Beacon Identity Recovery: Ed25519 Keys, Mnemonics and Avoiding Accidental Agent Rotation

An agent network becomes difficult to operate if every reinstall creates a new identity. Beacon addresses that with persistent Ed25519 identities and recovery options. The operational challenge is preserving continuity without leaking the secret that defines the identity.

Create a normal identity

pip install beacon-skill
beacon identity new
beacon identity show

The current Beacon documentation states that identities are stored under ~/.beacon/identity/agent.key. Treat that file like a signing key, not like a profile picture. Do not commit it, email it or paste it into logs.

Mnemonic-enabled creation

If you specifically want a recoverable mnemonic workflow, install the optional dependency and create the identity accordingly:

pip install "beacon-skill[mnemonic]"
beacon identity new --mnemonic

Store the recovery phrase offline. Anyone who obtains it may be able to recreate the signing identity.

Password-protected keystore

beacon identity new --password

A password can protect a stored key from casual file disclosure, but it does not make a compromised running process safe. Threat models still need filesystem permissions, host security and secret-handling discipline.

Modern restore

The current project documentation says mnemonic restoration defaults to the modern BIP39 derivation:

beacon identity restore "word1 word2 ... word24"

After restoration, immediately run beacon identity show and compare the resulting agent ID with the expected identity before sending anything publicly.

Legacy identity warning

Older Beacon identities used a different derivation. The project documents a legacy restore path so an old mnemonic does not silently rotate into a different agent ID:

beacon identity restore --legacy "word1 word2 ... word24"

Even safer, when you know the expected agent ID, make the command enforce it:

beacon identity restore --expect-agent-id bcn_a1b2c3d4e5f6 "word1 word2 ... word24"

This is an important operational pattern: recovery should fail closed when identity continuity cannot be proven.

Trust another identity

Beacon also exposes explicit trust of an agent/public-key pair:

beacon identity trust bcn_a1b2c3d4e5f6 <pubkey_hex>

Verify public keys through an independent channel before pinning them for sensitive workflows. Trust-on-first-use is convenient, but the first contact is exactly when impersonation risk matters most.

Backups and tests

A backup is not real until restoration has been tested. Use a disposable environment to confirm that your recovery material reproduces the expected public identity. Never perform the test by publishing secrets or replacing a production key without a rollback plan.

Identity is not reputation

A stable cryptographic identity lets history accumulate, but it does not automatically make the holder trustworthy. Reputation, authorization and payment policy belong above identity. Beacon’s contribution is making “same signing identity as before” testable.

For the latest commands and security guidance, use the canonical Beacon repository.

Disclosure: prepared with AI assistance for a paid Beacon ecosystem tutorial bounty.

0 comentarii

Lasă un comentariu