19.1 Overview
The Settings section allows Customers to maintain their personal account information, protect their login, complete identity verification, select interface preferences, and manage API keys for approved integrations.
Customer settings may include:
- Profile information
- Email verification
- Password management
- Two-factor authentication
- KYC verification
- Appearance preferences
- Language selection
- API keys
- Account deletion
These settings affect account security, feature access, communication privileges, and the ability to connect external applications.
Customers should review their settings when first creating an account and whenever their business information, email address, telephone number, authorized personnel, or security requirements change.
19.2 Opening Account Settings
To open Settings:
- Sign in to AIUNIFY Call Center.
- Open the account menu or main navigation menu.
- Select Settings.
The main Settings address redirects to the Profile page:
The Settings menu may include:
- Profile
- Password
- Two-Factor Auth
- KYC Verification
- Appearance
- API Keys
The options displayed depend on the signed-in user’s role.
19.3 Customer and Agent Settings Access
Customers can manage their own:
- Profile
- Password
- Two-factor authentication
- KYC verification
- Appearance
- API keys
- Account deletion
Agents can normally manage:
- Their own profile
- Their own password
- Their own two-factor authentication
- Their own appearance
Agents cannot create Customer API keys through the standard interface.
Agents also do not manage the Customer account’s business KYC, billing identity, or account deletion.
Part One
Profile Information
19.4 Opening Profile Settings
To open the Profile page:
- Open Settings.
- Select Profile.
The page is located at:
The current Profile form allows the Customer to update:
- Full name
- Email address
Other Customer information, such as KYC business details, is managed separately through KYC Verification.
19.5 Updating the Customer Name
To update the account name:
- Open Profile Settings.
- Locate the Name field.
- Enter the correct full name.
- Click Save Changes.
The name is required and may contain up to 255 characters.
The updated name may appear in:
- The account menu
- User-management records
- Reports
- Administrative records
- Customer communications
- Agent ownership information
Use the real name of the authorized account holder or business representative.
19.6 Updating the Email Address
To change the email address:
- Open Profile Settings.
- Replace the current email address.
- Confirm that the address is spelled correctly.
- Click Save Changes.
The email must:
- Be a valid email address
- Be unique within AIUNIFY Call Center
- Contain no more than 255 characters
- Not already belong to another account
The system stores email addresses in lowercase.
19.7 Email Reverification After a Change
Changing the account email address removes the previous email-verification status.
The new email address must be verified before all account functions can be considered fully available.
After changing the address:
- Open the new email inbox.
- Locate the AIUNIFY Call Center verification message.
- Open the verification link.
- Return to the platform.
- Confirm that the account no longer shows an unverified-email notice.
Do not continue relying on the old email address after the change.
19.8 Resending the Verification Email
When the email remains unverified, the Profile page provides an option to resend the verification message.
To resend it:
- Open Profile Settings.
- Locate the unverified-email notice.
- Click the resend-verification link.
- Check the inbox.
- Check the spam or junk folder.
- Open the most recent verification email.
- Follow the verification link.
Older verification links may expire or become invalid after a newer link is issued.
19.9 Verification Email Does Not Arrive
Confirm:
- The email address is correct
- The inbox has available storage
- The message is not in spam
- The email domain is accepting messages
- The account has not blocked AIUNIFY messages
- The platform’s mail system is operational
Do not repeatedly change the email address while troubleshooting.
Contact support when the resend function reports success but no message arrives.
19.10 Email Already in Use
If the platform reports that the email is already in use:
- Confirm that another account was not previously created
- Try signing in with that email
- Use Forgot Password when necessary
- Contact the account owner
- Use another authorized email address
The same email address cannot be assigned to two users.
Part Two
Password Management
19.11 Opening Password Settings
To change the password:
- Open Settings.
- Select Password.
The page is located at:
The form requires:
- Current password
- New password
- Confirm new password
19.12 Changing the Password
To update the password:
- Enter the current password.
- Enter the new password.
- Enter the same new password again.
- Click Save Password or Update Password.
The new password must satisfy the requirements displayed by the platform.
The confirmation must exactly match the new password.
19.13 Current Password Requirement
The current password verifies that the person making the change already controls the account.
If the current password is incorrect, the update will not be completed.
Do not use the Agent password, email password, Twilio Auth Token, or API key in this field.
