Account
Checking your sign-in status…
Sign in to manage identity verification, research access, organizations, billing and connection tokens here.
Google / GitHub only identify the account. Signing in itself uses a passkey or a wallet — never a password.
Approve a device
What does approving do?
Approving issues ONE personal API token to that device. Your passkey or wallet never travels to it. The code expires in ten minutes and can be exchanged once.
Deny anything you do not recognise. Check that the code on this screen is the same one the device is showing.
Account
What is a principal?
The principal is the stable identifier mithril.fund knows you by. It does not change when you replace a passkey or a wallet.
Linked accounts
What is a linked account?
Linking a Google or GitHub account lets "Continue with Google" offer this account's passkey next time. A linked account names the account; it is not a way to sign in.
Unlinking does not affect signing in with a passkey or a wallet.
Notification channels
What is a notification channel?
An email address is registered only as a place notifications go. It cannot sign you in, stand in for a passkey or a wallet, reset a password or recover the account.
It is confirmed by entering the code the mail carries into this signed-in page. The code is not a link and expires after 15 minutes.
Notifications sent to this address today: a notice when a connection token is issued.
Identity verification
How verification works
Card verification: register a credit or debit card to complete it (checkout.stripe.com). Prepaid and virtual cards are not accepted.
Document verification (Stripe Identity, verify.stripe.com) can be added. Card details and documents go to Stripe only; mithril.fund keeps the status, the expiry and an evidence reference. Verification expires after 365 days.
Research access
Approved scopes
What is a scope?
Each scope is approved on its own basis for research. An expired or suspended scope cannot run inference.
Organization
Organizations and teams
An organization is issued as a did:webvh DID; membership is managed with verifiable credentials (VC). The creator receives the owner role.
Invited members share API tokens, scopes and billing. Roles are owner / admin / member / billing.
Organization SSO (Team / Enterprise)
What is organization SSO?
Members are managed by the organization's identity provider (OpenID Connect: Google Workspace, Microsoft Entra ID, Okta and others). A member removed from the IdP loses organization access at the next re-authentication interval.
The IdP is not a way to sign in. Members first sign in with a passkey or a wallet, then authenticate with the organization's IdP to obtain membership. Roles are admin / member / billing; owner is never granted by an IdP.
Available to organizations on the Team / Enterprise plans. SAML is not supported yet.
Team
Member invitations open once an organization exists.
Security controls
Guardrail, firewall and compliance rules and their versions are shown under Security controls.
Billing and credits
About charges
The verified free research allowance is never charged. Paid capacity is bought without automatic top-up.
Use from a CLI / IDE
Issue a connection token for a local CLI / IDE agent. It is shown once.
For OpenAI-compatible clients: KOTOBA_API_BASE=https://api.mithril.fund/v1 and KOTOBA_API_TOKEN=kc_pat_… (token shown once after issue).