Account and security
Registration and sign-in
Stand registration creates an account from an accepted email setup or supported provider flow, while sign-in discovery offers only the methods configured for that account.
- Availability
- All plans
- Configured in
- stand.chat registration; app.stand.chat login; Dashboard → Profile → Security & sign-in
- Category
- Account and security
- Reference status
- Current
Create an account
- Open registration accepts an email, initial site information where requested, and explicit terms acceptance.
- Email-based setup sends a link so the recipient can finish creating the account.
- Google signup can create an account through that provider when enabled.
- An invited team member uses the invitation’s email and any required-provider rule rather than creating unrelated membership.
How sign-in discovers methods
Login begins with the account email. Stand resolves the account’s allowed methods and then presents only relevant choices: password, Google, passkey, or recovery-code fallback where configured. This avoids suggesting a method that cannot authenticate that account.
Sign-in methods
| Method | When shown |
|---|---|
| Password | A direct Stand password remains configured and the account is not in a passkey-protected mode that replaces ordinary password login. |
| The provider is linked and allowed for the account or required invitation. | |
| Passkey | The account has enabled passkey protection and registered a usable passkey. |
| Recovery code | A passkey-protected account needs its one-time fallback path. |
Dashboard session behavior
- Successful authentication establishes the dashboard session for the current browser.
- Signing out ends that session.
- Disabling a member invalidates organization access and signs the member out.
- Sensitive account changes can require a fresh recent sign-in even when the dashboard session is otherwise valid.
Failures and boundaries
- A temporary identity-service interruption produces maintenance or retry guidance rather than pretending the password is wrong.
- A provider requirement does not silently attach an existing account to that provider.
- The email setup link must be used by its intended recipient and can expire or be superseded.
- Registration creates Stand access; it does not authenticate visitors using the customer’s website chat.