The Telex web client can remember a human login on one browser profile without
storing the human's account password. This is optional. Leave remember this device unchecked to retain the original password-in-memory behavior.
When selected, the client first signs in with the ordinary account name and
password, creates or resumes its dr1... delivery installation, and asks the
control API for one random rd1... remembered-device credential bound to that
same installation UUID. The server returns the credential once and stores only
its SHA-256 digest. The browser stores the credential in the account/server
scope in IndexedDB, never LocalStorage or the service-worker cache.
The three secrets deliberately have different authority:
- the account password authenticates the human everywhere and can create a remembered-device credential;
rd1...authenticates only the named human installation and can reconnect the web client; anddr1...identifies only the installation's delivery checkpoint and cannot authenticate anything.
On a later launch, the web client uses the authentication ID
account/<installation-uuid> with the saved rd1... bearer, then proves the
matching dr1... installation during device binding. A mismatched pair is
rejected. Ordinary IRC clients remain unchanged and continue to use the bare
account name and password.
The integrated account screen lists active remembered devices with their browser-generated label and creation date. Revoking one credential closes live IRC, native, and Stage sessions bound to that installation but preserves its delivery checkpoint. The next password login can therefore resume without replaying the installation from zero.
Explicit disconnect in the web client requests revocation of that browser's
saved credential and always clears the local copy. If the revocation request
cannot reach the server, the account screen on another signed-in device can
revoke the orphaned entry, or a password change can revoke every remembered
device. An ordinary transport loss, background suspension, tab close, or
application close does not request revocation; those are the events the
remembered credential exists to survive.
Changing the account password atomically revokes every remembered-device
credential and disconnects every active session for the account. It preserves
account history, read state, installation tokens, and delivery checkpoints.
Creating another remembered credential or changing the password always
requires authentication with the actual account password; an rd1...
credential cannot mint another bearer or rotate the account password.
Remembered credentials have no independent expiry in v1. They remain active until explicit revocation, password change, or eviction of their underlying installation. The existing limit of 16 active installations per human account therefore also bounds remembered credentials.
Clearing browser site data removes the local credential without notifying the server. Use the account screen from another signed-in device to revoke the orphaned entry, or change the account password to revoke all remembered devices.