How does the Ushkur key work, and what if I lose it?

Short answer

The key is your account: you enter it to sign in, and the server stores only a hash of it. A lost key cannot be recovered, because there is no email or phone to reset it with.

What is the key?

The key is a secret text of 12 to 128 characters. You can let Ushkur generate a random one, or type a passphrase. Entering the same key on any device opens the same notes.

The key only proves who you are. It does not encrypt your notes: the notes are encrypted by the server with its own key. That also means anyone who has your key can open your notes, so treat it like a password.

How does the server check the key?

When you sign in, the key is sent once over HTTPS and hashed right away with PBKDF2, together with a secret value that exists only on the server. Only that hash is stored, so the key itself cannot be read back from the database. The key is never logged.

After you sign in, a session cookie that JavaScript cannot read keeps you signed in for up to 30 days, extended as you use it. The key is not kept in the browser.

What happens if I lose my key?

The account cannot be recovered. This is by design: there is no email or phone number, so there is nothing to send a reset link to, and the operator cannot look the key up either.

If you are still signed in on another device, open your notes there and copy the text you need. Changing the key also requires the current one, so it is not a way out.

How do I change my key or log out everywhere?

Both are in the account menu. Changing the key needs your current key and a new one, and it logs out every device, so you sign in again with the new key. Log out on all devices ends every session without changing the key.

If you think someone has your key, change it. To remove the account completely, delete it from the same menu.

Free to try, no sign-up

Get a key and start writing notes in a few seconds.

Frequently asked questions

Can the support team reset my key?

No. Only a hash of the key is stored and nothing links the account to a person, so a reset is not possible. The support email cannot recover it either, and you should never send your key by email.

What makes a good key?

A long, random one. The generate option creates a strong key, and a passphrase of several unrelated words also works. Short or common phrases are easy to guess.

Where should I store my key?

In a password manager, or in the .txt file the app offers to download when you create the key, kept somewhere only you can reach.

Does the server ever see my key?

Yes, for a moment. It is sent once over HTTPS when you sign in, hashed right away, and not stored or logged.

Related guides