Skip to content

Account Setup and Login

WebDecoy uses Auth0 for secure authentication. You can create an account using your email address or sign up with Google, GitHub, or other social providers.

  1. Navigate to WebDecoy

    • Go to https://app.webdecoy.com
    • Click the Sign Up button
  2. Choose Your Sign-Up Method

    • Email/Password: Enter your email and create a password
    • Social Login: Click Google, GitHub, or another provider to use your existing account
  3. Verify Your Email

    • Check your inbox for a verification email
    • Click the verification link to activate your account
  4. Complete Your Profile

    • After verification, you’ll be redirected back to WebDecoy
    • Your account is now ready to use

If signing up with email/password:

  • Minimum 8 characters
  • At least one uppercase letter
  • At least one lowercase letter
  • At least one number
  • At least one special character

  1. Go to the Login Page

    • Navigate to https://app.webdecoy.com/login
  2. Enter Your Credentials

    • Enter your email address
    • Enter your password
    • Or click a social login provider
  3. Complete Authentication

    • You’ll be redirected through Auth0’s secure login flow
    • After successful authentication, you’ll land on the dashboard

If you signed up with a social provider:

  1. Click the provider icon (Google, GitHub, etc.)
  2. Authorize WebDecoy to access your basic profile
  3. You’ll be automatically logged in
IssueSolution
Forgot passwordClick “Forgot Password” on the login page and follow the reset instructions
Email not verifiedCheck spam folder for verification email, or request a new one
Social login not workingEnsure you’re using the same provider you signed up with
Account lockedContact support after too many failed login attempts

When you log in for the first time, WebDecoy guides you through initial setup.

Login → First-Time Check → Onboarding → Dashboard
Existing user? → Dashboard directly

After your first login, you’ll see the onboarding screen:

  1. Enter Organization Name

    • Choose a name that represents your company or project
    • Examples: “Acme Corp”, “My E-commerce Site”, “Development Team”
    • Minimum 2 characters, maximum 100 characters
  2. Click Create Organization

    • WebDecoy creates your organization
    • A default property called “Default Property” is automatically created
    • You’re automatically added as the organization admin
  3. Trial Subscription Started

    • Your 14-day free trial begins automatically
    • Full access to all features during the trial
    • No credit card required to start

After organization creation, you’re taken directly to the dashboard where you can:

  • View the navigation sidebar
  • See your organization name and current property
  • Start creating decoys and configuring protection

When you create your organization, WebDecoy sets up:

ResourceDescription
OrganizationYour account container
Default PropertyA property to organize your first resources
Trial Subscription14-day trial with full feature access
Admin MembershipYou’re automatically the organization admin

  1. Click your user avatar in the bottom-left of the sidebar
  2. Select Profile from the dropdown menu

Your profile displays:

  • Name: Your display name (from Auth0 or social provider)
  • Email: Your login email address
  • Avatar: Generated from your initials or social profile picture
  • Current Plan: Your subscription tier (Trial, Starter, Pro, Enterprise)

Profile information is managed through Auth0:

  • Change password: Use Auth0’s password reset flow
  • Update email: Contact support to change your login email
  • Social connections: Manage connected accounts through your social provider

To log out of WebDecoy:

  1. Click your user avatar in the bottom-left of the sidebar
  2. Click Logout
  3. You’ll be redirected to the login page

Your session will also expire automatically after a period of inactivity for security.


WebDecoy implements several security measures:

FeatureDescription
JWT TokensSecure token-based authentication
Token ExpirationSessions expire after inactivity
HTTPS OnlyAll communication is encrypted
Auth0 SecurityEnterprise-grade authentication provider
  • Use a strong, unique password
  • Enable two-factor authentication through your social provider if available
  • Log out when using shared computers
  • Don’t share your login credentials

Now that you’re logged in, let’s set up your organization: