On this page

Service-independent Recovery

Keep the app, proof files and deployment data users need during a service outage.

Ship recovery with the deployment#

The recovery design combines a static app bundle identified by its hash and a holder-selected RPC. It lets the holder reopen an account, rebuild history and finalize queued actions, then use the original withdrawal path without the operator's API.

Distribute the bundle with the deployment. Preserve the codecs, proof files and contract identity needed by notes issued under that release; a future recovery page would not help users who need those files now.

Account access and recovery methods
Account access and recovery methods

Files and keys to retain#

ArtifactUsed for
Static app and worker codeOpen the account, find notes and prepare proofs
Proving and verification artifactsRun the original relations and check verifier identity
Deployment trust dataAuthenticate the chain, Pool, directory and runtime
Historical note and delivery codecsRead earlier key generations and account history
Encrypted operation bundlesRestore proofs and signatures that were never broadcast
Holder's passkeys or paper wordsOpen the private account without operator records

Read history from another RPC#

Check the RPC's chain and contract code against deployment data. Rebuild notes from public history and validate decrypted outputs before adding them to the spendable balance. A cached balance without those checks is historical display data.

Audit verification has a stricter history requirement: it reconstructs all finalized events from the deployment block. A checkpoint sufficient for an account scan can still omit events the auditor needs.

Finish or withdraw from a wallet#

Finalize a reserved receipt if the action has already returned its output. For an ordinary direct withdrawal, use the supported proof and submit from the holder's wallet. It pays gas and is publicly linked to that operation.

Controlled notes still need controller approval. A Pending source-revealing exit publishes additional information. Present those as separate choices so the holder knows which authority and disclosure each step requires.

Test with the service blocked#

In a fresh browser, block the app service and use the saved static bundle with an independent RPC. Restore the account keys, find its notes, reconcile an interrupted operation and complete a supported exit.

Record which deployment and devices you tested, including the funded result. Checking source files or finding an archive cannot tell you whether a user can actually complete recovery on that deployment.