Passkeys, phone approval, and recovery phrases
Cedar’s three approval methods are not interchangeable passwords. Each has a different job, and keeping those jobs separate is what gives Vault its 2-of-3 protection.
| Method | Main role in Cedar | Where the secret lives |
|---|---|---|
| Passkey | Sign-in, Pocket approval, and one Vault approval | Your authenticator or passkey provider |
| Phone approval | The normal second approval for Vault | Device-only secure storage used by Cedar Wallet on iPhone |
| Recovery phrase | Recovery and supported backup approval | The private, offline copy you keep |
Read How Cedar protects Pocket and Vault for the full mental model.
Passkey
Section titled “Passkey”Your current passkey signs you in, approves supported Pocket actions, and supplies one of the two approvals used by Vault.
Your device or password manager decides how you unlock it. That might be Face ID, Touch ID, Windows Hello, an Android screen lock, or the password manager’s own check. Cedar does not receive your fingerprint, face data, or passkey private key.
The Cedar review screen carries the important action details. A system passkey prompt may confirm only that you want to use the passkey; it may not repeat the wallet, recipient, asset, or amount. Read Cedar’s review first, then answer the system prompt.
Under the hood: Cedar uses a WebAuthn passkey. The authenticator creates the signing key and returns the public credential material plus signed assertions. Cedar stores what it needs to verify those assertions and represent the passkey as a smart-account signer. If your passkey provider supports encrypted syncing, the passkey may be available on more than one of your devices; it is not necessarily tied to one physical device.
Phone approval
Section titled “Phone approval”Phone approval is the normal second check for Vault. Cedar Wallet may ask you to continue on the trusted iPhone for Vault setup, sends, spending-limit changes, security-method changes, or recovery work.
When you see Continue on phone, open Cedar Wallet yourself. Approve only when the pending request matches the action you started. A push notification or handoff link is a route to the review screen, not proof that the request is legitimate.
Under the hood: Cedar Wallet creates a separate signing key on the iPhone and keeps it in device-only secure storage. Cedar’s API records its public address and verifies signatures from it; the private key is not uploaded. The key is not designed to move automatically to another phone, and this storage is not the same promise as a separate hardware wallet. Before replacing or erasing the iPhone, follow the trusted-phone change flow while your other approval methods are available.
Recovery phrase
Section titled “Recovery phrase”The recovery phrase is a 12-word backup approval method created during Vault setup. You use it to recover access or complete a supported backup path—not for routine Pocket or Vault activity.
Write it down and store it privately, offline, and separately from the trusted phone. Anyone who obtains the words has one of Vault’s three approval methods. Cedar support cannot make the words private again; if they may have been exposed, change the phrase while the other two methods are still available.
Under the hood: The 12 words are a BIP-39 phrase that derives an Ethereum signing key. Cedar registers the matching public address after the app proves control of it. When a supported flow asks for the phrase, Cedar processes it locally to create a signature; the API receives the signature, not the recovery words. The phrase can recover a protected Pocket only after Vault setup and Pocket protection are complete.
Before you approve
Section titled “Before you approve”Pause long enough to answer three questions:
- Did I start this? Reject an unexpected request, even if the app or notification looks familiar.
- Does every detail match? Check the wallet, network, asset, amount, recipient, requesting site, spending limit, or security change shown by Cedar.
- Is the approval path expected? Pocket normally asks for a passkey. Regular Vault work normally asks for a passkey and phone approval. Stop if Cedar asks for something different without explaining why.
If anything is unclear, close the request before approving. You can reopen a legitimate pending action from Activity.