Create your account and protect it
Glassbreak Team · Published 2026-07-19
Glassbreak is end-to-end encrypted: your contacts, secrets, and messages are encrypted in your browser before they reach us, and we never hold the keys. That gives you strong guarantees — and one responsibility that most products don't ask of you: if you lose your password and your recovery code, nobody, including Glassbreak, can restore your encrypted data. This guide gets your account set up safely.
Glassbreak is currently in early access, and new teams are onboarded in waves.
Sign up and verify your email
- Go to the app and choose Sign up. Enter your name, email, and a strong password. Your password is never sent to our servers in a readable form — login uses a protocol (OPAQUE) in which the password proof stays in your browser.
- Check your inbox for a verification email and follow the link. You can't sign in until your email is verified.
- Sign in. On first login your browser generates your personal encryption keys and a device Secret Key. The private keys are encrypted on your device before being stored; the server only ever sees ciphertext.
Save your recovery kit — do this now
During key setup Glassbreak creates an offline recovery kit and shows you a one-time recovery code (formatted like GB1-XXXXX-…).
- The code is shown once and never stored by Glassbreak. Write it down or save it in a safe place separate from your password.
- If you lose access to your devices, the recovery code restores your Secret Key on a new device. Without it, a lost device plus a forgotten password means your encrypted data is unrecoverable.
- A password reset deliberately does not restore encrypted data — resetting your password deactivates your old encryption keys, because the server never had the material needed to re-wrap them. The recovery kit is the safety net; the reset flow is not.
If you skipped or lost the kit, a persistent banner will nudge you until you create one from Settings.
Turn on multi-factor authentication
From Settings → Security you can add a second factor (you'll be asked to confirm your password):
- Authenticator app (TOTP) — scan the QR code with any authenticator app and confirm a six-digit code.
- Passkey (WebAuthn) — register a platform or security-key passkey.
- When you enrol your first method, Glassbreak generates ten single-use MFA recovery codes. They are shown once — save them alongside (but not with) your password.
Once MFA is on, login becomes two steps: password, then your chosen factor. Organizations can require MFA for all members.
Adding a second device
Signing in on a new device also needs your Secret Key. The easiest route is to display it (as text or a QR code) from a device you're already signed in on and enter it on the new one. If you have no enrolled device to hand, use Recover access at login with your recovery code.