Capy keeps your wrapped key material on your machines. Moving to another computer is therefore an explicit transfer, not a normal sign-in restoring a server-side key backup.
Move keys with a browser transport
- On a machine that already has your keys, run
capy transport.
- Open or scan the QR code in a browser you can access later. Sign in with the same Capy account. The browser activates the one-time transport.
- On the new machine, run
capy pair. Open or scan its QR code and approve the device grant in a browser.
- Read the account Capy shows and explicitly confirm it. The default is No. Only then does the new machine install its session and the key entries activated for that account.
The transport link expires at the time Capy prints. It is one-time: activation deletes the server-side transport record.
The full transport link is sensitive. Its fragment contains a fresh one-time key that is deliberately not sent to the service. Do not share or log the link, QR code, or --json output.
How the transfer protects keys
For Transport v4, the original machine encrypts a package containing its local key material with a fresh random key. The service stores the encrypted package. The browser link holds the transport id and random key separately, so the service cannot decrypt the stored package from its own data alone.
The browser requires a sign-in to activate the transport. capy pair uses a separate browser device grant and confirms the returned account before installing anything. That confirmation protects against silently attaching a shared machine to the wrong account.
Other recovery paths
If you own the organization and retained its 24-word recovery phrase, use capy recover on the new machine. The phrase re-derives the organization key locally; Capy cannot reconstruct a lost phrase.
If you do not have that phrase or another paired device, ask an admin to issue a fresh invite. Run capy redeem <code> on the new machine. Invite codes and browser transports are different flows: do not use capy redeem for a Transport v4 link.
See also
Last modified on October 2, 2026