Skip to main content

Synopsis

Description

capy transport packages this machine’s local key material for the current organization and prints a QR code and browser link. Open or scan the link in a browser you can reach later, preferably on your phone, and sign in as the same Capy account. The link activates a one-time browser-held transport. On the new machine, run capy pair to sign in and collect the keys from that browser. A transport can contain the matching key material for one organization; run the command again for another organization. The printed expiry is authoritative. The transport is deleted after activation and cannot be used again.
Treat the full link and QR code as sensitive. The fragment contains a one-time key that the service does not receive. Do not put it in a ticket, chat log, shell history, or screen recording.

What is protected

The CLI packs local.key and key.enc, encrypts that package locally with a fresh random key, and sends only the encrypted package to the service. The link carries the transport id and that fresh key in its fragment. The service can store the package, but cannot open it from the stored value alone. The browser activates the transport only after you sign in. capy pair then asks you to confirm the account returned by the device sign-in before it installs a session or any keys on the new machine.

Options

See also

Last modified on October 2, 2026