Create an account

LowRouter accounts are individual: one email, one identity, one credit balance. Team accounts and shared workspaces are on the roadmap; until they ship, share access via separate API keys rather than shared credentials.

Get an invite

LowRouter is in invite-only beta. Self-service sign-up is closed, so visiting the register page without an invite shows a waitlist form rather than a sign-up form. Join the waitlist there and we’ll email an invite link when a place opens up.

The invite link is single-use and expires. It takes you straight to the sign-up form with your email already filled in.

Sign up

Follow the invite link and fill in:

  • Email: used for verification, sign-in, and billing receipts.
  • Password: a strong, unique one. The full policy is below.
  • Country: used to compute the right tax treatment on invoices. You can correct it later from the settings page.

Alternatively, sign in with a federated identity provider listed on the sign-up page. Federated sign-in does not change anything about how your data is stored; see the privacy policy for details.

Password policy

A password must be at least 8 characters and contain at least one of each of:

  • an uppercase letter (A to Z)
  • a lowercase letter (a to z)
  • a digit (0 to 9)
  • a symbol, meaning anything that is not a letter or a digit (!, ?, -, #, and so on)

There is no maximum length, and no character is forbidden. Every rule is enforced server-side as well as in the form, so a password that fails one is rejected with a 400 naming the rule it missed rather than a generic error.

Verify your email

After registration we send a verification link. The link is valid for 24 hours. Until you verify, you can sign in but you cannot create API keys or top up credits. This guards against typos and disposable-mailbox sign-ups.

If the email doesn’t arrive, check spam, then use Resend verification on the sign-in page. If it still doesn’t arrive, contact support at the email on the legal page.

Top up credits

LowRouter is pre-paid. To send a request you need a non-zero credit balance.

  1. Go to the Credits page.
  2. Click Add credits.
  3. Pick an amount and complete the Stripe-hosted checkout.

Credits land in your account when Stripe confirms the payment, usually within a few seconds. The credit amount you pick is exclusive of the top-up fee and VAT. Checkout adds a single fee (5.5% + €0.30 with a verified EU VAT number, 6.5% + €0.30 in the EU/EEA without one, 8.5% + €0.30 outside the EU/EEA) and itemizes the total before you pay. Stripe (the seller of record) adds VAT and issues the invoice that lands in your inbox. Add your VAT number under Tax details on the credits page, or at checkout, before you top up; verification takes a moment. Worked examples are on the pricing page.

The full pricing model is documented in credits and billing.

Protect your account

Once your account holds credits, protect it: anyone with your session could create a key and spend them. On the Security page you can add:

  • A passkey (recommended). Stored on your device or in your password manager, it signs you in with a single tap and no password. It only works on this site, so a look-alike domain gets nothing, which makes it phishing-resistant. Add one per device you sign in from, and use Sign in with a passkey on the login page.
  • An authenticator app (fallback). Six-digit codes from an app such as Aegis, 1Password or Google Authenticator, for devices with no passkey support.

Neither is required. After your first top-up the dashboard shows a reminder until you add one or dismiss it (it comes back after a week while the account still holds credits). SMS codes are not offered: SIM swaps are a documented attack on exactly this kind of account.

Once you have a passkey or an authenticator app, signing in with your password or a connected provider also asks for it. Signing in with the passkey itself is a single tap and asks for nothing else.

Setting a first password on an account created through Google, GitHub, GitLab or Microsoft asks you to confirm it’s you first: with your passkey or authenticator app if you have one, otherwise by signing in again with that provider.

The confirmation covers only signing in and setting a first password. The actions that spend or expose credits once you are signed in (creating a key, changing your email, connecting a provider) are being extended to ask for the same confirmation; until that ships, keep your session and API keys private as you would today.

What’s stored

After sign-up the platform stores:

  • Your email address (sign-in, billing receipts).
  • A salted hash of your password (never the plaintext). Passkey public keys and authenticator-app secrets live in the identity provider; the passkey’s private key never leaves your device.
  • The country and any billing details you provided.
  • A unique numeric user ID used internally.

We do not store any prompt or response content. Token counts, model IDs, provider IDs, regions, latencies, and the eco numbers are stored per request; see usage accounting for the full schema.

Next

Create your first API key →