Sign in & accounts
The SuperFile family is several products with one idea about identity: you prove you hold a mailbox (or a passkey or a device you already trust), and from then on the file, the name or the tenant knows who you are. This page lists every sign-in path, product by product, and what happens to your session afterwards.
#superfile.com — your SuperFile Account
Your SuperFile Account is created the first time you reserve a name and confirm the 6-digit code we email you; there is no separate registration form. Sign in afterwards at superfile.com/signin.
| Path | How it works | Good for |
|---|---|---|
| Email link | Enter your address; we send a sign-in link. It is valid for 7 days and must be opened on the device you want signed in. | Everyone, every device |
| Sign in with your phone | On a desktop, the sign-in page shows a QR code. Open the camera on a phone that is already signed in, scan, tap Approve. The desktop signs in within seconds; the code expires after 10 minutes and works once. | A new laptop, a shared machine |
| Passkey | After your first sign-in, add a passkey in Settings → Sign-in & Security. From then on, sign in with Face ID, Touch ID, Windows Hello or a security key. | The fastest, phishing-resistant path |
A few details worth knowing:
- Old links to
/loginstill work; they redirect to/signin. - Signed-in visitors who open the sign-in page are sent straight to the dashboard.
- Sessions last 7 days from the last sign-in. Settings → Sign-in & Security → Where you're signed in lists every device with its browser, approximate location and last activity; sign any of them out, or sign out all other devices at once. Session tokens never reach the page, and IP addresses are shown masked.
- Reserving a name from a signed-in dashboard skips the code step — the mailbox was already proven at sign-in.
#beta.supersecure.com — SuperSecure
SuperSecure has its own accounts: an account is an account, the way a Gmail address is. The same person can hold several — say a personal one and one for their company — with separate files, sessions and billing.
- Sign up / sign in with a one-time code. Enter your email; we send a 6-digit code; type it in. There is no password to remember or leak.
- Sign in with sup. If you already hold a sup account, use it as your identity provider (OpenID Connect). Your SuperSecure account is linked to it on first use.
- One mailbox, several accounts. When a mailbox belongs to more than one account, sign-in shows a chooser; pending invitations from an organisation appear there as Join <org> and provision your seat when you pick them.
- Switch or sign out. The account rail lists every account signed in on this browser. Sign out of one, or of all of them; signing out of one hops you to the next signed-in account. Signing out clears the offline cache and every draft on that device — a per-device drafts vault holds files you dropped before signing in, and those are migrated into your vault automatically when you do.
- Invitation gate. During the beta some entry points ask for an invite code and an I agree on the beta terms before the sign-up form appears.
Drafts and preferences are stored per device; a second tab or browser starts from what the server knows, not from the first tab's unsaved state.
#superdrm.com — the SuperDRM portal
The portal at superdrm.com/portal is where a company runs its DRM tenant.
- Sign up with company name, email and password. The tenant is created at once on the developer plan in pending status, with its API key and token secret shown once.
- Verify your email from the link we send. That activates the tenant and signs you in. Licence endpoints refuse until this step is done.
- Sign in afterwards with email and password, or with Sign in with sup. Sessions are 30-day, secure, HTTP-only cookies. A password reset revokes every other session. Sign-in, sign-up and reset are rate-limited per address.
- Team: owners invite admins and members by email; the invitation link accepts into the tenant. The account switcher lists every tenant your sup identity can reach.
Everything the portal does is a plain JSON API under /v1/portal/*; see Portal & console.
#sup.com — Sup
Sup is messaging, calls and mail built on top of your files, and it doubles as an identity provider — Sign in with sup on superdrm.com and beta.supersecure.com uses it. Sup accounts sign in with a password and, where added, a passkey; a workspace can bind a business domain so colleagues sign in with their work address. Sessions are shared across sup.com sub-domains.
#Security notes that apply everywhere
- We never ask for your password by email, and superfile.com and beta.supersecure.com have no passwords at all: a link or a code that arrives unexpectedly should be ignored.
- Every sign-in path records the device, approximate location and time so you can audit it later from your settings.
- Personal data handling is described in the Privacy Policy and the Data & Subprocessors page; aggregate figures are published in the Transparency Report.
Updated September 2026