> ## Documentation Index
> Fetch the complete documentation index at: https://docs.centipidbilling.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Portal access and profile

> Sign in with PPPoE credentials, understand the current phone-code limitation, and keep subscriber contact details current.

# Sign in to the customer portal

The portal currently presents two sign-in methods, but only PPPoE credentials provide a complete production sign-in path:

* PPPoE username and password.
* phone number plus a verification code, whose SMS delivery is not implemented in this version.

## Use PPPoE credentials

Enter the PPPoE username (maximum 191 characters) and password. This method is intended for a matching PPPoE subscriber account. If rejected, verify the exact credentials and account state through the operator profile; do not create a second subscriber as a shortcut.

## Phone verification-code limitation

<Warning>
  Do not direct subscribers to phone-code sign-in in production. The current screen can generate a code in the server session and write a development/testing log record, but it does not dispatch that code through an SMS provider.
</Warning>

The phone-code controls remain visible in the portal, but the flow is incomplete for subscribers who cannot inspect development records. Requesting a code is not currently rate-limited. Incorrect code verification attempts are rate-limited.

Until SMS dispatch is implemented and verified, subscribers without working PPPoE credentials need ISP support through an approved identity-verification and credential-recovery process. Operators must not retrieve a generated code from logs and disclose it as a production workaround.

## Expired links

Payment/access links expire for security. The expired-link page directs the subscriber toward portal sign-in. In this version, use PPPoE credentials when available; otherwise contact the ISP instead of relying on the incomplete phone-code flow.

## Update the profile

The phone number is displayed read-only in the current profile. The subscriber can update:

* first name (optional, maximum 60);
* last name (optional, maximum 60);
* email (optional, valid email, maximum 120);
* address (optional, maximum 300).

Phone changes require operator support so account identity and contact data can be protected. Before changing a phone, the operator should verify the subscriber using approved account evidence.

## Sign out and shared devices

Sign out after using a shared device. Do not save PPPoE credentials in an untrusted browser. If access is suspected to be compromised, contact the ISP and change credentials through the supported process.
