READING EDITION / RESEARCH PREVIEW

This is a static guide, not a live service status. Public remote writes and execution remain disabled. No JavaScript is needed to read this page.

Your Self, your mailbox, your people

Start as a guest. Make a Self when you need your own signing identity. Publish a mailbox only when you want a public address and the deployment can accept it.

A Self is not your GitHub account, a network socket, or a cloud provider's record. It is your Cursors signing identity, stored encrypted in this browser. Cursors uses Self in the cockpit; the front navigation calls its controls SIGN IN + RESUME.

The local step

Choose CREATE WITH PASSKEY, complete the browser's verification, then UNLOCK WITH PASSKEY. The vault refuses to overwrite an existing identity. Creation leaves it locked, and unlocking makes the key available only in the page's memory.

The shell and cockpit share the same session. Switching views does not make a second Self. LOCK THIS SESSION removes the in-memory key while preserving the encrypted record.

The required passkey PRF encryption feature is not universally available. Unsupported browsers should report that limitation. Do not supply a password, private key, or API token to compensate. Local notes and inspection are separate from cloud identity operations.

The public step

The service strip distinguishes observed configuration, intentional pause, offline, unavailable, stale, and unknown. A configured service is not proof of an authenticated write.

When cloud controls are enabled, PUBLISH PUBLIC MAILBOX publishes a bounded public descriptor. Check the operation's own result. Your Identity address and Durable mailbox handle are public references, not unlocking credentials. The cloud composer uses the 40-character handle.

A failed descriptor lookup is unknown, not proof that no descriptor exists. Publishing a descriptor does not back up the private key or the contents of your cursors.

The human step

Use the local Your people card to attach a name to a public address. This creates no connection and sends no message. Guest contacts and Self contacts stay scoped to their local profile.

The experimental cloud ADD FRIEND control does something different: it updates that mailbox's remote policy. Verify an important person's public address through another trusted channel. A friendly label is not authentication, admission, or permission to execute a cursor.

Use introductions and remote notes only on a compatible available deployment. The browser's cloud note content is NOT E2E YET, so do not send secrets.

The recovery step

Export the encrypted Self and retain its original compatible unlocking credential. Optional GitHub recovery carries encrypted bytes; it is not an identity root or a universal login-based restore.

Recovering an identity and recovering cursor work are separate. Cursor work also requires its signed history, available immutable state and checkpoints, and verified authority carried with its continuation.

Read Resume Your Cursors, Chat with a Friend, and Continue with GitHub.