Sign-in
Sign-in links by email, Google, and who can create an account.
People sign in with a link sent to their email, or with Google. Each account gets its own organization, so people on the same Personal Agent Proxy never see each other's connections, agents or activity. Agents sign in apart from people, with the logins you make for them; nothing here changes theirs.
Who can create an account
Anyone who can open your Personal Agent Proxy can create an account, unless ALLOWED_SIGNUP_EMAILS
says who can. List addresses, and domains for everyone at a domain:
ALLOWED_SIGNUP_EMAILS="you@example.com,example.org"People who already have an account can always sign in, even once they are no longer on the list. Someone the list leaves out is not sent a link, and sees "This address cannot create an account here."
Sign-in links
Sign-in links work without any setup: until Personal Agent Proxy can send email, it writes each link to its log, and the sign-in page says so. That is enough when you are the only one signing in:
docker compose logs proxy | grep "Magic Link"To email the links, Personal Agent Proxy uses Resend:
Verify your domain
In Resend, add the domain the emails come from, and add the DNS records it shows you.
Create an API key
One with sending access is enough.
Set the variables
RESEND_KEY="re_…"
EMAIL_FROM="Personal Agent Proxy <login@example.com>"EMAIL_FROM has to be on the domain you verified.
A link works once, for 24 hours.
Create an OAuth client
In the Google Cloud console, create an OAuth client ID of the type Web application.
Add the redirect URI
Under Authorized redirect URIs, add your Personal Agent Proxy's address followed by
/auth/google/callback:
https://proxy.example.com/auth/google/callbackSet the variables
GOOGLE_CLIENT_ID="…apps.googleusercontent.com"
GOOGLE_CLIENT_SECRET="…"The sign-in page shows Continue with Google once both are set.
An address that first signed in with a link keeps signing in with links: Google sign-in for it says "This email already has an account."