> ## Documentation Index
> Fetch the complete documentation index at: https://darwin.so/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Personal

> Create and verify a personal account, then approve apps only when you need to Act.

Public Search does not require an account or API key. Creating an account does not create an agent, application, or API key. The public Act API accepts account-level consent with `human:actions`, but a target route must also be executable. This account-level path has not yet passed a live cookbook provider-response replay.

<Steps>
  <Step title="Register and verify">
    You do not need to open the Darwin web app or create a key first.

    ```bash theme={null}
    curl -X POST https://api.darwin.so/api/v2/accounts \
      -H "Content-Type: application/json" \
      --data '{
        "email":"you@example.com",
        "password":"replace-with-a-strong-password",
        "name":"Your name",
        "type":"personal"
      }'
    ```

    Darwin returns an unverified account and a `nextStep`; it does not silently create an agent, application, or credential.

    Request the verification email, then open its one-time link. Email ownership is the one out-of-band step; everything after it can stay in HTTP.

    ```bash theme={null}
    curl https://api.darwin.so/api/customer/auth/sign-in/magic-link \
      -H "Content-Type: application/json" \
      --data '{"email":"you@example.com"}'
    ```

    **Success:** the one-time email link marks the account as verified. The registration response's `nextStep` remains the authoritative instruction.
  </Step>

  <Step title="Start a session and finish the profile">
    Sign in with the password from registration and keep the returned secure session cookie in a temporary cookie jar.

    ```bash theme={null}
    curl -c darwin-session.txt https://api.darwin.so/api/customer/auth/sign-in/email \
      -H "Content-Type: application/json" \
      --data '{
        "email":"you@example.com",
        "password":"replace-with-a-strong-password",
        "rememberMe":false
      }'

    curl -b darwin-session.txt -X PUT https://api.darwin.so/api/customer/me/account-profile \
      -H "Content-Type: application/json" \
      --data '{
        "name":"Your name",
        "type":"personal"
      }'
    ```

    For a `business` or `software` account, include `organizationName` and `organizationDomain` in the profile request. A phone number is optional until an operation explicitly requires it.

    **Success:** the profile request returns `200`. If you are building an app, continue with [Developer](/docs/admin/account-developer).
  </Step>
</Steps>

## Approve an app when you need Act

When a product you use needs to Act, sign up or sign in through Darwin and review its requested OAuth access. You return to the product after consent. The product does not get your password, session cookie, or an API key. You can revoke the connection. An approved `human:actions` grant authorizes your account, not every target or effect; Darwin still checks route readiness and any separate provider, action, or payment request.

The developer cannot silently create a verified account and act as you. Account creation alone does not grant consent. Provider connections, action approvals, and payments may still require their own explicit steps.

## Choose the narrowest path

<CardGroup cols={2}>
  <Card title="Browse Search" icon="search" href="/docs/browse/search">
    Keep calling Search anonymously. No account or credential is required at the public limit.
  </Card>

  <Card title="AI client or coding agent" icon="plug" href="/docs/get-started/mcp">
    Use MCP and complete scoped sign-in and consent only when a protected operation needs it.
  </Card>

  <Card title="Browse with an agent" icon="play" href="/docs/browse/quickstart">
    Use your account-level OAuth grant for a verified, executable route. Do not treat a Search result as completed work.
  </Card>

  <Card title="Building a product" icon="key" href="/docs/admin/account-developer">
    Register an application and optionally create a server-side Search key. Search keys cannot authorize Act.
  </Card>
</CardGroup>

Application-only keys identify an application and can Search. They cannot impersonate a person or agent, and they cannot Act. See [Developer](/docs/admin/account-developer) for the complete credential and endpoint map.

## Saved payment methods belong to the authorized caller

Saved payment method references for a person remain under that person's private
Darwin account identity. Previously saved methods for a separately published agent
remain isolated; they are not silently copied into the person's account. Enrollment happens
only inside Darwin's signed-in first-party UI after an immutable payment request
asks for an accepted method and the user explicitly consents to save it. It is not
an Act or MCP operation and is intentionally absent from the developer SDK. Never
send card data, provider credentials or checkout secrets through the API, MCP or a
thread message.

After provider verification, Account APIs can list the safe Darwin reference,
choose a default within its provider and merchant context, or revoke it for future
selection. None of those operations authorizes spending. See [Pay](/docs/browse/pay)
for the setup states and current release gate.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.