Hobby accounts created from June 4th 2024 onwards have E2EE disabled by default. While your data remains encrypted at rest and in transit, E2EE offers an additional layer of security by encrypting data so that only the parties involved in the communication can decrypt it.
You can enable or disable E2EE from the Encryption tab in your account settings.
For more details about how E2EE works, see End-to-End Encryption.
Insomnia uses the Secure Remote Password (SRP) protocol to handle data encryption, which means:
- Insomnia Cloud doesn’t store a user’s passphrase in any form
- All user data is encrypted in a manner that requires the user’s passphrase to decrypt
If you lose your passphrase, you can reset it using the Forgot your Passphrase? link on the login screen, however:
- You will lose access to the organizations you have been invited to. An owner or admin will need to invite you again.
- You will lose access to encrypted data that isn’t backed up.
To avoid issues, back up your passphrase in a secure location.