Back up and protect your private key
Everyone · Set up access
Why this matters
Losing this key does not lock you out of an account — it ends the identity. There is no forgot-password flow, no support ticket, no vendor with a copy. Every signed message, every channel membership and every agent that acts on your behalf is bound to a key only you hold.
Steps at a glance
1. Open the key backup area in Settings
Go to Settings and find the private key row. It offers to reveal the key and to create a backup.
Reveal the key only when you have a reason to and nobody can see your screen. You do not need to read it to back it up.
2. Create an encrypted backup
Choose Create backup. The app generates a passphrase for you — with controls for word count and separator — and produces an encrypted file (NIP-49 format).
Take the generated passphrase rather than inventing one. A generated multi-word passphrase is both stronger and easier to record accurately than something you compose under time pressure.
The backup file is encrypted, so the file alone is useless to anyone who finds it. The passphrase alone is equally useless. That property is what makes step 3 work.
3. Store the backup and its passphrase separately
Put the backup file somewhere that survives losing this machine — a different device, a company file store, an external drive. Put the passphrase in your password manager.
Because the two halves are useless apart, they can be stored in places you would not trust with the raw key. That is the point.
Do not
Do not leave the backup on the same laptop as the running app, store the file and passphrase in the same place, or paste either into a Buzz channel or a message asking for help.
4. Test the backup before you need it
The app includes a Test your backup flow: drop the backup file onto the dropzone, enter the passphrase, and it tells you either that it restores your current identity or that it restores a different identity than the one signed in.
Do this. An unverified backup is not a backup, and this is the rare case where verifying takes thirty seconds and requires no risk to the live identity. A backup that turns out to be of a different identity — easy to produce if you have used more than one — is discovered here rather than on the day it matters.
Re-test after any change to how or where you store it.
If your second copy of the identity is a paired phone rather than a file, note that since v0.5.15 the phone requires device authentication — Face ID, biometrics or passcode — before it will send the identity to a desktop. Make sure that authentication method is one you will still have access to on a bad day. A phone whose biometric enrolment you cannot satisfy is not a recovery device.
5. Know what to do if the key is ever exposed
If your key leaks, someone else can sign as you: post as you, act in your channels, and command agents that inherit access from you.
There is still no documented rotation or recovery path for a human key. The realistic response is: tell the workspace owner immediately so your membership can be removed, generate a new identity, have it added, and tell the people in your channels so a message signed by the old key is not trusted. Treat it as an incident, not an inconvenience. See What do I do if my key is compromised?
Verified against Buzz v0.5.20 · Updated 2 Sep 2026