# Accounts and identity

> Who you sign in as, which account your API keys act for, and what belongs to that account.

You sign in to the Refabric app as a person. Your API keys act for your account: every job, file,
record and credit they touch is that account's. Your keys act for the account you sign in to.

Your login and your API keys are not the same thing. Signing in opens the app and its
Developers screens (**Panel › Developers › Overview**); a key calls the public API from your server; sign-in is for the app
([Authentication](https://docs.refabric.com/api-reference/platform/authentication#where-keys-work)).

## How it works

- You sign in to the Refabric app. Keys are created there, in **Panel › Developers › Keys**.
- A key is owned by the user who created it and acts as that user: it spends that user's credits,
  and the files it uploads or produces are that user's ([Authentication](https://docs.refabric.com/api-reference/platform/authentication#who-a-key-acts-as)).
- A key's scopes define what it may do, within its user's permissions.

## Sign in

The app's sign-in page offers e-mail and password, Google, and single sign-on (SSO) for
organisations that have it set up for their e-mail domain.

## Account types

What your account may do is set by its plan:

- API access depends on your plan; without it a key is answered `403 api_access_not_included`
  ([Authentication](https://docs.refabric.com/api-reference/platform/authentication#failures)).
- A task your plan does not allow answers `403 permission_denied`.
- Trial accounts receive watermarked images ([Files](https://docs.refabric.com/task-apis/files-and-media#download-urls)).

## Everything belongs to the account

| What | Belongs to |
|---|---|
| Jobs started with your keys | your account; `GET /v1/jobs` lists them |
| Files you upload and files your jobs produce | your account; you see them in the app too |
| Records (moodboards, fabrics, brand kits, range plans) | your account |
| Credits | your account's balance ([Pricing](https://docs.refabric.com/task-apis/pricing#credits)) |
| API keys | the user who created them |
| Webhook endpoints and the request log | your account (**Panel › Developers › Webhooks**, **Panel › Developers › Request log**) |

:::note
Jobs you start in the Refabric app are yours too, but they are not sent to your registered webhook
endpoints and not written to the request log ([Webhooks](https://docs.refabric.com/task-apis/calling-tasks/webhooks#asking-for-a-callback)).
:::

## Related

::::cards
:::card{title="Teams" href="/setting-up/teams"}
How a team relates to your keys and credits.
:::
:::card{title="Get your API key" href="/setting-up/get-your-api-key"}
Create, test, roll and revoke keys.
:::
:::card{title="Authentication" href="/api-reference/platform/authentication"}
How a key is sent and what each failure means.
:::
::::
