NewRun your whole inbox from Claude with the Kanso MCP

Get started

Accounts & security

Sign-up, sign-in, email verification, two-factor auth, sessions, and account deletion.

Sign-up & sign-in

Authentication is powered by Better Auth with a hardened plugin stack.

  • Email + password: Sign up with name, email, and a password (8-character minimum), then sign in.
  • Google OAuth: Auto-enabled only when Google credentials are configured; existing-user sign-in only — no silent auto-signup.
  • Invitation-only mode: Registration can be closed org-wide with a flag, enforced server-side so the UI can’t be bypassed.

Email verification

  • A one-time passcode (OTP) is emailed after sign-up — time-limited and hashed at rest.
  • Resend the code (rate-limited to 3 codes per 60 seconds).
  • Auto sign-in after successful verification.
  • Verification is required, which closes account-linking takeover vectors.

Password management

  • Forgot password: Emailed reset link (bearer token, never logged in production).
  • Reset: Set a new password straight from the link.
  • Change password: While signed in (requires your current password) — and it signs out all other devices on success.

Two-factor authentication

  • TOTP: Authenticator-app two-factor, with the issuer branded to the app name.
  • Backup codes: Hashed recovery codes for when you lose your authenticator.

Sessions & devices

  • Sign out from the sidebar user menu.
  • All other sessions are revoked automatically when you change your password.
  • Optional cross-subdomain session cookies for multi-subdomain deployments.
  • “Last login method” is tracked.

Account deletion

Deletion is permanent and irreversible, and asks for dual confirmation — re-type your email and enter your current password.

Looking for something specific in Kanso? Every feature area is covered in the sections on the left.