Your data

Teams

Teams shares hosts, snippets and credentials with the people you work with, end-to-end encrypted, without sharing your personal vault. It's optional and off until you switch it on.

Turning it on

Switch on Teams in Services (More menu → Services). The Teams window then opens from the More menu, or from Settings → Teams → Open teams. It has three tabs: Shared (hosts and snippets), Team vault (credentials) and Members.

Teams sync every five minutes, straight after each change you make, and when you press the Sync team button at the top of the window.

Creating a team and inviting people

  1. Choose New team. The first time, enter Your name - what your teammates see - then a Team name, and choose Create team. You are the team's first owner.
  2. To invite someone, open the Members tab and choose Invite (owners only). Synapse shows an invite code like 7KQ2M-X9D4R-B3N8P, with Copy code and Copy pairing link (code and mailbox address). Send it to them. A code works for one person and expires after 10 minutes.
  3. They open Teams on their computer, choose Join team, enter their name the first time and paste the code or link under Invite code, then choose Join. Before anything is shared they see the team's name, who invited them and the current members.
  4. Both screens then show the same six-digit verification code. Compare it over a call or chat - not in the same message as the invite - and choose They match on both sides. On your side you also choose whether they join as a Member or an Owner.
On your own mailbox?

A bare code is looked up on the joiner's own mailbox setting. If your team uses a mailbox you host yourself, send the pairing link instead: it carries the mailbox address too.

The invite screen also shows a QR code, but teams are joined from a computer: type the code or paste the link. Both computers need an up-to-date Synapse; a code from an older version asks you to update first. You can't rename a team or change your own name after creating them.

Roles

A team has two roles, Owner and Member. An owner can change another person's role with Make owner or Make member on the Members tab.

What you can doOwnerMember
Share hosts and snippets, add team credentialsYesYes
Change or remove what you sharedYesYes
Change or remove what someone else sharedYesNo
Connect to team hosts, copy hosts and snippets to your ownYesYes
Invite peopleYesNo
Remove members, make someone an owner or a memberYesNo
Delete the teamYesNo
Leave the teamYes, unless you're the last ownerYes

A team always keeps at least one owner: the last owner can't be removed or made a member, and has to make someone else an owner before leaving (unless nobody else is left). Items you can't change show no Stop sharing or Delete button.

What you can share

Hosts

On the Shared tab, pick one of your hosts under Choose a host to share…, optionally pick a team credential for it, and choose Share. Only the connection details travel: name, address, port, username, group, protocol, default directory, startup command and which team credential to use. Your personal passwords and keys, key files, jump hosts and proxies are never shared. Share the same host again to update the team's copy.

Team hosts are listed in the Teams window rather than your sidebar. Connect opens a session using the team credential, held in memory only. A team host without a credential signs in like an SSH agent host: your agent and default keys, then a password prompt. Copy to my hosts adds the connection details to your own host list; add a password or key to it in the host editor.

Startup commands ask first

A team host with a startup command asks "Run this startup command?" the first time you connect, and again whenever the command changes. Choose Run and connect only if you trust it. A team host that points at your own computer never runs a startup command.

Snippets

Under Snippets on the same tab, choose Choose a snippet to share… and Share. A snippet's environment variables are not shared. To use a team snippet, choose Copy to my snippets.

Team vault

Only credentials added on the Team vault tab are shared; your personal vault stays private. Under Add a team credential, choose Password or SSH key, give it a name and username, enter the password or paste the private key (and its passphrase), and choose Add to team vault. Credentials are typed in for the team and never copied from your own vault.

The window lists team credentials by name only, but every member's Synapse can decrypt them to connect, so treat a team credential as known to everyone in the team. Credentials can't be edited: delete one and add it again. Stop sharing on a host or snippet takes effect straight away, without asking.

Removing members and leaving

An owner removes someone with the remove button next to their name on the Members tab. Synapse asks to confirm: "They lose access and the team key is replaced. What they already saw stays with them: change shared passwords if needed."

Key rotation

Everything in a team is encrypted with a team key that only members hold. When an owner removes someone, the owner's Synapse makes a new team key at once, re-encrypts every shared item with it and hands it to the remaining members. When someone leaves on their own, the same happens at an owner's next sync. Members only accept a new key from an owner they already know.

Rotation protects everything shared from then on: a removed member can't read new or changed items. It can't take back what was already on their computer, which is why changing shared passwords matters.

Signed records

Every shared host, snippet and credential is signed by the member who wrote it, and the member list is signed by an owner. Each member's Synapse checks an item before using it:

Anything else is ignored without a message: nothing changes on that computer, and the next sync from the item's owner puts the right version back. So a member can't change someone else's item, and the mailbox server can't forge or alter one. Items shared from Synapse 0.2.9 or older aren't signed, so only owners can change them; members can simply share them again. Make sure every member runs an up-to-date Synapse.

Limits