Skip to content

Accounts & Licensing ​

Clusto requires a license. This page covers creating a Clusto account, claiming the permanently free Personal plan, buying Pro or Team, activating the desktop and mobile apps, signing in on the web client, managing devices, and what happens when a license goes offline, expires, or is revoked.

Accounts ​

  • Register at clusto.app/register. Public registration does not require an invitation or access code during normal operation. Registration and password management always happen on the website, not in the app. Open the verification link Clusto emails after registration before signing in. An unverified account cannot sign in with email and password or claim the Personal plan.
  • Manage your account, license, and devices at clusto.app/account.
  • Sign in inside the app from the full-screen license gate shown on first launch, or later via Settings > Account. Sign in with your email and password, or with Continue with GitHub.

Clusto may temporarily require an access code for new registrations during an abuse or service incident. If the registration page asks for one, new sign-ups are temporarily restricted until public registration reopens. Existing account holders can continue to sign in normally.

Using the website on smaller screens ​

On a phone or narrow window, open the navigation menu to reach Account and the other website pages. Press Escape to close the menu and return keyboard focus to its button.

Administrators can switch sections using the tabs on the admin page. Wide tables scroll horizontally within their own area so all columns and row actions remain available. With a keyboard, tab to the table's scroll area and use the arrow keys to reach columns outside the current view.

Signing in with GitHub ​

Continue with GitHub works everywhere: the web client, and the desktop and mobile apps.

  • Web client - stays on the site: you are redirected to GitHub and back to the app, all in the browser.
  • Desktop / mobile app - opens your system browser to complete the GitHub sign-in, then hands the session back to the app automatically over a clusto:// link. Approve the prompt to reopen Clusto if your browser asks. Once signed in, a device with an available license seat is activated automatically, same as an email sign-in.

The native callback never carries your Clusto session token. The app creates an unpredictable sign-in state and a PKCE verifier before opening the browser. After GitHub sign-in, the browser returns a one-time code that is bound to that PKCE challenge and expires after two minutes. The app checks the returned state, then exchanges the code over HTTPS. Reusing the code, presenting it from another client, or exchanging it without the verifier fails.

On Android and iOS, a successful sign-in should leave the browser and reopen Clusto. If the browser remains on the website, or Clusto reopens but stays signed out, update Clusto to the latest version and try again. Older mobile builds did not handle the browser callback correctly.

GitHub sign-in reuses an existing Clusto account with the same GitHub-verified email. Creating a brand-new account still goes through public registration; GitHub sign-in does not create a new account automatically.

The OAuth bridge keeps an allowlisted legacy route for the old Hive client. Clusto explicitly selects the clusto:// callback and Android package dev.vazac.clusto; omitted or unknown client values stay on the legacy route instead of becoming arbitrary deep-link schemes.

Managing your password ​

Signed-in users can manage their password on the account page:

  • If you joined with GitHub and do not have a Clusto password, enter and confirm a password under Password, then click Set password. Passwords must be 10 to 128 characters. You can then sign in with either your email and password or GitHub.
  • If your account already has a password, click Reset password. Clusto sends a secure reset link to your account email so you can choose a new password.

Transactional emails ​

Clusto sends account and sign-up messages, password resets, team invitations, and license notices from Clusto noreply@clusto.app. Replies are directed to the monitored support@clusto.app address. If an expected message does not arrive, check your spam folder and allow messages from noreply@clusto.app before requesting it again.

OpenRouter API key ​

Open Settings > Account > OpenRouter API, or press F1 and run Configure OpenRouter API key. This credential is independent of your Clusto account sign-in. One saved key is used by native OpenRouter chats and teams across the whole cluster. There is no node picker and no need to configure each node separately.

The key is write-only. Clusto reports whether the connected node is using the shared cluster key or a local environment fallback, but it never sends either value back to the app. Saving or replacing the key distributes it to every connected node and applies it to the next OpenRouter turn without restarting any daemon. A node that is offline during the change receives the latest value when it reconnects.

Clear stored key removes the shared key cluster-wide with the same immediate and reconnect-safe behavior. A node-level OPENROUTER_API_KEY is only a local fallback when no cluster key exists. Environment keys are not distributed and must be changed in each node's service environment. See Native OpenRouter API for environment, model, and runtime details.

Free Personal plan ​

Personal is permanently free for one verified Clusto account and one user. It includes activation on up to 3 devices and ongoing updates.

Claim Personal from clusto.app/pricing or the account page. Your email must be verified first. Claiming the plan creates the license directly and does not open Stripe or ask for payment details.

Earlier Clusto versions issued 14-day trial licenses. Existing trial licenses remain recognized for compatibility and still expire at the end of their original 14-day term. New account and pricing screens offer Personal instead of promoting a new trial.

