Form K-99 · Operating manual
User guide
Everything the register can do, in the order you'll meet it.
Registering a key
- Scan it. Hit Register key and the scan step opens. Plug the key into the machine you're browsing from and touch it when it blinks. Keeyo reads the model fingerprint (AAGUID), matches it against the live FIDO registry, and pre-fills vendor, model and form factor. Scanning also pairs the key, which unlocks identification and secret notes later. Nothing is written to the key and none of its passkey storage is used.
- Or add it manually. The small link below the scan button opens the plain form. Vendors, models, form factors and colors all accept custom entries — anything you type is remembered in your personal catalog (Settings → Catalog) for next time.
- Pick the variant if asked. Fingerprints identify a series — a YubiKey 5 NFC and 5C NFC share one — so when it's ambiguous, Keeyo narrows the model list and you pick the plug you're holding.
- Give it a name and a color. Name it for where it lives ("Desk drawer backup"), and match the color tag to a real sticker on the physical key. You can upload a photo instead of the schematic drawing.
Logging what's on a key
Open a key's tag and add sign-ins (passkeys and 2FA registrations) and TOTP codes. The service picker searches your existing services, offers one-tap buttons for common ones (GitHub, Google, …) and creates new services inline — with automatic favicons. Tick add another to log a whole key's contents in one sitting.
Registrations can be edited, moved to another key, or removed — deletions come with a 5-second Undo instead of a confirmation dialog.
Services & backup coverage
The Services view (the Keys / Services switcher at the top of the home screen) is the reverse lookup: every service, and colored squares for each key that covers it. Open a service to see exactly which keys hold it. Two warnings matter:
- no backup — add one: only one usable key covers this service. The chip is a button — it opens a key picker and pre-fills the registration form.
- not on any key — fix: no usable key covers it at all (e.g. the only key is marked lost).
The same warnings surface as a strip on the dashboard so gaps don't hide.
Losing a key
Set the key's status to lost. Its registrations become a revocation checklist — go to each service, remove the key there, and tick it off. The dashboard shows a hazard strip until the checklist is clean. If the key turns up later, the identify feature will recognize it and remind you it was marked lost.
"Which key is this?"
The identify button on the dashboard answers the question the whole app exists for. Plug in the mystery key, touch it, and Keeyo names the exact record — even several keys plugged in at once is fine, because the key you physically touch is the one that answers. Works for paired keys; unpaired ones fall back to a model read with candidate matches.
Secret notes (tap to reveal)
A paired key can hold one secret note — typically its PIN. The note is never shown in the app; revealing it requires tapping that exact physical key, and the server verifies the cryptographic response before releasing it.
On modern keys (anything supporting the WebAuthn PRF extension — YubiKey 5 series included), the note is also end-to-end encrypted: your browser derives the encryption key from the hardware itself, so the server only ever stores ciphertext. Saving asks for one extra tap; revealing doesn't — the same tap proves possession and unlocks the note. The key page labels every note E2E encrypted or server-stored so you always know which mode you're in; re-pairing an old key upgrades it.
Health check-ins
Backup keys rot in drawers. Whenever you actually use or test a key, press Tested on its page — the dashboard nudges you about any active or backup key that hasn't been confirmed working in six months.
The logbook
Every key keeps an append-only ledger: registered, paired, status changes, services added and removed, revocations, tests, files. It answers "when did I add this?" without you ever writing anything down.
Printing & exports
- Asset tag (key page → printer icon): a physical label with the key's name, tag number, barcode and a QR code linking back to its record. Stick it on the keychain.
- Register sheet (Settings → Account → Backup → Export PDF): the whole inventory as one ledger table — save it as a PDF or print it.
- CSV (Settings → Account → Backup): the same data for spreadsheets.
Protecting Keeyo itself
Settings → Security: add a second factor and logging in requires your password plus that factor.
- Security keys — enroll one or more hardware keys; sign-in asks for a tap. Enroll at least two so losing one never locks you out.
- Authenticator app — any TOTP app (Aegis, Ente Auth, Google Authenticator, …) works as an alternative or additional factor. Handy where WebAuthn isn't available, e.g. plain-HTTP LAN deployments don't support key taps but codes still work.
- Recovery codes — generate ten single-use codes and store them safely (password manager, printed sheet). Each signs you in once when your second factor is unavailable. They're shown only at generation time, and regenerating replaces the whole set.
If every factor is lost, the server owner still has the recovery paths: KEEYO_DISABLE_MFA=1 or scripts/reset-password.js.
Keyboard shortcuts
| Key | Action |
|---|---|
| / | Focus the search box |
| N | Register a new key (dashboard) |
| Esc | Close the open dialog |