packages/. It separates authentication from confidentiality so the guarantee stays precise.gsr_ recovery key and shown to the user. The control plane receives the public key.gitspace machine setup --pair <token> creates separate Ed25519 signing and X25519 key-exchange keys on the computer. It proves possession of the signing key before the browser can approve the request.gsr_ recovery key as the account root secret.| Purpose | Algorithm |
| Account, machine, and browser signing | Ed25519 |
| Machine credential key agreement | X25519 |
| Key derivation for sealed credentials | HKDF-SHA256 |
| Artifact, checkpoint, and credential encryption | AES-GCM |