19.14 Creating a Strong Password
A strong password should:
- Be unique to AIUNIFY Call Center
- Be difficult to guess
- Avoid business names
- Avoid telephone numbers
- Avoid birthdays
- Avoid repeated characters
- Avoid common passwords
- Not be reused across staff accounts
A password manager is recommended for storing complex passwords securely.
19.15 Password Update Rate Limit
The password-update route is rate-limited.
The current application permits up to approximately six update attempts within one minute.
Repeated failed attempts may temporarily prevent additional submissions.
When this happens:
- Stop submitting the form.
- Confirm the current password.
- Wait briefly.
- Try again once.
19.16 Forgot Password
When the current password is unknown:
- Sign out or open the login page.
- Select Forgot Password.
- Enter the account email address.
- Submit the request.
- Open the password-reset email.
- Follow the reset link.
- Create a new password.
- Sign in again.
Use the email address currently assigned to the AIUNIFY account.
19.17 Password Reset Email Does Not Arrive
Confirm:
- The correct account email was entered
- The address is spelled correctly
- The message is not in spam
- The inbox is operational
- The account still exists
- Platform email delivery is configured
For security reasons, the platform may not confirm whether a submitted email belongs to an account.
19.18 After Changing a Password
After a password change:
- Update the stored password in the approved password manager
- Sign out of shared devices
- Inform no one of the new password
- Confirm two-factor authentication remains active
- Review unexpected account activity
- Replace the password immediately if it was exposed
Each Customer and Agent should use a separate account and password.
Part Three
Two-Factor Authentication
19.19 What Is Two-Factor Authentication?
Two-factor authentication, also called 2FA, adds a second login requirement.
A person must provide:
- The account password
- A temporary code from an authenticator application or a recovery code
This helps protect the account when the password is stolen or guessed.
19.20 Opening Two-Factor Authentication
To manage 2FA:
- Open Settings.
- Select Two-Factor Auth.
The page is located at:
The page displays whether two-factor authentication is enabled.
19.21 Supported Authenticator Applications
The interface is designed for time-based authenticator applications, such as:
- Google Authenticator
- Authy
- Microsoft Authenticator
- Another compatible authenticator application
The application generates a temporary six-digit code that normally changes every 30 seconds.
19.22 Enabling Two-Factor Authentication
To enable 2FA:
- Open Two-Factor Auth.
- Click Enable Two-Factor Authentication.
- Wait for the QR code to appear.
- Open the authenticator application.
- Choose the option to add an account.
- Scan the QR code.
- Enter the six-digit code displayed by the application.
- Submit the confirmation.
- Confirm that the page reports 2FA as enabled.
Do not close the setup before confirming the code.
19.23 Manually Entering the Secret Key
When the QR code cannot be scanned, a compatible authenticator may allow manual secret-key entry.
Enter the secret exactly as displayed.
Protect the secret key as carefully as a password.
Anyone who obtains it may be able to generate valid login codes.
19.24 Confirming the Six-Digit Code
The code entered during setup confirms that:
- The authenticator was added correctly
- The phone time is synchronized
- The secret key was interpreted correctly
- Future login codes can be generated
When a code is rejected:
- Wait for a new code.
- Enter it promptly.
- Confirm the phone date and time are automatic.
- Confirm the correct authenticator account was selected.
19.25 Recovery Codes
After 2FA is enabled, the platform provides recovery codes.
Recovery codes can be used when:
- The phone is lost
- The authenticator application is unavailable
- The device is replaced
- The authenticator account is accidentally removed
Save the recovery codes immediately.
19.26 Protecting Recovery Codes
Store recovery codes:
- In a secure password manager
- In an encrypted file
- In a protected physical location
- Somewhere separate from the authentication phone
Do not store them:
- In a public note
- In a shared spreadsheet
- In an unsecured email
- In the same phone case as the device
- In screenshots accessible to others
Each recovery code should normally be treated as single-use.
19.27 Viewing Recovery Codes
The 2FA page may allow recovery codes to be shown or hidden.
Before displaying them:
- Confirm no one else can see the screen
- Avoid screen sharing
- Do not record the screen
- Close the page after storing them
19.28 Regenerating Recovery Codes
When the codes are exposed, lost, or mostly used:
- Open Two-Factor Auth.
