Skip to content

Accounts and sign-up ​

As a platform administrator you decide who can get an account, in Platform → Sign-up.

The three modes ​

Invitation only (the default). Nobody signs up by themselves. People arrive because an organization invited them, or because you created the account. Right for a company instance.

Email domains. Anyone with an address at a domain you list. Exact matches only: listing acme.com does not admit eu.acme.com, so add both if you need both. Right for a company where everyone has company email.

Open. Anyone with an email address. Right for a public service, and it needs email working and some thought about who pays for the models.

An organization's invitation always lets its recipient sign up, whatever the mode. That is how you bring in a contractor on an otherwise closed instance.

Confirming the address ​

Someone who signs up themselves must open a link sent to their address before they can sign in. The link lasts 48 hours, and using any emailed link confirms the address.

Signing up again with an address that was never confirmed takes that unconfirmed account over — it never proved anything — so a typo or an abandoned attempt is not a permanent block.

Accounts you create as an administrator count as confirmed: you vouched for the address.

Forgotten passwords ​

"Forgot password" emails a link valid for two hours. Using it signs that person out of every session, since a forgotten password is sometimes a stolen one.

Without email configured, the reset link is written to the API's log, and you can also mint a one-time link for someone from Platform → Accounts.

What is never revealed ​

Sign-up, "resend" and "forgot password" all answer the same whether or not an address has an account — the explanation goes to the mailbox instead. "Your email is not confirmed" is only said after the correct password. Each account gets at most one email of each kind per minute.

This means an attacker cannot use the sign-in page to learn who has an account.

Platform administrators ​

Platform administrators manage accounts, see the list of organizations from the outside (names and counts, not contents), offer models and tools, and read platform events: sign-ins, account changes, organizations created and deleted.

They get no access inside anyone's personal space or organization unless someone shares it with them. If you need to investigate an agent, someone in that organization has to let you in.

CrewHall