vigil

Dead-man's-switch companion to cinder. A management token is the entire access model — save it, it's shown once.

Create a switch

The payload is encrypted (tlock) before it's ever stored — not even vigil's own operator can read it before it fires.

1–730 days — the server enforces this range regardless of what's entered here.

Up to 2048 bytes. Each check-in re-wraps this message in a fresh layer of encryption rather than touching the original — that's what keeps it genuinely unreadable (not even to this system's own operator) the whole time it's still being renewed. Wrapping has a real, message-size-dependent limit on how many times a switch can be renewed before it must be replaced — a shorter message allows more renewals. If a switch runs out and you still want it to keep going, cancel it with your management token and create a fresh one — that's the intended way to extend indefinitely, not a workaround.

Manage an existing switch

Get a triggered message again

The original delivery link only lasts a few days. If you missed it, this fetches a fresh copy — the message itself is kept, separately from that link's own lifetime. Uses the delivery link from the notification email, not the switch owner's own management token.

Decrypt a delivered message

Paste the base64 shown by cinder's own Receive page for a triggered switch's delivery — no token needed. Works for anyone, once the switch's target round has actually passed; tlock provides no confidentiality to any particular holder after that, by design.

Fetches the message directly from cinder's own API and fills the field below — same data a manual copy-paste from cinder's Receive page would give you, no extra page visit needed.