Create an account
- Sign up with an email address and a password, or sign in with a connected provider (Google, Microsoft, LinkedIn, Apple or Facebook, where enabled).
- You receive an email to activate the account. Follow the link in it.
- Sign-up is rate limited per address and per network address, and may ask you to solve a captcha.
API: POST /v1/user/signup, POST /v1/user/register, GET /v1/user/activate.
Sign in
- Email or username plus password, or a connected provider.
- If two-step verification (MFA) is on for your account, you are asked for a code after the password.
- Repeated wrong passwords temporarily lock the account.
- You can review your active sessions and recent activity on your account page.
Your account page
Open User > Details. The left menu links to:
| Link | What it does |
|---|---|
| Change password | Set a new password. |
| Select workspace / Manage workspace | Choose the workspace you are working in. |
| Workspace invitations | Accept invitations sent to you. |
| API Keys | Create and delete your own API keys. Only shown on your own account. |
| Delete account | Permanently delete your account. |
The page also has sections for overview, security, workspaces, API keys, sessions and activity logs.
Profile
You can change your display name, username and profile picture from the overview section. Some fields, such as the user id, cannot be edited.
API: PUT /v1/user/{id}, POST /v1/user/profile_picture.
Email addresses
An account has one primary email and up to 3 additional addresses. Each new address must be verified before it can be used.
API: GET/POST /v1/user/{id}/email, POST /v1/user/{id}/email/primary,
POST /v1/user/{id}/email/resend, DELETE /v1/user/{id}/email, GET /v1/user/email/verify.
Passwords
- Forgot your password: request a reset link, then choose a new password from the link.
- Change password: while signed in, from your account page.
API: POST /v1/user/password_forgot, GET /v1/user/password_reset, POST /v1/user/password_set,
POST /v1/user/password_update.
Who can see and change a profile
GET /v1/user/{id} and PUT /v1/user/{id} are allowed for the account owner and for
administrators. Other users get 403 Forbidden.
Roles
Roles decide what a user may do. The built-in roles are super_admin, admin, workspace_admin,
super_user, user and readonly_user. A user's roles are kept per workspace, except the
platform-wide admin roles.
Export and delete your data
- Export:
GET /v1/user/{id}/exportreturns the data held about your account. - Delete: Delete account on your account page, or
DELETE /v1/user/{id}.
Authentication for API calls
Most endpoints accept one of:
- a signed-in session (the
access_tokencookie), or aBearertoken - HTTP Basic credentials, which can be a user name and password or an API key
Many requests also take an X-TenantId header naming the workspace to act in. You must be a member of
that workspace.