門 通門 · GATE
This session ends at the harbour nearest you.
Sessions are 12 hours, or 30 days on a device you tell us to remember.
Sign in
The console runs at every harbour. Your session opens at the one nearest you and ends there. No account yet? Create one — it takes a minute.
If two-factor is enrolled, the six-digit code is asked for on the next screen. Team accounts on SAML are sent to their identity provider instead — the four ways through the gate are set out below.
Higan Holdings Limited — England & Wales, No. 16914818Terms · Privacy · yunagi.cloud
鍵 Ways In
Four ways through the gate.
Every one of them ends in the same session. Which you use is a question of how much you want to carry and how many people share the account.
← the table scrolls sideways →
| Method | Second factor | Session length | Where it works | How to enrol |
|---|---|---|---|---|
| Password only | None — not permitted once billing is enabled | 12 hours | Console and API | At sign-up |
| Password + TOTP | Six digits, 30-second period, SHA-1, any authenticator app | 12 hours · 30 days on a remembered device | Console, API, CLI | Console → Security → Add authenticator |
| Passkey (WebAuthn) | The device is the factor | 12 hours · 30 days on a remembered device | Console only — the API takes tokens, not passkeys | Console → Security → Add passkey |
| SAML 2.0 single sign-on | Whatever your identity provider enforces | Your provider's assertion lifetime, capped at 12 hours | Console; API keys are still issued per user | Console → Team → Single sign-on |
| Machine token | None — the token is the credential | No expiry until revoked | API and CLI only; cannot open the console | Console → Security → API keys, or yg auth token create |
Every account with a payment method on file must carry a second factor from row 2, 3 or 4. Ten recovery codes are issued once, at enrolment, and are never re-issued. A machine token is not a sign-in method for a person and will be refused at the console.
戻 Getting Back In
If you cannot get in.
Every row below is a real path, with the real wait. Nothing here needs a phone call to a sales team, and nothing is resolved faster by shouting.
← the table scrolls sideways →
| What has happened | What to do | How long it takes |
|---|---|---|
| Forgotten password | Reset link to the account email | Immediate; the link is valid for 60 minutes and can be used once |
| Lost the TOTP device, have a recovery code | Use the code in place of the six digits | Immediate; the code is spent and the old secret is revoked on use |
| Lost the TOTP device, no recovery code | Ticket from the account email, then a video identity check with a contact already named on the account | The check is scheduled within one working day of the ticket |
| Account email no longer reachable | Ticket from any address, plus the last four digits of the payment method and one invoice number | One working day |
| The only account owner has left the organisation | Written request on company letterhead, signed by a director named at Companies House | Two working days |
| Single sign-on is enforced and the provider is down | Break-glass: one owner may hold a password-and-TOTP login exempt from SSO | Immediate — but only if the exemption was set beforehand |
| You believe the account is compromised | Console → Security → Revoke all sessions and keys, then a ticket marked SECURITY | Revocation is immediate, from the console, without waiting for us |
The first two rows are self-service and need nobody here. The rest are deliberately slow, because a recovery path that is fast for you is fast for whoever is pretending to be you. Set the break-glass exemption on the day you turn SSO on, not on the day your provider fails.
A compromised account is the one case that skips the queue: revoke every session from Console → Security, then write to [email protected]. A compromise report is picked up by a named engineer rather than a queue; revoking the sessions is the part that does not wait for us.