Table of Contents
Use a cloud account
You do not need an account to connect to MUDs or use local client features. A free Smudgy account adds cloud map synchronization and sharing, friends, and package publishing.
Sign in without a password
- Open Settings → Account.
- Enter your email address and choose Email me a code.
- Paste the one-time code from the email. Codes expire, so request another if it is no longer accepted.
- If asked, choose a public nickname. Other people use this nickname to find and add you; it is not a MUD character name.
Entering a new email address creates an account during the same flow. Smudgy does not ask you to create an account password.
Verify the email address before using friends, sharing, or synchronization. If the message does not arrive, check the address and spam folder before requesting another code.
Know what is stored
Smudgy tries to protect the signed-in session credential in the operating system's credential store. If that store is unavailable, it uses an obfuscated file in the Smudgy data directory; obfuscation is not encryption. Account profile details are cached locally so the UI can identify the account while the service is temporarily unavailable. Signing out removes the local session credential; it does not delete local profiles, automations, packages, or maps.
Cloud features send the data needed for that feature to Smudgy's service. For example, sharing a map uploads mapping data and identifies the people who can access it. Do not put passwords or private game tokens in map names, room text, package metadata, or other fields you intend to share.
Review access to the account
Open Settings → Security to see API keys and signed-in sessions.
- An API key is for another program acting as your account. Its secret is shown once when created. Copy it directly into its intended secure storage; never put it in a script, package, screenshot, issue, or chat message.
- A session represents a signed-in Smudgy installation. Revoke one you no longer recognize or use. Revoking the current session signs this installation out.
- Sign out everywhere revokes sessions on other devices as well as the current one. Use it after a device is lost or an account credential may have been exposed.
If an API key secret is exposed, revoke the key and create a replacement. Editing a screenshot to cover a secret after capture is less safe than arranging the screen so the secret never appears.


