appoint?

    B′ is a fresh TRON key created at delivery (usually on the receiving group’s combiner machine). Appoint is a single on-chain permission update: Rally’s Owner becomes B′. That costs about 100 TRX from Rally’s balance (the reserve funded earlier). After appoint, control of Rally is the B′ private key — not the ceremony’s shared signing group. The private key stays sealed on the machine that ran appoint; it cannot be rebuilt from the address alone.

    Must B′ be activated on chain to use Rally?

    No. Activating B′ only gives B′ itself an on-chain presence. Rally can already receive TRX and, after appoint, be spent with the B′ key even if B′ was never funded. Anyone can add TRX to an active Rally; spending Rally’s balance requires the current Owner key (B′ after appoint). Activating B′ is separate from moving or spending Rally funds.

    What can the wider world see about who controls Rally?

    Ceremony participants (organizer and seats) know Group B’s contact identities by design. The wider world should not learn those people’s names or emails from the chain, and should not be able to prove “this Rally is controlled by that group.” After appoint, explorers show Rally’s Owner as a TRON address (B′). Privacy here means unlinkability: that Owner is a fresh key, not a known wallet belonging to a named person — not that ownership is invisible on-chain.

    Leave B′ inactive (stealthed) vs activate B′ — what changes for visibility?

    Leave B′ inactive (preferred for privacy). B′ never receives TRX, so it often does not appear as its own funded account on explorers. Rally still works as a transfer account: it can be topped up and spent with the B′ key. Outsiders who look up Rally may see an Owner address, but B′ itself stays quiet — no separate B′ balance history, and no “B′ was funded from X” trail. This is the stealthed controller pattern.

    Activate B′. B′ becomes a visible on-chain account (explorer presence, its own balance). That helps public validation and using B′ as a normal wallet, but it increases visibility. Funding B′ from a known operator wallet can also create a linkable chain trail to B′. Use activation when you want B′ obvious; skip it when you want the final controller to stay as quiet as the chain allows.

    Who knows B′ exists, and who can control it?

    The unload machine (usually the Group B combiner) creates and holds the B′ private key. Ceremony participants may learn the B′ address at delivery. Rekey’s service must never hold that private key. Control of Rally after appoint is whoever has the B′ key — not whoever merely sees the address. A later ownership change is another permission update signed by the current Owner (again needing Rally fee balance), still without requiring B′ to have been activated.