19.1 Overview

The Settings section allows Customers to maintain their personal account information, protect their login, complete identity verification, select interface preferences, and manage API keys for approved integrations.

Customer settings may include:

  1. Profile information
  2. Email verification
  3. Password management
  4. Two-factor authentication
  5. KYC verification
  6. Appearance preferences
  7. Language selection
  8. API keys
  9. Account deletion

These settings affect account security, feature access, communication privileges, and the ability to connect external applications.

Customers should review their settings when first creating an account and whenever their business information, email address, telephone number, authorized personnel, or security requirements change.

19.2 Opening Account Settings

To open Settings:

  1. Sign in to AIUNIFY Call Center.
  2. Open the account menu or main navigation menu.
  3. Select Settings.

The main Settings address redirects to the Profile page:

/settings/profile

The Settings menu may include:

  1. Profile
  2. Password
  3. Two-Factor Auth
  4. KYC Verification
  5. Appearance
  6. API Keys

The options displayed depend on the signed-in user’s role.

19.3 Customer and Agent Settings Access

Customers can manage their own:

  1. Profile
  2. Password
  3. Two-factor authentication
  4. KYC verification
  5. Appearance
  6. API keys
  7. Account deletion

Agents can normally manage:

  1. Their own profile
  2. Their own password
  3. Their own two-factor authentication
  4. Their own appearance

Agents cannot create Customer API keys through the standard interface.

Agents also do not manage the Customer account’s business KYC, billing identity, or account deletion.

Part One

Profile Information

19.4 Opening Profile Settings

To open the Profile page:

  1. Open Settings.
  2. Select Profile.

The page is located at:

/settings/profile

The current Profile form allows the Customer to update:

  1. Full name
  2. Email address

Other Customer information, such as KYC business details, is managed separately through KYC Verification.

19.5 Updating the Customer Name

To update the account name:

  1. Open Profile Settings.
  2. Locate the Name field.
  3. Enter the correct full name.
  4. Click Save Changes.

The name is required and may contain up to 255 characters.

The updated name may appear in:

  1. The account menu
  2. User-management records
  3. Reports
  4. Administrative records
  5. Customer communications
  6. Agent ownership information

Use the real name of the authorized account holder or business representative.

19.6 Updating the Email Address

To change the email address:

  1. Open Profile Settings.
  2. Replace the current email address.
  3. Confirm that the address is spelled correctly.
  4. Click Save Changes.

The email must:

  1. Be a valid email address
  2. Be unique within AIUNIFY Call Center
  3. Contain no more than 255 characters
  4. Not already belong to another account

The system stores email addresses in lowercase.

19.7 Email Reverification After a Change

Changing the account email address removes the previous email-verification status.

The new email address must be verified before all account functions can be considered fully available.

After changing the address:

  1. Open the new email inbox.
  2. Locate the AIUNIFY Call Center verification message.
  3. Open the verification link.
  4. Return to the platform.
  5. Confirm that the account no longer shows an unverified-email notice.

Do not continue relying on the old email address after the change.

19.8 Resending the Verification Email

When the email remains unverified, the Profile page provides an option to resend the verification message.

To resend it:

  1. Open Profile Settings.
  2. Locate the unverified-email notice.
  3. Click the resend-verification link.
  4. Check the inbox.
  5. Check the spam or junk folder.
  6. Open the most recent verification email.
  7. Follow the verification link.

Older verification links may expire or become invalid after a newer link is issued.

19.9 Verification Email Does Not Arrive

Confirm:

  1. The email address is correct
  2. The inbox has available storage
  3. The message is not in spam
  4. The email domain is accepting messages
  5. The account has not blocked AIUNIFY messages
  6. The platform’s mail system is operational

Do not repeatedly change the email address while troubleshooting.

Contact support when the resend function reports success but no message arrives.

19.10 Email Already in Use

If the platform reports that the email is already in use:

  1. Confirm that another account was not previously created
  2. Try signing in with that email
  3. Use Forgot Password when necessary
  4. Contact the account owner
  5. Use another authorized email address

The same email address cannot be assigned to two users.

Part Two

Password Management

19.11 Opening Password Settings

To change the password:

  1. Open Settings.
  2. Select Password.

The page is located at:

/settings/password

The form requires:

  1. Current password
  2. New password
  3. Confirm new password

19.12 Changing the Password

To update the password:

  1. Enter the current password.
  2. Enter the new password.
  3. Enter the same new password again.
  4. Click Save Password or Update Password.

The new password must satisfy the requirements displayed by the platform.

The confirmation must exactly match the new password.

19.13 Current Password Requirement

The current password verifies that the person making the change already controls the account.

If the current password is incorrect, the update will not be completed.