License keys ​

New license keys use CLST-XXXX-XXXX-XXXX. Existing HIVE-XXXX-XXXX-XXXX keys remain valid during and after the rename overlap; both prefixes use the same checksum and activation rules. Personal includes one seat and up to 3 devices. Paid Pro and Team licenses carry the seat and device capacity shown at purchase. The web client does not consume a device slot - it checks the license on sign-in instead.

Pro and Team billing ​

Choose Pro or Team at clusto.app/pricing, then select Monthly or Annual billing. Both paid plans are subscriptions, completed securely on Stripe-hosted Checkout. Personal stays free and is claimed directly without Stripe.

PlanMonthlyAnnualCapacity
ProEUR 6EUR 591 user, up to 10 devices
TeamEUR 15EUR 1495 users, up to 99 devices per user

Team licenses can also share end-to-end encrypted connection profiles with every member. See Team Profiles.

Paid access lasts through the paid subscription period. Renewal extends that period after payment succeeds. There is no perpetual license or version you can keep using after a paid subscription expires.

Account owners can open the Stripe Customer Portal from the account page to manage payment methods, download invoices, switch plans or billing intervals, and cancel renewal. Cancellation takes effect at the end of the paid period, so access continues until that date.

Clusto activates a purchase only after Stripe verifies that payment succeeded. Returning to the website after Checkout does not activate a license by itself, so allow a short time for payment confirmation if the account page still shows the purchase as processing. A refunded payment, or a payment dispute that revokes the purchase, deactivates the license on its next online validation.

Activating desktop and mobile ​

The desktop (Windows / Linux / macOS) and mobile (Android) apps must be activated on each device. On first launch a full-screen gate asks for a license; after that, activation lives in Settings > Account. Two paths:

  • Sign in with your Clusto account (email/password or Continue with GitHub). The device is activated automatically using the account's license - no key to type.
  • Anonymous activation - enter the license key only, no account sign-in. Useful for machines you would rather not tie to an account session.

Activation stores an Ed25519-signed license blob on the device. The signature is verified offline on every launch, so day-to-day use does not need network access to the license server (see Offline behavior below).

Web client sign-in ​

The web client at clusto.app/app works differently: there is no device activation on the web. Instead you must sign in with a Clusto account that holds an active license. Without a licensed account, the web app does not let you past the sign-in gate.

Managing devices ​

Deactivate a device to free its slot:

  • From the account page - clusto.app/account lists every activated device with a deactivate action. Use this for devices you no longer have access to.
  • From the app - Settings > Account > Deactivate this device (requires being signed in).

Renaming a device ​

Each device in the account dashboard has a Rename button next to Deactivate. The license owner can rename any device on the license; a member can rename their own devices. Renaming only changes the label shown in the dashboard - it does not re-activate the device or consume a seat.

On smaller screens, device actions appear below the device details.

The desktop app reports its real machine hostname when it activates, so a new device lands in the list under a recognizable name. Earlier builds could register a generic label such as "linux-device"; rename any of those from the dashboard.

Website and API safeguards ​

Clusto enforces Personal-plan claims, legacy trial issuance, access-code use, license seats, team invitations, and device capacity in atomic PostgreSQL operations. Concurrent requests cannot claim a second Personal license for an account, mint a second legacy trial, redeem a bounded code too many times, or exceed the seat or device limits shown in the account dashboard. Expired invitations do not consume a seat.

Public and authentication-adjacent endpoints use shared PostgreSQL rate limits with atomic counter updates, so the limits remain effective across multiple website processes. Sensitive auth pages and API responses disable browser caching and referrer forwarding. The website also sends strict transport, content-type, framing, permissions, and Content Security Policy headers.

Offline behavior ​

  • The signed license blob is verified offline, and the app re-validates online periodically in the background.
  • Personal has a 30-day offline grace period from the last successful check. After that, reconnect so the app can re-validate the license.
  • Pro and Team require an unexpired paid subscription period. The 30-day offline grace never extends access beyond the paid expiry date. Connect after a renewal so the device can download its updated signed license.
  • Legacy trials expire 14 days after issue, regardless of offline grace.
  • Expiry returns desktop, mobile, and web clients to the license gate even if the app stays open. Leaving a client running does not extend paid access.

Troubleshooting ​

The app surfaces the license state in Settings > Account and on the license gate. The states you may see:

StateMeaningFix
ExpiredA time-limited license, including a legacy trial, is past its end date.Claim Personal or renew or buy a paid plan at clusto.app/pricing, then re-activate.
RevokedThe key was revoked (refund, abuse, key rotation). The next online check picks this up.Activate a valid key, or contact support if unexpected.
StaleNo successful online re-validation within the 30-day grace window.Get the device online once so it can re-validate; if the device is permanently offline, deactivate and re-activate it.
No seats / device limitEvery device slot on the seat is in use.Deactivate an old device from the account page, then activate again.

If sign-in fails on the web client with a valid account, check that the account actually holds an active license on the account page - a web sign-in without a license is rejected by design.

Clusto - remote AI coding agents over WebSocket.