Self-hosting
Recovering an account
Recover access using account flows or an operator command.
Password and verification
Use the password reset flow. Without a system sender, only the first installation administrator’s account links appear in backend logs. Restrict access to these logs. Other account mail needs a sender configured in Amazon SES settings; invitations show “Account email isn’t set up yet…” when it is missing. Password reset keeps a generic response to avoid revealing whether an account exists.
pnpm backend logs --history 50Broken SSO
An operator holding the deployment admin key can disable SSO enforcement for a team. This invalidates the connection test and previous proofs; it does not grant membership or reveal the provider secret.
pnpm backend run sso:recover '{"organizationId":"YOUR_TEAM_ID"}'Transfer installation ownership
Transfer the installation administrator role to an existing verified account when handing over operations.
pnpm backend run installationAdmin:transfer '{"email":"new-admin@example.com"}'Operator password recovery
With the deployment admin key, run this command from your app checkout:
pnpm backend run accountRecovery:resetPassword '{"email":"admin@example.com"}'Open the returned one-time link within one hour to choose a new password. The command prints the link only in CLI output; it does not email or log it. Resetting revokes existing sessions and invalidates OAuth grants. Unknown accounts fail without logging the address. Recovery does not bypass MFA or SSO.
Development account links
LOG_AUTH_LINKS=true logs every account’s links while no sender is set. Use it only for local development or e2e tests, never on a real installation. With a sender configured, delivery failures never fall back to logging secret links.