Skip to main content
POST
Create an Operator Account
The Create account browser flow starts with an email address. POST /v0/users returns 202 and requests a six-digit code. It creates no User, primary Account, browser session, or OAuth grant. New and existing addresses receive the same public response. Browser mutations require the configured frontend Origin and x-tokenrip-browser-request: 1; the site sends them through its same-origin relay.

Request a registration code

The response is 202:
The code expires after ten minutes. Requesting another code rotates the active one.

Prove the email

The browser posts the code to POST /v0/auth/email-verification/login with its original registration intent:
For a new email, successful proof creates a verified User, aliasless primary Account, binding, keypair, and browser session together. The response is 200, includes user_id, session_id, expires_at, email, and outcome: "registered", and sets an HTTP-only browser_session cookie. A handle and password can be added later in account settings. If the email already belongs to an account, the code signs in that account after proof and returns outcome: "existing_account". The browser still sends purpose: "register". An invalid, expired, replayed, or locked code creates no session. Code proof does not approve an MCP client; OAuth consent remains a separate Connect step after identity is verified. For sign-in without a password, request a code from POST /v0/auth/email-verification/request with { "email": "[email protected]", "purpose": "login" }, then prove it with purpose: "login"; success returns outcome: "logged_in". A login request for an unknown address creates no account.

Errors