Skip to content
ArchiveZaunEkko Docs
Reading
Text size
Fonts
简体中文English
Show contents

Account and security

Status
Current
Updated
2026-08-28
Scope
ZaunEkko Account

ZaunEkko Account is the only identity source across every site. Whatever "sign in" you see anywhere, it ends up at Account and comes back with the result.

No site creates its own password. If a page asks you for a password separate from your Account, that is not normal — do not enter it.

Signing up

Registration is two stages on one page:

  1. Enter your email and receive a message with a 6-digit code.
  2. Create the profile: the code, a username, a public nickname, and a password.

The link in the email fills in the email and code for you and jumps to stage two, but it does not submit — you still confirm before the account is created. Changing the email returns you to stage one; resending a code invalidates the previous one.

Username and nickname are different things

PurposeAllowed characters
UsernameGlobally unique identifier, used to sign inlowercase letters, digits, underscore, hyphen
NicknameThe name other people seeanything

The username field checks availability as you type and shows one of four states: available, taken, invalid, or checking. If that check is temporarily unavailable, it will not block submission — the decision that counts is made at submit time. The live check only tells you earlier.

Signing in

A normal sign-in needs only your username and password. Second-factor verification appears only when the server judges the attempt risky — an unfamiliar device, for instance. It defaults to TOTP; you can switch to an emailed code or a one-time recovery code.

"Remember password" is not "Stay signed in for 30 days"

These two checkboxes get read as one switch. They do entirely different things:

That long-lived credential can be revoked any time from the security page.

Forgotten password

/forgot-password resets your password through a verified email address. The page returns the same message whether or not the address exists — so it cannot be used to discover which addresses are registered.

Resetting the password revokes every existing session and trusted device. If you suspect someone else has access, resetting is the most direct response.

Security page

The security page manages:

Sensitive operations require re-authentication. After you complete the verification panel, you are asked to confirm the original action again — it is never silently replayed. That is deliberate: what gets submitted must be the thing you thought you were doing.

API keys

The API keys page manages keys for your account, used to call API Platform services as yourself. See Authentication and calls for how to use them.

Points

Balance, reservations and ledger all live in Account and work across every site. Calling a service on the API Marketplace spends points, and the record lands in the same Account ledger.

Points cannot be topped up or withdrawn. They circulate inside the platform: providers earn them, callers spend them.

The balance splits into available and held. Held points are reserved for in-flight calls that have not settled yet.

Levels

Two independent scales, easy to confuse:

Neither converts into the other. See ZaunEkko's Blog for how levels and capabilities work there.

Site access

The account page shows only the grants you actually hold. With none, it says "basic access, no admin capability" — that is not an error, it is an accurate description.

The page never claims you have admin capability on a site just because you are a registered user there.