API reference › @evolu/common › local‑first/Owner › OwnerSecret

const OwnerSecret: brand(
  "OwnerSecret",
  union(Entropy16, Entropy20, Entropy24, Entropy28, Entropy32),
);

Defined in: packages/common/src/local-first/Owner.ts:198

BIP-39 entropy used to derive Owner keys.

A Mnemonic represents an OwnerSecret, so each valid mnemonic converts to exactly one secret with mnemonicToOwnerSecret and back with ownerSecretToMnemonic. A 24-word mnemonic holds 32 bytes, a 12-word mnemonic holds 16 bytes, and 15, 18, and 21 words hold 20, 24, and 28 bytes.

createOwnerSecret generates 32 random bytes, which keep the owner post-quantum safe. The OwnerId is public and derived from the secret, so anyone who stores an owner's encrypted data can test guesses of the secret offline, and a quantum computer needs only about the square root of the guesses. 32 random bytes leave about 128 bits of security, while 16 bytes leave about 64. A secret derived from a smaller root, such as a 20-word SLIP-39 share, is no stronger than that root, whatever its length. Shorter secrets are accepted for owners created outside Evolu, typically from 12-word mnemonics.