Sign in and licence
Sign in to your Gatesys account in the browser, activate Gatesys Pro with your plan or a licence key, move Pro to another computer, and use offline grace.
An account is optional. It carries Gatesys Pro to every device you use; a licence key activates Pro without one; and the Free plan needs neither. You sign in on Gatesys’s own page in your browser, so the app never sees your password.
Where to find it
- First-run setup: the Account and Licence steps. See First-run setup.
- Settings › Account: the account button at the foot of the Settings list. It holds the Gatesys account card, the GateSys Pro card, What GateSys sends to Gatesys, and Run setup again.
Sign in
- Open Settings › Account and click Sign in with Gatesys. The line under the button names the page it opens, for example Opens gatesys.ai in your browser, then brings you back here.
- The card says Opening your browser… while it checks that Gatesys can be reached, then opens the sign-in page on gatesys.ai in your default browser.
- Sign in there with your email and password. Forgot password? on that page resets it. The app never shows a password field.
- When you finish, the browser comes back to the app. The card says Signing you in…, then Welcome with your first name, your email and your plan, and the app comes to the front on its own. Click Done (in the setup, Continue).
The browser tab says You’re signed in, with your name and plan. Close it, or click Return to GateSys to bring the app to the front.
While the app waits
The card says Waiting for your browser… and counts down the link’s time, for example 9:41 left on this link. A link works for 10 minutes. After that the wait ends and the card says The sign-in link expired; nothing has changed, and you can start again.
| Button | What it does |
|---|---|
| Copy sign-in link | Puts the link on the clipboard, for when the browser did not open or you want another browser on this computer. It reads Copied for a moment |
| Open again | Opens the same link in the browser once more |
| Cancel | Stops waiting and closes the app’s listener. Nothing changes, and the card shows its buttons again |
While the card still says Opening your browser…, only Cancel is offered. If the browser cannot be opened at all, the card says Open the sign-in link instead: click Copy sign-in link and open it in a browser on this computer.
The link works only on this computer
The browser returns the sign-in to a listener the app starts on 127.0.0.1, so open the link in a browser on the same computer. The listener takes one answer, and only one that carries the check the app put in the link; then it closes. What comes back is a one-time code, never your password. The app trades it for a sign-in kept in its vault.
Return to GateSys uses the gatesys-ssh:// link, which only ever brings the app to the front. It never carries a sign-in: a gatesys-ssh:// link that tries to is ignored.
Create an account
- Click Create account. Gatesys’s sign-up page opens in your browser, and the card says Create your account on gatesys.ai.
- Enter your name, email and a password there, and confirm your email address.
- Back in the app, the card says Your account is ready. In the setup’s Account step, the heading says Account created.
Your 3-month Pro trial starts when your email is confirmed. See Plans.
Switch account
Once signed in, click Switch account on the Gatesys account card. The sign-in page opens with its login form, even when the browser is already signed in to Gatesys, so you can choose another account. Right after a sign-in, Use another account does the same. The account you sign in with replaces the one before on this computer.
Staying signed in
The sign-in lasts until you sign out. When the app needs your account, for example to activate Pro with your account’s plan, and the sign-in is about to run out, it renews it with Gatesys. Each renewal replaces the one before, so an older copy stops working.
If Gatesys no longer accepts the sign-in, the app forgets it on this computer and says Your sign-in has ended — sign in again. The licence on this device is not affected.
Activate Gatesys Pro
Pro is activated per device, on the GateSys Pro card in Settings › Account or in the setup’s Licence step.
- With your account’s plan. Signed in to an account with a Pro or Team plan, click Use my account’s plan in Settings, or Activate with my Pro plan in the setup. There is no key to type.
- With a licence key. Type the key, such as
GSYS-XXXX-XXXX-XXXX, into the Licence key field and click Activate. No account is needed. The app upper-cases what you type and keeps only the key’s last four characters.
