Discoverable credentials let you sign in without typing an identifier, with a private key that never leaves your device. Here is how they work, where they fail, and how they fit a zero-knowledge vault.
Three private surfaces. Same zero-knowledge architecture.
A non-discoverable credential requires the site to tell the authenticator which credential ID to use, which means you must identify yourself first.
That is why a strong login cannot rescue a lost password, and why the Recovery Kit exists: a printable, offline key holder that lets you rebuild access without ever giving us the ability to do it for you.
Three private surfaces. Same zero-knowledge architecture.