> ## Documentation Index
> Fetch the complete documentation index at: https://rain-sandbox-trial.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Key Export

> Let users export their recovery phrase or a per-chain private key, decrypted on their device, and present it safely.

Allow users to export their recovery phrase or private keys so they can access their wallet outside Rain.

Key export is a high risk action. Anyone who obtains an exported recovery phrase or private key can control the associated funds. Rain cannot revoke, rotate, or recover an exported secret.

Use key export for portability and emergency recovery, not as the default backup authentication method.

## Why it exists

* **Portability.** Users can move their wallet to another compatible wallet provider without relying on Rain.
* **Emergency recovery.** If a user permanently loses access to every authentication method, a previously exported recovery phrase or private key may still allow them to regain control of their funds. See [Backup and recovery](/docs/embedded-wallets/backup-and-recovery).
* **Interoperability.** Users can import their wallet into compatible software or hardware wallets.

## Formats

The available export formats are the same on iOS and Android.

| Export | Call | Format | Import into |
| - | - | - | - |
| Recovery phrase | `exportRecoveryPhrase()` | 12 word BIP 39 recovery phrase | Any BIP-39 wallet; Ethereum at `m/44'/60'/0'/0/0`, Solana at `m/44'/501'/0'/0'` (the defaults in MetaMask and Phantom) |
| Ethereum private key | `exportPrivateKey(.ethereum)` / `exportPrivateKey(ETHEREUM)` | Hex encoded private key | MetaMask, Rabby, and other EVM wallets |
| Solana private key | `exportPrivateKey(.solana)` / `exportPrivateKey(SOLANA)` | Base58 encoded keypair | Phantom, Solflare, and the Solana CLI |

Use the recovery phrase when the user needs to restore the full wallet. Use a private key only when the user specifically needs access to an individual account.

## Export a secret

Export requires an active session. If no session is available, the SDK returns `RAIN_201`.

<CodeGroup>
  ```swift iOS theme={null}
  let phrase = try await wallet.exportRecoveryPhrase()
  let ethereumKey = try await wallet.exportPrivateKey(.ethereum)
  let solanaKey = try await wallet.exportPrivateKey(.solana)
  ```

  ```kotlin Android theme={null}
  val phrase = wallet.exportRecoveryPhrase()
  val ethereumKey = wallet.exportPrivateKey(RainWalletKeyAccount.ETHEREUM)
  val solanaKey = wallet.exportPrivateKey(RainWalletKeyAccount.SOLANA)
  ```
</CodeGroup>

## Presenting the export safely

Exported recovery phrases and private keys give direct control of the wallet. Only display them after an explicit user action, and never send, store, or log them.

<Steps>
  <Step title="Require reauthentication">
    Require biometrics or the device passcode immediately before the export call: `LocalAuthentication` on iOS, `BiometricPrompt` on Android. Don't cache the result across screens.
  </Step>

  <Step title="Warn before revealing">
    Show a confirmation screen before displaying the secret. Make clear that:

    1. Anyone with the recovery phrase or private key can control the wallet.
    2. Rain and your support team will never ask the user to share it.
    3. The user should store it securely and avoid screenshots or digital copies.

    Require an explicit action to reveal the secret.
  </Step>

  <Step title="Protect the rendering">
    * iOS: mark the view `.privacySensitive()` so it's blurred in the app switcher, and consider hiding it when `UIScreen.capturedDidChangeNotification` reports recording.
    * Android: set `FLAG_SECURE` on the window so screenshots and screen recording are blocked, and exclude the view from Compose or View-level accessibility text dumps.
    * For recovery phrases, display numbered words rather than a paragraph so users can copy them accurately by hand.
  </Step>

  <Step title="Handle the clipboard carefully">
    If you offer **Copy**, use a local-only clipboard entry (iOS: `UIPasteboard.general.setItems(_:options: [.localOnly: true, .expirationDate: ...])`) with a short expiry, and tell the user it will clear. Never copy the secret automatically.
  </Step>

  <Step title="Keep it out of logs">
    Do not log exported secrets, attach them to analytics or crash reports, persist them locally, or send them to your backend. Clear references to the secret when the export screen is dismissed.

    Review third party SDKs that capture screens, view hierarchies, logs, or analytics to ensure they cannot collect exported secrets.
  </Step>
</Steps>

<Warning>
  Do not build a flow that sends an exported recovery phrase or private key to your servers, including encrypted storage for recovery purposes. Once your systems store a copy of the secret, you become responsible for protecting credentials that can directly control user funds.
</Warning>

## Export is not a substitute for backup authentication

Key export should not be the primary recovery method. Exported recovery phrases and private keys can be lost or compromised, and many users will never export them at all.

For most users, the recommended recovery setup is a second authentication method, preferably a verified email address. Offer key export to users who want portability or direct control of their wallet, not as a replacement for backup authentication. See [Backup and recovery](/docs/embedded-wallets/backup-and-recovery).

## What's next

<Columns cols={2}>
  <Card title="Backup and recovery" icon="life-ring" href="/docs/embedded-wallets/backup-and-recovery">
    The recovery model and the support runbook.
  </Card>

  <Card title="Security model" icon="shield-halved" href="/docs/embedded-wallets/overview#security-model">
    Where keys live and who can sign.
  </Card>
</Columns>
