Restoring under another key
A pg_dump holds the ciphertext of the two encrypted columns and none of the key: the key is in
your .env, and only there. Restoring into an instance whose .env carries another one is
therefore a restore that half works, and it is worth knowing exactly which half before you find out.
Everything you keep figures in comes back untouched, because none of it was ever encrypted: accounts, balances, operations, holdings, prices, snapshots, categories, achievements. Your password comes back too, so you sign in normally. What does not come back is the two things that were sealed with the key that is gone.
Your provider API keys
Section titled “Your provider API keys”The row is there, the last four characters beside it are in the clear, and the value cannot be read. Settings → Access marks such a key unreadable rather than configured, and says to paste it again; a wallet sync refuses with the same sentence rather than blaming the provider. Delete the line, paste the key, and that half is over.
Your second factor
Section titled “Your second factor”An account with 2FA on cannot be signed into with its authenticator any more: the code is correct
and the secret it is checked against cannot be opened, so the answer is Code required, the same one
an empty field gets.
Sign in with one of the recovery codes printed when 2FA was turned on. That works, and it is the only thing that does.
Each sign-in spends one recovery code, so the way out is to turn 2FA off once you are in. Settings -> Security says the stored secret is unreadable and asks for your password instead of a code, because a code is exactly what nothing here can check any more. Confirm it and the second factor is off, the unreadable secret and the leftover recovery codes gone with it; sign in with your password alone from then on, and turn 2FA back on whenever you like, which mints a secret under the key this instance actually runs on.
Only that one account is concerned, and only while its secret cannot be opened: everywhere else, turning 2FA off still takes a code.
If you would rather keep the second factor as it is, mint a fresh set of recovery codes from the same screen before you run out. That needs no code either, only the session you are already in.
What it costs
Section titled “What it costs”A key you no longer have costs you your provider keys and one round trip through 2FA for the accounts that had it. Neither loses a figure.
A JSON export sealed with a passphrase has none of this problem. Its secrets are re-encrypted under the key of the instance doing the restoring, which is why a sealed backup opens on a machine that never saw the old one.