<a id="local-user-accounts"></a>

<a id="manage-local-user-accounts"></a>

# Manage Local User Accounts on Confluent Cloud

**RBAC role required**: [OrganizationAdmin](../../../access-control/rbac/predefined-rbac-roles.md#organizationadmin-role) or [AccountAdmin](../../../access-control/rbac/predefined-rbac-roles.md#accountadmin-role).

Create and manage local user accounts that sign in to Confluent Cloud and authenticate using

- [Local user: username/password](#local-user-username-password)
- [Local user: Sign in with Google](#sign-in-with-google-accounts)
- [Local user: Sign in with GitHub](#sign-in-with-github-accounts)

<a id="local-user-username-password"></a>

## Local user: username/password

### Create a local user (initial)

When you sign up for Confluent Cloud, you can create a local user account that authenticates

If you don’t have a Confluent Cloud account, you can create a local user account
authenticating using a username and password.

To create a local user in Confluent Cloud:

1. Go to the Sign-up page for Confluent Cloud at
   [https://confluent.cloud/signup](https://confluent.cloud/signup).
2. The **Welcome to Confluent Cloud** page appears.
3. To sign up for a new account, click **Sign up and try it for free**.
4. On the **Confluent Cloud** page, you can sign up and start using the account
   in minutes by completing the form, fill in values for your full name, organization,
   email address, and country. Then click **Start free**.

   A verification link is sent in an email message to the email address.
5. Open the email message received from `no-reply@confluent.io` with the subject
   header “Verify your email address <signup-email-address>”.
6. In the “Welcome to Confluent Cloud!” message, click **Verify email address**.

   You are redirected to Confluent Cloud to the **Let’s set up your password!** page.
7. In the **Create new password** section, verify the signup email address and
   enter a valid password based on the pop-up password requirements that appear
   when you click in the **Password** field.

   You can also review the password requirements in [Password requirements](#password-requirements-local-users).
8. Click **Continue**.

   You are redirected to the Confluent Cloud Console and are signed in to the Confluent Cloud Console.

   If you are not redirected to the Confluent Cloud Console, go to
   [https://confluent.cloud/login](https://confluent.cloud/login) and sign in
   using your email address and password.

<a id="add-local-user-console"></a>

### Add a local user account using the Confluent Cloud Console

If you have been granted the [OrganizationAdmin](../../../access-control/rbac/predefined-rbac-roles.md#organizationadmin-role),
[EnvironmentAdmin](../../../access-control/rbac/predefined-rbac-roles.md#environmentadmin-role), or [CloudClusterAdmin](../../../access-control/rbac/predefined-rbac-roles.md#cloudclusteradmin-role)
role, you can use the Confluent Cloud Console to add, or invite, a local user.

For SSO-enabled organizations, only a user with the [OrganizationAdmin](../../../access-control/rbac/predefined-rbac-roles.md#organizationadmin-role)
role can invite a user to a [local user account](#local-user-accounts).

1. Go to the Confluent Cloud Console and sign in using a local user account that has
   been granted an OrganizationAdmin role.
2. Go to **ADMINISTRATION > Accounts and access**. The **Accounts and access**
   page appears listing **User account**.
3. Click **Add user**. The **Add user** page appears.
4. In **Account**, enter the email address for the user and, optionally, grant
   one or more role assignments.
5. Click **Review** to verify that the email address and role assignments are
   correct, and then click **Create**.

The new user is sent an email message to verify their account.

#### IMPORTANT
An invitation for a user account expires 7 days after being sent.

For the maximum default quota on invitations (pending user accounts),
see [Organization quotas](../../../../quotas/service-quotas.md#ccloud-resource-limits-organization).

### Invite a user with Terraform

Invite a user by using the Confluent Terraform provider. For more
information, see [confluent_invitation Resource](https://registry.terraform.io/providers/confluentinc/confluent/latest/docs/resources/confluent_invitation).

<a id="password-requirements-local-users"></a>

### Password requirements

Local user accounts in Confluent Cloud and the [Confluent Support Portal](http://support.confluent.io)
require passwords that conform to the following restrictions:

- Minimum length of 14 characters.
- Must contain at least one character from each of the following four character types:
  - Uppercase letter (A-Z)
  - Lowercase letter (a-z)
  - Integer
  - Special character (`! @ # $ % ^ & *`)

Confluent Cloud local user accounts use [Auth0](https://auth0.com) for authentication. For details about password
strengths, see [Password Strength in Auth0 Database Connections](https://auth0.com/docs/authenticate/database-connections/password-strength).

<a id="sign-in-with-google-accounts"></a>

## Local user: Sign in with Google

You can create a local user account for Confluent Cloud that uses Google as your social
identity provider (IdP). This simplifies registration and sign-in as a convenient
alternative to mandatory account creation.

