Living Document Notice
Published 2026-09-17. The evolving architecture and revisions for this dispatch live in the Stax Digital Garden.
Secure Family Invites and Cryptographic Session Revocation
Inviting non-technical family members into self-hosted applications often stumbles over complex multi-factor authentication setup or insecure shared passwords. When an invite link leaks or a relative loses a mobile device, household administrators need immediate cryptographic revocation without locking out other family members.
Embers solves invite onboarding through single-use, cryptographically signed invitation tokens. Invites bind directly to named family accounts or time-bounded guest sessions. If an account credential requires revocation, administrators invalidate active session tokens instantly from the local management console.
Invitation Lifecycle and Verification
The invite sequence ensures tokens cannot be reused or guessed:
Admin Console ──► Issues 32-byte signed invite token (TTL: 48h)
│
▼
[ New Family Member ] ──► Redeems invite via HTTPS
│
▼
[ Embers Auth Gate ] ──► Verifies Ed25519 signature
│
├─► Binds account to household circle
└─► Burns invite token in SQLite database| Security Primitive | Conventional Cloud Pattern | Embers Household Pattern |
|---|---|---|
| Invite Mechanism | Open signup or unbounded link | Single-use cryptographically signed token |
| Revocation Scope | Delete user account entirely | Per-device session invalidation in SQLite |
| Credential Storage | Vendor cloud identity store | Local Argon2id password hashes |
Session Invalidation in Node.js
import Database from "better-sqlite3";
import crypto from "crypto";
const db = new Database("/var/lib/embers/data/embers.db");
export function revokeSession(sessionId: string, userId: string): boolean {
const stmt = db.prepare(
"UPDATE sessions SET revoked_at = datetime('now') WHERE id = ? AND user_id = ?"
);
const info = stmt.run(sessionId, userId);
return info.changes > 0;
}
export function validateSession(sessionId: string): boolean {
const stmt = db.prepare(
"SELECT id FROM sessions WHERE id = ? AND revoked_at IS NULL AND expires_at > datetime('now')"
);
const row = stmt.get(sessionId);
return row !== undefined;
}CLI Session Revocation Commands
Revoke compromised credentials from the command line:
# Invalidate specific user sessions
sqlite3 /var/lib/embers/data/embers.db "UPDATE sessions SET revoked_at = datetime('now') WHERE user_id = 'usr_fam_08';"
# Verify active session count
sqlite3 /var/lib/embers/data/embers.db "SELECT count(*) FROM sessions WHERE revoked_at IS NULL;"- Directus Target: embers
- Garden Source Reference: MOC - The Digital Necropolis and Cold Decadal Storage, MOC - Bosun PKM Tools
- Garden Source Reference: [EMB-1008 - Secure Family Invites and Cryptographic Session Revocation](EMB-1008 - Secure Family Invites and Cryptographic Session Revocation)