Skip to main content

Multi-Device Sync

Overview

Your HUMΛN Passport isn't tied to a single device—you enroll additional passkeys into a device mesh (phone, laptop, tablet). Losing one device does not mean losing your identity, as long as another enrolled authenticator remains.

Why Multi-Device?

  • Portability: Sign in from any enrolled device
  • Resilience: Losing one device does not lock you out
  • Sovereignty: You control which devices are trusted
  • Ceremony-based: Enrollment is WebAuthn — not a fake server-side Passport.enrollDevice() SDK call

Think of it like: Adding a second house key — both open the same door; neither is a copy of your fingerprint.

How Device Enrollment Works

  1. Authorize on an existing device — prove you already control the Passport
  2. Register options for the new authenticator — WebAuthn create on the new device
  3. POST the new device — bind the credential under /v1/passport/identities/:did/devices
  4. Optional vault sync/v1/passports/:did/devices/sync/* for encrypted vault relay (Phase 6)

Command Plane /v1/control-plane/devices is org edge topology, not human passkey sync — do not confuse them.

SDK Examples

Enroll a new passkey device

>
SDK:

Optional vault-relay sync

While online, initiate encrypted sync between enrolled devices:

POST /v1/passports/{did}/devices/sync/initiate
Authorization: Bearer <token>
Content-Type: application/json

{
  "initiating_device_id": "dev_laptop",
  "current_device_signature": "…",
  "ephemeral_public_key": "…"
}

Then …/sync/approve and …/sync/complete on the peer device. This is a ceremony, not HumanOS.Passport.syncToCloud().

Revoke a compromised device

DELETE /v1/passport/identities/{did}/devices/{device_id}
Authorization: Bearer <token>

Honest limitations

Fantasy Reality
HumanOS.Passport.generateDeviceKey WebAuthn creates credentials on-device
One REST call enrolls everything Auth options + register options + POST devices
CP devices API Org edge devices — different domain
P2P sync SDK method Optional /devices/sync/* vault relay

Go / Rust tabs are omitted — enrollment needs a WebAuthn UI (see multilang exceptions). CLI explores the same REST options.

Security Considerations

DO

Authorize enrollment from an already-trusted device

Revoke lost devices immediately via DELETE …/devices/:id

Refresh revocation snapshots for offline verifiers

DON'T

Do not invent Passport.syncToCloud / enrollDevice SDK methods

Do not confuse control-plane devices with passkey enrollment

Do not store primary auth private keys in cloud sync blobs

Alias: multi-device-passport-sync

Older links to /docs/patterns/passport/multi-device-passport-sync point here. Enrollment is always WebAuthn + /v1/passport/identities/:did/devices — there is no separate “passport sync” SDK.

Next Steps

See Also

  • Identity device routes: /v1/passport/identities/:did/devices/*
  • Sync ceremony: /v1/passports/:did/devices/sync/*
  • Community: ECDH device mesh

← All patterns