We hold nothing that opens it
The key is made on your device and never sent to us. There is no copy here to hand back, and no support queue that can restore you.
Recovery · the paper is the key
The words you wrote down are not a backup of your key. They are the key. Type them into any of the three tools below and the same four addresses come back, on Sui, Ethereum, Solana and Bitcoin.
We hold nothing that can do this for you. That is why it still works on a machine that has never heard of us.
Three ways back, in order
All three run the same derivation and land on the same addresses. The first is the easiest. The second needs nothing from us at all.
Type the twenty-four words and the same four addresses come back in this tab. It needs you signed in to a ONE account, because it records the restored addresses there. The words themselves are never sent. This is the quickest way, and the only one of the three that runs on a page we serve.
Restore in the browserWords in, four addresses and a signer out, with no ONE server in the path. It was tested with the network blocked. Add --rpc sui=<url> to read a balance from a node you choose; there is no default node and ours is refused. The package also carries a single-file page, dist/page.html, that you can copy to a USB stick and open on a machine that has never been online.
npx -y @oneie/recoverThe same derivation in the ONE CLI. key recover rebuilds the key from its words, key public prints the public identity and the four addresses, and key verify checks that identity against what the server holds without sending the key. The words come from a hidden prompt or stdin, never from the command line, so they stay out of your shell history.
npx oneie key recoverBefore you type your words
A page that asks for your words should be checked, not trusted. This is the SHA-256 of dist/page.html in @oneie/recover 0.1.0. Run the three lines below on your own machine and compare. A different hash means a different file: do not type your words into it.
sha256 · dist/page.html · @oneie/recover 0.1.0
8b160c5026c71a5170d4278aab463ecbecdf13a2774e8468a7deeba08d39826e
npm pack @oneie/recover@0.1.0
tar xzf oneie-recover-0.1.0.tgz
shasum -a 256 package/dist/page.html
On Windows: certutil -hashfile page.html SHA256. The page
also seals itself: its Content-Security-Policy names the hash of its own code, so a
browser refuses to run a copy with one byte changed, and it loads nothing from the
network except a balance node you type in yourself.
The boundary
The key is made on your device and never sent to us. There is no copy here to hand back, and no support queue that can restore you.
If the device and the twenty-four words are both gone, nobody can recover the key. Not us, not anyone. That is the same property that stops anyone else taking it.
Whoever holds the paper holds the key. We cannot freeze it or reverse what they do with it. Keep the paper apart from the device.
They are BIP-39 words, and a key made at one.ie today is not one another wallet can open. Typed into other software, the same words produce addresses that look valid, hold nothing and are not yours. Recover with one of the three tools above. The offline tool prints two address sets, labelled v1 and v2, because keys made under the older and the newer derivation land on different addresses. Check which set holds your money before you send anything.
How the key is made and kept: one.ie/key. Your keys and where each copy rests: one.ie/keys. The tools are free under the ONE License. One obligation in return: keep the ONE mark and the link to one.ie in whatever you deploy.