Do not use the Agent password, email password, Twilio Auth Token, or API key in this field.

19.14 Creating a Strong Password

A strong password should:

  1. Be unique to AIUNIFY Call Center
  2. Be difficult to guess
  3. Avoid business names
  4. Avoid telephone numbers
  5. Avoid birthdays
  6. Avoid repeated characters
  7. Avoid common passwords
  8. Not be reused across staff accounts

A password manager is recommended for storing complex passwords securely.

19.15 Password Update Rate Limit

The password-update route is rate-limited.

The current application permits up to approximately six update attempts within one minute.

Repeated failed attempts may temporarily prevent additional submissions.

When this happens:

  1. Stop submitting the form.
  2. Confirm the current password.
  3. Wait briefly.
  4. Try again once.

19.16 Forgot Password

When the current password is unknown:

  1. Sign out or open the login page.
  2. Select Forgot Password.
  3. Enter the account email address.
  4. Submit the request.
  5. Open the password-reset email.
  6. Follow the reset link.
  7. Create a new password.
  8. Sign in again.

Use the email address currently assigned to the AIUNIFY account.

19.17 Password Reset Email Does Not Arrive

Confirm:

  1. The correct account email was entered
  2. The address is spelled correctly
  3. The message is not in spam
  4. The inbox is operational
  5. The account still exists
  6. Platform email delivery is configured

For security reasons, the platform may not confirm whether a submitted email belongs to an account.

19.18 After Changing a Password

After a password change:

  1. Update the stored password in the approved password manager
  2. Sign out of shared devices
  3. Inform no one of the new password
  4. Confirm two-factor authentication remains active
  5. Review unexpected account activity
  6. Replace the password immediately if it was exposed

Each Customer and Agent should use a separate account and password.

Part Three

Two-Factor Authentication

19.19 What Is Two-Factor Authentication?

Two-factor authentication, also called 2FA, adds a second login requirement.

A person must provide:

  1. The account password
  2. A temporary code from an authenticator application or a recovery code

This helps protect the account when the password is stolen or guessed.

19.20 Opening Two-Factor Authentication

To manage 2FA:

  1. Open Settings.
  2. Select Two-Factor Auth.

The page is located at:

/settings/two-factor

The page displays whether two-factor authentication is enabled.

19.21 Supported Authenticator Applications

The interface is designed for time-based authenticator applications, such as:

  1. Google Authenticator
  2. Authy
  3. Microsoft Authenticator
  4. Another compatible authenticator application

The application generates a temporary six-digit code that normally changes every 30 seconds.

19.22 Enabling Two-Factor Authentication

To enable 2FA:

  1. Open Two-Factor Auth.
  2. Click Enable Two-Factor Authentication.
  3. Wait for the QR code to appear.
  4. Open the authenticator application.
  5. Choose the option to add an account.
  6. Scan the QR code.
  7. Enter the six-digit code displayed by the application.
  8. Submit the confirmation.
  9. Confirm that the page reports 2FA as enabled.

Do not close the setup before confirming the code.

19.23 Manually Entering the Secret Key

When the QR code cannot be scanned, a compatible authenticator may allow manual secret-key entry.

Enter the secret exactly as displayed.

Protect the secret key as carefully as a password.

Anyone who obtains it may be able to generate valid login codes.

19.24 Confirming the Six-Digit Code

The code entered during setup confirms that:

  1. The authenticator was added correctly
  2. The phone time is synchronized
  3. The secret key was interpreted correctly
  4. Future login codes can be generated

When a code is rejected:

  1. Wait for a new code.
  2. Enter it promptly.
  3. Confirm the phone date and time are automatic.
  4. Confirm the correct authenticator account was selected.

19.25 Recovery Codes

After 2FA is enabled, the platform provides recovery codes.

Recovery codes can be used when:

  1. The phone is lost
  2. The authenticator application is unavailable
  3. The device is replaced
  4. The authenticator account is accidentally removed

Save the recovery codes immediately.

19.26 Protecting Recovery Codes

Store recovery codes:

  1. In a secure password manager
  2. In an encrypted file
  3. In a protected physical location
  4. Somewhere separate from the authentication phone

Do not store them:

  1. In a public note
  2. In a shared spreadsheet
  3. In an unsecured email
  4. In the same phone case as the device
  5. In screenshots accessible to others

Each recovery code should normally be treated as single-use.

19.27 Viewing Recovery Codes

The 2FA page may allow recovery codes to be shown or hidden.

Before displaying them:

  1. Confirm no one else can see the screen
  2. Avoid screen sharing
  3. Do not record the screen
  4. Close the page after storing them

19.28 Regenerating Recovery Codes

When the codes are exposed, lost, or mostly used:

  1. Open Two-Factor Auth.
  2. Select Regenerate Recovery Codes.
  3. Save the new codes.
  4. Delete the older stored copy.

