Passkey-PRF unlock — N independent methods, one key (header-free)

The DB's key (DEK) is not stored. It is wrapped by an envelope with one slot per unlock method. Add a passkey, a second passkey, a written recovery code — each wraps the same DEK, so any one opens the DB and losing one loses nothing. Adding/removing a method re-wraps the DEK; it never re-encrypts the database.

1 · Enroll

2 · Add unlock methods

3 · Unlock / lock the session

4 · Move to another device (server-blind)

Export bundles the envelope + credential id + the encrypted DB image into one binary .freehold file — no key inside. Import it on device B, then unlock there with the same synced passkey (tests PRF stability) or the recovery code (works anywhere by construction).

Methods on this envelope

Idle. Needs a platform authenticator (Windows Hello / Touch ID) or a
security key supporting the WebAuthn prf extension.