I've started implementing credentials for Obnam 3. They will allow access to the per-client chunk, which contain the encryption keys for all data chunks.
I started implementing an OpenPGP software key credential, but it was more work than I anticipated so I'm retroactively claiming what I did today to be a prototype that let me plan actual implementation work for the next few session.