Regenerating codes invalidates the previous set.

19.29 Signing In with 2FA

After entering the email and password, the platform displays a two-factor challenge.

To complete it:

  1. Open the authenticator application.
  2. Locate the AIUNIFY Call Center entry.
  3. Enter the current six-digit code.
  4. Submit the challenge.

Enter the code before it changes.

19.30 Signing In with a Recovery Code

When the authenticator is unavailable:

  1. Open the two-factor challenge.
  2. Select the recovery-code option when available.
  3. Enter one unused recovery code.
  4. Sign in.
  5. Review the 2FA settings.
  6. Regenerate codes when necessary.
  7. Configure the replacement authenticator device.

19.31 Disabling Two-Factor Authentication

To disable 2FA:

  1. Open Two-Factor Auth.
  2. Click Disable Two-Factor Authentication.
  3. Review the warning.
  4. Confirm the action.

Disabling 2FA reduces account security.

It should normally be done only while replacing an authenticator or resolving an access issue.

19.32 Replacing the Authentication Phone

Before replacing the phone:

  1. Confirm recovery codes are available.
  2. Sign in to AIUNIFY Call Center.
  3. Disable 2FA.
  4. Enable it again using the new phone.
  5. Scan the new QR code.
  6. Confirm the new six-digit code.
  7. Save the newly generated recovery codes.

Do not erase the old phone until the new setup has been tested.

19.33 Two-Factor Security Practices

Customers should require 2FA for account owners and trusted managers who can access:

  1. Billing
  2. Contacts
  3. Campaigns
  4. Recordings
  5. AI Agents
  6. API keys
  7. Agent accounts
  8. Business verification information

Never share:

  1. QR codes
  2. Secret keys
  3. Authenticator codes
  4. Recovery codes

Part Four

KYC Verification

19.34 What Is KYC Verification?

KYC means Know Your Customer.

AIUNIFY Call Center uses KYC to verify the identity and business information of Customers who use telephone, messaging, AI, and advanced communication services.

KYC helps the platform:

  1. Reduce fraud
  2. Verify account ownership
  3. Protect telephone resources
  4. Support provider requirements
  5. Apply account limits
  6. Control access to advanced features
  7. Review business legitimacy
  8. Protect Customers and recipients

19.35 Opening KYC Verification

To open KYC:

  1. Open Settings.
  2. Select KYC Verification.

The page is located at:

/settings/kyc

The KYC page may display:

  1. Verification tier
  2. Current status
  3. Verified phone number
  4. Business name
  5. Submission date
  6. Approval date
  7. Expiration date
  8. Document statuses
  9. Rejection reason
  10. Renewal requirement

19.36 KYC Tiers

The current system contains three Customer verification levels.

Unverified

The Customer has not completed Basic verification.

Basic — Tier 1

The Customer has verified a telephone number.

Business — Tier 2

The Customer has provided business information and supporting documents and received approval.

19.37 KYC Statuses

A verification record may have one of the following statuses.

Pending

The submission is waiting for review or confirmation.

Approved

The verification has been accepted.

Rejected

The submission was not approved.

Expired

The previous verification is no longer current and may require renewal.

19.38 Current Feature Access by Tier

The current source defines Customer feature access approximately as follows.

Unverified Customer

No verified telephony access.

Basic Customer

May receive access to:

  1. Phone numbers
  2. Campaigns
  3. Calls
  4. SMS
  5. Contacts

Business Customer

May receive access to everything in Basic, plus:

  1. AI Agents
  2. Knowledge Bases
  3. Advanced features

Role permissions and account configuration can still limit access.

19.39 Current Basic-Tier Limits

The current source defines Basic Customer limits of approximately:

  1. Maximum three phone numbers
  2. Maximum 100 calls per day
  3. Maximum deposit of $500

These are current application defaults and may be changed by future system updates or platform policy.

Business-tier limit fields are currently configured as unrestricted.

19.40 Beginning Basic Verification

To begin Basic verification:

  1. Open KYC Verification.
  2. Select Start Basic Verification.
  3. Enter a reachable telephone number.
  4. Include the country code.
  5. Submit the form.
  6. Wait for the verification SMS.

The Basic form is located at:

/settings/kyc/basic

19.41 Entering the Phone Number

Use a telephone number that:

  1. Belongs to the authorized Customer
  2. Can receive SMS messages
  3. Includes the correct country code
  4. Will remain available to the business
  5. Is not a temporary public messaging number

Example international format:

+13135551234

The actual number should be entered without missing digits.

19.42 Receiving the Verification Code

After the number is submitted, the platform generates and sends a six-digit numerical verification code.

