Rhea Key
Access built on cryptographic proof, not passwords.
Rhea Key provides cryptographic authentication and approval for supported Rhea workflows. It connects the person using RED with the actions they are authorized to approve, using signatures rather than a shared login password.
01 — What it does
Current functions.
Rhea Key currently supports four functions: authentication, signing, connection approval, and approval of sensitive actions inside RED.
Rhea Key currently provides cryptographic authentication and approval in supported Rhea workflows. Broader use across external applications and services depends on planned integrations. Connection to verified identity attributes through Rhea ID is also planned.
Private authentication material remains protected by the user's device and is not transmitted to Rhea. Rhea does not operate a key-recovery service.
02 — Clients
Where Rhea Key runs today.
Rhea Key client availability
| Client | Status | Meaning |
|---|---|---|
| WebStatus: Available todayrheakey.com | Status: Available today | rheakey.com |
| AndroidStatus: Available todayDevice-based cryptographic authentication and approval | Status: Available today | Device-based cryptographic authentication and approval |
| iOSStatus: Coming soonPlanned iOS client | Status: Coming soon | Planned iOS client |
03 — How it works
A trusted device becomes the key.
Authentication and signing
Private authentication material stays protected by the device. Authentication and approvals are signed on-device and verified downstream.
Connection approval
Users approve or reject trusted connection requests instead of relying on shared secrets that can leak.
RED sensitive-action approval
Sensitive actions in supported RED workflows can require an approval signed through Rhea Key on the user's device.
Device-local biometric gate
Biometrics act as a device-local gate to the Rhea Key application. They are not an identity-verification mechanism and are not transmitted to Rhea.
Authentication and authorization are separate: connecting Rhea Key proves control of a key, while organizational permissions determine which resources and actions it can access.
04 — Recovery
Two recoveries that are often confused.
Rhea Key authentication keys
Rhea does not hold, escrow or recover a Rhea Key authentication key. If the key and its backup are lost, Rhea cannot restore it.
RED organizational-data recovery
RED organizational-data recovery is available through guardian-based threshold recovery with browser-side reconstruction, where configured. A configured threshold of guardians, each holding their own key, gives a signed single-use consent; reconstruction happens only in the initiating administrator's browser.