hachiflow.com
Keys

Two keys. The app only backs up one.

A Hachiflow workspace involves two different keys. They are the same shape, they both start with nsec, and they get conflated constantly. One proves you are you. The other proves you own the workspace. Read the table before you read anything else on this page. If you are looking for the setup walkthrough instead, it is on connect your app.

01 · The distinction

One proves who you are. The other proves what you own.

Buzz creates your personal identity key on your own device the first time you run it. Our control plane generates your workspace owner key when it builds your workspace. Neither key knows anything about the other, and they are not interchangeable. Losing one of them is an inconvenience. Losing the other, with nothing in escrow, ends the workspace.

How they differ Personal identity key Workspace owner key
Generated by Your own device, by Buzz, on first run. Our control plane, when your workspace is provisioned.
What it proves I am this person. I own this workspace.
Where it lives Your system keychain. Our escrow, which we can read, plus wherever you put it after claiming.
If you lose it Recoverable only from whatever you saved when you signed out. Reclaimable from us at app.hachiflow.com/keys.
Backed up by Buzz's sign-out prompt Yes. No.
read this twice

The prompt backs up the wrong key

Buzz prompts you to save your key when you sign out. That backs up your personal identity, not your workspace. The prompt is a real safety net and it is the easiest way to get your own key out of a running app. It is also the reason a careful customer can save a key, file it properly, feel covered, and hold no copy of the key that actually confers ownership.

Our escrow is the only backup for the key that confers ownership. That is the honest core of what escrow is for.

Both keys are an nsec1... string and nothing in either one says which is which. Label them when you save them. "yourteam workspace owner key" and "my Buzz identity" is enough.

02 · The owner key

The root of authority, and we keep a copy on purpose.

Your workspace owner key is a real cryptographic keypair, generated when your workspace was built. It is what your relay recognises as the owner. Anyone holding it is the owner, which is why it is worth being careful with, and why we hold a copy so that a lost key does not mean a dead workspace.

What is the workspace owner key?

The root credential for your workspace. It proves ownership to the relay, it can take administrative action inside the workspace without us, and it is what you need to move the workspace to your own infrastructure or hand it to someone else.

It is yours, not ours. We are a hosting company, not a gatekeeper standing between you and your own workspace. If we vanished tomorrow, the owner key plus a backup is everything you need to stand your workspace up somewhere else.

What happens when I claim it?

You claim it in the dashboard at app.hachiflow.com/keys. There are two steps before anything happens: a screen explaining what claiming commits you to, then a screen that confirms it. The key is printed after that, on one screen. Have your password manager open before you start, because that page will not print it a second time.

Claiming destroys nothing. No key is rotated, nothing is revoked, and your workspace runs exactly as it did before. Our control plane records every handover, repeats included, so the trail shows each time the key left us and which address it went to. Lose it later and we can hand over the escrow copy again once we have verified who you are.

Do you keep a copy, and can you read it?

Yes to both. Your workspace secrets sit in private object storage that only our credentials reach, at Cloudflare R2, which encrypts them at rest under its own keys and moves them over TLS. That defeats a stolen disk and anyone without our credentials. It does not defeat us, and we will not imply otherwise.

Readability is the mechanism, not a gap. Handing back a key you have lost is only possible while a copy we can read still exists. If you would rather we could not, say so and we delete our copy. One caveat we would rather say than have you discover: a copy also sits in every backup we retain, and we keep the newest 14, so the last readable copy goes about a fortnight after you ask rather than the same day. Say the word and we will purge the backups too. Once the last one is gone, losing yours means nobody can recover the workspace, including us. No reset, no override, no backdoor. Plenty of customers want exactly that, it is a legitimate choice, and it is not reversible.

Where should I put it?

A password manager. 1Password, Bitwarden, whatever your team already uses. Not a sticky note, not a message to yourself, not a file called key.txt on your laptop. Treat it like the root password to a server you cannot rebuild.

Who is allowed to claim it?

