Start here
Sign in
Everyone signs in with a password and a code from an authenticator app. A stolen password alone is never enough.
Tested. Every step on this page runs in a real browser against the real service in the build pipeline for every change.
Get an account
Section titled “Get an account”Accounts are made by your team’s owner; nobody can sign themselves up. Inviting people from the dashboard comes in a later release. Until then, whoever runs the service makes the first owner:
pnpm --filter @kiyesi/api admin create-owner <team-id> you@example.com "Your Name"It asks for the password twice, without showing it. A password needs at least 12 characters, and one found in a known data leak is refused.
Sign in and set up the authenticator app
Section titled “Sign in and set up the authenticator app”Open app.kiyesi.dev and sign in with your email and password. The first time, Kiyesi asks for your password again, then shows a QR code. Scan it with an authenticator app such as 1Password, Google Authenticator, Microsoft Authenticator or Aegis, and type the 6-digit code it shows.
Kiyesi then shows 10 backup codes, once. Each works one time, if you lose your phone. Keep them in your password manager.
From then on, each sign-in asks for the current code. You can tick Trust this browser for 30 days.
Add a passkey (optional)
Section titled “Add a passkey (optional)”In Settings, Passkeys, choose Add a passkey. Next time, choose Sign in with a passkey and use your fingerprint, face or device PIN instead of a password and code.
Sign in on your laptop
Section titled “Sign in on your laptop”kiyesi loginIt shows a code and opens the dashboard. Check the code matches and choose Approve. The token goes into the macOS Keychain, or the Secret Service on a Linux desktop; where there is neither, into ~/.config/kiyesi/login.yaml, readable by you only. Then:
kiyesi servers # every server, worst firstkiyesi server checkout-api-prod # its latest report, with every fixkiyesi logoutLost your phone
Section titled “Lost your phone”Use a backup code: on the code screen, choose Use a backup code. If you have none left, whoever runs the service removes the authenticator app, and you set it up again at your next sign-in:
pnpm --filter @kiyesi/api admin reset-two-step you@example.comForgot your password
Section titled “Forgot your password”Email reset arrives with email sending in a later release. Until then, whoever runs the service sets a new one; you are signed out everywhere:
pnpm --filter @kiyesi/api admin reset-password you@example.com