Security Kit
Token, passkey, and recovery-code handling for paid accounts.
Token-first access
The account token identifies the account. Keep it out of screenshots, tickets, prompts, shell history, and shared documents.
- Store the token in a password manager
- Use passkeys for paid login where possible
- Export the local access kit only to a trusted local file
Lost access
If token, passkey, and recovery codes are all lost, Shhhs cannot restore secret access. Support may help cancel billing after validating billing metadata.
- No secret recovery
- No plaintext recovery
- Billing cancellation support is metadata-only