Save your backup codes when you create the identity, not later. They are what lets you reset access if something goes wrong, and the moment you need them is the moment you cannot generate them.
Decide consciously about UIID Cloud. Leaving it enabled keeps an encrypted backup, so a lost device does not mean a lost identity. Switching it off and relying on an exported .uiid file means that file is your only copy — back it up somewhere separate from the device.
Set up more than one way in. Depending on your configuration you can sign in by email, with your UIID or .uiid file, or with a login certificate. Having a second route configured is what turns a lockout into an inconvenience.
Use aliases by default. Reach for your Core ID only where a service genuinely needs a verified, high-trust identity. This limits what any single service learns about you.
Review agent permissions. AI agents and automated systems act under narrowly defined, time-limited permissions. Revoke anything you no longer use — that option exists precisely so it gets used.
Reporting a problem: Send security reports by email to [email protected] rather than posting them publicly, with enough detail to reproduce the issue.