User GuideAPI ReferenceAI Applications

👤 Profile & Security

View or manage account information, linked accounts, notification and behavior preferences, security settings, 2FA management, Passkey management, and login session management.

After logging in, click the "Profile" button in the left navigation bar to access the profile page /profile. Here you can centrally manage account information, third-party linked accounts, notification preferences, interface language, sidebar customization, daily check-in, Two-Factor Authentication (2FA), Passkeys, access tokens, and device login sessions.

View Account Information

View basic account information in real time, including username, user ID, current available balance, total consumed quota, and historical API request counts.

Manage Account Linked Information

Supports linking email addresses and third-party OAuth accounts:

  1. In the settings section, locate "Account Linking" → "Email" → click "Link".
  2. Enter the email address to be linked and click "Send" to receive a verification code.
  3. Enter the received verification code and click "Link Email" to complete the process.
  1. In the settings section, locate "Account Linking" → "Third-Party OAuth Account".
  2. Click the corresponding "Link" button for the target third-party platform (such as GitHub, Discord, etc.).
  3. You will be redirected to the third-party authorization page. After authorization is complete, you will automatically return, and the status will display as "Linked".

Configure Notification and Behavior Preferences

Notification Settings

  1. Notification Method: Supports receiving system notifications via Email, Webhook, Bark, or Gotify.
  2. Balance Warning Threshold: Customize the balance alert threshold to automatically send notifications when the account balance falls below this value.
  3. Notification Email: Specify a dedicated email address for receiving notifications; if left blank, the primary linked email address of the account is used by default.
  4. After making changes, click "Save Settings" to apply.

Behavior Preference Settings

  1. Accept Unpriced Models: When enabled, allows calling models that are not individually priced (billed according to the platform default ratio; disabled by default to prevent unexpected consumption).
  2. Log IP Address: When enabled, records the source IP address of API requests in usage logs for security auditing and troubleshooting.
  3. After making changes, click "Save Settings" to apply.

Enabling "Accept Unpriced Models" may result in unexpectedly high quota consumption. It is strongly recommended to keep it disabled by default.

Configure Interface Language Preferences

You can customize the console interface language preference. This setting will synchronize across all devices logged into the current account and serve as the preferred language for API error messages.

Customize Left Sidebar Display

Customize the functional modules displayed in the console left sidebar, enabling or hiding corresponding entries according to your daily usage habits.

This setting only adjusts the visibility of navigation items in your personal view and does not affect underlying API access permissions.

Daily Check-in

If the platform has check-in perks enabled, you can claim quota rewards daily here and view historical check-in statistics:

  1. Click "Check In Now" to claim the day's quota reward.
  2. The page displays total check-in days, quota earned this month, and historical total rewards in real time.
  3. Check-in is limited to once per day, and rewards are directly credited to the account's available balance.

Security Settings

Manage account credentials and core access security:

  1. Change Password: Update your account login password; regular updates can enhance security.
  2. Access Token: Used to generate and manage console administrative API tokens (different from model invocation API Keys).
  3. Delete Account: Permanently delete the current account and all its historical data. This action is irreversible, please confirm carefully.

Access tokens are only used for console management-level APIs and differ from API keys (API Keys) used for LLM calls. Do not enter them into third-party AI chat clients.

Enable or Disable Two-Factor Authentication (2FA)

Enable Two-Factor Authentication (2FA) for your account to add an extra layer of security beyond passwords:

  1. Enable Two-Factor Authentication: Click the "Enable" button next to "Two-Factor Authentication".
  2. Scan QR Code: Use an authenticator app such as Google Authenticator or 1Password to scan the QR code or manually enter the secret key.
  3. Save Backup Codes: Make sure to record and safely store the system-generated backup codes (used to restore access if you lose your device).
  4. Verify and Bind: Enter the 6-digit dynamic verification code currently generated by the authenticator and click "Enable 2FA" to complete the setup.

Backup codes are displayed only once and cannot be viewed again after the modal is closed. Please make sure to back them up properly in advance.

Passwordless Login with Passkeys

After enabling Passkeys, you can log in with a single click using device biometrics (Fingerprint/Face ID), system lock screen PIN, or hardware security keys, eliminating the hassle of entering passwords and verification codes:

  1. Enable Passkey: Click "Enable Passkey" in the "Passkey Login" section.
  2. Security Verification: Enter the 6-digit dynamic verification code from your authenticator or a backup code for permission verification.
  3. Register Passkey: Follow the browser or operating system prompts to complete fingerprint or facial biometric enrollment.
  4. Complete and Manage: Once linked successfully, subsequent logins can be completed instantly with one click; to disable, click "Unlink Passkey".

Login Session Management

Monitor and manage active sessions for the current account across all devices and browsers in real time:

  1. View Session List: Displays login device type, operating system, browser, source IP, last active time, and expiration time.
  2. Terminate Specific Device: Click "Log Out" next to the corresponding session to immediately invalidate that device's session.
  3. Log Out of All Other Sessions: Click "Log Out Other Sessions" to clear all login credentials except for the current device with one click.
  4. Security Alert: If you notice an unfamiliar device or remote IP login record, it is recommended to immediately revoke all sessions and change your account password.

Was this page helpful?

👤 Profile & Security | OpenRely Docs