Account management
The self-service account screen and what each tab does.
Open it with AuthUI.open("account"), from the <authui-user-button> menu, or embed it directly with <authui-account>.
Profile
- Name: update the display name.
- Account ID: muted mono badge under the profile fields. Click to copy the user
$idto the clipboard (screen readers hear "Copied"). - Email: change the address (requires the current password). When the address is unverified, Auth UI starts an in-panel email OTP (with an optional security phrase) and falls back to a verification link if the project does not return OTP mode. A badge shows whether the address is verified.
- Phone: change the number (requires the current password), send an SMS code and verify it.
- Delete account: calls
account.updateStatus(), which blocks the account and ends the session. Appwrite keeps the record so an administrator can restore it. Client-side deletion is not offered by Appwrite; use a server function if you need it.
Guest accounts see a Create your account form instead, which attaches an email and password to the existing user.
Security
- Change password, with the current password when the account has one. OAuth-only accounts can set a first password.
- Two-factor authentication switch, authenticator enrollment and removal.
- Recovery codes generation, display and regeneration.
Changing the password ends other sessions when the project's session-invalidation policy is on. Auth UI refreshes its state afterwards.
Sessions
Lists every active session with client, operating system, country and IP, and marks the current device. Each row has a sign-out action. Sign out everywhere ends all sessions, including the current one.
Connections
Lists connected OAuth identities with the provider's email or user ID, offers to disconnect each, and shows buttons for any configured provider that is not yet connected. Connecting goes through the same OAuth redirect as sign in.
Authorized apps
When Appwrite exposes OAuth2 consents (listConsents), the account screen shows an Authorized apps tab. Users can review client apps, the scopes they granted, and revoke access. When the server also exposes consent token families (listConsentTokens), each app row can list and revoke individual devices without revoking the whole consent. The tab hides itself on servers without the route.
Teams
Create teams, leave teams, and (as an owner) invite members by email. Invite links use Auth UI's redirect handler so recipients land back on your page and join automatically. The same surface is linked from Manage teams on <authui-user-button show-teams>.
Activity
The account security log from account.listLogs(), when the server exposes it. Appwrite Cloud 2.2.0 does not (the route returns 404), and some self-hosted builds omit it too. Auth UI probes once on load and only shows the Activity tab when the endpoint responds successfully.