Sessions and devices
How login sessions and co-signing devices work on a Botanary account.
Two related but different things keep a Botanary account both usable and safe day to day: your login session, and the set of devices that can co-sign for your account.
Sessions
Logging in exchanges your Privy authentication for a Botanary session - an opaque, revocable bearer token. The backend never holds a signing key as part of this; the session only identifies you and which chains and account you're operating against. A session expires after 24 hours, and you can end one yourself at any time (signing out, or locking).
Locking your session is about availability, not custody. Your funds stayed in custody the whole time - everything you granted is still bounded and revocable.
Devices
"Devices" are the co-signing keys on your account's root validator - the M-of-N multisig described in The smart account. Every device carries an address, an optional label, and a flag for whether it's the one you're currently signed in with.
N of M to move money or change rules. Any one device can freeze the account instantly.
Adding, removing, and re-thresholding devices are all owner-lane operations: Botanary builds the unsigned operation, and you sign and relay it yourself, the same as any other action. A few rules apply:
- Adding a device rejects a duplicate address, and doesn't change your signing threshold by itself.
- Removing a device is refused if it would drop your device count at or below your current threshold
- lower the threshold first.
- Setting a threshold must be a positive number no greater than your current device count.
None of these three operations cost gas, and none of them are treated as risk-reducing the way a freeze is - they're routine account maintenance, not emergency actions.