# Key Export

> The owner-controlled policy that decides who may export wallet private keys, and how ownership is transferred.

- URL: https://docs.sumo.trade/account/key-export
- Markdown: https://docs.sumo.trade/account/key-export.md
- Docs index: https://docs.sumo.trade/llms.txt

Every organization has exactly one **owner**, and only the owner decides who may use [Export Keys](/wallets/export-keys) — the bulk export of wallet private keys from a profile's **Wallets** tab and from **Wallet Farm**. The controls live under **Settings → Key Export**, a section that is visible to the owner alone.

This policy covers those two surfaces only. The launch **deployer** export and the **Snipe Deck** wallet export are separate flows, available to admins regardless of these toggles.

## Who May Export

| Toggle                                  | Effect                           | Default |
| --------------------------------------- | -------------------------------- | ------- |
| **Allow me to export private keys**     | The owner may export             | On      |
| **Allow admins to export private keys** | Every admin and above may export | Off     |

When admins are allowed, pick how long the grant lasts: **1 hour**, **24 hours**, or **until turned off**. A timed grant expires on its own — the section shows the exact expiry — and the toggle returns to off with no further action.

Members below the admin role can never export, whatever the toggles say, and Export Keys on those two surfaces is always blocked while an account is being impersonated.

## One-Time Code

Turning either toggle on **or** off sends a 6-digit code to your email or Telegram, following your two-factor preference. The change is applied only after the code is entered, so a hijacked session cannot quietly widen key access.

Exports themselves never ask for a code — the policy above is the gate.

> The switch reflects the saved server state, not your click: it moves only once the code is accepted.

## What Exporting Does

Exporting reveals private keys for up to **250 wallets** at a time and flips each exported wallet's custody from **Sumo** to **Shared** — the key now also exists outside Sumo. Custody never flips back, and every export is recorded in [Audit Logs](/reporting/audit-logs).

Export lives in two places, both governed by this policy:

* [Profile wallets](/wallets/export-keys) — the **Wallets** tab's **More** menu
* [Wallet Farm](/wallets/export-keys&#x29; — the toolbar's &#x2A;*⋯** menu

The deployer key export (**Export Deployer PK**, same **More** menu) and the Snipe Deck wallet export are not governed by these toggles; see [Security & Encryption](/wallets/security-encryption).

## Ownership

The **Ownership** sub-section names the current owner and can hand ownership to another member. Pick any active member with the admin, ops manager, or superadmin role, then confirm with a one-time code.

Ownership transfer takes effect immediately: the new owner gains the Key Export section and you lose it, so transfer only to someone who should hold that control. A Sumo superadmin can also reassign an organization's owner with a recorded reason — for example when the current owner has left.

- [User Management](/account/user-management): Roles and who can be made owner.

- [Security & Encryption](/wallets/security-encryption): How Sumo stores wallet keys.