- Select Regenerate Recovery Codes.
- Save the new codes.
- Delete the older stored copy.
Regenerating codes invalidates the previous set.
19.29 Signing In with 2FA
After entering the email and password, the platform displays a two-factor challenge.
To complete it:
- Open the authenticator application.
- Locate the AIUNIFY Call Center entry.
- Enter the current six-digit code.
- Submit the challenge.
Enter the code before it changes.
19.30 Signing In with a Recovery Code
When the authenticator is unavailable:
- Open the two-factor challenge.
- Select the recovery-code option when available.
- Enter one unused recovery code.
- Sign in.
- Review the 2FA settings.
- Regenerate codes when necessary.
- Configure the replacement authenticator device.
19.31 Disabling Two-Factor Authentication
To disable 2FA:
- Open Two-Factor Auth.
- Click Disable Two-Factor Authentication.
- Review the warning.
- Confirm the action.
Disabling 2FA reduces account security.
It should normally be done only while replacing an authenticator or resolving an access issue.
19.32 Replacing the Authentication Phone
Before replacing the phone:
- Confirm recovery codes are available.
- Sign in to AIUNIFY Call Center.
- Disable 2FA.
- Enable it again using the new phone.
- Scan the new QR code.
- Confirm the new six-digit code.
- Save the newly generated recovery codes.
Do not erase the old phone until the new setup has been tested.
19.33 Two-Factor Security Practices
Customers should require 2FA for account owners and trusted managers who can access:
- Billing
- Contacts
- Campaigns
- Recordings
- AI Agents
- API keys
- Agent accounts
- Business verification information
Never share:
- QR codes
- Secret keys
- Authenticator codes
- Recovery codes
Part Four
KYC Verification
19.34 What Is KYC Verification?
KYC means Know Your Customer.
AIUNIFY Call Center uses KYC to verify the identity and business information of Customers who use telephone, messaging, AI, and advanced communication services.
KYC helps the platform:
- Reduce fraud
- Verify account ownership
- Protect telephone resources
- Support provider requirements
- Apply account limits
- Control access to advanced features
- Review business legitimacy
- Protect Customers and recipients
19.35 Opening KYC Verification
To open KYC:
- Open Settings.
- Select KYC Verification.
The page is located at:
The KYC page may display:
- Verification tier
- Current status
- Verified phone number
- Business name
- Submission date
- Approval date
- Expiration date
- Document statuses
- Rejection reason
- Renewal requirement
19.36 KYC Tiers
The current system contains three Customer verification levels.
Unverified
The Customer has not completed Basic verification.
Basic — Tier 1
The Customer has verified a telephone number.
Business — Tier 2
The Customer has provided business information and supporting documents and received approval.
19.37 KYC Statuses
A verification record may have one of the following statuses.
Pending
The submission is waiting for review or confirmation.
Approved
The verification has been accepted.
Rejected
The submission was not approved.
Expired
The previous verification is no longer current and may require renewal.
19.38 Current Feature Access by Tier
The current source defines Customer feature access approximately as follows.
Unverified Customer
No verified telephony access.
Basic Customer
May receive access to:
- Phone numbers
- Campaigns
- Calls
- SMS
- Contacts
Business Customer
May receive access to everything in Basic, plus:
- AI Agents
- Knowledge Bases
- Advanced features
Role permissions and account configuration can still limit access.
19.39 Current Basic-Tier Limits
The current source defines Basic Customer limits of approximately:
- Maximum three phone numbers
- Maximum 100 calls per day
- Maximum deposit of $500
These are current application defaults and may be changed by future system updates or platform policy.
Business-tier limit fields are currently configured as unrestricted.
19.40 Beginning Basic Verification
To begin Basic verification:
- Open KYC Verification.
- Select Start Basic Verification.
- Enter a reachable telephone number.
- Include the country code.
- Submit the form.
- Wait for the verification SMS.
The Basic form is located at:
19.41 Entering the Phone Number
Use a telephone number that:
- Belongs to the authorized Customer
- Can receive SMS messages
- Includes the correct country code
- Will remain available to the business
- Is not a temporary public messaging number
Example international format:
The actual number should be entered without missing digits.
19.42 Receiving the Verification Code
After the number is submitted, the platform generates and sends a six-digit numerical verification code.
