Getting started

Your account

Everything about the account itself: creating it, signing in, keeping it secure, the devices it's signed in on, and what happens when you disable or delete it. Profile looks (avatar, banner, name colors) are in Profiles and status.

Creating an account#

Sign up at sunflare.me/signup. You need:

FieldRules
Username3 to 20 characters. Letters, numbers, and underscores (_) only. Not case-sensitive. Must not already be taken.
EmailA real address you can read. One account per email.
PasswordAt least 8 characters.
BirthdayYou must be 13 or older. 13 to 17 year olds get teen protections.

During signup you can also choose whether to get announcement emails. You can change that any time later.

Verifying your email#

Right after signup, Sunflare emails you a verification code. Enter it from the banner at the top of the app (Verify). If it didn't arrive, check spam, then use Resend code.

Signing in#

Sign in at sunflare.me/login with your username and password. Normally you stay signed in for 7 days; tick Remember me to stay signed in for 30 days on that device.

Signing in with a QR code#

Already signed in on your phone? On the computer, click Log in with QR Code on the sunflare.me login page. Then in the Android app open Settings → My Account → Scan QR Code and point it at the code. The computer signs in as you without a password. A QR code expires after about 90 seconds; open it again for a fresh one.

Username and display name#

Username
Your unique handle, used for @mentions and finding you. Change it in My Account; the same 3 to 20 character rules apply.
Display name
Optional, up to 32 characters, and doesn't have to be unique. It's shown instead of your username in messages and member lists. Spaces, capitals, and other characters are fine here.
Example

Username kai_r, display name Kai Rivera. People see "Kai Rivera" next to your messages and type @kai_r to mention you.

Email and birthday#

Both are hidden on the My Account page until you click Reveal, so they don't show up on a stream or a screenshot. You can update them there. Your birthday decides which safety rules apply to you, so keep it accurate.

Changing your password#

  1. Go to Settings → My Account → Change Password.
  2. Enter your current password, then the new one twice. The new password needs at least 8 characters.
  3. Click Change Password.

Every other device signed in to your account is signed out straight away; the one you're using stays signed in. That way, changing your password also locks out anyone who got into your account.

Forgot your password?#

Click Forgot password? on the login page (or go to sunflare.me/forgot).

  1. Enter your username or your email and click Send code.
  2. Check your email for an 8-character code like K7PX-M2QA. It's valid for 30 minutes.
  3. Enter the code and your new password (at least 8 characters) twice, then click Reset password.
  4. Sign in with the new password.

The code isn't fussy about capitals, spaces, or the dash. You can ask for a new one once a minute.

Two-factor authentication#

Two-factor authentication (2FA) adds a second step to signing in: after your password, you enter a 6-digit code from an authenticator app on your phone. Someone who learns your password still can't get in without your phone.

  1. Install an authenticator app, such as Google Authenticator, Authy, or the one built into your password manager.
  2. Go to Settings → My Account → Enable Two-Factor Authentication.
  3. Scan the QR code with the app, or type the key it shows.
  4. Enter the 6-digit code the app shows to prove it worked. 2FA only turns on once a real code checks out, so a bad scan can't lock you out.
  5. Save your backup codes. Sunflare shows a list of one-time codes exactly once.

When 2FA is on, signing in asks for your code after your password. Each code lasts 30 seconds, and the one just before or after is accepted too, in case your phone's clock is slightly off. Use a backup code instead if you don't have your phone.

To turn 2FA off, click Disable and enter your password.

Devices and sessions#

Lists every device currently signed in to your account. For each one you can:

Sign it off
Ends that session. The device has to sign in again.
Ban it
Signs out every session on that device and blocks that browser or app from signing in to Sunflare again.

Both actions first send a one-time code to your email, which you have to enter. That way, someone who gets into your account can't use this page to kick you out.

Blocked users#

My Account lists everyone you've blocked, with an unblock button, so you don't have to find their profile again. What blocking does is covered in Safety and age rules.

Disabling your account#

Disabling is a pause button. Your account is hidden from other members, can't be found in search, and can't receive friend requests. Nothing is deleted.

  1. Settings → My Account → Disable Account.
  2. Enter your password to confirm. You're signed out.
  3. To come back, just sign in again with your password. The account reactivates automatically.

Deleting your account#

What happens:

Before you can delete, you must not own any servers. For each one, either transfer it to someone else or delete it (both in Server Settings → Danger Zone). The delete button tells you which servers are in the way.

  1. Optional but recommended: download your data first.
  2. Cancel any Cosmos subscription so you're not billed again.
  3. Settings → My Account → Delete Account, then enter your password.

You can also read how deletion works, without signing in, at sunflare.me/delete-account.