aice console Sign out

Your organizations

Sign in to see the organizations you own and their status.

Sign in with Google

Start your space

You are signed in and you do not own a space yet. Create one now — it takes a moment, costs nothing, and only your address can sign in to it.

Building your space

This takes up to a minute — a bucket, an identity pool and a front door are being created for you. This page updates itself when it is ready.

Address not verified

An organization is assigned to your address, but your identity provider did not confirm that the address is verified, so we will not claim ownership on your behalf. Signing in with a verified Google account resolves this.

Signed in with the wrong provider

An organization is assigned to your address, but it is bound to a different sign-in — another provider. Sign out and sign back in with that provider to see it. We will not move the binding for you: it is what stops a re-registered address from taking an organization over.

Sign out

Your organizations

    Could not load your organizations

    Something went wrong reaching aice. Reload to try again.

    ← Your organizations

    Address

    Your space answers on the addresses below. You can also claim one name of your choosing under aicex.app — it starts working the moment it is yours, alongside the address you already have.

      People

      Who can reach this organization, and who administers it. Adding someone here lets them sign in and publish; it does not make them an administrator.

      Loading who can reach this organization…

      Members

      Nobody is admitted by name — an allowed email domain below is what admits people here.

      Allowed email domains

      No email domain is allowed, so only the named addresses above can sign in.

      Administrators

      Their sign-in link

      Send them this link. It is not a secret — it only works for an address this organization admits.

      Adding another publishing identity

      See the paid plans

      Set up sign-in

      Sign-in for runs on your organization's own identity provider, so the accounts that can reach your space stay yours.

      Identity provider

      1. In the Google Cloud console, create an OAuth client ID of type Web application.
      2. Add the authorized redirect URI below, exactly.
      3. Add the authorized JavaScript origin below.
      4. Paste the client ID and secret Google gives you.
      1. In the Azure portal, open Microsoft Entra ID → App registrations and register a new application.
      2. Under Authentication, add a Web platform and paste the redirect URI below as its Redirect URI.
      3. Under Certificates & secrets, create a client secret and copy its Value — Azure shows it once.
      4. Under Token configuration, add the optional claim email to the ID token. Without it Entra sends no address and every sign-in is refused.
      5. Under API permissions, grant admin consent if your organization requires it.
      6. From the app's Overview, copy the Application (client) ID and the Directory (tenant) ID.

      Authorized redirect URI

      Authorized JavaScript origin

      The secret is passed straight to your space's identity pool and stored only there. It is never written to our records and never shown again.

      Custom domain

      Serve on a domain you own, like intranet.acme.com. You will publish two DNS records in your domain's zone; nothing about your space changes until the second one is in place, so a domain that is live elsewhere stays up while you set this up.

      Publish both CNAME records, exactly as shown. The first proves you own the domain and issues its certificate; the second sends visitors to your space.

      Names are shown in full; the Copy buttons give the zone-relative name, since most DNS providers append your domain themselves. Values copy exactly as shown.

      1. Certificate validation — record name: record value:
      2. Traffic — record name: record value:

      Your storage

      This space's content lives in — an S3 bucket your organization owns, in region . For it to serve and update, the bucket must grant this service access. Set that up below; every check runs live against the bucket.

      1. In the AWS account that owns the bucket, open its Permissions tab and set this bucket policy, exactly:
      2. Only if the bucket is encrypted with a customer-managed KMS key: merge these statements into that key policy (skip this otherwise):
      3. Check that the grant is live — cross-account permissions can take a minute to propagate, and checking again is always safe.

        Search by meaning

        Search normally matches the words on your pages. Meaning-based search also finds the passage that answers a question when the author used different words — and to do that, short passages of your page text have to be stored somewhere as vectors. Your pages themselves never move: they stay in the bucket above.

        Create it in your own account — aice attaches and verifies it, and never creates or deletes it. Re-apply the bucket policy above afterwards: it gains the vector grant.

        Branding

        Your space wears its default look. Branding lets you put your own colours, logo and type on every page it serves.

        Loading your organization's colours…

        Branding cannot be opened right now.

        Read your website and we will suggest the whole look — colours for light and dark, your typeface, your corners and your logo — or pick a colour and a logo yourself and everything else is derived for you. Open Palette or Advanced when you want more. Nothing changes on your space until you save, and Reset always brings your space's default look back.

          Every role, in both modes. Leave one alone and it keeps following your colour; change one and that single value is what gets saved.

          LightDark

          Type and shape. Typefaces come from a list we host ourselves, so your pages never call out to anyone else to render.

          Preview

          A page and a slide from your space, drawn with what you have picked. Nothing is saved yet.

          Light
          Dark

          Showing the last preview that passed. What is listed below has to be fixed before this can be saved.

            This clears your colours, logo and type. Your pages are untouched.

            Features

            What your organization allows. Every change here takes effect within about a minute, and none of them undoes anything that already happened.

            There are no organization features to change yet.

            Front page

            Who can change what your organization's front page says. The people you name here can set its opening line from their own agent — with aice root set-intro or the aice connector. Everyone else is refused, and so is everyone while this list is empty.

              Nobody can change your front page yet. Add someone below.

              Use an address that can sign in to your organization — the same address they use for aice, not the one you sign in to this console with.

              Billing

              What your organization is on, and how to change it. Publishing is never interrupted by anything on this page.

              Loading your billing details…

              Plan
              Authors
              Seats billed

              Adding an author

              Paid plans

              Manage your subscription

              Your plan, your payment method, your invoices and cancellation are all in Stripe's billing portal.

              aice console