Account
Signing up, signing in, the profile and the organization — what the platform remembers about an account, what of it you change in the console, and what you cannot change yourself.
Create an account
Signing up requires only an email address and a password. There is nothing to install, and no card is required; a key can be issued the moment you are through.
- Open the consoleIt runs on a hostname of its own, and every account operation lives there.
- Give an address and a passwordAt least **6 characters**; the ceiling is 256 **bytes** of UTF-8. The floor counts characters, so six letters are six letters in any alphabet. The ceiling counts bytes, because it bounds the hashing work and a Cyrillic letter costs two: 256 bytes is 128 Cyrillic letters.
- Accept the two consentsThe terms of the public offer, and a separate consent to the processing of personal data. Both are required, and the form validates each consent separately; the [documents themselves](https://kumorouter.com/legal) live on the main site.
- You are already inThe same answer that creates the account issues the session: the console sets its own cookie and opens the overview, so there is nothing to sign in to and nothing to copy.
One transaction creates three things: the user, its personal organization, and that organization's financial defaults. The organization appears on its own, and from then on it is what owns everything you issue and everything you spend.
Email addresses are compared case-insensitively, so an address differing only in letter case is already taken.
The confirmation email arrives in its own time, and its link vouches that the address is yours. Today that is all it does: confirming opens no door, and an unconfirmed account signs in and works. The link lives for a day and works once, and every rejected link receives the same response; to request another email, go to the console, which sends it to the current session's own address.
Your first call in three minutes → Issue a key →
Signing in, signing out, the password
Signing in verifies the address-and-password pair and issues a session in a cookie. An unknown address and a wrong password are one rejection with one sentence: any visible difference between them would tell a stranger which addresses you have registered.
For the same reason a password-reset request always answers identically — whether the address has an account or not. The email goes out only in the first case, but from the form's side the two are indistinguishable. The link in it is valid for thirty minutes and works once.
Changing the password in settings verifies the current one before anything changes, and ends every session — including the one you are doing it from. That is exactly the behavior expected from a password change: if the old password leaked, somebody else's open tab has to stop working in the same second. A reset by email does the same.
Signing out revokes the session the cookie names and clears the cookie itself. It is about one device; to end them all, change the password.
The profile
The profile consists of four fields, and all four are edited in the console's settings.
The username
5 to 32 characters: Latin letters, digits and underscores. It starts with a letter, ends with a letter or a digit, and never carries two underscores in a row. A leading at sign is accepted and stripped, and the handle is stored lowercased.
It can be changed twice in the life of the account, and the console shows how many changes are left. Once both are spent, only support can change it — and their change does not spend one of yours. Some usernames are reserved by the platform, taken by it rather than by another account.
The email
The address is changed in the same place. After a change, the new address is unverified until you open the link in the new email — the console offers to send it. That does not stop anything working, but email about the account now goes to the new address, which makes a typo there costlier than a typo anywhere else in the profile.
How the console looks
Three preferences, and the difference between them matters more than it looks.
- Theme — light, dark or system.
- Interface language — the console only. The choice does not travel to other Kumo hosts: this documentation has its own control in its header.
- Display currency — what the console prints prices and the balance in. It is a shop window and not an account: payment is processed in roubles regardless, and the internal accounting unit is one and does not move with this control.
The organization
An account signs in to the console, but what pays and what owns is not the account — it is its organization.
- A key is issued to the organization, not to a user: every call it authenticates is counted and charged against the organization.
- The wallet belongs to the organization, and so does the package: there is one for the whole account.
- The request log, the money movements and the usage reports are read for the whole organization. None of those operations carries a "whose" selector: the scope is always the current session's own organization.
- Projects are a label inside the organization, by which keys are grouped among themselves.
What a key pays with → How keys are grouped →
Deleting the account
Account deletion does not happen at the press of a button, and by construction cannot: the request creates a review request and never anonymizes the account by itself. The request passes three states — raised, approved, applied — and the console shows which one it is in.
There is no self-service deletion yet, and the console says so plainly: the request is handled by hand. Write to support from the address the account is registered to and the answer comes by email. Keys are switched off on confirmation, and whatever is left on the wallet is returned.