The signed-in owner of that workspace, and nobody else. A workspace your address does not own answers exactly as though it does not exist, so the page cannot be used to find out whether someone else's workspace is real. Every claim is recorded against the address it was handed to.

03 · Your identity

Your personal key is made on your own machine.

Buzz uses an identity key instead of an account. Every member of a workspace, human or agent, signs everything it does with its own keypair, which is what makes the audit trail worth having. Your personal key is created locally and kept in your system keychain. We never see it.

What is my personal identity key?

The keypair that represents you in any Buzz workspace. Buzz creates it on first run, stores it in your operating system keychain, and signs your messages with it. Its public half is your public ID, safe to share. Its private half should never leave your machine.

Buzz asked me to save my key when I signed out. Which key was that?

Your personal identity key. That prompt never touches your workspace owner key, and saving it is not a workspace backup. If the workspace matters to you, claim the owner key separately and store it separately.

I chose "Create a new identity key" and got a key I already had

We have reproduced that on Buzz 0.5.2. On an install that already holds an identity in the keychain, "Create a new identity key" can report that a key has been created and then hand back the existing one. We are writing it up for the upstream project.

It matters here for one reason. If you imported the workspace owner key first and then pressed that button expecting a separate personal identity, you may still be holding the root credential for the workspace while believing you are not. If you are unsure which identity an install is holding, send us the public ID it shows and we will tell you whether it is your owner key.

Should I paste the owner key into the app?

It works. The owner key is already enrolled on your relay, so pasting it under "Use an existing key" and then entering your relay URL puts you in with owner standing. We have driven that path against a freshly provisioned workspace.

We suggest the other order anyway: create a personal identity, send us its public ID so we can enrol it, and claim the owner key later, deliberately, straight into a password manager. Importing the owner key moves your root credential onto a laptop on day one.

04 · Getting in

Two doors work. Two others go somewhere else.

Block builds Buzz and also hosts it. Two buttons in the app are for their hosting, and they are labelled the way an owner would expect, so an owner clicks them. Ours is a different door. Knowing which is which before you start saves you the detour.

Which buttons get me into a Hachiflow workspace?

On "Join or create a community", choose Join a community and paste your relay URL. If the app asks for your role instead, choose I'm a member or admin and paste your relay URL there. Your role is restored when you connect, so an owner does not need the owner-labelled button.

What happens if I press "Create a community" or "I own the community"?

Both open Builderlab in your browser. Builderlab is Block's own hosted service for Buzz, and those two buttons are how you sign in to it. Nothing is wrong with them and nothing breaks if you press one. They are for Block's hosting rather than for a workspace we host for you, which is a different door with a less obvious label.

If you end up there, step back in the app and take one of the two doors above.

Do I always need the relay URL?

Yes, on any fresh install. A key is a keypair and nothing in it points at a hostname, so no key can tell the app where your workspace is. Your relay URL looks like https://yourteam.hachiflow.chat. Either the URL, or an invite link that carries it, goes in the field labelled "Invite link or community URL".

I pasted a key and my workspace appeared without a URL

That install had connected before, and the app restored local state from a previous session. It will not happen on a new machine. Keep the relay URL somewhere you can find it rather than relying on that behaviour.

The app says "Not a member yet"

Your relay admits keys that have been enrolled on it, and the identity Buzz just created for you has not been. The screen shows your public ID with a copy button and tells you to send it to a relay admin. On a workspace we host, that is us.

Email hello@hachiflow.com with your public ID and your workspace name. Enrolling it takes seconds, and the app clears the wall as soon as you press "Try again". Send us the public ID before you connect and you never see that screen at all. Nothing you send us to get in is secret.

The step-by-step version of all of this, download to first message, is on connect your app.

05 · Safety

We will never ask for your private key.

A public identity is safe to hand over. A private key is not, and there is no legitimate reason for anyone to ask you for one. This section is short, and it is the part worth remembering.

Why do you ask for my public ID?

Because it is the half that is safe to give away. Your public ID, an npub, names you without granting anything. Enrolling it on your relay is what turns "Not a member yet" into a workspace. The app says as much on the screen where it offers it: this is your public identity, it is safe to share.

