Skip to content

Signing up and signing in

How you sign in depends on your deployment configuration. Telmoni supports both native email/password authentication, external identity providers, and device authorization for CLI workflows.

On standalone and self-hosted instances using Telmoni’s built-in authentication:

  • Sign up: Enter your email address, a password (minimum 8 characters), and optionally a display name. Telmoni emails a confirmation link that expires in 24 hours. The account cannot be used until you verify your address.
  • Sign in: Authenticate with your email and password. To protect against brute force attacks, ten consecutive incorrect attempts lock the account for 15 minutes.
  • Password reset: Selecting Forgot your password? emails a single-use reset link valid for 60 minutes. Using the link terminates all active sessions.

Passwords are salted and hashed using Argon2id.

A deployment can configure external identity providers (such as Google, GitHub, or corporate OIDC / SAML single sign-on). In this mode, user authentication is handled by the provider. Telmoni validates the identity token, provisions the local account, and never handles the raw password.

To sign in from terminal sessions, SSH hosts, or the Telmoni CLI, Telmoni implements the OAuth 2.0 Device Authorization Grant (RFC 8628):

  1. The CLI initiates the authorization flow and displays a confirmation code alongside a verification URL (/auth/device?code=...).
  2. Open the verification URL in any browser where you are signed in.
  3. Confirm that the displayed user code matches what your terminal displays, then select Approve.
  4. The CLI session is established immediately without transmitting credentials over SSH or logging passwords in terminal shell histories.

The first time you sign in while sign-ups are open, Telmoni automatically provisions:

  1. An Organization, seating your account as its Owner. The organization is labeled by your email address until you name it.
  2. A Default Project inside your organization, named Default Project, so you can immediately create API keys and configure connectors.

Your account is separate from the organization. You can create multiple organizations, hold projects within each, and accept invitations to organizations managed by others.

When an operator disables public sign-ups:

  • New users cannot register without an active invitation.
  • Existing users can sign in normally.
  • If you belong to no organization (e.g. after leaving or deleting one), you are presented with an account-only screen offering:
    • Pending invitations: Accept or decline invitations to existing workspaces.
    • Deleted organizations: Restore an organization deleted within the last 14 days.
    • Account settings: Manage email, password, and session termination.
    • Account deletion: Permanently delete your account and personal data.

Each sign-in generates an active session backed by an HTTP-only cookie. Your account’s Privacy page (/account/privacy) lists all active sessions, including device details and last active timestamps. You can revoke any other session remotely.

Changing your email address or resetting your password terminates all active sessions immediately.

Signing out destroys your active session token in the database and clears the session cookie.