Skip to content
Saphira Linux

Resources ยท Account signup

Create your Saphira account

Saphira accounts are free. There are no account passwords: your passkey or security key is the normal human authentication mechanism.

Saphira Linux dragon mascot

The signup process

Keep this page open while you complete the steps.

1. Enter your details

Start
Enter a display name and an email address on the account signup page. The address is used to send the verification link and is not a public profile field.

2. Record AIP-56

Do this once
Saphira displays an AIP-56 recovery key once. Record it carefully, print it if useful, and keep it private. This is the only emergency way to reset a lost passkey.

3. Check your inbox

Within four hours
Open the Saphira account verification email and follow its link within four hours. The link is single-use and takes you to passkey enrolment.

4. Enrol your key

Finish signup
Register a YubiKey, FIDO2 security key, platform passkey, or supported phone/cross-device WebAuthn credential. After success, return to the sign-in page.

What are AIP-56 and AIE?

AIP-56 is Saphira's emergency account-recovery format. It generates a one-time recovery key for you to store offline. Saphira stores only an Argon2id verifier of the key; the original key cannot be displayed again. Successful recovery permits registering a replacement passkey, but the recovery key is not a permanent login method.

AIE stands for Application Identity Envelope. It is Saphira's authenticated identity and transport model. After a successful passkey authentication, Saphira issues an AIE bearer token for the authenticated browser state. Account API requests use that token explicitly in the Authorization header, and browser state is kept in session storage rather than cookies or localStorage.

Sensitive browser POST requests also use the AIE transport envelope: the browser first obtains a one-time action-bound ECDH P-256 challenge, then encrypts the actual payload with AES-GCM. Email addresses, profile details, recovery data, and WebAuthn data are not sent as plain application JSON.

If the email does not arrive

Check spam, junk, and filtered folders. Confirm that the address was entered correctly. The verification link expires after four hours and can be used only once.

If the link has expired or was already used, start a fresh signup. An email address already associated with an account cannot be registered repeatedly.

Saphira account communications are off by default. The verification message is an essential, non-marketing account message.