Skip to main content
Allow users to export their recovery phrase or private keys so they can access their wallet outside Rain. Key export is a high risk action. Anyone who obtains an exported recovery phrase or private key can control the associated funds. Rain cannot revoke, rotate, or recover an exported secret. Use key export for portability and emergency recovery, not as the default backup authentication method.

Why it exists

  • Portability. Users can move their wallet to another compatible wallet provider without relying on Rain.
  • Emergency recovery. If a user permanently loses access to every authentication method, a previously exported recovery phrase or private key may still allow them to regain control of their funds. See Backup and recovery.
  • Interoperability. Users can import their wallet into compatible software or hardware wallets.

Formats

The available export formats are the same on iOS and Android. Use the recovery phrase when the user needs to restore the full wallet. Use a private key only when the user specifically needs access to an individual account.

Export a secret

Export requires an active session. If no session is available, the SDK returns RAIN_201.

Presenting the export safely

Exported recovery phrases and private keys give direct control of the wallet. Only display them after an explicit user action, and never send, store, or log them.
1

Require reauthentication

Require biometrics or the device passcode immediately before the export call: LocalAuthentication on iOS, BiometricPrompt on Android. Don’t cache the result across screens.
2

Warn before revealing

Show a confirmation screen before displaying the secret. Make clear that:
  1. Anyone with the recovery phrase or private key can control the wallet.
  2. Rain and your support team will never ask the user to share it.
  3. The user should store it securely and avoid screenshots or digital copies.
Require an explicit action to reveal the secret.
3

Protect the rendering

  • iOS: mark the view .privacySensitive() so it’s blurred in the app switcher, and consider hiding it when UIScreen.capturedDidChangeNotification reports recording.
  • Android: set FLAG_SECURE on the window so screenshots and screen recording are blocked, and exclude the view from Compose or View-level accessibility text dumps.
  • For recovery phrases, display numbered words rather than a paragraph so users can copy them accurately by hand.
4

Handle the clipboard carefully

If you offer Copy, use a local-only clipboard entry (iOS: UIPasteboard.general.setItems(_:options: [.localOnly: true, .expirationDate: ...])) with a short expiry, and tell the user it will clear. Never copy the secret automatically.
5

Keep it out of logs

Do not log exported secrets, attach them to analytics or crash reports, persist them locally, or send them to your backend. Clear references to the secret when the export screen is dismissed.Review third party SDKs that capture screens, view hierarchies, logs, or analytics to ensure they cannot collect exported secrets.
Do not build a flow that sends an exported recovery phrase or private key to your servers, including encrypted storage for recovery purposes. Once your systems store a copy of the secret, you become responsible for protecting credentials that can directly control user funds.

Export is not a substitute for backup authentication

Key export should not be the primary recovery method. Exported recovery phrases and private keys can be lost or compromised, and many users will never export them at all. For most users, the recommended recovery setup is a second authentication method, preferably a verified email address. Offer key export to users who want portability or direct control of their wallet, not as a replacement for backup authentication. See Backup and recovery.

What’s next

Backup and recovery

The recovery model and the support runbook.

Security model

Where keys live and who can sign.