# Sign in, recover an account, update a profile, or delete an account

Use this guide for account access and settings. Authentication secrets belong only in Domino's own forms; a user should never send a password, verification code, magic link, session cookie, or Agent Access token to an assistant.

## Sign in with a phone number

When Domino presents **Sign in to Domino** with **Phone number**:

1. Enter the user's own reachable phone number.
2. Continue to the phone challenge.
3. Use the verification code or supported magic-link behavior Domino sends.
4. Wait until Domino confirms verification and returns to the intended page.

If the user followed an invitation or shared-list link, verify that the original intent resumes after sign-in.

Do not guess a country code or use another person's phone number.

## Sign in with email and password

When the account uses email credentials:

1. Open **Log in**.
2. Enter the account email and password directly in Domino.
3. Use **Remember me** only on a trusted device.
4. Continue and confirm the expected Domino account opened.

An assistant can explain these steps but should not collect the credentials.

## Register

Use **Register** only when the person does not already have the intended Domino account. Enter the required name, email, password, and password-confirmation fields shown by the current form, then complete any required verification.

Before creating a second account during a shared-link flow, try the user's existing sign-in method.

## Verify an email address

If Domino says the email is unverified:

1. Open the verification message in the user's own email account.
2. Follow the Domino verification link.
3. Return to Domino and confirm verification completed.
4. Use the resend control only when necessary.

Do not paste the verification link into an AI chat.

## Recover or reset a password

1. On **Log in**, choose **Forgot your password?**
2. Enter the account email.
3. Choose **Email Password Reset Link**.
4. Open the reset link from the user's inbox.
5. Set and confirm the new password on Domino's **Reset Password** page.
6. Sign in and verify the expected account.

If no email arrives, check the entered address and spam folder before repeatedly requesting links.

## Update profile information

Open **Profile** to update supported fields such as name, email, phone number, avatar, or other visible account details. Save and confirm the new value.

Changing a private Friend in Mind belongs on **Friends**; it does not edit the real connected user's profile.

## Update a password

Use **Update Password** from Profile. Enter the current password and new password directly in Domino. A user should use a unique password and a trusted password manager where available.

## Calendar and Agent Access settings

- Use **Profile → Availability** for Google, Apple, Microsoft, or other calendar connections.
- Use **Agent Access** to create or revoke MCP/API bearer tokens.

These credentials have different purposes. A calendar subscription URL and an Agent Access token must never be placed in a normal conversation.

## Delete an account

**Delete Account** is destructive. Before proceeding:

1. Confirm the user means the Domino account, not a Friend in Mind, Ideas List, draft, plan, token, or calendar connection.
2. Read the current deletion warning.
3. Complete the password or confirmation requirement in Domino.
4. Choose the final **Delete Account** control only when the user intentionally wants the account removed.

Do not infer account deletion authority from a request to clear one kind of data.

## Shared-link and invitation recovery

If sign-in loses the original destination:

1. Finish authentication first.
2. Reopen the original shared-list or invitation link.
3. Confirm the sharer or host and intended object.
4. Continue with copy, join, or RSVP.

## LLM answering guidance

- Explain where to enter a secret; never ask the user to reveal it.
- Keep phone verification, email verification, password recovery, and Agent Access tokens distinct.
- Warn before account deletion and verify scope.
- For compromised Agent Access, revoke the token rather than changing an unrelated login password only.
