mChat · document
Using mChat
Nothing to install. It all happens in the browser, and your keys are made on your device the first time you open it.
Creating an account
A username of two to twenty four characters, in letters, digits or underscores, and a passcode. The passcode encrypts your keys before they leave the browser's memory; the server receives a vault it cannot open. A phone number is optional and only serves to sign back in elsewhere.
Verifying a fingerprint
Every conversation shows a short fingerprint under the person's name. Compare it with them through another channel, out loud for instance. If both match, nobody slipped in between you. If a fingerprint changes one day for no reason, stop and ask again.
Writing
Search a name in the directory and open the conversation. The encrypted channel establishes itself on first open; the indicator turns green when it is ready. Until then, nothing leaves.
Rooms
A room is created with a name and members taken from your contacts. Every join and every leave rotates the group key: nobody reads what was said before they arrived, nor after they left.
Calling
The call buttons appear in a conversation's header once the channel is established. Audio and video go through our own server; the token that opens the room is signed by your account key.
If you lose your passcode
There is no recovery, and that is not an oversight: a recoverable passcode would mean somebody else can open your vault. Losing it means creating a new account and having your fingerprints verified again.