Skip to content

Screens

A tour of the Obsign app. Every image here is generated automatically from the app’s own browser test harness across named scenarios, so the pictures track the real UI and cannot quietly go stale.

The first launch asks a single question — what’s your situation? — and routes you from your answer: starting fresh, bringing in an account you already have, rebuilding from your backup shares, or getting off a server that’s gone.

Obsign welcome screen, 'Add an identity — what's your situation?', with 'Starting fresh', 'I have an account somewhere', 'I lost access to my wallet', and 'My server is gone' options
First launch: one situation question, routed to the matching flow.

Creating an identity needs a Custos server. Point the wallet at one that only speaks the standard lexicons and it says so on the server screen, before you have filled anything in, with import one tap away.

Obsign screen reading 'This server can't create identities', naming the configured host, with 'Import an identity' and 'Use a different server' buttons
An honest early stop: this server can host your identity, it just can't create one.

If your phone is lost, any two of your three backup shares can bring your identity to a new device. Recovery starts from your handle or DID; Share 1 is loaded automatically if iCloud Keychain carried it to the new phone. When it didn’t — iCloud Keychain was off, or the identity predates Obsign syncing that share — the screen says so and your saved Share 3 takes its place. See 2-of-3 Shamir backup.

Obsign recovery start screen with a looked-up identity and Share 1 found on the device
Recovery starts from a handle or DID; Share 1 auto-loads from the Keychain when it is present.

With one share in hand, the second can come from your server’s escrow (released with an emailed code) or from the word-phrase backup you saved.

Obsign share-collection screen showing one of two shares collected, with escrow and manual-entry options
Collecting two of three shares: ask the server for its escrow share, or enter a saved one.

A server can hold the escrow share for a waiting period before handing it over. The delay is a protection — anyone still signed in to your account can stop a release they didn’t ask for, and the wait continues on the server even if you close the app.

Obsign escrow release wait screen showing when the share becomes available and a 'Check again' button
The escrow waiting period — a release you didn't ask for can be cancelled from any signed-in device.

The home surface lists your seals with tamper monitoring shown live at the top.

Obsign home screen showing one identity and an 'All identities secure' banner
The home surface, with monitoring shown live at the top.

A single wallet can hold several identities; the root-key badge is tracked per identity.

Obsign home screen with two identities, one marked 'Root key' and one 'Not root'
Several identities in one wallet; the root-key badge is per identity.

Tapping an identity opens its DID document, decoded. A current-model identity carries three rotation keys — your device key, your recovery key, and the server’s key.

Obsign identity detail showing the decoded DID document with three rotation keys
An identity's DID document — identifier, handle, all three rotation keys (device, recovery, PDS), services.

An identity created before the recovery-key model was introduced is offered a calm, one-tap upgrade on the home surface — an improvement, not an alarm.

Obsign home screen showing an 'Add a recovery key' prompt beneath an identity card
An older identity without a recovery key is offered the upgrade in place.

App passwords are separate, revocable credentials for signing the official Bluesky app — or any app that asks for a password — into your account without ever exposing your keys. Direct-message access is off unless you allow it per credential.

Obsign app-passwords screen with a create form and two active credentials, one marked 'DMs allowed'
App passwords: what they can and cannot do, and each active credential with its own revoke.

Agents you have authorized to act on your behalf are listed under My agents, each with its permissions and full activity record.

Obsign 'My agents' screen showing a connected agent
The agents you've approved, with their permissions and activity record.
Obsign settings screen with the appearance control
Appearance and app settings.

The Media backup screen (opened from an identity) holds two backups you control: your media and your posts.

Choosing Back up media keeps your own content-verified copy of that account’s photos and video in iCloud Drive, restorable to your server byte for byte if the server ever loses the originals. The mirror size is always shown.

Obsign media-backup screen showing 3 items backed up, 8.7 MB of iCloud storage, and 'Back up now' and 'Restore to server' actions
The media backup for one identity: how much is mirrored, back up now, or restore it to the server.

A Media backup section in Settings keeps opted-in identities topped up in the background, with controls to turn that off, restrict it to while charging, or skip cellular data.

Obsign settings screen showing the Media backup section with 'Back up in the background', 'Only while charging', and 'Use Wi-Fi only' switches
The background media-backup controls in Settings — status is carried by the switch position, never color alone.

Below the media controls, Back up your posts mirrors an integrity-checked snapshot of your repository — every post, like, follow, and profile edit — into the same iCloud Drive. It’s the one part of your account that otherwise lives only on your server.

Obsign 'Back up your posts' section showing a 2.3 MB repository snapshot backed up to iCloud, with a 'Back up posts now' action
Backing up your posts — an integrity-checked snapshot of your repository, held in your own iCloud Drive.

If Obsign detects an unauthorized change to your identity’s public record, the home surface raises an alert — status is always shown with text and an icon, never color alone.

Obsign home screen showing a tamper alert banner
A tamper alert on the home surface — text and icon, not color alone.

Opening the alert shows the change and a live countdown of the 72-hour recovery window.

Obsign alert detail with a recovery-window countdown
The alert detail, with a live recovery-window countdown.

Local failures are surfaced inline with a way to retry, never a dead end.

Obsign home screen showing an inline 'Failed to load identities' error with a Try again button
An injected local failure surfaces inline with a retry, never a dead end.