The code:
- Contains exactly six digits
- Is sent by SMS
- Expires after approximately 10 minutes
- Must be entered before expiration
Do not share the code with anyone claiming to be support staff.
19.43 Verifying the Phone Number
To verify:
- Open the SMS message.
- Copy the six-digit code.
- Enter it on the verification page.
- Click Verify Phone.
- Wait for the confirmation.
The verification page is located at:
/settings/kyc/verify-phone
A successful code confirms the Basic KYC phone requirement.
19.44 Invalid Verification Code
A code may be rejected when:
- It is not six digits
- It contains letters
- It was entered incorrectly
- It expired
- A newer code was requested
- The maximum number of attempts was reached
- The account is verifying another number
Enter the most recently issued code.
19.45 Resending the Phone Code
To request a new code:
- Confirm the phone number was already submitted.
- Open the verification page.
- Select Resend Code.
- Wait for the new SMS.
- Enter the new code.
The resend process:
- Generates a new code
- Gives it a new 10-minute expiration
- Resets the verification-attempt count
The old code should no longer be used.
19.46 Verification SMS Does Not Arrive
Confirm:
- The number includes the country code
- The number can receive SMS
- The device has signal
- The message is not filtered
- The number is not a landline
- Twilio messaging is functioning
- The destination country is supported
Use Resend Code once after checking the number.
Repeated resends may produce several messages, but only the newest code should be used.
19.47 Beginning Business Verification
Business verification requires completed Basic phone verification.
To begin:
- Open KYC Verification.
- Confirm Basic verification is complete.
- Select Upgrade to Business Verification.
- Complete the business-information form.
- Upload the required documents.
- Submit for review.
The Business form is located at:
19.48 Business Information Required
The Business form may request:
- Business name
- Business registration number
- Business type
- Address line 1
- Address line 2
- City
- State or province
- Postal code
- Country
Enter information exactly as it appears in official business documents.
19.49 Business Name
Enter the registered legal business name.
Do not enter:
- A temporary campaign name
- An unrelated brand
- An employee name
- An abbreviation not shown in registration documents
When the business operates under a trade name, use the legal information requested by the form.
19.50 Registration Number
Enter the official registration, incorporation, or licensing number associated with the business.
The number should match the uploaded business document.
Formatting varies by country and business type.
19.51 Business Type
Select or enter the structure that accurately describes the organization, such as:
- Sole proprietorship
- Limited liability company
- Corporation
- Partnership
- Nonprofit
- Other supported structure
Use the structure shown in the official registration records.
19.52 Business Address
The business address should match official records whenever possible.
Include:
- Street address
- Suite or unit
- City
- State or province
- Postal code
- Country
Do not use an address the business is not authorized to represent.
19.53 Required Business Documents
The Business verification workflow requires three document categories:
- Identification document
- Business document
- Selfie with identification
The form enforces the applicable file and validation requirements.
19.54 Identification Document
The identification document verifies the authorized representative.
The form may request an ID type, such as:
- Passport
- Driver’s license
- National identification card
- Another supported government-issued document
The document should:
- Be current
- Be readable
- Show the full required information
- Not be cropped improperly
- Match the account representative
19.55 Business Document
The business document should verify the existence and registration of the organization.
Examples may include:
- Articles of incorporation
- Business-registration certificate
- Operating license
- Tax-registration document
- Official registry document
- Another accepted record
Use the document most appropriate to the organization and country.
19.56 Selfie with Identification
The selfie should show the authorized representative holding the same identification submitted in the form.
The image should be:
- Clear
- Well lit
- Unedited
- Recent
- Large enough to review
- Consistent with the identification image
Avoid glare, shadows, masks, filters, or unreadable documents.
19.57 Document Storage
Business KYC documents are stored in the application’s private storage area rather than its ordinary public-file directory.
Customers should still upload only the information required for verification.
Do not upload unrelated documents or credentials.
19.58 Submitting Business Verification
Before submission:
- Confirm the business name.
- Confirm the registration number.
- Confirm the address.
- Review each uploaded document.
- Confirm the selfie is readable.
- Confirm all information is accurate.
- Click Submit for Review.
The record changes to Pending after successful submission.
19.59 Business Verification Review
The interface advises that the compliance team generally reviews a Business submission within approximately 24–48 hours.
