Key Command
The ppk key command group generates, verifies, and packages recovery keys. This manual covers:
key generatekey checkkey export-recovery-kitkey verify-recovery-kitkey print-recovery
Standard key directory contains:
ppk.pub: public key used for backupppk.key: private key used for restoreppk.pwd: passphrase file—only when you explicitly choose file-based passphrasesmanifest.json: non-sensitive metadata
Backup nodes keep only the public key; restore nodes keep the private key and passphrase material. Prefer --key-home for the standard key directory; legacy backup_recipient.pub / backup_recipient.key remain supported.