One key, one network — never both. Declaring it lets the toggle filter your keys, and lets a mirror-node lookup shout if the key turns up on the other one.
Keys you watch
current · due soon · overdue · unconfirmed — never proven, or overdue too long to count on
Accounts you look after
Paste anything with account ids in it — a list, a document, a hashscan page. Every 0.0.N is picked out and added for the network selected above. Look up asks that network's mirror node for the account's key structure, its last account update, and its balance. Then the rings: inner is what the chain requires, m of n; outer is one wedge per key, coloured by what this ledger knows — the key's health, or white for a key we have no record of. A key that is a salted child of a master you hold is found from the master alone.
ready — the keys held satisfy the threshold and are current · held, but checks overdue · not enough keys held · no keys on record
Confirm you have these keys
Tap a key to include it or leave it out. One challenge, every key you pick. Scan it with KSIGN, Sign all matched, and bring each signature back. The challenge starts with the bytes KPOP1, which no Hedera decoder accepts — signing it can move nothing.
payload and raw bytes
Key health
Four things measured per key: how strong the key is, how it is held, how much it controls, and whether you keep proving it. Possession, availability and custody are kept apart — a proof shows the first, a pattern the second, and the third is what you record here.
—
The ladder
Levels are qualifications, not vanity. Demotion happens on Unconfirmed, never on a single miss. Guardian and Steward need attested custody and recovery drills, which this device cannot measure alone.
About KPOP
The idea. A keyholder is never asked to sign a transaction. Every so often, inside a window they cannot predict, they prove one thing: can you still produce a signature with this key? Everything else — how much the key controls, whether a recovery could be satisfied today — is derived from those proofs.
Four states. Current, due soon, overdue, unconfirmed. Overdue is not lost. The app never records "key lost"; it records "possession not demonstrated within policy".
Policy. Set by the key's authority: how often, within what window, how fast, with what verification. Practice keys are weekly with a day to answer; critical keys weekly with an hour, on an attested device.
What it holds. Public keys, names, custody notes, receipts. No secrets, nothing that can sign. All of it in this browser; Back up hands it to you as one line.
What it does not do. Sign — that is KSIGN's, or a wallet's. Talk to a server — sharing is by paste. Issue notifications — a static page cannot; the window and the issue day are shown instead.
Online, when you ask. Look up accounts on a key asks the public Hedera mirror node which accounts use it. Nothing else ever leaves the device.
Versions. The footer shows the build running in this tab. KPOP keeps its own copy of itself so it opens with no network, which means a new deploy does not appear until that copy is replaced — when one is out, a banner offers it. If a browser ever gets stuck on an old build, Get a fresh copy below drops the cached copy and reloads. It does not touch your keys, names or receipts: those live in this browser's storage, which neither button goes near.
Questions and what comes next. The FAQ covers why the challenge is what it is, the four states, the network rule, and — separately from rotation — the flows where custody itself moves: a leak and break-glass, an interim 1-of-1, a hand-over, a sale. It is the working notes for where KPOP goes.