The code:

  1. Contains exactly six digits
  2. Is sent by SMS
  3. Expires after approximately 10 minutes
  4. Must be entered before expiration

Do not share the code with anyone claiming to be support staff.

19.43 Verifying the Phone Number

To verify:

  1. Open the SMS message.
  2. Copy the six-digit code.
  3. Enter it on the verification page.
  4. Click Verify Phone.
  5. Wait for the confirmation.

The verification page is located at:

/settings/kyc/verify-phone

A successful code confirms the Basic KYC phone requirement.

19.44 Invalid Verification Code

A code may be rejected when:

  1. It is not six digits
  2. It contains letters
  3. It was entered incorrectly
  4. It expired
  5. A newer code was requested
  6. The maximum number of attempts was reached
  7. The account is verifying another number

Enter the most recently issued code.

19.45 Resending the Phone Code

To request a new code:

  1. Confirm the phone number was already submitted.
  2. Open the verification page.
  3. Select Resend Code.
  4. Wait for the new SMS.
  5. Enter the new code.

The resend process:

  1. Generates a new code
  2. Gives it a new 10-minute expiration
  3. Resets the verification-attempt count

The old code should no longer be used.

19.46 Verification SMS Does Not Arrive

Confirm:

  1. The number includes the country code
  2. The number can receive SMS
  3. The device has signal
  4. The message is not filtered
  5. The number is not a landline
  6. Twilio messaging is functioning
  7. The destination country is supported

Use Resend Code once after checking the number.

Repeated resends may produce several messages, but only the newest code should be used.

19.47 Beginning Business Verification

Business verification requires completed Basic phone verification.

To begin:

  1. Open KYC Verification.
  2. Confirm Basic verification is complete.
  3. Select Upgrade to Business Verification.
  4. Complete the business-information form.
  5. Upload the required documents.
  6. Submit for review.

The Business form is located at:

/settings/kyc/business

19.48 Business Information Required

The Business form may request:

  1. Business name
  2. Business registration number
  3. Business type
  4. Address line 1
  5. Address line 2
  6. City
  7. State or province
  8. Postal code
  9. Country

Enter information exactly as it appears in official business documents.

19.49 Business Name

Enter the registered legal business name.

Do not enter:

  1. A temporary campaign name
  2. An unrelated brand
  3. An employee name
  4. An abbreviation not shown in registration documents

When the business operates under a trade name, use the legal information requested by the form.

19.50 Registration Number

Enter the official registration, incorporation, or licensing number associated with the business.

The number should match the uploaded business document.

Formatting varies by country and business type.

19.51 Business Type

Select or enter the structure that accurately describes the organization, such as:

  1. Sole proprietorship
  2. Limited liability company
  3. Corporation
  4. Partnership
  5. Nonprofit
  6. Other supported structure

Use the structure shown in the official registration records.

19.52 Business Address

The business address should match official records whenever possible.

Include:

  1. Street address
  2. Suite or unit
  3. City
  4. State or province
  5. Postal code
  6. Country

Do not use an address the business is not authorized to represent.

19.53 Required Business Documents

The Business verification workflow requires three document categories:

  1. Identification document
  2. Business document
  3. Selfie with identification

The form enforces the applicable file and validation requirements.

19.54 Identification Document

The identification document verifies the authorized representative.

The form may request an ID type, such as:

  1. Passport
  2. Driver’s license
  3. National identification card
  4. Another supported government-issued document

The document should:

  1. Be current
  2. Be readable
  3. Show the full required information
  4. Not be cropped improperly
  5. Match the account representative

19.55 Business Document

The business document should verify the existence and registration of the organization.

Examples may include:

  1. Articles of incorporation
  2. Business-registration certificate
  3. Operating license
  4. Tax-registration document
  5. Official registry document
  6. Another accepted record

Use the document most appropriate to the organization and country.

19.56 Selfie with Identification

The selfie should show the authorized representative holding the same identification submitted in the form.

The image should be:

  1. Clear
  2. Well lit
  3. Unedited
  4. Recent
  5. Large enough to review
  6. Consistent with the identification image

Avoid glare, shadows, masks, filters, or unreadable documents.

19.57 Document Storage

Business KYC documents are stored in the application’s private storage area rather than its ordinary public-file directory.

Customers should still upload only the information required for verification.

Do not upload unrelated documents or credentials.

19.58 Submitting Business Verification

Before submission:

  1. Confirm the business name.
  2. Confirm the registration number.
  3. Confirm the address.
  4. Review each uploaded document.
  5. Confirm the selfie is readable.
  6. Confirm all information is accurate.
  7. Click Submit for Review.

The record changes to Pending after successful submission.

