Documentation
Accounts
How login, roles, and organization membership work.
Login & register
Public register and login set an HTTP-only session cookie. Forgot/reset password flows remain available from the sign-in page.
Roles
client— self-serve creators; scoped to their organizations and sitessuper_admin— platform console (users, roles, settings, impersonation, WhatsApp)
Impersonation
Super admins can start a timed session as a client from Users, with a required reason. A banner lets you leave and restore the operator token. Nested impersonation, impersonating another super admin, and operator mutations (users, roles, branding) are blocked until you leave. Sessions are audited.
Invite members
On an organization page, attach an existing user by email and choose a membership role (owner, admin, editor, member). Detach removes access to that tenant.
