Enrol a new device with no password: the new device makes an
ephemeral keypair, an already-unlocked device wraps the master key to it, and
only ciphertext crosses the gap. Proves the whole chain — the new device ends
up able to read an encrypted note it has never seen the key for.
Open this page twice (two tabs, or two devices) and use the
left panel on one and the right panel on the other. Payloads move by
copy-paste here; production carries the public key in a QR code. Either way the
fingerprint comparison is the security control, and that works
identically.