Actual review time may depend on:
- Document quality
- Business type
- Country
- Information consistency
- Verification volume
- Need for additional review
The Customer should monitor the KYC page and account email.
19.60 Document Statuses
Each submitted document may have an individual status, such as:
- Pending
- Approved
- Rejected
The overall KYC status may remain Pending while one or more documents are being reviewed.
Do not replace documents unless the interface or administrator instructs the Customer to do so.
19.61 Approved Business Verification
After approval:
- The KYC status changes to Approved
- The Business tier becomes active
- Advanced Customer features may become available
- Account limits may be expanded or removed
- The approval date is recorded
- An expiration date may be displayed
Sign out and sign back in when newly approved features do not appear immediately.
19.62 Rejected Verification
When a submission is rejected, the KYC page may display a rejection reason.
Common reasons can include:
- Unreadable document
- Expired identification
- Business-name mismatch
- Registration-number mismatch
- Address mismatch
- Incomplete image
- Incorrect document type
- Selfie mismatch
- Unsupported information
Review the stated reason before resubmitting.
19.63 Correcting a Rejected Submission
To correct a rejection:
- Read the complete rejection reason.
- Obtain corrected documents.
- Confirm all information matches.
- Open the KYC section.
- Use the available resubmission option.
- Upload the corrected records.
- Submit again.
Do not repeatedly upload the same rejected files.
19.64 Expired KYC
KYC verification may expire or require renewal.
The KYC dashboard may show:
- Expiration date
- Expired status
- Renewal notice
- Renewal requirement
When renewal is required:
- Review the current business information.
- Obtain current documents.
- Follow the renewal instructions.
- Submit before access is interrupted.
19.65 Downloading the Customer’s Documents
The system provides a protected route for Customers to access their own submitted documents.
Document access should be used only when necessary.
Do not download identity documents onto:
- Public computers
- Shared devices
- Unencrypted storage
- Unprotected email accounts
Delete local copies when they are no longer required.
19.66 KYC and Agent Accounts
Agents work under the verified Customer account.
The current application code does not apply Customer KYC restrictions directly to Agent-role accounts in the same way.
However, an Agent’s ability to use Customer phone numbers, campaigns, credits, and AI services still depends on the parent Customer’s operational access and resources.
Agents should not submit Business KYC on behalf of a Customer unless formally authorized.
Part Five
Appearance and Language
19.67 Opening Appearance Settings
To change the visual theme:
- Open Settings.
- Select Appearance.
The page is located at:
The current interface provides three appearance options:
- Light
- Dark
- System
19.68 Light Mode
Light mode uses a light background and darker text.
It may be preferred in:
- Bright offices
- Daytime use
- High-light environments
- Printed demonstrations
19.69 Dark Mode
Dark mode uses a darker background and lighter text.
It may be preferred in:
- Low-light environments
- Evening use
- Long monitoring sessions
- Workspaces where bright screens are distracting
19.70 System Mode
System mode follows the appearance setting of the device or operating system.
For example:
- When the computer uses light mode, AIUNIFY displays light mode.
- When the computer uses dark mode, AIUNIFY displays dark mode.
This is useful when the device automatically changes themes by time of day.
19.71 Changing the Appearance
To change the theme:
- Open Appearance Settings or the appearance menu.
- Select Light, Dark, or System.
- Confirm that the interface updates.
The change normally applies immediately.
The current interface does not provide complete Customer controls for custom fonts or custom color schemes, even though general help text may reference additional customization.
19.72 Selecting a Language
When more than one active language is available, a language selector appears in the interface.
To change the language:
- Locate the globe or language control.
- Open the language list.
- Select an available language.
- Wait for the interface to refresh.
Only languages activated by the platform administrator appear.
19.73 What the Language Setting Changes
The language setting may translate:
- Navigation labels
- Buttons
- Form labels
- System messages
- Settings pages
- Standard interface text
It does not automatically translate:
- Contact names
- Customer-entered notes
- Campaign messages
- Knowledge Base content
- Call transcripts
- Uploaded files
- AI Agent prompts
Those items must be entered in the desired language.
19.74 Incomplete Translations
Some interface labels may remain in English when:
- A translation has not been added
- A newer feature has not been translated
- The selected language is incomplete
- User-generated text is being displayed
Report missing standard translations to the administrator.