19.59 Business Verification Review

The interface advises that the compliance team generally reviews a Business submission within approximately 24–48 hours.

Actual review time may depend on:

  1. Document quality
  2. Business type
  3. Country
  4. Information consistency
  5. Verification volume
  6. Need for additional review

The Customer should monitor the KYC page and account email.

19.60 Document Statuses

Each submitted document may have an individual status, such as:

  1. Pending
  2. Approved
  3. Rejected

The overall KYC status may remain Pending while one or more documents are being reviewed.

Do not replace documents unless the interface or administrator instructs the Customer to do so.

19.61 Approved Business Verification

After approval:

  1. The KYC status changes to Approved
  2. The Business tier becomes active
  3. Advanced Customer features may become available
  4. Account limits may be expanded or removed
  5. The approval date is recorded
  6. An expiration date may be displayed

Sign out and sign back in when newly approved features do not appear immediately.

19.62 Rejected Verification

When a submission is rejected, the KYC page may display a rejection reason.

Common reasons can include:

  1. Unreadable document
  2. Expired identification
  3. Business-name mismatch
  4. Registration-number mismatch
  5. Address mismatch
  6. Incomplete image
  7. Incorrect document type
  8. Selfie mismatch
  9. Unsupported information

Review the stated reason before resubmitting.

19.63 Correcting a Rejected Submission

To correct a rejection:

  1. Read the complete rejection reason.
  2. Obtain corrected documents.
  3. Confirm all information matches.
  4. Open the KYC section.
  5. Use the available resubmission option.
  6. Upload the corrected records.
  7. Submit again.

Do not repeatedly upload the same rejected files.

19.64 Expired KYC

KYC verification may expire or require renewal.

The KYC dashboard may show:

  1. Expiration date
  2. Expired status
  3. Renewal notice
  4. Renewal requirement

When renewal is required:

  1. Review the current business information.
  2. Obtain current documents.
  3. Follow the renewal instructions.
  4. Submit before access is interrupted.

19.65 Downloading the Customer’s Documents

The system provides a protected route for Customers to access their own submitted documents.

Document access should be used only when necessary.

Do not download identity documents onto:

  1. Public computers
  2. Shared devices
  3. Unencrypted storage
  4. Unprotected email accounts

Delete local copies when they are no longer required.

19.66 KYC and Agent Accounts

Agents work under the verified Customer account.

The current application code does not apply Customer KYC restrictions directly to Agent-role accounts in the same way.

However, an Agent’s ability to use Customer phone numbers, campaigns, credits, and AI services still depends on the parent Customer’s operational access and resources.

Agents should not submit Business KYC on behalf of a Customer unless formally authorized.

Part Five

Appearance and Language

19.67 Opening Appearance Settings

To change the visual theme:

  1. Open Settings.
  2. Select Appearance.

The page is located at:

/settings/appearance

The current interface provides three appearance options:

  1. Light
  2. Dark
  3. System

19.68 Light Mode

Light mode uses a light background and darker text.

It may be preferred in:

  1. Bright offices
  2. Daytime use
  3. High-light environments
  4. Printed demonstrations

19.69 Dark Mode

Dark mode uses a darker background and lighter text.

It may be preferred in:

  1. Low-light environments
  2. Evening use
  3. Long monitoring sessions
  4. Workspaces where bright screens are distracting

19.70 System Mode

System mode follows the appearance setting of the device or operating system.

For example:

  1. When the computer uses light mode, AIUNIFY displays light mode.
  2. When the computer uses dark mode, AIUNIFY displays dark mode.

This is useful when the device automatically changes themes by time of day.

19.71 Changing the Appearance

To change the theme:

  1. Open Appearance Settings or the appearance menu.
  2. Select Light, Dark, or System.
  3. Confirm that the interface updates.

The change normally applies immediately.

The current interface does not provide complete Customer controls for custom fonts or custom color schemes, even though general help text may reference additional customization.

19.72 Selecting a Language

When more than one active language is available, a language selector appears in the interface.

To change the language:

  1. Locate the globe or language control.
  2. Open the language list.
  3. Select an available language.
  4. Wait for the interface to refresh.

Only languages activated by the platform administrator appear.

19.73 What the Language Setting Changes

The language setting may translate:

  1. Navigation labels
  2. Buttons
  3. Form labels
  4. System messages
  5. Settings pages
  6. Standard interface text

It does not automatically translate:

  1. Contact names
  2. Customer-entered notes
  3. Campaign messages
  4. Knowledge Base content
  5. Call transcripts
  6. Uploaded files
  7. AI Agent prompts

Those items must be entered in the desired language.

19.74 Incomplete Translations

Some interface labels may remain in English when:

  1. A translation has not been added
  2. A newer feature has not been translated
  3. The selected language is incomplete
  4. User-generated text is being displayed

Report missing standard translations to the administrator.

