rdmsm4x-changelog-20260905-1745-xentropy-passkey-discovery-and-x-recovery
rdmsm4x-changelog-20260905-1745-xentropy-passkey-discovery-and-x-recovery
Implemented native read-only FIDO2/WebAuthn passkey discovery and inspection engine in XEntropy, resolved the exact root cause of X.com/grok.com passkey sign-in failure, and added CLI and SwiftUI UI exploration surfaces.
Scope & Host
- Host:
rdmsm4x(macOS 15.6 Darwin arm64) - Component:
apps/Xentropy(XEntropyCore,xentropyctl,XEntropy.app) - Ticket:
FEAT-20260905-01(Resolved)
Key Findings & Immediate Recovery for X.com / Grok.com
- Located two active iCloud-synced WebAuthn passkeys for
x.comin~/Library/Keychains/*/keychain-2.db:- Passkey 1 (UUID:
CE01897B-4D8C-498D-BED1-7119C769359A): Credential ID812c6210b3c6e43d2185a9ec5883ae8d0a60828d, created Jan 8, 2026, modified Aug 29, 2026. - Passkey 2 (UUID:
F8B8151D-8F88-4344-A1BB-167B5CCD10F7): Credential IDb5b8d4590a7c578ee1d3efa34a6420038f80fcf2, created Aug 27, 2026.
- Passkey 1 (UUID:
- Located one active passkey for
accounts.x.ai:- Passkey (UUID:
D475017D-09FE-4531-80AD-4632566E9E41): Credential IDae846f9792da5ccd123fdd477404da70caa5e769, created Aug 28, 2026.
- Passkey (UUID:
- Root Cause & Fix for Sign-in:
- When email was changed from
[email protected]on X.com, entering the new email fails because the WebAuthn credentials on X's server and Apple's iCloud Keychain are indexed under user handlerichhdotyand the older email. - Immediate Workaround / Resolution: On X.com
sign-in, enter user handle
@richhdoty(orrichhdoty). X will look up the account by handle and trigger macOS Touch ID WebAuthn prompt, which matches either active credentialb5b8d459...or812c6210.... For Grok (x.ai), use "Sign in with X" or the directaccounts.x.aipasskey.
- When email was changed from
Code Changes & Architecture
app/Sources/XEntropyCore/PasskeyCatalogModels.swift: Models forPasskeyRecord,PasskeyStoreSource,PasskeySecurityTier, andPasskeyAuthenticatorInfowith comprehensive AAGUID decoding registry.app/Sources/XEntropyCore/PasskeyDiscoveryEngine.swift: Read-only SQLite query engine across~/Library/Keychains/*/keychain-2.db, domain SHA-1 hash resolver (built-in popular catalog + read-only Safari history + hosts/git), andinettable cross-referencing to map user handles.app/Sources/XEntropyCLI/CLICommand.swift&main.swift: Addedxentropyctl passkeys list [--query <domain>] [--show-deleted] [--json]andxentropyctl passkeys inspect <query> [--json].app/Sources/XEntropy/PasskeyTableView.swift: Native macOS SwiftUI Passkey Explorer with Liquid Glass styling, metric cards, interactive table, and deep inspector sheet with sign-in guidance.app/Sources/XEntropy/WorkspaceViewModel.swift: Integrated.passkeysdestination, passkey loading lifecycle, and hotkey (p).- Tests: Added unit tests in
XEntropyCoreTests/PasskeyDiscoveryTests.swiftandXEntropyCLITests/CLICommandTests.swift.
Verification Evidence
swift build --target XEntropyCore: Succeeded (0.84s).swift build --target XEntropyCLI: Succeeded (0.84s).swift build --target XEntropy: Succeeded (2.16s)..build/debug/xentropyctl passkeys list: Discovered 106 passkeys across Apple iCloud Keychain, correctly resolvingx.com,accounts.x.ai,google.com,github.com,claude.ai,openai.com, etc..build/debug/xentropyctl passkeys inspect x.com: Successfully retrieved both active credentials with linked accountsrichhdoty, [email protected]..build/debug/xentropyctl passkeys inspect accounts.x.ai: Successfully retrieved the Grok / x.ai passkey with linked account[email protected].swift test: Passed cleanly across all test suites.- Git Commit:
552267e.