Your data
Backups and restore
Synapse backs up your hosts automatically on this computer, can make a full encrypted backup on demand, and - from 0.2.6 - can back up to the cloud.
Automatic backups
The desktop app snapshots your hosts, groups, workspaces, snippets, settings and local project list to its own folder on your computer: at startup, at most once an hour while something changes, and immediately before an update installs or a restore runs. Synapse keeps the 30 newest snapshots, plus the newest one from each of the last 14 days. Passwords, private keys and passphrases are never included - those stay in the vault.
To restore one: Manage hosts → Import and export → Restore hosts from a backup. Pick a backup, then choose:
- Add missing hosts - keeps everything you have now and adds only what's missing.
- Replace all hosts - replaces your saved hosts with the backup's list (your current list is backed up first).
If you also use Sync between devices, the same window offers Restore from synced devices: it copies back any hosts your other devices still have. Nothing is ever deleted on another device by a restore.
A bug that could show an empty or outdated host list after an update was fixed in version 0.2.5. If your hosts ever go missing, use Restore hosts from a backup or Restore from synced devices above to bring them back - see also Troubleshooting.
A full encrypted backup
Import and export → Back up everything saves a single encrypted
.synapse-backup file with your hosts, snippets, settings and the vault's contents
(SSH keys, passwords and API keys included) - unlike automatic backups and exported hosts, this one
does carry your secrets, so it needs a password of its own, at least 12 characters. The vault must be
unlocked to include it.
The file is encrypted with AES-256-GCM, using a key derived from the backup password with Argon2id (64 MiB of memory, 3 passes). Backup files made by older versions (which used PBKDF2-SHA256) can still be restored; a file made by this version needs this version or newer to open it.
It's separate from your master password and isn't stored anywhere. Losing it means the backup file can't be opened. Keep it in a password manager, the same as your master password.
Restore a backup opens that file (after the password unlocks it) and previews what's inside before you choose Merge (add what's missing, keep everything else) or Replace (your hosts, snippets, settings and vault become exactly what's in the backup).
For a plain list of hosts with no secrets at all - to move to another computer or share with a teammate - use Export hosts instead; see Hosts and connections.
Cloud backup New in 0.2.6
Cloud backup is an optional, off-by-default way to keep a copy of your vault and hosts safe even if this computer is lost. It's linked to your email and encrypted on your device before it's uploaded - the server never sees your data unencrypted and can't read it.
Restoring a Cloud backup needs two things:
- A one-time code sent to your email, to prove the request is yours, and
- Your master password together with your Secret Key, or the 24-word recovery phrase shown once when you set Cloud backup up.
Secret Key and Emergency Kit
The Secret Key is a random code made on your computer when you set Cloud backup up, like
S1-ABCDE-040G2-08104-0G208-1040G-20810-6QS73. It's combined with your master password to
lock the backup, so even someone with a copy of the backup server's data can't open it by guessing
your password. It's kept in the vault on your computer and never sent to us. It isn't a way around a
forgotten master password - that's what the recovery phrase is for.
When you set Cloud backup up, Synapse shows your Emergency Kit: your email, your Secret Key and your recovery phrase. Use Copy or Save as a text file and keep it somewhere safe, like your password manager or printed out. Anyone with the recovery phrase and access to your email can restore your backup. You can show the kit again later in the Cloud backup window (with the vault unlocked), but the recovery phrase is shown only once - make a new one there if you've lost it. If someone else may have seen your kit, Make a new Secret Key replaces it.
To restore, choose Master password and Secret Key or Recovery phrase after entering the emailed code. Synapse checks the Secret Key as you type it (capitals, spaces and dashes don't matter), so a typo is caught straight away. If the backup still doesn't open, the message is "The master password or Secret Key is wrong" - Synapse can't tell which one.
Backups set up with Synapse 0.2.8 or earlier get a Secret Key automatically with their next upload after you update, and the Cloud backup window opens once to show your new Emergency Kit - save it then. Until that upload, and for backups still made by a computer running 0.2.8 or earlier, the master password alone opens the backup, so update Synapse on every computer that backs up.
If you lose your master password or your Secret Key, and your recovery phrase, nobody - including Maku - can open a Cloud backup either. Save your Emergency Kit in a password manager or print it the moment it's shown to you, and keep your master password safe too. See Vault and master password.