Part Six

API Keys

19.75 What Is an API Key?

An API key is a credential used by an approved application, website, widget, or integration to identify itself to AIUNIFY Call Center.

API keys may be used for authorized functions such as:

  1. Calling integrations
  2. SMS integrations
  3. Website widgets
  4. Internal applications
  5. Custom workflows
  6. Approved API access

An API key is not the same as:

  1. The Customer password
  2. A Twilio Auth Token
  3. A CRM webhook secret
  4. A two-factor recovery code
  5. A temporary login session

19.76 Who Can Manage API Keys?

API-key management is available to:

  1. Customers
  2. Administrators

Agents cannot create or manage API keys through the standard Settings routes.

Only trusted Customer account owners or technical administrators should manage keys.

19.77 Opening API Keys

To open API-key management:

  1. Open Settings.
  2. Select API Keys.

The page is located at:

/settings/api-keys

The page lists keys owned by the signed-in Customer account.

19.78 Information Stored for an API Key

An API-key record may include:

  1. Name
  2. Key value
  3. Type
  4. Active status
  5. Allowed domains
  6. Permissions
  7. Last-used date
  8. Expiration date
  9. Creation date

The full key is treated as sensitive information.

19.79 Live and Test Keys

The system supports two API-key types.

Live

Live keys use a prefix similar to:

pk_live_

They are intended for approved production integrations.

Test

Test keys use a prefix similar to:

pk_test_

They are intended to identify testing integrations.

The current source uses the type primarily to label and prefix the key. Customers should not assume that a Test key automatically creates a completely isolated sandbox unless the connected API specifically documents that behavior.

19.80 Creating an API Key

To create a key:

  1. Open API Keys.
  2. Click Create API Key.
  3. Enter a descriptive name.
  4. Select Live or Test.
  5. Configure any available domains, expiration, or permissions.
  6. Create the key.
  7. Copy the key securely when it is provided.
  8. Store it in an approved secret manager.

Use a name such as:

Customer Website Calling Widget
Sales CRM Test Integration
Production SMS Application

19.81 Default API Permissions

The current API-key model creates new keys with permission metadata for:

  1. Calls
  2. SMS

Customers should verify which API endpoints actually enforce each permission before relying on the metadata as the only security control.

Grant only the access needed by the integration.

19.82 Allowed Domains

An API key can contain a list of allowed domains.

This can restrict where the key is accepted or used when the connected integration checks the requesting domain.

Examples include:

example.com
app.example.com

When no allowed domains are stored, the current model treats all domains as allowed.

For browser or website integrations, customers should configure domain restrictions whenever supported.

19.83 Domain Formatting

Enter only authorized domains.

Confirm whether the interface expects:

  1. Domain names
  2. Full URLs
  3. One domain per line
  4. Comma-separated entries

Do not authorize broad or unrelated domains.

Review both the primary domain and any required subdomains.

19.84 API-Key Expiration

An API key may have an optional expiration date.

After the expiration date passes, the key is considered invalid.

Use expiration dates for:

  1. Temporary projects
  2. Contractor access
  3. Testing
  4. Short-term integrations
  5. Security rotation schedules

A key without an expiration date remains valid until deactivated or deleted.

19.85 Active and Inactive Keys

Active

The key is eligible for use when it has not expired and other requirements are satisfied.

Inactive

The key remains stored but is not considered valid.

Deactivate a key when:

  1. Troubleshooting an integration
  2. Temporarily suspending access
  3. Rotating credentials
  4. Investigating misuse
  5. Preserving configuration before deletion

19.86 Deactivating an API Key

To deactivate:

  1. Open API Keys.
  2. Locate the key.
  3. Select the status toggle or Deactivate action.
  4. Confirm the status changes to Inactive.

The application using that key should stop receiving authorized access.

Test the integration to confirm deactivation.

19.87 Reactivating an API Key

To reactivate:

  1. Locate the inactive key.
  2. Select Activate or the status toggle.
  3. Confirm the key is Active.
  4. Test the integration.

An expired key may remain unusable even when Active is selected.

19.88 Editing an API Key

Depending on the interface, a key may be updated to change:

  1. Name
  2. Type
  3. Allowed domains
  4. Permissions
  5. Expiration date
  6. Active status

The key value itself should not normally be edited manually.

When the secret value must change, create a replacement key and retire the old one.

19.89 Deleting an API Key

To permanently revoke a key:

  1. Open API Keys.
  2. Locate the key.
  3. Select Delete.
  4. Review the confirmation.
  5. Confirm deletion.

The key record is removed and cannot normally be restored.

Update or disable the external application before deletion to avoid unexpected service failure.