If your organization starts on Confluent Cloud using the “Sign in with Google” option,
you can migrate later to use SAML single sign-on (SSO). For more information,
see [Sign in to Confluent Cloud using SSO](../user-idps/sso/overview.md#sso-sign-in-to-ccloud).

### Use Sign in with Google to authenticate

You can sign up for a Confluent Cloud local user account with Google and then
you will be able to use Sign in with Google on every future visit.

To use Sign in with Google:

1. Go to the Sign-up page for Confluent Cloud at
   [https://confluent.cloud/signup](https://confluent.cloud/signup).
2. Click **Sign up with Google**.
3. On the **Choose an account** page, click on your Google account.
4. In the **Finish creating your Confluent account** section, enter values
   for your **Full name**, **Organization**, and **Country**.  **Submit** is now enabled.
5. Click **Submit**. You are signed in to Confluent Cloud and can now begin exploring
   and using the Confluent Cloud Console.

After registering your Google account with Confluent Cloud, you can sign in to Confluent Cloud by
going to the Confluent Cloud Console and clicking **Sign in with Google**.

<a id="sign-in-with-github-accounts"></a>

## Local user: Sign in with GitHub

Users can create a local user account for Confluent Cloud using GitHub as their social
identity provider (IdP). As a convenient alternative to mandatory account creation,
using Sign in with GitHub simplifies user registration and sign-in.

If your organization starts on Confluent Cloud using the “Sign in with GitHub” option,
you can migrate later to use SAML-based single sign-on (SSO).

### Use Sign in with GitHub to authenticate

You can sign up for a Confluent Cloud local user account with GitHub and then
you will be able to use Sign in with GitHub on every future visit. The
primary email address on your GitHub account will be associated with
your Confluent Cloud account.

To use Sign in with GitHub:

1. Go to the Sign-up page for Confluent Cloud at
   [https://confluent.cloud/signup](https://confluent.cloud/signup).
2. Click **Sign up with GitHub**. The **Sign in to GitHub to continue
   to Confluent Cloud** dialog appears.
3. Complete the **Username or email address** and **Password** fields
   and then click **Sign in**. The **Two-factor authentication** dialog
   appears.
4. Verify that you are signing in using two-factor authentication and,
   optionally, select the option to **Use this method for future logins**.
5. In the **Finish creating your Confluent account** section, enter values
   for your **Full name**, **Organization**, and **Country**.  **Submit** is
   now enabled.
6. Click **Submit**. You are signed in to Confluent Cloud and can now begin exploring
   and using the Confluent Cloud Console.

After registering your GitHub account with Confluent Cloud, you can sign in to Confluent Cloud by
going to the Confluent Cloud Console and clicking **Sign in with GitHub**.

<a id="change-authentication-method"></a>

## Change the authentication method

A local user account in Confluent Cloud can use one of three authentication methods:
[username/password](#local-user-username-password), [Google](#sign-in-with-google-accounts),
or [GitHub](#sign-in-with-github-accounts). After the user account is
created, only the user can change their authentication method.

To change the authentication method for your local user account:

### Confluent Cloud Console

1. Go to the **Settings** page in the Confluent Cloud Console at
   [https://confluent.cloud/settings/user-settings/identity](https://confluent.cloud/settings/user-settings/identity).

   You can also access your **Settings** page by opening the sidebar menu and
   clicking your user account name.
2. In the **Authentication settings** section, click the **Edit authentication
   settings** icon.

   The **Authentication type** and **Authentication method** options appear.
3. Select the authentication type you want to use: **username/password**,
   **Google** or **GitHub**.

   After you select a different option than the current selection,
   **Save Changes** is enabled.
4. Click **Save Changes**.

   The authentication type you selected is now active.

### REST API

OrganizationAdmin and AccountAdmin users can use the Confluent Cloud APIs to change
the authentication method for a local user account from local user to SSO
user.

```bash
curl --request POST \
  --url 'https://confluent.cloud/api/users/u-123/auth' \
  --header 'Authorization: Basic <base64 apikey:secret> or Bearer <token>' \
  --header 'content-type: application/json' \
  --data '{"auth_type":"AUTH_TYPE_SSO"}'
```

<a id="delete-local-user-account"></a>

## Delete a local user account

To delete a local user account:

1. Go to the Confluent Cloud Console and sign in using a local user account that has
   been granted an OrganizationAdmin role.
2. Go to **ADMINISTRATION > Accounts and access**.

   The **Accounts and access** page appears listing **User account**.
3. Find the user account you want to delete in the list of user accounts.
4. Click **Delete** for the user account.

The user account is deleted.

## Related content

- [User account types](overview.md#user-accounts)
- [Manage SSO User Accounts](manage-sso-user-accounts.md#manage-sso-user-accounts)
