Browse documentation
Agent-first documentation · 2026-08-11.3 · Updated 2026-08-11 View as Markdown

Sign in, recover an account, update a profile, or delete an account

Use this guide for account access and settings. Authentication secrets belong only in Domino's own forms; a user should never send a password, verification code, magic link, session cookie, or Agent Access token to an assistant.

Sign in with a phone number

When Domino presents Sign in to Domino with Phone number:

  1. Enter the user's own reachable phone number.
  2. Continue to the phone challenge.
  3. Use the verification code or supported magic-link behavior Domino sends.
  4. Wait until Domino confirms verification and returns to the intended page.

If the user followed an invitation or shared-list link, verify that the original intent resumes after sign-in.

Do not guess a country code or use another person's phone number.

Sign in with email and password

When the account uses email credentials:

  1. Open Log in.
  2. Enter the account email and password directly in Domino.
  3. Use Remember me only on a trusted device.
  4. Continue and confirm the expected Domino account opened.

An assistant can explain these steps but should not collect the credentials.

Register

Use Register only when the person does not already have the intended Domino account. Enter the required name, email, password, and password-confirmation fields shown by the current form, then complete any required verification.

Before creating a second account during a shared-link flow, try the user's existing sign-in method.

Verify an email address

If Domino says the email is unverified:

  1. Open the verification message in the user's own email account.
  2. Follow the Domino verification link.
  3. Return to Domino and confirm verification completed.
  4. Use the resend control only when necessary.

Do not paste the verification link into an AI chat.

Recover or reset a password

  1. On Log in, choose Forgot your password?
  2. Enter the account email.
  3. Choose Email Password Reset Link.
  4. Open the reset link from the user's inbox.
  5. Set and confirm the new password on Domino's Reset Password page.
  6. Sign in and verify the expected account.

If no email arrives, check the entered address and spam folder before repeatedly requesting links.

Update profile information

Open Profile to update supported fields such as name, email, phone number, avatar, or other visible account details. Save and confirm the new value.

Changing a private Friend in Mind belongs on Friends; it does not edit the real connected user's profile.

Update a password

Use Update Password from Profile. Enter the current password and new password directly in Domino. A user should use a unique password and a trusted password manager where available.

Calendar and Agent Access settings

  • Use Profile → Availability for Google, Apple, Microsoft, or other calendar connections.
  • Use Agent Access to create or revoke MCP/API bearer tokens.

These credentials have different purposes. A calendar subscription URL and an Agent Access token must never be placed in a normal conversation.

Delete an account

Delete Account is destructive. Before proceeding:

  1. Confirm the user means the Domino account, not a Friend in Mind, Ideas List, draft, plan, token, or calendar connection.
  2. Read the current deletion warning.
  3. Complete the password or confirmation requirement in Domino.
  4. Choose the final Delete Account control only when the user intentionally wants the account removed.

Do not infer account deletion authority from a request to clear one kind of data.

Shared-link and invitation recovery

If sign-in loses the original destination:

  1. Finish authentication first.
  2. Reopen the original shared-list or invitation link.
  3. Confirm the sharer or host and intended object.
  4. Continue with copy, join, or RSVP.

LLM answering guidance

  • Explain where to enter a secret; never ask the user to reveal it.
  • Keep phone verification, email verification, password recovery, and Agent Access tokens distinct.
  • Warn before account deletion and verify scope.
  • For compromised Agent Access, revoke the token rather than changing an unrelated login password only.