Registration and Login
Every user who accesses BioT through a BioT portal, your own application, or directly through the APIs needs to have a user account with login credentials in order to access data. This page explains how accounts are created and how users sign in, so you can decide both before you configure templates or build a login screen.
How a user account is created
An account is created in one of three ways:
- Invitation: A user added through a BioT portal receives an email asking them to verify their account. See Verifying Your BioT Account.
- Self signup: Patients can register themselves through your own application, using the self signup APIs. See Patient Self Signup.
- Provisioning through the API: For automated flows such as testing, a service user can create caregivers, organization users and patients directly in an active state, without a verification email. See the create caregiver, create organization user and create patient API references.
How a user signs in
There are two decisions:
- How a user proves who they are: with a password, or with a one-time code sent to their phone.
- Whether that user must also complete multi-factor authentication (MFA).
Credential type
Password: Unless you choose otherwise, a user signs in with a username and password. The rules that passwords must satisfy, and the number of failed attempts allowed, are described in Password Policy. A user who has forgotten their password uses the flow in Reset Password.
One-time password (OTP): Instead of a password, a user can sign in with a one-time code sent to their phone by SMS. The credential type is chosen when the user is registered and cannot be changed afterwards. OTP login is available through the API only; the BioT portals sign users in with a password. Self signup supports password users only. See OTP Login.
Multi-factor authentication
MFA applies to users who sign in with a password. It cannot be enabled for OTP users.
After signing in, the user must also enter a one-time code sent by email or by SMS. See Multi-Factor Authentication.
Updated about 1 hour ago
