Customer portal and teams
Let customers manage devices, team members, plans and invoices on their own. How the Keygate customer portal, seats and sign in rules work.
Every Keygate install comes with a customer portal at BASE_URL/portal. Customers use it to find their keys, manage their devices and team, and handle billing without writing to you. It carries your site name and logo, and it is translated into English and Chinese.
Signing in
Customers sign in with the email address their license was issued to. Keygate emails them a six digit code that is valid for ten minutes, so there are no passwords to reset. Link to the portal from your app's help menu and from your website so people can find it when they need it.
What customers can do
| Task | Where in the portal |
|---|---|
| See their licenses, keys, plans and end dates. | Licenses |
| Free a device they no longer use, such as a lost or replaced laptop. | Active Devices on the license |
| Add and remove team members. | Team Members on the license |
| Switch plans, for example from monthly to yearly. The change applies once they confirm it, and Stripe prorates the difference. | Change Plan |
| Cancel a subscription at the end of the period, or at once. | Cancel Subscription |
| Download invoices, and update the card on a Stripe subscription. | View Invoices, Update Payment |
| Extend the update period of a perpetual license. | Renew updates |
The billing actions appear only for licenses paid through Stripe. See Selling with Stripe for what happens behind each of them.
Teams and seats
Seats are for SaaS and hybrid products. On those, Max Seats on the plan sets how many people may share a license, and 0 means no limit. The owner invites people by email from the portal; each invitee receives a link, signs in and joins the license.
Roles
- Owner: the person the license was issued to. Can do everything, including billing.
- Admin: can invite and remove other members.
- Member: uses the license but cannot change who else does.
When the seat limit is reached, new invitations are refused until a member leaves or the owner moves to a larger plan. Every change sends the seat.added or seat.removed webhook, so a SaaS backend can grant or withdraw access to the people on the team as it happens.
Who can sign in
By default anyone can request a login code. If the portal should only be for paying customers, open Settings, find Who can create an account and choose Only emails that hold a license. Keygate then stops sending codes to unknown addresses, which also keeps strangers from using your server to send mail. People who already have an account can always sign in.
Last updated October 4, 2026