Sign in safely
Mibyan supports email and password, Google, and a phone number with a one-time code. Email sign-ups must confirm the address before signing in, and repeated failed attempts are slowed down for a minute.- If you sign in with a phone number, your number is your verified identifier. Add an email in Settings so you can receive notifications and sign in from other devices.
- On a shared or lost device, sign out. Then review your connected services and the devices linked to WhatsApp.
- To sign in to Mibyan Desktop, use the same account. The desktop app never stores your account session inside your project folders, and it has no guest mode.
What protects your work
Account habits
- Use a unique password for the account connected to Mibyan.
- Review active sessions and connected integrations regularly.
- Sign out or revoke access after using a shared device.
- Keep your recovery email and phone information current.
Protect workspace data
Only upload files you are allowed to process. Before sharing an output, check that it does not contain private customer data, credentials, internal-only assumptions, or unverified claims.Connected services
When you connect a service, review what access it grants and remove the connection when it is no longer needed. For WhatsApp QR linking, use a number you control and review Linked Devices in WhatsApp after connecting.API key safety
API keys belong to the developer platform, not to browser-visible product settings. Store them in a server-side secret manager, rotate exposed keys immediately, and never include them in support screenshots or source code.Desktop and personal agent safety
- Choose your approval mode deliberately. Manual asks before every sensitive action, and Smart asks only when needed. Avoid YOLO mode except in a folder where a mistake is cheap.
- A
sudopassword or a secret goes only to your local agent. - A remote gateway runs commands and reads files on that machine. Connect only to hosts you trust. See Connections and profiles.
- Gateway tokens are kept in your operating system’s secure storage when it exists.
If something goes wrong
- A key or token was exposed. Revoke it and create a new one. For project keys, see API keys.
- You lost a device. Sign out of Mibyan, remove the device from WhatsApp Linked Devices, and review your connected services.
- You found a security problem. Report it to security@mibyanai.com. Please include steps to reproduce, and do not access data that is not yours.

