Signing In
Trinity requires a trinityailabs.com account. When you first launch the app, you'll see the login screen.
Device Code Flow
Trinity uses a device code flow for authentication — similar to how streaming apps sign in on TVs:
- Click Sign In in the Trinity desktop app
- A device code appears (e.g.,
BE279D70) - Click Open in Browser to open trinityailabs.com/desktop in your default browser — or click Copy Link to paste the URL in any browser or profile
- Log in on the website if needed
- The code is automatically confirmed
- Trinity detects the approval and signs you in
On a brand-new account, you'll see a Setting up your workspace checklist for about a minute right after authorization while Trinity provisions your personal database. After that you land in the app. Subsequent sign-ins skip this step.
The device code expires after 10 minutes. If it expires, click Cancel and start again.
If your account isn't in the beta. Trinity is running a closed beta, and only approved accounts can sign in while it does. If yours isn't one, the code is approved on the website but the app stops with a notice — "Trinity is currently in a closed beta" — and a join the beta program link that opens the application page in your browser. That's the end of that attempt: Trinity stops polling rather than retrying, and a fresh code gets the same answer until your application is approved. Once the beta opens, any account signs in and this state stops existing.
Choose Your Handle
If your account doesn't have a handle yet, the first thing you see after signing in is a full-screen Claim your handle to continue screen in place of the app. A handle is your unique @name — used for invites and identification across Trinity — and it's required, so there's no skip or dismiss: the screen stays until you save a valid one.
As you type, Trinity checks availability live and only enables Save for a well-formed, free handle (3–30 lowercase letters, numbers, and hyphens; no leading, trailing, or consecutive hyphens). Once saved, the gate clears and you land in the app. You can change your handle later from App Settings → Profile → Handle.
Tell Trinity What You Do
Once your handle is set, Trinity asks one short question: what do you do? Add a row for each thing that fits and set the level you work at on each — new, mid, or senior — so "I'm a senior dev and a mid designer" is two rows rather than a compromise. The roster covers the usual crafts: engineer/developer, designer, product manager, founder/business, data, QA, DevOps/infrastructure, marketing, student/hobbyist, and other.
Skip is a real answer. Click Skip and Trinity records that you'd rather not say, and the question never comes back — on this device or any other. The same goes for answering it: the question is keyed on whether your account has an answer at all, so you see it once, on whichever machine you sign in on first, and never again. Change it any time from App Settings → Profile → Details.
What it does: Trinity's agents read it as context about whoever is talking, so an explanation lands at the level you asked for instead of somewhere generic. In a shared conversation that's per person — the same answer can be pitched two ways to two people in it. It never changes what Trinity offers you, hides an option, or lowers the bar on the plan; saying you're new gets you more explanation, not less rigor.
Save Your Recovery Phrase
Right after you sign in on a brand-new device, Trinity shows a blocking Save your recovery phrase screen: 12 words that are the only way back into your account if every device is lost. Write them down and confirm you've saved them — there's no skip, and the screen returns on your next launch if you close the app first. An account that already confirmed its phrase (a second device you're adding, for instance) skips straight past this screen.
First-Time Workspace Setup
Every workspace you belong to needs three things before Trinity can work in it: a connected git account (Trinity creates repos and opens PRs as you, and a workspace grants repository access by account), a default destination (the host and organization new repositories land in), and the agent CLI your workspace's models run on. If any is missing when you enter a workspace, Trinity shows a setup screen in place of the app until it's done.
Set up Git for this scope comes first. You can:
- Click Use @you if Trinity finds a GitHub account your
ghCLI is already signed in to - Auto-import from your CLIs — pick from the accounts
gh,glab, orteaalready hold - Sign in with GitHub — connect a GitHub account by OAuth: Trinity shows a short code, you open GitHub and enter it to authorize Trinity, then Trinity finishes connecting the account
- Connect an account manually with a token, or through a guided CLI sign-in
- Install & sign into the GitHub CLI if you don't have
ghyet — Trinity walks you through it (and shows install instructions for Git itself if it's missing)
Where should new repos go? comes next: pick the host, the owner/organization, who you act as, and HTTPS or SSH. You can change this any time later in your git settings. Only owners and managers can set a workspace's default — if you're a member of a workspace that doesn't have one yet, you'll see who to ask and a Check again button; the app unblocks the moment it's set.
The agent CLI check comes last, once the git setup is done. Your workspace's four model tiers each name a model, and every model runs on either the Claude Code CLI or the Codex CLI — so Trinity checks that the one your tiers resolve to is actually on this machine. It's the same binary the in-app help assistant and Trinity's own setup helper use, so this check applies even before you open a project. If it's missing you get two fixes on the same screen: install it here (Trinity runs the install for you, step by step) or switch those tiers to a CLI you already have — one click, and Trinity moves only the affected tiers onto that engine's recommended models. Either way the screen clears on its own, with no restart.
Opening a project runs the same check once more, because a project can point its own tiers at a different engine than your workspace does. When it does, the retarget saves wherever the setting actually came from — your workspace settings if the project simply inherited it, your per-project overrides if the project set it for itself — and the screen tells you which before you click. Neither check ever blocks the Projects list, your Account page, workspace settings, or a project's own settings page, so the place to change the setting by hand is always one click away, and you can switch to a different project from the screen itself.
