What is the Wallet pass?
Updated September 2026
It is a card in Apple Wallet, and it is the main thing your keyholder holds. It pulls its own updates from the server and banners their lock screen only when something actually changed, so a calm card stays quiet for weeks at a time. The front carries your first name, their role, one status word, your day count, and while an early exit is open the code they scan to approve it in person. There is no app to install, and a keyholder without an iPhone gets the same facts by email and on a web page instead.
What the card is made of
The front is a composition rather than a list of fields. Your first name sits beside the mark. The header carries two words: their role, written out as Keyholder or Witness so nobody has to infer which they are, and one status word. Under the picture is a facts row: the day count, one signal, and one live process fact. A running fixed term counts down as days left; an ongoing one counts up, because it has no total to count down from.
The back carries a current status row written from their side, saying what is true and what it asks of them, then a short charter for the role they are wearing, then the state rows. The guide link is always last and always present, so their questions never wait for something to go wrong.
The card is marked so that it cannot be shared out of Wallet, and every version of it is generated by the server. Nothing on it is typed by a person.
The sky and the moon
The strip is a night sky, and it is an instrument rather than scenery. The sky reports the state: a steady starfield while all is well, a dim starless one while something needs attention, first light when the commitment is over. The moon is the only thing in it that is not sky, and it reports progress toward the next earned moment. Past the last milestone it stays full. When there is no progress to report at all, the sky carries no moon rather than a moon claiming day one.
If Wallet's image cache lags, the words still carry the state. The moon is an enhancement and is never the only thing saying what is true.
It speaks only when something changed
Every event that reaches a partner sets a content free banner on the field it updates, so their lock screen shows one line when something turns and nothing at all when it does not. An unchanged value fires no banner by design, which is why a card that has sat on Protected for a month has never interrupted them.
A live problem outranks a process. If the phone stopped confirming while an early exit was open, the status word reports the phone rather than the exit, because protection being off is the larger fact; the request stays on the card in words. In that one ordering the pass fires no banner for the request, and the email carries it instead.
Two faces of the same card
-
A calm card
Role, status, the day count, and a tip pointing at the back. There is no request, so there is no code and nothing is asked of them. This is what the card looks like for almost the whole of a term.

Nothing needed
-
An open exit request
The card gains the date they have to decide by and a scannable code, and the strip draws the three stations of the request. The code appears only while a request is open and disappears when it closes, and it is served only against the pass's own credential, so the code never reaches you. The middle station reads seven days equals yes, and it means what it says: silence for seven days approves the request on its own, as if you had no keyholder, and the wait that follows is fourteen days rather than 72 hours.

A request open
How a card ends
A card that has stopped meaning anything retires itself instead of freezing on a status it can no longer prove. When a handover takes effect, the old keyholder's card carries an expiry set to that moment. A released commitment leaves its card readable for 30 days. A removed partner's card serves one last ending face for seven days, and then the pass simply stops answering.
Each ending has its own word in the status slot, and the same word is baked into the stamp on the front, so the picture and the text cannot disagree. The ending is always written and served before the thing that silences the card, because a card cannot speak after it has been cut off.
Do they need it
No. The same facts live on their web page, and every consequential alert reaches them by email as well. A keyholder on Android or a laptop has the full floor without a pass. The pass is the surface that tells them the moment something turns without their going to look, which is the whole reason it is the primary one.
What this does not do
The pass grants no authority over your phone. It cannot unlock anything, cannot end a wait that is running, and cannot approve an exit remotely: the code on it records an approval given in person and nothing else. It carries no app name, no site, no browsing record, no amount of money and nothing you typed. A witness card is the same card minus the ask and the code, because a witness has nothing to decide. And the card never decides anything itself; it is a picture of what the server already holds.
Still stuck? Email support@foldem.app and we answer within two working days.