Henedo

Your collection · Export reader

Your collection, within reach.

Open a Henedo export with the recovery details you kept. Your files and memories stay on this computer, without an internet connection.

Works offlineNo network requests

Open your export

Choose a henedo-export-*.zip bundle. For an Eternal Vault disc with two key halves, use the separate disc reader included on that disc.

Choose how to unlock

Use the 32-byte Master Key you saved offline: 64 hexadecimal characters or its base64 representation.

Passphrase recovery may take a few seconds. Keep this page open while it works.
Choose an export and enter your recovery details.

Vault files(0)

Journal(0)

Life Book(0)

Life Story answers(0)

Will / estate(0)

Eternal Vault(0)

Conversations, Ask, capsules and attachments

How recovery works

The crypto used by this page mirrors the production Henedo client byte-for-byte. Anyone with a competent crypto library can re-implement it from this spec.

1. KEK = Argon2id(passphrase [+ ASK_hex for v2/v3], kdf_salt, m=64MB (v1/v2) or 128MB (v3), t=3, p=4) → HKDF-SHA-256('henedo-kek-v1'|'henedo-kek-v2'|'henedo-kek-v3', 32 bytes) The version is manifest.json → kdf.version; this page dispatches on it. 2. MK = AES-256-GCM.decrypt(KEK, EMK, mk_iv) ─ OR ─ recovery_aes_key = HKDF-SHA-256(recovery_raw, 'henedo-recovery-aes-v1') MK = AES-256-GCM.decrypt(recovery_aes_key, emk_recovery, recovery_iv) (The recovery-key path never changes across KDF versions.) ─ OR ─ MK is whatever 32 bytes you stored offline. 3. For each encrypted file in the manifest: FEK = AES-256-GCM.decrypt(MK, EFEK, fek_iv) plaintext = AES-256-GCM.decrypt(FEK, ciphertext, file_iv) 4. File and folder names are decrypted with MK using encrypted_file_name + file_name_iv / encrypted_name + name_iv. Custom badge labels use encrypted_badge + badge_iv under MK; preset palette ids (finance, health, legal, …) stay plaintext in `badge`. 5. Journal entries, Life Book, Life Story answers, and Will payloads are AES-256-GCM ciphertexts encrypted directly under MK. Will payloads bind {"table":"wills","version":N,"will_id":""} as AAD (rows sealed before that binding carry none). A row whose data_iv is the literal 'v0-plaintext' pre-dates client-side encryption: encrypted_data is base64-wrapped UTF-8 JSON, not ciphertext. 6. Eternal Vault: EVAK = AES-256-GCM.decrypt(MK, EEVAK, eevak_iv); manifest = AES-256-GCM.decrypt(EVAK, encrypted_manifest, manifest_iv); display_data (owner file tree + personal letter, envelope {v,iv,ciphertext}) = AES-256-GCM.decrypt(EVAK, ciphertext, iv) with AAD 'henedo-eternal-vault-display-data-v:'. Legacy rows store that tree as a flat plaintext object instead. This page embeds its recovery libraries, including Argon2id and hybrid envelope support for Ask and capsules. AES-GCM and HKDF use Web Crypto. No network connection is required.

Keep your recovery copy

Runs offline
All crypto is in this file. Open it from a thumb drive, an M-DISC, or your laptop's airplane mode — same result.
No network calls
CSP connect-src 'none'. Your passphrase, ASK, and Master Key never leave this tab.
Audit-ready source
View source. Argon2id, HKDF-SHA-256, AES-256-GCM — every line is right here.
Keep the original
Keep your encrypted export and recovery details after opening it. Test your saved copy periodically with a compatible browser.