Keys are the heart of sovereignty.

LIVRE OS uses a three-key model:

1. Control Key

Default key for actions, proofs, signing requests.

Control key - signs state transitions (updates, rotations).

Not directly exposed in the Identity Commitment.

2. Recovery Key

Used when the control key is lost.

Encrypted and stored safely offline or multi-device.

Recovery key - used only for recovery flows.

Their commitment is **control_key_commitment** in the Identity State.

3. Delegation Keys (optional)

Allow apps, institutions, or devices to request actions or proofs without giving up control.

Auth / session keys - used for app logins, device sessions, etc.

Key Lifecycle Stages