After the setup screens clear, you may still see a dismissible banner saying some accounts aren't set up on this device — that happens when an account you connected on another machine needs its credential here too. Click Set up here next to the account to fix it; it doesn't block you from working.
On a brand-new machine the banner instead asks you to approve this device first. A new device has to be approved before it can read your encrypted credentials, so until then every account looks unset — approving the device is the one thing to do first, and it clears the rest. Approve it from a machine you're already signed in on, or restore it on the spot with your recovery code, from App Settings → Profile → Devices.
Commit email per account
Trinity commits and tags as you, so each commit needs a real author email. For GitHub and GitLab that's derived automatically from your account. For providers that don't expose a public commit email — Bitbucket and self-hosted Forgejo/Gitea — you set one yourself, and Trinity won't commit until you do (it pauses at the Commit Email Needed gate rather than stamping the commit as an unknown user).
You can set it in two places:
- When you connect the account — the connect sheet shows a Commit email field for these providers. Click Check verified emails to pull the verified addresses on that account and pick one as a chip (or keep it private). You choose from your account's verified addresses — there's no free-text entry.
- Any time afterward — in your git settings' Git accounts list, open an account's menu and choose Set commit email (or Edit commit email). A "Commit email saved" confirmation appears when it's stored. The same menu has a Sync account info item that re-fetches your handle and display name from the provider.
The address must be a verified email on that host — only verified addresses are accepted, since a commit stamped with an unverified email lands as an unknown user. In a shared workspace, a member who still needs to set one shows as Email needed on the workspace's Project Access card (see Workspaces).
Recovery Phrase & Identity Key
App Settings → Profile → Devices gives you three everyday actions plus one break-glass one:
- Show recovery phrase — re-displays your 12 words on any device that already holds your identity key, no code entry needed.
- Regenerate recovery phrase — mints a fresh 12-word phrase and invalidates the one in place the moment it saves; your devices, workspaces, and identity key are unaffected, and you're shown the fresh words once.
- Rotate your keys — click Rotate keys to issue a fresh generation of your member key and every workspace key you hold, across every workspace you're in, with no device revoked. Use this if you believe a key may be compromised, or to finish a device revoke whose rotation didn't complete. There's no confirmation dialog — rotating mints a new key generation without touching the old one, so old ciphertext stays readable. It's a personal action available to any account holding its identity key, not something gated on being an owner or manager of a workspace.
- Rotate identity key — tucked under an Advanced disclosure, since it's the break-glass response to a stolen identity key rather than a routine action. Rotating swaps your account's whole identity keypair: every device you own is re-keyed, every workspace key you hold is re-issued (a workspace may need to re-grant access that was issued to the identity key you're leaving behind), and your current recovery phrase stops opening your account the moment the cutover lands. You're shown a fresh 12-word phrase to save once every key finishes re-issuing — if that doesn't finish in one pass, a Finish key rotation button stays on the card until it does.
Trinity emails you whenever a security-relevant event happens on your account: a device is added or revoked, your recovery data is accessed (which happens whenever a device restores from your 12-word phrase), your recovery phrase is regenerated, or your identity key is rotated. Each email names what happened and when, carries no key material, and points you back to Settings → Devices if it wasn't you.
Free Trial
While the closed beta runs, a beta seat stands in for the trial. An approved application comes with complimentary access for as long as the beta lasts, so there's no countdown, no card to enter, and no Subscription section on your settings page — and the pricing page isn't reachable.
Once the beta opens, new accounts get a 15-day free trial automatically — no credit card required. Your trial starts the first time you sign in. While trialing, you have full access to all features, and your settings page shows a countdown with days remaining. When the trial ends, Trinity shows a "Your free trial has ended" screen — subscribe at trinityailabs.com/pricing to keep your work and continue using the app.
Account Types
While the closed beta runs there's nothing to pick: access comes from an approved beta application and is complimentary for as long as the beta lasts, and the billing surfaces that would offer you a plan are hidden.
Once the beta opens:
- Free trial — 15 days of full access, auto-started on first sign-in
- Self-paid — subscribe at $20/month for continued access
- Sponsored seat — somebody else pays for your membership, offered from their Dashboard → Billing
Both paid types get the same features. One subscription per person.
Signing Out
Click your avatar (initials bubble) in the top-right corner of the sidebar header, then click Sign out.
Session Persistence
Your login persists across app restarts. You won't need to sign in again unless:
- You explicitly sign out
- Your session is revoked server-side
Trinity requires an active internet connection to do most things — all project data (PRDs, stories, recaps, etc.) lives on trinityailabs.com and is reached via the /api/* HTTP layer, so reads and writes both need connectivity. AI providers and git operations (push, PRs, merges) obviously need it too.
Multiple Accounts
Trinity supports signing in with more than one account simultaneously.
Adding an account
- Click your avatar in the top-right corner of the sidebar header
- Click Add account
- A new device code appears — open the link in any browser window (use Copy Link to open it in a different browser profile or incognito window)
- Approve the code on the website
- The new account appears in the account switcher
Switching accounts
Click your avatar → click any other account listed in the menu. Trinity switches the active session and reconnects to that account's database.
Signing out vs removing an account
Click your avatar → click Sign out at the bottom of the menu to sign out of the active account. The account stays in the picker so you can sign back in without re-entering your email.
To fully remove an inactive account from this device, click the × next to it. The account disappears from the picker and its local cache is wiped.