Skip to content
Your account

Sign-in and your account

Create an account, manage connected logins and sign out safely.

Open Fungi sign-in. Fungi uses email codes, magic links and, when shown on the form, GitHub. There is no account password.

  1. Choose Create account if you are new, or Sign in if you already have an account. For a new account, enter your name, accept the Terms and enter the invite code you received if one is required.
  2. Enter your email and choose Send code. Enter the code from that inbox, then choose Continue with code. This verifies your email and signs you in; for a new account it also creates the account. Or choose Use a magic link and open the link sent to the same inbox. Continue with GitHub appears when GitHub sign-in is configured.
  3. If Fungi still asks you to verify your email, open the separate verification link in your inbox, then choose I’ve verified my email. An invitation works only with the verified email address it was sent to.

Email sign-in codes and magic links expire after 15 minutes. If a message does not arrive, check the email address and spam folder, then choose Use another email or resend. If Fungi asks you to wait before requesting another message, wait before retrying. If email sign-in is unavailable, try again later; GitHub may be an option if its button appears. Never share a sign-in code or link.

If you previously used a Fungi password, request a code for that same email address to access your existing account.

You sign in once, at fungi.computer. Opening a Team at its own address, such as acme.fungi.computer, carries that sign-in to the Team. Each Team keeps its own session cookie, which no other Team or App can read. Every request still checks that you are a current member of the Team.

On Account, you can change your display name, check email verification and manage Signed-in devices. Sign out this device ends the selected browser session. Sign out ends the current browser session, including its linked Team sessions; it leaves independent browser sessions and Local logins alone. Sign out all other devices ends your other browser sessions and revokes your OAuth logins, including Local connections. It keeps the current browser signed in. Fungi may ask you to sign in again before managing devices.

Run fungi login --provider fungi to sign in through your browser. Review Authorize Fungi access, then choose Allow or Deny. The permissions cover your name and email, staying signed in on this device, using your Teams’ Fungi models and accessing their issue tracker repositories. Team membership and permissions still limit what the login can do.

Local uses one Fungi account login for hosted models and Team MCP connections. Choose the Team that pays for models when prompted. To connect to a Team’s Computers, copy its MCP address from Connect fungi CLI and run fungi login --fungi-mcp <address>. The model billing Team and the project’s Computer endpoint are separate choices. See Use the terminal.

Other model providers have their own logins. Choose one with fungi login or /login in the TUI. ChatGPT (your plan) is local only; it does not connect that subscription to hosted Agents. Fungi does not meter your own subscription or BYOK model runs.

Open Account → Connected logins on the Hub. Find the device using its label, Connected date and Last used time. Revoke this login ends that one login, including its ability to refresh. Other logins for the same App keep working. Local must sign in again before making new authorized requests; already-running requests and streams may finish.

Under App-wide access, Revoke all logins ends every login for the chosen App and removes its consent. Use this when you want to disconnect the App everywhere. Revocation prevents further refreshes. Local refuses new requests immediately, but an already-issued third-party JWT access token may remain valid until it expires, at most 15 minutes, even if the App had a refresh token. Third-party Apps using opaque access tokens lose access immediately.

The list shows logins with an active refresh token. A login without one is not listed, so it cannot be selected for individual revocation here. This visibility limit is separate from the third-party JWT expiry window.

These connections are separate from GitHub repository connections, Team App permissions and attached local folders. Revoking an OAuth login does not detach a folder whose running backend already holds a device key.

Run fungi logout --provider fungi, or fungi logout --fungi-mcp <address> for the saved Fungi origin. Local tries to detach its saved Computer attachments and revoke its login. It retries a failed login revocation once and always removes the local credential and device private keys, even if the Hub cannot be reached. Logging out of another model provider affects that provider’s login instead.

If revocation cannot be confirmed, Local says: “Signed out here. Couldn’t confirm with Fungi; you can revoke this login under Connected logins.” Use Account → Connected logins → Revoke this login to finish remotely.

If a Computer’s detach cannot be confirmed, Local names it and links its Hub Computers page. Detach it there, or press Ctrl-C in the terminal running fungi computer attach. That process can still serve Team commands using its in-memory device key until it is detached or stopped. Removing a saved key alone does not stop it. Ctrl-C stops serving but leaves the registered attachment offline; detach removes it.

Local saves only account, login and attachment identifiers for unfinished cleanup, never tokens or private keys. It retries after the next successful sign-in to the same account on the same Fungi service. Signing in to a different account or service discards that pending cleanup. There is no startup prompt. Use Connected logins and Computers for manual recovery if you do not sign in again. See Attach a local folder.

The first time you sign in, create a Team or select one you own as your personal Team. This choice is permanent. See Teams and invitations.