Two keys, two completely different stakes
People often lump "keys" together. Here they are not the same thing at all. One is a replaceable access token. The other is what makes your data readable, and only you ever hold it.
| API key | Encryption key | |
|---|---|---|
| Looks like | sk-claw_… |
A secret centraid manages on your device (a key or recovery phrase) |
| What it does | Lets centraid talk to the Clawgnition service on your behalf | Seals and unseals your actual vault data |
| Who holds it | Created in the Clawgnition dashboard; you paste it into centraid | Only you, on your device — it never reaches Clawgnition |
| If you lose the value | Replaceable: create a new key, delete the old one. Your data is safe. | Irreplaceable: your backups become permanently unreadable |
| Can Clawgnition help? | Yes — make a new key any time | No — we never had it, so we cannot recover it |
The API key: an access token, and replaceable
An API key (the sk-claw_… value) is how centraid
identifies itself to Clawgnition. Think of it like a password for the storage service,
not for your data. It lets centraid list your vaults, register snapshots, and request
short-lived permission to move bytes.
Two things to know:
- It is shown once. When you create a key, its full value appears a single time. Copy it then. If you close the dialog without copying, you cannot reveal it again.
- Losing the value is not a problem. If you lose it, or it may have leaked, just create a new key and paste that into centraid, then delete the old one. Nothing about your stored data is affected.
Because an API key is so easy to replace, treat it like any other credential: give each device its own named key, and delete or rotate one the moment you suspect it has been exposed.
The encryption key: your data, and irreplaceable
Your encryption key is the secret centraid uses to seal your vault before it is uploaded, and to unseal it when you restore. It lives on your device and is managed by centraid. It never travels to Clawgnition — that is the whole reason we can promise we cannot read your data.
Key loss means data loss. If you lose your encryption key and every copy of it, we cannot recover your data. Your backups will still be sitting in storage, but they are sealed, and without your key nobody — including us — can open them. This is not a limitation we can waive or an exception we can make; it is the direct consequence of real end-to-end encryption. Protecting this key is your responsibility, and it is the most important thing in these docs.
How to keep your encryption key safe
centraid owns the exact way keys and recovery phrases work, so follow its guidance for the specifics. In general:
- When centraid gives you a key or recovery phrase, save it somewhere durable that survives losing your device — a password manager, and ideally a second offline copy.
- Do not keep the only copy on the same machine you are backing up. If that machine dies, you would lose the key and the vault together.
- Test that you can actually restore before you rely on it. A restore you have never tried is a guess.
Rotating and revoking API keys
You can create and delete API keys freely in the dashboard. Deleting (revoking) a key stops new activity from using it. Note one practical detail: revoking a key stops new storage permissions from being issued from it immediately, but any short-lived permission already handed out keeps working until it expires on its own — a short window measured in hours. If you suspect a key was stolen, revoke it and treat that window as the time to watch. Full detail is on Privacy & security.
Common questions
I lost my API key value. Is my data at risk?
No. The API key is just an access token. Create a new one, paste it into centraid, and delete the old one. Your backups are untouched.
I lost my encryption key. Can you get my data back?
No. We never receive that key, so we cannot unseal your backups. If every copy of the key is gone, the data cannot be recovered. This is why keeping a safe copy of the encryption key matters more than anything else.
Which key does the one-time reveal in the dashboard refer to?
The API key. The dashboard shows the sk-claw_… value once at creation. Your
encryption key is never shown in the dashboard at all, because Clawgnition never has it.
Someone might have seen my API key. What should I do?
Delete that key in the dashboard and create a new one for centraid. Because a stolen key could have already been used to request a short-lived read permission, treat the next few hours as a window to watch — see Privacy & security.