Skip to content

Start here

Sign in

Everyone signs in with a password and a code from an authenticator app. A stolen password alone is never enough.

Tested. Every step on this page runs in a real browser against the real service in the build pipeline for every change.

Accounts are made by your team’s owner; nobody can sign themselves up. Inviting people from the dashboard comes in a later release. Until then, whoever runs the service makes the first owner:

Terminal window
pnpm --filter @kiyesi/api admin create-owner <team-id> you@example.com "Your Name"

It asks for the password twice, without showing it. A password needs at least 12 characters, and one found in a known data leak is refused.

Open app.kiyesi.dev and sign in with your email and password. The first time, Kiyesi asks for your password again, then shows a QR code. Scan it with an authenticator app such as 1Password, Google Authenticator, Microsoft Authenticator or Aegis, and type the 6-digit code it shows.

Kiyesi then shows 10 backup codes, once. Each works one time, if you lose your phone. Keep them in your password manager.

From then on, each sign-in asks for the current code. You can tick Trust this browser for 30 days.

In Settings, Passkeys, choose Add a passkey. Next time, choose Sign in with a passkey and use your fingerprint, face or device PIN instead of a password and code.

Terminal window
kiyesi login

It shows a code and opens the dashboard. Check the code matches and choose Approve. The token goes into the macOS Keychain, or the Secret Service on a Linux desktop; where there is neither, into ~/.config/kiyesi/login.yaml, readable by you only. Then:

Terminal window
kiyesi servers # every server, worst first
kiyesi server checkout-api-prod # its latest report, with every fix
kiyesi logout

Use a backup code: on the code screen, choose Use a backup code. If you have none left, whoever runs the service removes the authenticator app, and you set it up again at your next sign-in:

Terminal window
pnpm --filter @kiyesi/api admin reset-two-step you@example.com

Email reset arrives with email sending in a later release. Until then, whoever runs the service sets a new one; you are signed out everywhere:

Terminal window
pnpm --filter @kiyesi/api admin reset-password you@example.com