Identity and the gate
The key is the identity, and it has two possible homes. There is no login and no account screen. An encrypted Ed25519 key file, whose private half only opens on this machine, is what unlocks Vigia. On a pen drive, it is sealed under the machine's device fingerprint and the drive is the protection: no password exists, and pulling the drive locks the console. Drives over 128 GB or Time Machine destinations are refused as keys with no override: a key is a stick small enough to leave with its owner. On this computer, the same key file sits in a folder of its own under Vigia's data folder, and a password of twelve characters or more seals it — the key is encrypted under the fingerprint and the password, so the file opens nothing without it; five wrong answers and the account stops answering for fifteen minutes. The choice is asked once, after the activation key, and is never final: Setup → Move to a pen drive / Move to this computer takes the same account — same key, same servers, same vault, same licenses — to the other home, writing and proving the new one before the old one is removed. Multiple keys can live on one machine, on drives or on the computer; the door lists them by the name and company on their license, a session pins to its key, other keys' servers are never listed, and one license opens one account per computer.
An account on the computer travels as a file. Its encrypted backup sits beside the key on the same disk, so Setup → Encrypted backup has Save a backup file: the key's travel copy and the backup in one file, opened by the backup's passphrase. Restore an account from a backup file, at the door of any computer, brings the account back under a new password. A duplicate of a drive whose account has since moved onto the computer is no longer accepted as a way in; the password page in Setup lists it and removes the old key from it.
Two factors at the door, key first. The gate order is KEY, then Touch ID. With no key plugged Vigia shows the "Welcome to Vigia" door with "I have a key" and "Start a new account" — it never assumes a new account. Touch ID falls back to the account password on a Mac with no sensor or a closed lid, and to key-only where nothing can be evaluated; the degraded state is always said on screen. The Windows build has no biometric step.
Product activation key (LFL1.). A new account opens with the activation key from lockflare.com/create-account, opened on this computer with the envelope key built into Vigia and LockFlare's Ed25519 signature checked locally — nothing is asked of anyone. The key is written onto the drive beside the identity and carries the account: name, email, and how many servers are free.
Server licenses (LFS1.). A server license is issued at lockflare.com for one IP address and carries that address inside it, signed. Adding a Vigia server means pasting the key; the address comes out of it, nothing is typed twice. Three checks: at the door (a key issued to another account is refused, so accounts cannot be pooled onto one map), on the box (/var/lib/lens/license is read on every connect and kept right), and at the root door (every root path in the app asks whether this is a licensed server). The shell itself is never refused for a license.
Vigia server vs console. Two kinds of server go on the map. A Vigia server carries a license and gets everything Vigia does to a box as root: Security Setup, System Setup, Backups, the tools, the clusters. A console carries no license and no count: a box Vigia is a terminal to — shell, Files, Tunnels, Snippets, History, everything the login can do by hand. Locked features stay on the rail, marked, and say what they are when pressed — never greyed, never silent. A console becomes a Vigia server on Edit the day a key for its address is pasted.
Remove permanently / Remove and add another. A licensed server leaves two ways and the license goes with it: REMOVE PERMANENTLY hands its remaining days back to the account as credit; REMOVE AND ADD ANOTHER moves the license and its time to a new address. Both finish on lockflare.com; servers removed with a license still pending are held in the store and counted on the map and in Setup › Licenses so a closed browser loses nothing. Renewal opens 60 days before a key ends.
Recovery bundle. For the worst day (key lost, no backup, computer gone): lockflare.com/recover takes the account's email, password and one of its server addresses, mails a 6-digit code, and hands back a bundle — the account license and every server key as one string. Pasted at the gate, Vigia writes a new key with the account inside and every server goes back on the map with its license. Vigia sends nothing; the visit is the browser's.
Encrypted backup on the key (.lf-backup.enc). One file on the pen drive holding everything Vigia has: the whole map document (servers, groups, boards, snippets, tunnels, grants, templates, diagrams, clusters), the audit ledger, the certificate vault and the saved credentials, decrypted from the credstore at write time and sealed inside. The data key is wrapped twice: under the operator's passphrase (PBKDF2-SHA512 + AES-256-GCM, the recovery path that works on a new machine) and under the drive's deterministic signature (so the automatic rewrite while the key is plugged needs no passphrase). A fresh Vigia with a verified key offers the restore at the gate, before anything draws.
Travel copy (.lf-travel-<id>.key). A key is bound to the machine that made it, and a new account elsewhere would be a new key id, invalidating every server license. The travel copy is the same key pair, id and account license sealed under a passphrase, written beside the encrypted backup. On a new computer the gate offers "Your key, on a new computer": it enrols the same key id there and, with the backup on the drive, brings the whole map back under the same passphrase. Setup › Your key makes, reseals or removes it, and the trade-off (possession + a secret instead of possession + a machine) is said on screen.
Duplicate my USB drive. A locked, full-screen ceremony that makes a twin key for the drawer or the other bag. The key is read into memory first under Touch ID while the source is plugged, so the screen can say UNPLUG YOUR CURRENT KEY and mean it; the new stick is watched for, written, read back, and only then called ready. Nothing else in Vigia can be clicked mid-ceremony and the key-removed overlay stands down because the key being out is the plan.
Key-removed lock. Pulling the drive after unlocking raises an opaque overlay ("Connect your pen drive"): the unlocked state, the shells and every job survive underneath, and reinserting the key puts the operator back exactly where they were. A lock, not a logout. The overlay is opaque on purpose: what is behind it is exactly what the absent key protects.
Session lock. A button in the title bar blurs the console past reading and asks for the second factor to come back. The key stays in, shells stay open, jobs carry on; keystrokes are swallowed at the capture phase so a terminal behind the blur cannot be typed into. Nothing dismisses it but the factor.
Welcome. One branded moment per unlock: what this is, that you are in, and with which physical key. Skippable by any key or click; nothing load-bearing, no "sign in as" language anywhere.
