Credenza
Sudo approval
Host
User
Bundle
Run as
Directory
Executable
Owner
SHA-256
Provides
Expires
Rejection reason
(optional)
Reject
Approve
Register phone passkey
Allow password manager to replace a same-account passkey
Register passkey
Inspect registered passkeys
Vault encryption canary
Run canary
Reset
Encrypted vault
Replace an existing secret with this ID
Store encrypted secret
Vault passkeys
Add a backup passkey that can unlock the same vault.
Register it above first, then enroll it here: you confirm an enrolled passkey once and the new passkey twice.
Add a passkey to the vault