Part Six
API Keys
19.75 What Is an API Key?
An API key is a credential used by an approved application, website, widget, or integration to identify itself to AIUNIFY Call Center.
API keys may be used for authorized functions such as:
- Calling integrations
- SMS integrations
- Website widgets
- Internal applications
- Custom workflows
- Approved API access
An API key is not the same as:
- The Customer password
- A Twilio Auth Token
- A CRM webhook secret
- A two-factor recovery code
- A temporary login session
19.76 Who Can Manage API Keys?
API-key management is available to:
- Customers
- Administrators
Agents cannot create or manage API keys through the standard Settings routes.
Only trusted Customer account owners or technical administrators should manage keys.
19.77 Opening API Keys
To open API-key management:
- Open Settings.
- Select API Keys.
The page is located at:
The page lists keys owned by the signed-in Customer account.
19.78 Information Stored for an API Key
An API-key record may include:
- Name
- Key value
- Type
- Active status
- Allowed domains
- Permissions
- Last-used date
- Expiration date
- Creation date
The full key is treated as sensitive information.
19.79 Live and Test Keys
The system supports two API-key types.
Live
Live keys use a prefix similar to:
They are intended for approved production integrations.
Test
Test keys use a prefix similar to:
They are intended to identify testing integrations.
The current source uses the type primarily to label and prefix the key. Customers should not assume that a Test key automatically creates a completely isolated sandbox unless the connected API specifically documents that behavior.
19.80 Creating an API Key
To create a key:
- Open API Keys.
- Click Create API Key.
- Enter a descriptive name.
- Select Live or Test.
- Configure any available domains, expiration, or permissions.
- Create the key.
- Copy the key securely when it is provided.
- Store it in an approved secret manager.
Use a name such as:
Customer Website Calling Widget
Sales CRM Test Integration
Production SMS Application
19.81 Default API Permissions
The current API-key model creates new keys with permission metadata for:
- Calls
- SMS
Customers should verify which API endpoints actually enforce each permission before relying on the metadata as the only security control.
Grant only the access needed by the integration.
19.82 Allowed Domains
An API key can contain a list of allowed domains.
This can restrict where the key is accepted or used when the connected integration checks the requesting domain.
Examples include:
example.com
app.example.com
When no allowed domains are stored, the current model treats all domains as allowed.
For browser or website integrations, customers should configure domain restrictions whenever supported.
19.83 Domain Formatting
Enter only authorized domains.
Confirm whether the interface expects:
- Domain names
- Full URLs
- One domain per line
- Comma-separated entries
Do not authorize broad or unrelated domains.
Review both the primary domain and any required subdomains.
19.84 API-Key Expiration
An API key may have an optional expiration date.
After the expiration date passes, the key is considered invalid.
Use expiration dates for:
- Temporary projects
- Contractor access
- Testing
- Short-term integrations
- Security rotation schedules
A key without an expiration date remains valid until deactivated or deleted.
19.85 Active and Inactive Keys
Active
The key is eligible for use when it has not expired and other requirements are satisfied.
Inactive
The key remains stored but is not considered valid.
Deactivate a key when:
- Troubleshooting an integration
- Temporarily suspending access
- Rotating credentials
- Investigating misuse
- Preserving configuration before deletion
19.86 Deactivating an API Key
To deactivate:
- Open API Keys.
- Locate the key.
- Select the status toggle or Deactivate action.
- Confirm the status changes to Inactive.
The application using that key should stop receiving authorized access.
Test the integration to confirm deactivation.
19.87 Reactivating an API Key
To reactivate:
- Locate the inactive key.
- Select Activate or the status toggle.
- Confirm the key is Active.
- Test the integration.
An expired key may remain unusable even when Active is selected.
19.88 Editing an API Key
Depending on the interface, a key may be updated to change:
- Name
- Type
- Allowed domains
- Permissions
- Expiration date
- Active status
The key value itself should not normally be edited manually.
When the secret value must change, create a replacement key and retire the old one.
19.89 Deleting an API Key
To permanently revoke a key:
- Open API Keys.
- Locate the key.
- Select Delete.
- Review the confirmation.
- Confirm deletion.
The key record is removed and cannot normally be restored.
Update or disable the external application before deletion to avoid unexpected service failure.
19.90 Rotating an API Key
A safe rotation process is:
- Create a replacement key.
