Access help · private by design

Password help without handing over your keys.

Your Pooka can help untangle passwords, passkeys, two-factor authentication, recovery choices, and vault clutter. It should do the routine work and bring you only the decisions or physical actions that are truly yours.

Start here · one account lane

What kind of access mess is this?

Describe the outcome, not the key. PookaKind prepares one bounded next step and keeps the actual secret with you.

Local planning is available. Private continuation is not connected to this visit. You can still prepare and use the plan here; PookaKind will not show a private carry control it cannot honor.

What this changes: Starts by helping you choose one account and classify the problem.

0 / 600 UTF-8 bytesNo secret or provider action is accepted here.
Does this account control anything high-risk?

What this changes: PookaKind keeps the steps specific to the problem you selected.

What this changes: Changes only how the plan is framed: one safest next-step plan.

Local intake · nothing prepared yet.

What your Pooka can handle

Less password chaos. Less busywork.

  • Untangle duplicate, stale, or confusing password-vault entries
  • Choose between a passkey, security key, authenticator app, or recovery path
  • Prepare routine sign-in and security-setting work before a genuine decision
  • Leave a no-secret receipt showing what was fixed, hardened, or stopped

When you still step in

Real gates stay human.

  • Touching a physical security key
  • Approving a prompt on your phone
  • Choosing where a passkey should be saved
  • Scanning a 2FA setup code or confirming a final security change
  • Any banking, lockout, billing, or uncertain account-ownership decision

How progress is reported

One account. One honest climb.

PookaKind never calls an account fixed merely because something was saved. Each step needs evidence from the real provider, and a stop preserves the last thing that was actually proved.

  1. 01
    Prepared

    One provider lane and one bounded next action are identified.

  2. 02
    Submitted

    The official provider received one exact change or sign-in attempt.

  3. 03
    Provider accepted

    The real provider accepted the intended credential or sign-in method.

  4. 04
    Sign-in verified

    A fresh sign-in proves the accepted method works on the intended account surface.

  5. 05
    Vault reconciled

    One canonical vault item matches the provider-proved method; duplicates are not treated as truth.

  6. 06
    Right item offered

    The intended browser or app offers the canonical item at the real sign-in surface.

  7. 07
    Hardened

    The chosen passkey, authenticator, security key, and recovery posture are verified before leaving the session.

Key Dock · feature progress

Candidate passkey-response checks exist. They are not connected to your accounts.

Key Dock is intended to check that a candidate passkey response matches the original request before anything is called accepted.

Built and tested · not connected

What it is being built to check

  • The passkey response belongs to the request that started it.
  • The authenticator reports that the person was present and verified.
  • The site, credential, and returned evidence still match the request.

Platypus · feature progress

Verification codes still stay with you.

PookaKind has a local prototype under review, but it is not connected to your phone, messages, provider, or account. It cannot read or submit a real verification code.

Source recorded · independent review pending · not connected

This is build progress, not a working phone connection. Pending reviews are not counted as completed reviews.

Safety promises

Account work stays narrow and explainable.

  • A saved item never counts as a working sign-in.
  • A page changing later does not prove what caused the change.
  • One authorized specialist performs an account action.

Independent review without wider exposure

The key stays private. The evidence can still be checked.

  • Reviewers receive only redacted plans and evidence.
  • Unknown outcomes remain inconclusive.
  • There is no automatic retry or background account activity.
Technical evidence and test status Optional details

Test evidence does not establish a live account connection.

Sanitized receipt fixture

Evidence can move without carrying a key.

NOT LIVE · NOT AN ACCOUNT · NOT CONNECTED
Last proved rung
PROVIDER ACCEPTED
Sign-in proved
No
Receipts accepted
3
Current hold
CLEAR

Decision fixture

One bounded next move.

NOT LIVE · NO ACCOUNT · NO SECRET
Last proved rung
PREPARED
Demo decision
Would continue in a connected lane
Human action needed
No
Continuation
Required
pookakind.access-momentum/v1 · No browser control · No background loop

Complete reviewed Key Dock source declaration

Proved in source

  • Bind one provider WebAuthn request to one admitted Key Dock ceremony.
  • Require user presence and user verification in returned authenticator evidence.
  • Check the relying-party hash, allowed credential, signature counter, and component hashes before sealing evidence.
  • Read the bounded Windows assertion result from synthetic unmanaged memory and reject malformed pointer, size, and version combinations.

Not proved

  • The credential signature is valid without the credential public key.
  • The provider accepted the assertion or signed the person in.
  • A hardware key, vault, provider account, or live browser is connected to PookaKind.

Engineering next seam: Prove allocation and cleanup for the admitted Windows request with a synthetic call harness while the real credential call stays disabled.

Source commit
05d395b79cbc016b90c18219f5ff90ffe49044a0
Receipt commit
9a00db4899e71940e6a3a5422f2559f5a606e599
Focused tests
30

Platypus source-custody declaration

Source commit
f5e542d001adffccd5905091469126f1ec2bbcb8
Receipt commit
685f374a6b1327a72ec4b41591211bb12295fc5a
Terminal reviews
0
Pending reviews
2
Integrity hashes

Source: 5ef85da2fa529089f8a11c9044a09c722070036eb47d46df2641c9149f1498ec

Receipt: c268322356ed130dffa79d7212ae8a53b29541dbfe6283f7458296499c8ad2d9

Current product boundary

The safe intake works now. Private execution is not connected here yet.

The intake above identifies one access problem and prepares a bounded local plan—never a box asking for a password. It never accepts a master password, 1Password Secret Key, one-time code, recovery material, or vault export, and it does not connect to a vault or provider.

Live execution remains blocked until a provider-specific receipt proves usable sign-in, the intended autofill or passkey destination, recovery viability, and the promised hardening state.

Return homeNo account connection · No secret input · No background work