19.90 Rotating an API Key

A safe rotation process is:

  1. Create a replacement key.
  2. Give it the required settings.
  3. Update the external application.
  4. Test the new key.
  5. Monitor usage.
  6. Deactivate the old key.
  7. Confirm the integration still works.
  8. Delete the old key.

Do not delete the old key before the replacement is tested.

19.91 Last Used At

The API-key record can store the date and time it was last used.

Use this field to identify:

  1. Active integrations
  2. Unused keys
  3. Abandoned projects
  4. Unexpected activity
  5. Keys suitable for retirement

A blank Last Used value may mean:

  1. The key is new
  2. The integration has not used it
  3. Usage tracking is not reached by that endpoint
  4. The integration is failing

19.92 API-Key Ownership

The application checks that the signed-in user owns an API key before allowing updates, deletion, or status changes.

A Customer should not be able to manage another Customer’s API key through the normal routes.

Report any key that appears to belong to another account.

19.93 Current API-Key Storage Security Note

The current source stores the complete API-key value in the database and hides it from normal model output.

This is less secure than storing only a cryptographic hash of the key.

Customers should:

  1. Treat every key as highly sensitive
  2. Restrict database access
  3. Rotate exposed keys immediately
  4. Avoid including keys in logs
  5. Avoid placing keys in browser-visible source code
  6. Use server-side secret storage

The platform developer should consider updating API-key storage to use one-way hashing and a one-time key display process.

19.94 Do Not Place Secret Keys in Public Website Code

A key embedded directly in public JavaScript may be visible to website visitors.

For public website widgets:

  1. Use domain restrictions
  2. Use limited permissions
  3. Use a dedicated key
  4. Follow the widget documentation
  5. Avoid using a general production key
  6. Monitor usage

Sensitive server-to-server keys should remain on a protected backend server.

19.95 API-Key Exposure

When a key is exposed:

  1. Deactivate it immediately.
  2. Create a replacement key.
  3. Update the authorized integration.
  4. Review Last Used activity.
  5. Review related call and SMS activity.
  6. Delete the exposed key.
  7. Investigate where it was disclosed.

Do not simply rename an exposed key.

Part Seven

Account Deletion

19.96 Opening the Delete Account Section

The Delete Account control appears on the Profile Settings page.

The current route allows Customers and Administrators to delete their own accounts through the standard interface.

Agents do not receive this deletion route through the same Customer workflow.

19.97 Account Deletion Warning

The interface warns that deleting the account:

  1. Cannot be undone
  2. Permanently deletes the account
  3. Deletes associated resources and data
  4. May remove campaigns, contacts, and call history
  5. Signs the user out

Treat account deletion as permanent.

19.98 Preparing Before Account Deletion

Before deleting a Customer account:

  1. Export required contacts.
  2. Export call records.
  3. Export campaign reports.
  4. Export transaction history.
  5. Download required recordings.
  6. Stop active campaigns.
  7. Stop Follow-Up Sequences.
  8. Review active AI Agents.
  9. Review assigned phone numbers.
  10. Review Agents connected to the Customer.
  11. Review CRM integrations.
  12. Review API keys.
  13. Resolve outstanding payments or refunds.
  14. Contact the administrator about telephone-number release.
  15. Save records required for legal or business purposes.

19.99 Deleting the Account

To delete:

  1. Open Profile Settings.
  2. Scroll to Delete Account.
  3. Click Delete Account.
  4. Read the warning.
  5. Enter the current password.
  6. Confirm deletion.

The system then:

  1. Logs the user out
  2. Deletes the account record
  3. Invalidates the active session
  4. Regenerates the session security token
  5. Returns the browser to the public site

19.100 Account Deletion and External Services

Deleting the AIUNIFY account may not automatically cancel or remove:

  1. External CRM accounts
  2. Twilio resources
  3. SIP carrier contracts
  4. Payment-provider accounts
  5. External webhook endpoints
  6. Locally stored exported files
  7. Third-party automation workflows

Review external services separately.

Part Eight

Troubleshooting and Security

19.101 Profile Changes Will Not Save

Confirm:

  1. The Name field is complete
  2. The email is valid
  3. The email is not used by another account
  4. The session is still active
  5. The browser has internet access
  6. No validation error is displayed

Refresh only after confirming the form was not still processing.

19.102 Email Became Unverified

This is expected after changing the email address.

Open the verification email sent to the new address and complete the verification.

19.103 Password Change Fails

Confirm:

  1. The current password is correct
  2. The new password meets the requirements
  3. The confirmation matches
  4. The rate limit has not been reached
  5. The account session is active

Use Forgot Password when the current password is unknown.

