Your master passphrase is what signs you in to Axiom. A fourth subkey under axiom:api:v1 becomes the credential, and the server keeps only its SHA-256 — it still cannot decrypt a thing. Your access key keeps working as break-glass.
Self-Tests
idle.
Threshold Recovery
Split the root key into n shares over GF(2⁸) so any k rebuild it and any k−1 reveal nothing. Not "less" — zero. Every possible key stays exactly as likely.
sign in with your passphrase to split your root key
threshold k
shares n
Shares · tap to select
no shares yet
idle.
Shares are shown here and never leave the browser. Write them down, split them across places, and the vault survives a forgotten passphrase.