Once active, the pill reads Pro active and the card lists:
| Field | What it shows |
|---|---|
| Plan | Pro or Team |
| Licence | The licence id, and from your account or the key’s last four characters |
| Seats | How many of the licence’s seats are in use: one on a Pro plan |
| Last check | When the licence was last checked with Gatesys |
| Works offline until | The last day Pro works without a check |
| This device | A random id made for this installation and kept in the vault, never derived from the hardware |
Under the list, a chip for each Pro feature shows what the licence unlocks.
Seats
A Pro plan has one seat: Pro is active on one computer at a time. Activating an installation takes the seat, and activating the same installation again reuses it rather than taking another. A Team plan has the seats your organisation bought, one per installation.
When the seat is taken, activating Pro on a second computer says Pro is active on another computer. To move Pro, free the seat first:
- On the device itself: Settings › Account › Deactivate this device. The seat is free at once and the device drops to Free.
- From anywhere: sign in on gatesys.ai/account/devices and remove the device. Pro ends there at its next daily check.
Deactivating while offline
If Gatesys cannot be reached, Deactivate this device keeps the licence, because removing it from this device alone would leave the seat taken. The card then offers Remove from this device only. That removes the licence here anyway; the seat stays in use until you remove the device on gatesys.ai.
The daily check and offline grace
The app checks its licence on this computer and asks Gatesys once a day.
- Each check brings a freshly signed certificate. A check that fails is tried again after an hour. Check now checks straight away.
- Offline grace. Pro keeps working for 14 days after the last certificate, with no network access to Gatesys. The pill then reads Offline grace with the time left, and the card says the check will run again on its own.
- After 14 days with no successful check, the licence shows Expired and the app works as Free. Nothing is removed. The app keeps trying, and Pro comes back as soon as a check goes through.
- The grace cannot be stretched. It counts from the date Gatesys signed into the certificate, so editing
license.jsondoes not extend it. - An ended licence ends Pro at once. If a check says the licence was revoked or has expired, or that this device was removed, the licence shows Ended or Expired. Activate again to bring Pro back.
Every Free feature, including every SSH connection, works with no network access to Gatesys at all.
Sign out
On the Gatesys account card, or in the setup’s Account step, click Sign out. The app asks Gatesys to revoke the sign-in, so it stops working there too, and forgets it on this computer whatever the reply, even when Gatesys cannot be reached.
The licence stays. It belongs to the device, not to the sign-in, so Pro keeps working after you sign out. To free the seat as well, click Deactivate this device.
Another account server
The account server is account.apiBase in settings.json, https://api.gatesys.ai by default. The sign-in page is on the same server’s web address without api., so the default signs you in at gatesys.ai. account.authorizeUrl names a different sign-in page outright.
When the file names any other server or sign-in page, the account card says Approve the account server first and names where your browser would sign in. Nothing is sent, and no browser opens, until you click Use with that server’s name. Approve it only if you set it yourself. The approval is kept as a hash in the vault, so a program that edits settings.json cannot approve itself.
What the app sends to Gatesys
Settings › Account › What GateSys sends to Gatesys lists every call:
| When | What is sent |
|---|---|
| Signing in | Happens on the web, in your browser: the app never sees your password. It gets back a one-time code, which it trades for a sign-in kept in the vault, and your name, email and plan |
| Activating | The licence key, or your account’s sign-in, with the device id, this computer’s name, the OS and the app version |
| Once a day | The licence id, the device id, the app version and the current certificate, only while a licence is active |
| Never | Your hosts, keys, passwords, sessions, files, commands, audit log or Farabi conversations |
Renewing the sign-in, and signing out, send only the sign-in itself.
What the app keeps
| Where | What |
|---|---|
~/.gatesys-ssh/account.json | Your account’s name, email and plan. Never the sign-in itself |
~/.gatesys-ssh/license.json | The licence id, this device’s id, the last certificate and the last check |
| The local vault | The sign-in, bound to the server that issued it, and this device’s id |
Both files are readable only by you (mode 0600). No password is kept, because the app never has it.
Something unclear or wrong? Tell us.