19.104 Two-Factor Code Fails

Confirm:

  1. The correct authenticator entry is open
  2. The newest code is being used
  3. The device time is automatic
  4. The code was entered before it changed
  5. The correct account QR code was scanned

Use a recovery code when the authenticator cannot be restored.

19.105 Recovery Codes Are Lost

When still signed in:

  1. Open Two-Factor Auth.
  2. Regenerate recovery codes.
  3. Store the new set securely.

When completely locked out, contact authorized platform support and be prepared to verify account ownership.

19.106 KYC Page Is Missing

Confirm:

  1. The signed-in account is a Customer
  2. The account is active
  3. KYC is enabled by the platform
  4. The correct account is being used
  5. The browser session is current

KYC Verification is not shown as a normal Agent setting.

19.107 Basic Verification Cannot Be Completed

Confirm:

  1. The phone number is valid
  2. The number can receive SMS
  3. The latest six-digit code is being used
  4. The code has not expired
  5. The country is supported
  6. The SMS provider is operational

Request a new code only after checking the number.

19.108 Business Verification Form Is Unavailable

Business verification requires completed Basic phone verification.

Return to the KYC dashboard and confirm that the phone is verified.

19.109 Business Documents Are Rejected

Review:

  1. File readability
  2. Expiration date
  3. Business-name match
  4. Registration-number match
  5. Address match
  6. Identification type
  7. Selfie clarity
  8. Stated rejection reason

Upload corrected documents rather than renaming the same invalid file.

19.110 Approved Features Do Not Appear

After KYC approval:

  1. Sign out.
  2. Sign back in.
  3. Refresh the dashboard.
  4. Confirm the KYC page shows Approved.
  5. Confirm the account has the required role permissions.
  6. Contact the administrator when access remains unavailable.

KYC approval does not override subscription, role, provider, or billing requirements.

19.111 API Key Does Not Work

Confirm:

  1. The key is Active
  2. It has not expired
  3. The correct key was copied
  4. The allowed domain is correct
  5. The integration uses the correct API route
  6. The required permission metadata is present
  7. The key has not been deleted
  8. The request format is correct

Do not paste the complete key into a public support request.

19.112 API Key Shows No Recent Use

Confirm:

  1. The external application is running
  2. It is using the correct key
  3. It is reaching AIUNIFY
  4. Requests are not failing before authentication
  5. The correct Customer account owns the key
  6. Usage tracking is supported by the endpoint

19.113 Interface Language Does Not Change

Confirm:

  1. More than one language is active
  2. The selected language was saved
  3. The page was refreshed
  4. Browser storage is enabled
  5. The translation is available

Some content may remain in English because it has not been translated.

19.114 Appearance Returns to Another Theme

When System is selected, the interface follows the computer or device theme.

Select Light or Dark directly when a fixed appearance is preferred.

Also confirm that browser privacy settings are not clearing saved preferences.

19.115 Customer Account Security Checklist

Customers should regularly confirm:

  1. The profile name is correct.
  2. The email address is current and verified.
  3. The password is unique.
  4. Two-factor authentication is enabled.
  5. Recovery codes are stored securely.
  6. KYC information is current.
  7. Expiration and renewal notices are reviewed.
  8. API keys have clear names.
  9. Unused API keys are deactivated or deleted.
  10. Allowed domains are restricted.
  11. Exposed keys are rotated.
  12. Agents use separate accounts.
  13. Former personnel no longer have access.
  14. Billing and credit activity is reviewed.
  15. Important data is exported before account deletion.

19.116 Chapter Summary

The Customer Settings section controls account identity, login security, verification, visual preferences, language, integration credentials, and account deletion.

Customers can update their name and email address from Profile Settings. Changing the email removes its verified status and requires verification of the new address.

Password Settings require the current password, a new password, and matching confirmation. Password updates are rate-limited.

Two-factor authentication uses a compatible authenticator application, QR code, rotating six-digit codes, and recovery codes. Recovery codes should be stored securely and regenerated when exposed.

KYC Verification contains Basic and Business tiers. Basic verification confirms a telephone number through a six-digit SMS code. Business verification requires business details, identification, a business document, and a selfie with identification.

Basic verification provides access to standard calling and contact features under current limits. Business verification provides access to AI Agents, Knowledge Bases, and other advanced functions.

Appearance Settings provide Light, Dark, and System themes. The language selector displays languages activated by the platform administrator.

Customers and Administrators can create API keys. Keys may be Live or Test, Active or Inactive, domain-restricted, permission-limited, and optionally assigned an expiration date. API keys must be stored and rotated securely.

Account deletion requires the Customer’s current password and is treated as permanent. Customers should export all required data and resolve telephone, campaign, Agent, billing, and integration matters before deleting the account.

Write Your Comment