Sealed capsule
Seal something now so that it cannot be opened before a moment you choose.
format: beattime-seal-v1 · sealed in your browser
This page does the sealing, not the server. The text, the file, the master secret and the recovery code are produced here and stay here — there is no endpoint that would accept them. What the service publishes is the public half: the chain parameters, the operator registry and the shares that are released once their moment has passed. The format is described in full under time-sealed envelopes.
1What goes in
A message, or a file. The name and type of a file are encrypted together with it — the envelope itself gives nothing away.
2When it opens
Your local time. It is stored as a @beat index — one number, the same everywhere on Earth, with no timezone to get wrong.
3Who holds the keys
The key is split so that no single holder can open the capsule alone — including us.
Sealed
- capsule
- opens
- threshold
- holders
- size
Your recovery code — shown once. It is not stored anywhere, here or on the server. Write it down; it is designed to survive being copied by hand.
1The capsule
Load the file you saved, or paste its contents.
2What it says
- capsule
- opens
- threshold
- holders
This capsule keeps its contents in a separate file.
A recovery code, if you have one. It stands in for one holder — it does not make the capsule open any sooner.
Opened
Keep the capsule file. It is the only copy — nothing about it is stored on this site. Back it up the way you would back up a photograph you cannot retake.
Once a moment has passed, the shares that open capsules for it are ordinary public data. Anyone can fetch, mirror or archive them, and the operators are in neither the trust path nor the availability path. That is what makes a capsule outlive the service that made it.