Skip to content

Devices and members

There is no bae account. A device’s identity is a key pair it generates for itself and keeps in the operating system’s keyring; the library recognizes devices by their keys. Adding a device means an existing device vouching for a new one, cryptographically, with no one in the middle.

Two different doors, for two different situations:

  • Joining: a new device is approved by a device that already has the library. Use this to add your phone, or another person’s device.
  • Restoring: your own new or reinstalled device recovers the library directly from the cloud home, using a recovery code. No approver involved.

On a device that already has the library, an owner opens Settings, Devices, Add a device. bae shows one pairing code as a QR and starts listening on the local network.

On the new device, choose Join a library and scan that code. Sign in to the storage provider when asked. Both devices show the new device’s fingerprint; compare them, then approve on the existing device. The new device receives its sealed access through the same local connection, downloads the library, and starts syncing. No code travels back.

The pairing code contains neither the library key nor lasting storage credentials, and an interrupted or rejected pairing grants nothing. Details in Identity and membership.

Settings, Devices lists every member: fingerprint, role, and which one is this device. The founding device is an owner; devices it approves join as members. Both read and write the library; only owners approve and remove devices.

Owners can remove any member. Removal doesn’t just close the door: the library’s encryption key is rotated, and the removed device never receives the new key. What it already copied it keeps, nothing can unsend data, but everything the library writes from that point on is unreadable to it.

A recovery code is a bearer secret for your own library: cloud home coordinates plus the encryption key, in one string. Show recovery code in Settings displays it; store it somewhere safe, like a password manager. On a new device, Restore from cloud with the code rebuilds the library, no approver needed.

On Apple platforms the code is also kept in the iCloud Keychain automatically, so a new Mac or iPhone signed into your Apple ID can restore with one tap.

Anyone holding the code holds the library, so treat it like the key it is.

Lock Library removes the encryption key from the device’s keyring. The library stays on disk, unreadable, until someone enters the key again; bae checks it against a stored fingerprint before accepting it. Use it for a laptop that leaves the house.

iOS and Android join and restore exactly this way; it’s their whole onboarding. A phone can also remove its copy of the library (Settings, remove from this device), which deletes local files and touches nothing in the cloud.