Skip to main content

Sign-in and public profile

A Product Account keeps a person's identity and contributions together. The agreed design supports email codes and Google sign-in. A public nickname identifies the contributor; the confirmed email stays private.

The 3 October 2026 source inspection found account, sign-in, session and nickname onboarding flows in the application code. It did not establish a successful live provider test or release. Account work explains that evidence and its limits.

Email code or Google​

With email sign-in, a person proves access using a six-digit code. The accepted rules give a code ten minutes and at most five incorrect attempts. Resending an active code is allowed after 60 seconds; it sends the same code without extending its expiry or resetting attempts. Sending an email is not proof that it arrived or that the person owns the address.

Google sign-in can lead to the same Product Account. If a Google identity is new and its email already belongs to an account, an email-code proof is required before linking. Some Google email cases also require this proof before an account can be created. Returning with an already linked Google identity opens its existing account, even if the email reported by Google later changes.

For example, someone who first signs in by email and later chooses Google with the same address should prove the link and keep one account. The system must not silently create a duplicate or merge two accounts because their details look similar.

Choose the public name before contributing​

A new account can have a limited session while onboarding is unfinished. Contribution privileges require a unique nickname. Returning later resumes the unfinished step. The design permits a nickname change monthly; the exact format and collision rules belong to the account implementation.

An email address is a sign-in identity, not a public display name. Product accounts are also separate from staff accounts used to manage content. Signing in does not grant editorial permission, contributor reputation or rewards.

Sessions and sign-out​

A session has a fixed maximum lifetime of 30 days and can end earlier. Continuing to use the product does not extend that absolute deadline. Account restrictions apply on the next protected request.

Confirmed sign-out ends the current session, rather than every device. If the server outcome is unconfirmed, the product must not report a confirmed server logout. Some interrupted authentication flows require a fresh sign-in.

Apple and Facebook sign-in remain deferred. The accepted design has no manual recovery process for a person who loses every sign-in method, and it does not assume that two different email addresses belong to the same person.

Read articles and reviews and interactions and following for what an account means in community features. Their detailed participation policies are covered by the community review brief.