Getting started
Create a GuwinUS ID, sign in, then use Account to choose Standard or Expert presentation. Your experience setting changes what technical detail is shown; it never grants permissions.
Security
Use an authenticator app for TOTP MFA and add passkeys for phishing-resistant sign-in. Keep recovery codes somewhere safe and separate. Security events appear in Notifications; supported devices can receive Web Push.
Your digital ID
The ID Card uses an opaque, revocable QR credential. The QR itself does not contain your name, email, employer, job title, phone number, or account UUID. A signed-in scanner resolves it server-side and only receives fields you have chosen to share.
Organizations
Organizations group people and domains for business use. Owners and admins can manage members, roles, domains, and directory-source preparation from the Organization Manager. A member can belong to more than one organization.
Developer tools
Create API keys for server-to-server integrations and OAuth/OIDC applications for “Continue with GuwinUS”. Use the minimum scopes your integration needs. Confidential client secrets and API keys are shown only when created.
Privacy model
Applications should request only the identity data they need. GuwinUS keeps the core account stable while app-specific profile data stays namespaced by application key. Digital ID disclosure is controlled separately by the member.
