Account
What a niyase account is, plus how to manage your profile, belong to multiple spaces, issue API tokens, and close your account.
What is an account
A niyase account is an ID tied to a "user = individual." A single account can belong to multiple spaces (for work and personal use).
- Account: a user identifier keyed by email address
- Profile: personal information such as display name, icon, and contact details
- Membership: a record representing your role within each space (OWNER / ADMIN / MEMBER, etc.)
A "resident registration (account)" and a "company talent list (employee)" are separate concepts. Business data inside a space uses "employee" records that contain a copied transcription of your account information.
Behavior with local use (desktop / mobile)
On desktop and mobile, all features work even when you are not logged in.
- Not logged in: everything stays local, using the local profile (this device's default)
- Sign up: obtain the right to use the cloud. Local data is kept as-is
- Log in: link to your account. Cloud sync is turned ON by an explicit, per-space action
Even after you log out, the local profile remains as "this device's default." One device has one local profile.
Account settings
You can change the following from /account:
| Tab | Contents |
|---|---|
| Profile | Display name, first/last name, address, avatar |
| Security | Password, passkeys, multi-factor authentication (MFA), active sessions, login history, API tokens |
| Notifications | How you receive notifications (see Notifications for details) |
| Appearance | Customize the theme and accent color |
| Spaces | Billing info, list of spaces you belong to (delete, leave, change plan) |
| Danger Zone | Close your account |
API tokens (Personal Access Tokens)
You can issue your own API token (PAT) to call the niyase API from scripts or automation tools. A token has the same permissions you personally hold at the time of the request, and is sent with an Authorization: Bearer pat_xxx header.
Creating a token
- Account settings → Security → "API Tokens" → "New token"
- Give it a label that describes what it's for (e.g.
GitHub Actions deploy) - Choose an expiry (30 days / 90 days — default and recommended / 1 year)
- The raw token is shown only at this moment. Save it somewhere safe, such as a password manager
What a token can't do
- You can't issue a token with no expiry. It expires after at most one year (re-issuing takes just a few clicks whenever you need to)
- It can't be used for full-data operations — backups, data exports, or data migration. Those require an interactive login session
- It can't do more than you can. A token's permissions are always capped at your own current permissions; if your access is reduced or revoked, that takes effect on the token from the next request
Revoking a token
- Revoke one: Account settings → Security → "API Tokens" list → "Revoke" button
- Revoke all at once: Running "Log out of all devices" in the Security tab also revokes every API token you've issued
A space's member list shows how many active API tokens each member holds and when they were last used (token names and contents are never shown).
Closing your account
When you close your account, it is disabled immediately and physically deleted after 30 days. If you are the OWNER of a space, you must transfer ownership from that space's settings or delete the space before closing your account.
Terminology: sign up / log in / log out
niyase standardizes its authentication terms as follows ("sign in" and "sign out" are not used):
- Sign up = create an account
- Log in = authenticate an account
- Log out = end an authentication session