Will Hachiflow ever ask for my private key?

No. Never, through any channel. Not by email, not in a support thread, not on a call, not in a form on this site. We do not need it. Everything we do for you is done with your public ID, or with the escrowed owner key we already hold.

Nobody legitimately will. Not us, not Block, not a teammate, not anyone presenting themselves as support. Treat any request for a private key as an attack no matter how ordinary it looks, and send it to hello@hachiflow.com so we can look at it with you.

Will macOS refuse to open Buzz?

No. The app is signed by Block, Inc. and notarized, the ticket is stapled, and spctl reports accepted. There is no unidentified-developer wall, no right-click ritual, nothing to strip off the download. One habit worth keeping: drag Buzz to Applications and launch it from there rather than running it out of the mounted disk image.

Is every platform in that state?

No, and we will not pretend otherwise. The app inside the macOS disk image is signed and notarized, but the .dmg wrapper itself is not signed, so anyone who checks the download with codesign sees that and reasonably worries. The Windows build currently ships as an unsigned alpha and SmartScreen warns about it.

06 · Agents

Agents are unlimited, and the reason is structural.

You pay for a workspace, not for the members in it. Agents are not counted or sold by the head, and that is not generosity: the expensive part of an agent runs on your side of the line, not ours.

How many agents can I run?

As many as the work needs. There is no per-agent charge and no agent add-on. An agent is a member of your relay: its own keypair, its own channel access, its own signed history, so it uses storage and relay capacity like an active teammate. What it does not use is our compute.

Where does an agent actually run?

On your machine, by default. The desktop app starts the agent runtime as a local child process, and we have watched it do exactly that in a process listing. Inference runs on your own LLM keys, billed to you by your provider at cost. We never proxy that traffic and we never mark up inference.

Do my agents need to be enrolled separately?

No. An agent gets its own keypair, and your relay admits it on the strength of an attestation signed by your key. The app mints that attestation and passes it to the runtime with no action from you. We verified it against a live workspace: the same agent key was refused without the attestation and accepted with it, and it never entered the member list.

Where do my LLM provider keys live?

Not in the keychain, and never with us. Buzz keeps identity keys in your system keychain, but provider API keys are written into its own configuration files under the app data directory on your machine, readable only by your user account. A provider key never reaches us: it is in nothing we provision, store or back up. Worth knowing in both directions before a security review asks.

07 · If you lose one

What comes back, and what does not.

The answer depends entirely on which key you lost, which is why the rest of this page spends so long on the difference. Find your row.

I lost my personal identity key

If you saved it when you signed out, import it again under "Use an existing key". If you did not, it is gone: it only ever lived in your keychain and we never had a copy. Nothing about your workspace is lost. Create a new identity, send us the new public ID, and we enrol it. Your old messages stay where they are, on your relay, signed by the old key.

I lost the workspace owner key

Ask us for it. We still hold the escrow copy, and we hand it over again once we have verified who you are. Email hello@hachiflow.com from the address that owns the workspace. Nothing about your workspace is affected while you sort it out: day-to-day use does not depend on you holding that key.

I lost both

Then you are in the ordinary case. Generate a new personal identity and send us its public ID, which puts you back in the workspace, and ask for the owner key out of escrow in the same email. The first one is minutes. The second waits on us verifying who you are, and it is not urgent.

I asked you to delete the escrow copy, and now my key is gone

Then the workspace cannot be re-owned, once the backups we retain have aged out and taken the last readable copy with them. Not by you, not by us, not by anyone, and we are not going to pretend there is a way around the thing you deliberately chose. Your data is still on a server we run and we can still export all of it for you.

Before you conclude the key is gone, look everywhere it could be: password manager history, a deleted-items list, an old laptop, a printed copy in a safe. People find them more often than you would think.

One rule

Back up the key that confers ownership.

Claim it, put it in a password manager, label it. Then tell us whether you want our copy kept or deleted. Email hello@hachiflow.com with your workspace name and a human answers, and during early access the people answering are the people running your relay.

Email us about keys