Profile & security
Your profile is where you manage your account details, interface language, the extra profile fields your organisation asks for, and your personal API tokens.
Profile details
Your profile shows your name, email and role. Keep your display name recognisable — it's what colleagues see in assignments, comments and mentions.
Interface language
Choose your interface language on the profile page. The choice is yours alone: it doesn't affect anyone else, and your administrator's default only applies until you pick one.
Your language also travels with your notifications — emails and messenger notifications are written in your language, not the language of whoever triggered them.
Appearance (theme)
The theme switcher sits in the top bar, offering dark, dark compact, light and high-contrast, or following your operating system. Dark compact tightens spacing to fit more on screen. Your choice is remembered on your device and affects nobody else.
Additional profile fields
If your administrator has defined additional profile fields — phone, messenger handle, job title and the like — you fill them in on your profile. Required fields are marked, and depending on how strictly your organisation has configured this you'll either see a reminder banner or be asked to complete them before continuing.
Your values are private to you: other users don't browse them. Where they are used is up to you — for example, marking a contact as usable for notification channels.
Notification preferences
Notification settings live on the Notifications page rather than in the profile: which events reach you, through which channel, due-date reminders, and linking Telegram. See Search & notifications.
Your password
Change your password using Forgot password on the sign-in screen — you'll get a reset link by email. Administrators can also set a password for you or send you a reset link from the user administration page.
If you can't sign in
An administrator can send you a reset link, set a new password, or end all your sessions if you think your account has been used by someone else. Ask them rather than working around it.
Personal API tokens
API tokens let external tools act on your behalf — connect an AI assistant over MCP, or call the API from a script. Manage them on your profile page.
Creating one asks for:
- A name — so you can tell later what a token is for.
- Permissions — read-only (MCP) or full access.
- An expiry — 30 days, 90 days, 1 year, or never.
Once created, the token is shown only once — copy it then and store it somewhere safe. The list afterwards shows each token's name, permissions, creation date, expiry, last use and status (active, revoked or expired), and lets you revoke one at any time. Revocation takes effect immediately.
A token inherits your permissions — it can do exactly what you can, and no more.
Treat tokens like passwords
Anyone holding a full-access token can act as you. Store tokens in a password manager or secret store, prefer read-only when a tool only needs to read, set an expiry rather than "never" when you can, and revoke tokens you've stopped using. For automation that shouldn't be tied to a person, ask an administrator to set up a dedicated bot account.
Using tokens with AI clients and the API is covered in Integrations → AI & API access.
Where to go next
- AI & API access — connect assistants and scripts.
- Search & notifications — manage what reaches you.