Living Document Notice
Published 2026-09-17. The evolving architecture and revisions for this dispatch live in the Stax Digital Garden.

Secure Family Invites and Cryptographic Session Revocation

Secure Family Invites and Cryptographic Session Revocation: Warm sepia-white phosphor P4/P20 vector CRT macro showing an authorization distribution hub with a severed revocation path dissolving into phosphor decay

Inviting non-technical family members into self-hosted applications often stumbles over complex multi-factor authentication setup or insecure shared passwords. When an invite link leaks or a relative loses a mobile device, household administrators need immediate cryptographic revocation without locking out other family members.

Embers solves invite onboarding through single-use, cryptographically signed invitation tokens. Invites bind directly to named family accounts or time-bounded guest sessions. If an account credential requires revocation, administrators invalidate active session tokens instantly from the local management console.

Invitation Lifecycle and Verification

The invite sequence ensures tokens cannot be reused or guessed:

Admin Console ──► Issues 32-byte signed invite token (TTL: 48h)
                         │
                         ▼
             [ New Family Member ] ──► Redeems invite via HTTPS
                         │
                         ▼
             [ Embers Auth Gate ] ──► Verifies Ed25519 signature
                         │
                         ├─► Binds account to household circle
                         └─► Burns invite token in SQLite database
Security PrimitiveConventional Cloud PatternEmbers Household Pattern
Invite MechanismOpen signup or unbounded linkSingle-use cryptographically signed token
Revocation ScopeDelete user account entirelyPer-device session invalidation in SQLite
Credential StorageVendor cloud identity storeLocal Argon2id password hashes

Session Invalidation in Node.js

import Database from "better-sqlite3";
import crypto from "crypto";
 
const db = new Database("/var/lib/embers/data/embers.db");
 
export function revokeSession(sessionId: string, userId: string): boolean {
  const stmt = db.prepare(
    "UPDATE sessions SET revoked_at = datetime('now') WHERE id = ? AND user_id = ?"
  );
  const info = stmt.run(sessionId, userId);
  return info.changes > 0;
}
 
export function validateSession(sessionId: string): boolean {
  const stmt = db.prepare(
    "SELECT id FROM sessions WHERE id = ? AND revoked_at IS NULL AND expires_at > datetime('now')"
  );
  const row = stmt.get(sessionId);
  return row !== undefined;
}

CLI Session Revocation Commands

Revoke compromised credentials from the command line:

# Invalidate specific user sessions
sqlite3 /var/lib/embers/data/embers.db "UPDATE sessions SET revoked_at = datetime('now') WHERE user_id = 'usr_fam_08';"
 
# Verify active session count
sqlite3 /var/lib/embers/data/embers.db "SELECT count(*) FROM sessions WHERE revoked_at IS NULL;"

  • Directus Target: embers
  • Garden Source Reference: MOC - The Digital Necropolis and Cold Decadal Storage, MOC - Bosun PKM Tools
  • Garden Source Reference: [EMB-1008 - Secure Family Invites and Cryptographic Session Revocation](EMB-1008 - Secure Family Invites and Cryptographic Session Revocation)