> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Sign-in and sessions

> Browser sessions and CLI sign-ins, how long they last, signing out one or everywhere, and the password lock.

## Kinds of sign-in

| Sign-in | Created by | Lasts |
| --- | --- | --- |
| Browser session | Signing in to the console at console.kiste.run with e-mail and password | 7 days |
| CLI sign-in | `kiste login`, approved in the browser | 30 days |
| API key | You, in the console or with `kiste auth token create` | the lifetime you choose, up to a year; see [API keys](https://docs.kiste.run/account/api-keys.md) |

`kiste login` opens the console at console.kiste.run, where you approve the
computer. The approval
page names the computer and the account, and the answer goes only to the CLI on
that computer. Approve only if you just ran `kiste login` yourself. After 30
days, run `kiste login` again.

The console shows your browser and CLI sign-ins under **Account**, each with
the computer or browser it belongs to and when it was last used.

## Sign out

- **The console:** **Sign out** ends this browser's session on the server, not
  only in the browser.
- **The CLI:** `kiste logout` revokes the CLI's sign-in and removes this
  computer's [device key](https://docs.kiste.run/ssh/devices.md) and SSH entry. `--local` only removes
  them on this computer, for when kiste.run can't be reached.
- **One sign-in:** end any single browser or CLI sign-in from the console's list.

Signing out never stops your Kisten. Desktops and terminals that are open stay
open; they belong to the account, not to a sign-in.

## Sign out everywhere

**Sign out everywhere** in the console ends every browser and CLI sign-in of
your account at once, including the one you use, and closes every open desktop
viewer and browser terminal. Use it when a computer was lost or you suspect
someone else signed in.

API keys stay valid; revoke them separately under [API
keys](https://docs.kiste.run/account/api-keys.md). Device keys of computers you no longer have are
removed with `kiste devices remove`.

## Too many wrong passwords

Repeated wrong passwords are slowed down per network address. When someone
tries many passwords for your account from anywhere (20 wrong attempts within
15 minutes), password sign-in is locked for browsers that have never signed in
to your account before: for 15 minutes, doubling with each repeat up to a day.
A browser you have signed in with before keeps working during a lock, so the
lock can't shut you out of your own account.

If you need to lift a lock, any valid CLI sign-in or API key of the account
can do it:

```bash
curl -sS -X POST https://kiste.run/v1/auth/unlock -H "Authorization: Bearer $KISTE_TOKEN"
```

A lock also raises an [alert](https://docs.kiste.run/account/webhooks-alerts.md).

## Related topics

- [Overview](https://docs.kiste.run/account.md)
- [API keys](https://docs.kiste.run/account/api-keys.md)
- [Webhooks and alerts](https://docs.kiste.run/account/webhooks-alerts.md)
- [Plans and billing](https://docs.kiste.run/account/billing.md)
- [Export your data](https://docs.kiste.run/account/data-export.md)
- [Delete your account](https://docs.kiste.run/account/delete-account.md)
- Previous: [Overview](https://docs.kiste.run/account.md)
- Next: [API keys](https://docs.kiste.run/account/api-keys.md)
