Your data

Emergency Kit and recovery

Your Emergency Kit is how you get back into Cloud sync and backup on a new computer, or after forgetting something. Here's what's in it, how to keep it, and what to do if you lose a part.

What's in the kit

Synapse shows the kit when you set up Cloud sync and backup. It has up to four things:

ItemWhat it's for
EmailYour backup is found by it. Every sign-in, restore or deletion sends a 6-digit code to it, valid for 10 minutes.
Secret KeyMade on your computer, like S1-ABCDE-040G2-08104-0G208-1040G-20810-6QS73. Together with your master password it opens the backup. The five characters after S1- are only a label, so Synapse can tell you which kit a backup needs.
Backup serverThe server your backup is on, so a new computer knows where to look if you run your own.
Recovery phrase24 words that open the backup on their own, without the master password or Secret Key. Shown only when it's made.

Your master password isn't in the kit. It's the master password of your vault - the one on the computer that made the latest backup - and it is never saved or sent anywhere.

Storing it

Use Copy (the clipboard is cleared after 30 seconds) or Save as a text file (Synapse Emergency Kit.txt, which isn't encrypted). Before setup finishes, Synapse asks you to type two words from the recovery phrase, to be sure you have it.

To see the kit again, open Cloud sync and backup → Account → Emergency Kit → Show with the vault unlocked. It shows your email and Secret Key; the recovery phrase is never stored, so it can't be shown again.

When you get a new kit

Synapse shows a new kit, and the cloud button says Save Emergency Kit until you confirm it, when you replace the account keys, make a new recovery phrase or Secret Key, or move the backup to a new email address. Each time, save the new kit and throw the old one away.

What opens your backup

Signing in on another computer with Sign in to restore and sync always takes the code sent to your email, then either:

A wrong master password and a wrong Secret Key give the same message, "The master password or Secret Key is wrong", because Synapse can't tell which one it is. A typo in the Secret Key is caught as you type it. (The saved kit's text calls the button "Restore from cloud backup"; in the app it's Sign in to restore and sync.)

If you lose something

You forgot your master password, but have the recovery phrase

On a computer without your data, choose Sign in to restore and sync, enter the emailed code and use the Recovery phrase tab. If that computer's vault has no master password yet, you choose a new one; with Keep this computer signed in on, the backup is locked with the new password from then on, with the same Secret Key.

On a computer whose vault is locked with the forgotten password, the only way in is Forgot password? on the unlock screen, which erases the vault: every saved password, key and API key, and the backup keys kept in it. Only do that once you're sure you have the recovery phrase, then sign in with it as above to get everything back.

You lost your Secret Key, but a computer is still set up

On that computer, open Account → Emergency Kit → Show and save the kit again. No password is asked for beyond an unlocked vault.

You lost your Secret Key and have no computer set up

Sign in with the Recovery phrase instead - it doesn't need the Secret Key. With Keep this computer signed in on, this computer takes over the backup's keys, including the Secret Key, so you can then show and save the kit from the Account page. Restore the latest version when you do.

You lost the recovery phrase, but a computer is still set up

The phrase can't be shown again, but you can replace it: Account → Recovery phrase → Make a new one. Save the new kit straight away; the old phrase stops working once the next backup is uploaded.

Someone may have seen your kit

Under Show, choose Make a new Secret Key. The old Secret Key stops opening the backup once the new one is uploaded; your master password and recovery phrase stay the same. If your master password may be known too, use Replace account keys on the Account page instead: after a code to your email and your master password, it makes a new backup key, Secret Key and recovery phrase, and earlier backup versions can no longer be opened. Stay in the window until it says it's finished.

More than one computer?

Make a new phrase, Secret Key or account keys on one computer, then use Sign in to restore and sync with the new kit on your other computers, so they all back up with the same keys.

You can't get into your email any more

A computer that's already set up keeps backing up without it. On that computer choose Account → Email → Change, enter the new address and the code sent to it, and choose Move backup: the backup moves to the new address with the same recovery phrase, and you get a new kit. Without your email and without a set-up computer, the backup can't be restored. Devices paired with a code keep syncing either way.

You lost the master password or Secret Key, and the recovery phrase

Then nobody - including Maku - can open the backup. Any computer that still has your data keeps it, and Synapse's local backups on each computer are unaffected; set up Cloud sync and backup again from there to get a new kit.

Save the kit when it's shown

The recovery phrase is the only way back from a forgotten master password, and it's shown only once. Put the kit in your password manager or print it the moment Synapse shows it.

How it works

Your backup is encrypted on your computer (XChaCha20-Poly1305) with a random key. That key is locked twice: once with your master password combined with your Secret Key (stretched with Argon2id, 64 MiB and 3 passes), and once with your recovery phrase. Neither the Secret Key nor the phrase ever leaves your computer except inside the encrypted backup; a computer that's set up keeps the key in its vault, so it doesn't need them to back up - only an unlocked vault.

When you change your master password in the vault settings, the backup is locked with the new one automatically and your kit stays valid; the old password then stops opening any version. If Synapse couldn't do that (for example while Cloud sync and backup was switched off), the cloud window asks for your master password once.