kkeyroost

Learn · resetting

Resetting a key, safely

A reset gives you a clean slate — and is irreversible. Here's what each applet's reset actually erases, and the checklist to run first.

What a reset does

Each applet resets independently — wiping the FIDO function doesn't touch OATH, and so on. In every case the point is the same: keys and credentials are destroyed, not recoverable. Because the secrets only ever lived on the device, there is no backup to restore from unless you made one.

A whole-key reset is a sweep of independent steps, not a single atomic act. Each applet that completes comes back in factory condition, and every step reports its own outcome — so a run can legitimately end with some applets wiped, one failed, and the key still needing attention. Read the report; don't assume a clean slate because the command finished.

Before you reset — the checklist

  1. Have another way in. A second registered key, or current recovery codes, for every account this key unlocks. Verify it works before wiping.
  2. Re-derive what you'll re-add. Make sure you can re-enroll OATH seeds and regenerate or re-import OpenPGP/PIV keys.
  3. Decryption keys are special. Data encrypted to an OpenPGP encryption key or PIV key-management slot can't be read after the key is gone — decrypt or re-key it first.
  4. Then reset, set a fresh PIN, and re-register before relying on it.
There is no undo

A reset can't be reversed and the destroyed keys can't be regenerated from the device. When in doubt, stop and confirm your recovery path first.

How keyroost treats resets

k

A destructive command never guesses which key it is aimed at. With one key connected it uses that key; with several it refuses until you name one with --device, and it rejects --reader and --device together, since those can name different keys. Every wipe also needs an explicit --yes. Reset support spans the FIDO2, OATH, OpenPGP, PIV, Token2 on-device OTP, and Molto2 applets; read-only inspection (list, fido info, piv status) never changes anything and never needs a PIN.

Resetting a whole key at once

One command wipes every resettable applet the key exposes, in order — OATH, OpenPGP, PIV, Token2 on-device OTP, then FIDO2 last, because its reset needs an unplug/replug and a touch:

keyroostctl factory-reset --yes

The card applets run silently; the OTP step wants a confirming button press on the key; the FIDO2 step prompts you to re-plug and touch. keyroost pins the key's identity before the sweep starts and verifies the key that comes back after the replug is the one you confirmed — a key that exposes no serial is accepted only when it is unambiguously the only one connected. Each step prints its own result and the command exits nonzero if anything failed.

The desktop app offers the same sweep as a Factory reset card on a key's Overview tab, with a live per-step report — including a FIDO2 row — so you can see exactly which applets came back clean and which need another pass.

The Token2 Molto2 is not part of this sweep; it has its own keyroostctl molto reset --yes, which also needs a physical button confirmation on the token. Molto2 →

Authoritative resources