- Give it the required settings.
- Update the external application.
- Test the new key.
- Monitor usage.
- Deactivate the old key.
- Confirm the integration still works.
- Delete the old key.
Do not delete the old key before the replacement is tested.
19.91 Last Used At
The API-key record can store the date and time it was last used.
Use this field to identify:
- Active integrations
- Unused keys
- Abandoned projects
- Unexpected activity
- Keys suitable for retirement
A blank Last Used value may mean:
- The key is new
- The integration has not used it
- Usage tracking is not reached by that endpoint
- The integration is failing
19.92 API-Key Ownership
The application checks that the signed-in user owns an API key before allowing updates, deletion, or status changes.
A Customer should not be able to manage another Customer’s API key through the normal routes.
Report any key that appears to belong to another account.
19.93 Current API-Key Storage Security Note
The current source stores the complete API-key value in the database and hides it from normal model output.
This is less secure than storing only a cryptographic hash of the key.
Customers should:
- Treat every key as highly sensitive
- Restrict database access
- Rotate exposed keys immediately
- Avoid including keys in logs
- Avoid placing keys in browser-visible source code
- Use server-side secret storage
The platform developer should consider updating API-key storage to use one-way hashing and a one-time key display process.
19.94 Do Not Place Secret Keys in Public Website Code
A key embedded directly in public JavaScript may be visible to website visitors.
For public website widgets:
- Use domain restrictions
- Use limited permissions
- Use a dedicated key
- Follow the widget documentation
- Avoid using a general production key
- Monitor usage
Sensitive server-to-server keys should remain on a protected backend server.
19.95 API-Key Exposure
When a key is exposed:
- Deactivate it immediately.
- Create a replacement key.
- Update the authorized integration.
- Review Last Used activity.
- Review related call and SMS activity.
- Delete the exposed key.
- Investigate where it was disclosed.
Do not simply rename an exposed key.
Part Seven
Account Deletion
19.96 Opening the Delete Account Section
The Delete Account control appears on the Profile Settings page.
The current route allows Customers and Administrators to delete their own accounts through the standard interface.
Agents do not receive this deletion route through the same Customer workflow.
19.97 Account Deletion Warning
The interface warns that deleting the account:
- Cannot be undone
- Permanently deletes the account
- Deletes associated resources and data
- May remove campaigns, contacts, and call history
- Signs the user out
Treat account deletion as permanent.
19.98 Preparing Before Account Deletion
Before deleting a Customer account:
- Export required contacts.
- Export call records.
- Export campaign reports.
- Export transaction history.
- Download required recordings.
- Stop active campaigns.
- Stop Follow-Up Sequences.
- Review active AI Agents.
- Review assigned phone numbers.
- Review Agents connected to the Customer.
- Review CRM integrations.
- Review API keys.
- Resolve outstanding payments or refunds.
- Contact the administrator about telephone-number release.
- Save records required for legal or business purposes.
19.99 Deleting the Account
To delete:
- Open Profile Settings.
- Scroll to Delete Account.
- Click Delete Account.
- Read the warning.
- Enter the current password.
- Confirm deletion.
The system then:
- Logs the user out
- Deletes the account record
- Invalidates the active session
- Regenerates the session security token
- Returns the browser to the public site
19.100 Account Deletion and External Services
Deleting the AIUNIFY account may not automatically cancel or remove:
- External CRM accounts
- Twilio resources
- SIP carrier contracts
- Payment-provider accounts
- External webhook endpoints
- Locally stored exported files
- Third-party automation workflows
Review external services separately.
Part Eight
Troubleshooting and Security
19.101 Profile Changes Will Not Save
Confirm:
- The Name field is complete
- The email is valid
- The email is not used by another account
- The session is still active
- The browser has internet access
- No validation error is displayed
Refresh only after confirming the form was not still processing.
19.102 Email Became Unverified
This is expected after changing the email address.
Open the verification email sent to the new address and complete the verification.
19.103 Password Change Fails
Confirm:
- The current password is correct
- The new password meets the requirements
- The confirmation matches
- The rate limit has not been reached
- The account session is active
Use Forgot Password when the current password is unknown.
