Get started
Accounts & security
Sign-up, sign-in, email verification, two-factor auth, sessions, and account deletion.
Sign-up & sign-in
Authentication is powered by Better Auth with a hardened plugin stack.
- Email + password: Sign up with name, email, and a password (8-character minimum), then sign in.
- Google OAuth: Auto-enabled only when Google credentials are configured; existing-user sign-in only — no silent auto-signup.
- Invitation-only mode: Registration can be closed org-wide with a flag, enforced server-side so the UI can’t be bypassed.
Email verification
- A one-time passcode (OTP) is emailed after sign-up — time-limited and hashed at rest.
- Resend the code (rate-limited to 3 codes per 60 seconds).
- Auto sign-in after successful verification.
- Verification is required, which closes account-linking takeover vectors.
Password management
- Forgot password: Emailed reset link (bearer token, never logged in production).
- Reset: Set a new password straight from the link.
- Change password: While signed in (requires your current password) — and it signs out all other devices on success.
Two-factor authentication
- TOTP: Authenticator-app two-factor, with the issuer branded to the app name.
- Backup codes: Hashed recovery codes for when you lose your authenticator.
Sessions & devices
- Sign out from the sidebar user menu.
- All other sessions are revoked automatically when you change your password.
- Optional cross-subdomain session cookies for multi-subdomain deployments.
- “Last login method” is tracked.
Account deletion
Deletion is permanent and irreversible, and asks for dual confirmation — re-type your email and enter your current password.
This cascades
Deleting your account cleans up your data and removes any organizations you solely own, so no orphaned workspaces are left behind. There is no undo.
Looking for something specific in Kanso? Every feature area is covered in the sections on the left.