Identity, plain and patient.
Yubico, Ledger, and Trezor make great hardware. Auth0 and Clerk authenticate users into web apps. Turnip is the only identity layer designed for an operating system that holds real money — every elevation is hardware-bound, every capability is time-bound, every action chains back to a human DID.
Settings
Multi-Factor Authentication
Require MFA for all team members
Session Timeout (minutes)
Inactive sessions will expire after this duration
WebAuthn / Passkeys
Passkey management is available through your browser's security settings. Supported browsers include Chrome, Safari, and Firefox.
Step-up verification
This action is sensitive. Verify it's you to continue.
PasskeyPreferred
Use your L1fe passkey in the browser for this sensitive action.
Authenticator app
Verify with a one-time code from an enrolled authenticator app.
Password
Confirm with your account password.
Email code
Receive a one-time code by email.
Capabilities are minted just-in-time, with a 6-check policy gate.
When an agent needs to act, it requests a capability scoped to one action with a TTL in minutes. Turnip verifies the delegation chain, requires a hardware step-up, and signs the Arsenal token. Revoking the parent capability instantly collapses every descendant token.
API Keys
API Key Created
Copy it now — it won't be shown again.
gk_live_9f2e81c4a07d…3bActive keys
Scopes: Global · Platform · Project — least privilege by default| Name | Key | Scope | Created | Last Used | Expires | |
|---|---|---|---|---|---|---|
| billing-bot · production | gk_live_9f2e•••• | Project | Apr 02, 2026 | 2 minutes ago | Sep 30, 2026 | Revoke |
| close-agent · scoped | gk_live_4471•••• | Project | May 18, 2026 | 1 hour ago | Pending | Revoke |
| platform · treasury sync | gk_live_c30d•••• | Platform | Jan 27, 2026 | Yesterday | — | Revoke |
| ci · read-only | gk_test_88e1•••• | Global | Feb 09, 2026 | 3 days ago | — | Revoke |
Identity built for money, not for marketing emails.
Auth0 and Clerk authenticate users. Turnip authorises capabilities.
| Capability | Auth0 | Clerk | Okta | Turnip |
|---|---|---|---|---|
| WebAuthn / passkey | ✓ | ✓ | ✓ | ✓ |
| Hardware-bound step-up | — | — | MFA | ✓ scope + ttl |
| Capability tokens (scoped) | — | — | — | ✓ Arsenal |
| Time-bound minting | session | session | session | ✓ seconds-scale |
| Lineage proofs for agents | — | — | — | ✓ |
| Shamir / guardian recovery | — | — | — | ✓ |
| Multi-device + threshold | — | — | — | ✓ FROST |
| Audit-chained auth events | logs only | logs only | ✓ | ✓ blake3 |
Agents mint capabilities. Humans authorise scopes.
An agent never holds a long-lived credential. It exchanges a delegated capability for a just-in-time Arsenal token. The token binds to one action and scope — and dies in seconds.
Eight capabilities your auth stack can't.
- 01WebAuthn / passkey enrollment and step-up
- 02Hardware-bound session elevation (YubiKey, Ledger, Trezor, Apex)
- 03Time-bound, scope-bound Arsenal capability tokens
- 04Just-in-time capability minting (no long-lived secrets)
- 05Shamir-on-paper recovery ceremonies
- 06Multi-device pairing under one identity
- 07Lost-device revocation under threshold
- 08Audit-chained auth events sealed to Bean




