Help center
Accounts, sign-in, and security.
How to manage your account, set up multi-factor authentication, and configure single sign-on.
Managing your account
Signing in
You sign in with your work email and password at your workspace's sign-in page. Sessions use OpenID Connect with PKCE; the dashboard and your AI client each hold their own short-lived tokens, and nothing shares your password.
Resetting a forgotten password
Use Forgot password? on the sign-in screen. We email you a single-use reset link that expires after a short window. If the email does not arrive within a few minutes, check spam, then confirm you entered the address your account was created with.
Changing your password
While signed out, the reset flow above is also the supported way to rotate your password. Email and display-name changes are handled by support at support@kanonik.ai, with verification from the account's email address.
Inviting teammates
Workspace administrators can invite teammates through the connected AI (ask it to invite an actor) or via support. Every workspace member gets their own identity; approval decisions are always attributed to a named person, never a shared login. Seats are unlimited on every plan, so there is no reason to share credentials.
Leaving or deleting a workspace
Export your record first (the Auditor Export bundle is a complete, signed copy). Workspace deletion follows a 30-day grace period, after which your tenant's encryption keys are destroyed and the data becomes cryptographically unrecoverable. The full mechanism is described in our Privacy Policy.
Multi-factor authentication
What we support
Kanonik uses time-based one-time passwords (TOTP) with any standard authenticator app: 1Password, Google Authenticator, Microsoft Authenticator, Authy, and similar. We do not use SMS codes; SMS is vulnerable to SIM-swap attacks and does not meet the bar for a compliance product.
Who is required to use it
Accounts holding privileged operator access (staff-level access that spans workspaces) are required to use TOTP. If a required account has no authenticator enrolled, enrolment is forced at the next sign-in: you scan a QR code with your app and confirm one code, and from then on sign-in asks for your current code.
Turning it on for your own account
Email support@kanonik.ai from your account address and we enable TOTP enrolment for you; your next sign-in walks you through the QR-code setup.
If you lose your authenticator
Contact support from your account's email address. We verify you, reset the enrolment, and your next sign-in sets up a new authenticator. Note that the approval links at the heart of Kanonik are separately protected: each is single-use, signed, and expires in minutes, whether or not MFA is involved.
Single sign-on
How sign-in works today
Every workspace authenticates through Kanonik's identity service (OpenID Connect with PKCE). Your AI client connects over MCP using OAuth with dynamic client registration; it never sees or stores your password, and its tokens are short-lived and scoped to your workspace.
Bringing your own identity provider
Enterprise plans can connect their own identity provider over SAML 2.0 or OpenID Connect: Okta, Microsoft Entra ID, Google Workspace, or any standards-compliant IdP. Your people then sign in through your IdP, your IdP's MFA and session policies apply, and deprovisioning in your directory ends access to Kanonik.
Configuration
IdP connections are configured with our team during Enterprise onboarding: you provide the metadata URL or client credentials from your IdP, we establish the trust and map email as the identity attribute, and we verify the round trip together before anyone is switched over. Write to hello@kanonik.ai to start.
Directory sync
Membership changes are made in the workspace; there is no automatic directory sync (SCIM). If SCIM matters for your rollout, tell us at hello@kanonik.ai.
Getting more help
Support is async by design and answered by people who work on the product: support@kanonik.ai. Security questions and our posture live on the security page; the binding terms are in the Terms, Privacy Policy, and DPA.
More help
Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email support@kanonik.ai and a person who works on the product answers.