Service-independent Recovery
Keep the app, proof files and deployment data users need during a service outage.
Ship recovery with the deployment#
The recovery design combines a static app bundle identified by its hash and a holder-selected RPC. It lets the holder reopen an account, rebuild history and finalize queued actions, then use the original withdrawal path without the operator's API.
Distribute the bundle with the deployment. Preserve the codecs, proof files and contract identity needed by notes issued under that release; a future recovery page would not help users who need those files now.
Files and keys to retain#
| Artifact | Used for |
|---|---|
| Static app and worker code | Open the account, find notes and prepare proofs |
| Proving and verification artifacts | Run the original relations and check verifier identity |
| Deployment trust data | Authenticate the chain, Pool, directory and runtime |
| Historical note and delivery codecs | Read earlier key generations and account history |
| Encrypted operation bundles | Restore proofs and signatures that were never broadcast |
| Holder's passkeys or paper words | Open the private account without operator records |
Read history from another RPC#
Check the RPC's chain and contract code against deployment data. Rebuild notes from public history and validate decrypted outputs before adding them to the spendable balance. A cached balance without those checks is historical display data.
Audit verification has a stricter history requirement: it reconstructs all finalized events from the deployment block. A checkpoint sufficient for an account scan can still omit events the auditor needs.
Finish or withdraw from a wallet#
Finalize a reserved receipt if the action has already returned its output. For an ordinary direct withdrawal, use the supported proof and submit from the holder's wallet. It pays gas and is publicly linked to that operation.
Controlled notes still need controller approval. A Pending source-revealing exit publishes additional information. Present those as separate choices so the holder knows which authority and disclosure each step requires.
Test with the service blocked#
In a fresh browser, block the app service and use the saved static bundle with an independent RPC. Restore the account keys, find its notes, reconcile an interrupted operation and complete a supported exit.
Record which deployment and devices you tested, including the funded result. Checking source files or finding an archive cannot tell you whether a user can actually complete recovery on that deployment.