19.104 Two-Factor Code Fails
Confirm:
- The correct authenticator entry is open
- The newest code is being used
- The device time is automatic
- The code was entered before it changed
- The correct account QR code was scanned
Use a recovery code when the authenticator cannot be restored.
19.105 Recovery Codes Are Lost
When still signed in:
- Open Two-Factor Auth.
- Regenerate recovery codes.
- Store the new set securely.
When completely locked out, contact authorized platform support and be prepared to verify account ownership.
19.106 KYC Page Is Missing
Confirm:
- The signed-in account is a Customer
- The account is active
- KYC is enabled by the platform
- The correct account is being used
- The browser session is current
KYC Verification is not shown as a normal Agent setting.
19.107 Basic Verification Cannot Be Completed
Confirm:
- The phone number is valid
- The number can receive SMS
- The latest six-digit code is being used
- The code has not expired
- The country is supported
- The SMS provider is operational
Request a new code only after checking the number.
19.108 Business Verification Form Is Unavailable
Business verification requires completed Basic phone verification.
Return to the KYC dashboard and confirm that the phone is verified.
19.109 Business Documents Are Rejected
Review:
- File readability
- Expiration date
- Business-name match
- Registration-number match
- Address match
- Identification type
- Selfie clarity
- Stated rejection reason
Upload corrected documents rather than renaming the same invalid file.
19.110 Approved Features Do Not Appear
After KYC approval:
- Sign out.
- Sign back in.
- Refresh the dashboard.
- Confirm the KYC page shows Approved.
- Confirm the account has the required role permissions.
- Contact the administrator when access remains unavailable.
KYC approval does not override subscription, role, provider, or billing requirements.
19.111 API Key Does Not Work
Confirm:
- The key is Active
- It has not expired
- The correct key was copied
- The allowed domain is correct
- The integration uses the correct API route
- The required permission metadata is present
- The key has not been deleted
- The request format is correct
Do not paste the complete key into a public support request.
19.112 API Key Shows No Recent Use
Confirm:
- The external application is running
- It is using the correct key
- It is reaching AIUNIFY
- Requests are not failing before authentication
- The correct Customer account owns the key
- Usage tracking is supported by the endpoint
19.113 Interface Language Does Not Change
Confirm:
- More than one language is active
- The selected language was saved
- The page was refreshed
- Browser storage is enabled
- The translation is available
Some content may remain in English because it has not been translated.
19.114 Appearance Returns to Another Theme
When System is selected, the interface follows the computer or device theme.
Select Light or Dark directly when a fixed appearance is preferred.
Also confirm that browser privacy settings are not clearing saved preferences.
19.115 Customer Account Security Checklist
Customers should regularly confirm:
- The profile name is correct.
- The email address is current and verified.
- The password is unique.
- Two-factor authentication is enabled.
- Recovery codes are stored securely.
- KYC information is current.
- Expiration and renewal notices are reviewed.
- API keys have clear names.
- Unused API keys are deactivated or deleted.
- Allowed domains are restricted.
- Exposed keys are rotated.
- Agents use separate accounts.
- Former personnel no longer have access.
- Billing and credit activity is reviewed.
- Important data is exported before account deletion.
19.116 Chapter Summary
The Customer Settings section controls account identity, login security, verification, visual preferences, language, integration credentials, and account deletion.
Customers can update their name and email address from Profile Settings. Changing the email removes its verified status and requires verification of the new address.
Password Settings require the current password, a new password, and matching confirmation. Password updates are rate-limited.
Two-factor authentication uses a compatible authenticator application, QR code, rotating six-digit codes, and recovery codes. Recovery codes should be stored securely and regenerated when exposed.
KYC Verification contains Basic and Business tiers. Basic verification confirms a telephone number through a six-digit SMS code. Business verification requires business details, identification, a business document, and a selfie with identification.
Basic verification provides access to standard calling and contact features under current limits. Business verification provides access to AI Agents, Knowledge Bases, and other advanced functions.
Appearance Settings provide Light, Dark, and System themes. The language selector displays languages activated by the platform administrator.
Customers and Administrators can create API keys. Keys may be Live or Test, Active or Inactive, domain-restricted, permission-limited, and optionally assigned an expiration date. API keys must be stored and rotated securely.
Account deletion requires the Customer’s current password and is treated as permanent. Customers should export all required data and resolve telephone, campaign, Agent, billing, and integration matters before deleting the account.