Signing in
You can sign in to Qorin with an email address and a password, or with Google, Microsoft, GitHub or Apple. They all lead to the same place.
One person, one account
Qorin identifies you by your email address. If you registered with a password and later press "Continue with Google" on that same address, you land in your existing account — same organisations, same hosts, same workspaces. There is no separate "Google account" or "GitHub account" to keep in sync.
Signing in with a provider is free on every plan. (The SSO / SAML line on the Billing page is a different thing: it is about an organisation centrally managing how its members sign in.)
If a provider is missing from the sign-in page, it is not configured on that deployment. Use another one, or your password.
Signing in is not the same as having a seat
Signing in proves who you are. It does not put you in an organisation and it does not give you a plan.
To actually run workspaces you need a seat, and a seat comes from exactly two places, the same as always:
- someone invites you to their organisation, or
- you create your own organisation and pick a plan.
Nobody can add you to their organisation because you happen to share an email domain with them, and no sign-in button changes what you are allowed to do.
When Qorin will not connect a provider to your account
Your email address is what ties everything together, so we only let a provider attach to an existing account when that provider has verified the address itself:
| Provider | Address we accept |
|---|---|
| Any address Google has confirmed. | |
| Microsoft | Only when your tenant has proved it owns the domain (see below). |
| GitHub | Your primary, verified GitHub address — not the one shown on your public profile. |
| Apple | Any address Apple returns, including a private-relay one. |
If the check fails, you will see a message rather than a blank page, and the way in is your password: sign in with your email and password, or reset it from the sign-in page. Receiving that reset mail proves the mailbox is yours, which is exactly the proof the provider did not give us.
Microsoft: "we could not confirm that address"
Entra ID only tells us an address is genuine when the app registration includes the optional xms_edov claim ("email domain owner verified"). Without it, the address in the token is just a directory field that any administrator could have typed, and we will not merge accounts on it. If your company hits this, ask whoever manages your Microsoft tenant about that claim.
Apple: what "Hide My Email" does to you
If you choose Hide My Email, Apple gives us an address like something@privaterelay.appleid.com. It is a real, working mailbox that forwards to you — but it is not the address your colleagues know you by.
That matters, because your account is keyed to the address you signed in with. Create your account through a private relay address and the invitation your team later sends to your work address will create a second, separate account. If you plan to work with a team, use your work address (choose "Share My Email") when you first sign in.
Signing in with an invite
While Qorin is invitation only, creating a new account needs an invite code, whichever button you use.
The code is checked before you leave for the provider, so a typo is caught straight away, and it is only used up at the moment your account is actually created. If you change your mind on Google's consent screen and close the tab, your code is untouched and still works.
An invite is a gate at the entrance, not a toll. Once your account exists you never need a code again — not after it has been used, not if it is later revoked.