Change a passkey, trusted phone, or recovery phrase
Use this guide while you can still sign in and control the other approval methods you will need. It is the right path before replacing a phone, when retiring a passkey, or after you suspect one method was exposed.
After Vault setup, each change still needs two approvals. A passkey change uses the current passkey and phone approval. A trusted-phone change uses the passkey plus the current phone or recovery phrase. A recovery-phrase change uses the passkey and phone approval. Keep the old method available until Cedar confirms the replacement on every required network. If Vault setup has started but is not complete, finish it before changing a method.
Without Vault, you can change a Pocket-only passkey in the web app after activating Pocket. Phone approval and recovery-phrase changes apply only after Vault setup.
These changes can include separate Pocket and Vault steps. If you leave before a final status, return to Security or Activity and resume the existing change instead of starting another one.
Change the passkey
Section titled “Change the passkey”Use this path only while the current passkey still works. If it is lost, use Recover access with the current trusted phone and recovery phrase.
Pocket without Vault: In the web app, open Security → Passkey, choose Change passkey, then create the replacement and follow Cedar’s review. Wait for Activity to show a successful final status.
After Vault setup:
- On the current trusted iPhone, open Cedar Wallet and go to Security → Passkey.
- Choose Change passkey.
- Name the replacement, choose Create new passkey, and complete the system passkey prompt.
- Review the required Pocket and Vault changes, then choose Change passkey.
- Complete the passkey and phone approvals Cedar shows.
- Wait for Cedar to return to Security, and check Activity for a successful final status on each step.
Cedar may update Pocket first and Vault second. If the flow is interrupted, resume it; do not create another replacement passkey for the same change.
You are done when Security shows the replacement as the current passkey and the previous passkey no longer works for Pocket or Vault approvals. Do not remove the previous passkey from its provider before that point.
Change the trusted phone
Section titled “Change the trusted phone”Set up the new iPhone before erasing or giving up the current trusted phone.
- Install Cedar Wallet on the new iPhone and sign in with the current passkey.
- Open Security → Device Key and choose the setup action Cedar shows for this phone.
- When the new phone is set up but the other phone still handles approval, choose Change Device Key.
- Choose how to finish the change:
- To use the current trusted phone, choose Prepare for current phone, then open the change on that phone.
- If the current phone is unavailable, choose Continue on this phone and enter the current recovery phrase.
- Review which phone will take over, then complete the passkey and second approval Cedar requests.
- Wait for Activity to show a successful final status before removing Cedar from the previous phone.
You are done when Security → Device Key identifies the new iPhone as the phone that approves Vault actions and the previous phone can no longer approve those actions.
Signed-out emergency recovery cannot replace a lost phone. If the old phone is gone, use the signed-in path above with the current passkey and recovery phrase.
Change the recovery phrase
Section titled “Change the recovery phrase”Use the current trusted phone, and prepare a private, offline place for the new 12 words before you begin.
- Sign in on the trusted iPhone and open Security → Recovery Phrase.
- Choose Change recovery phrase.
- Under Your new 12-word phrase, write every word down in order. Do not take a screenshot or save the words online.
- After checking your copy, choose I wrote it down.
- Review the change and complete the passkey and phone approvals.
- Wait for Recovery phrase changed and a successful final status in Activity.
Only after the final status should you destroy the old copy. You are done when Security confirms that recovery-phrase access is ready and only the new phrase works when Cedar asks for recovery-phrase approval.
If you lost a method
Section titled “If you lost a method”- Lost passkey: Recover access with the current trusted phone and recovery phrase.
- Lost trusted phone: follow Change the trusted phone above with the current passkey and recovery phrase.
- Lost recovery phrase: follow Change the recovery phrase above with the current passkey and trusted phone.
If two or more Vault methods are unavailable, Cedar’s current 2-of-3 recovery cannot restore access.