KH Connect

Admin control plane

Forgot password

A reset link is emailed to you. It changes the password only — your authenticator is still required to sign in.

Email is not configured on this deployment. The owner can set a new password at the iam host:
iam passwd -email you@… -reason "forgot"

Choose a new password

At least 12 characters. Every session is signed out; you will sign in with the new password and your authenticator.

Lost your authenticator?

Still have a recovery code? — it replaces the code once.

Otherwise we email you a link to add a new authenticator. You will also need your password or a recovery code; the email alone is never enough.

Email is not configured on this deployment. The owner re-enrols you at the iam host, with you present:
iam mfa-reset -email you@… -reason "lost phone"

Replace your authenticator

Prove it is you with ONE of your recovery codes. Your password cannot replace an authenticator — whoever reads your email could reset it. No codes left? Ask the owner to reset your authenticator at the host (iam mfa-reset).

Replacing your authenticator pauses changes (root, car writes, OTA, APKs, operators) for 48 hours. Viewing keeps working.

Scan with Google Authenticator (or any TOTP app). Your current authenticator keeps working until this one is confirmed.

Finish setting up

Checking…

Choose your own password. The one you were given works once and is now finished with.

Scan this with Google Authenticator (or any TOTP app), then type the code it shows.

Until both are done this account has no session and can do nothing at all — not here, not in the phone app.

Welcome to KH Connect

Checking your invitation…

1. Scan this with Google Authenticator (or any TOTP app).

2. Choose your password (at least 12 characters).

3. Enter the first code the app shows.

Your recovery codes

Each signs you in once in place of your authenticator. Store them offline now — they are shown once and never again.

    Download as a text file

    Developed by Khalid Aboelmagd

    KH Connect control plane
    connecting…
    ⚠ iam is in RELAXED (bring-up) mode: car writes are not asked for the PIN or a fresh code by iam, and OTA push is refused. Signing in to this plane still requires your authenticator. Turn GEN5W_IAM_RELAX_OWNER off for production.
    You signed in with a recovery code. If your authenticator is lost, replace it: sign out → “Lost your authenticator?”, or ask the owner to run iam mfa-reset. Check how many codes you have left under Account.
    ⚠ This account completed an account recovery or an authenticator replacement. Changes — root, car writes, OTA, APK uploads, operators — are paused until . Viewing still works. If this was not you, tell the owner now: the owner can freeze the account at the host (iam mfa-reset -no-enrol).
    You signed in with your password only. Viewing is open; every change — a car command, a version probe, an OTA push, a credential, role or operator change — asks for your password and a fresh authenticator code at the moment you make it. A code works once: if one is refused, use the next.

    Fleet

    Car

    Cellular radio

    The head unit owns this model; a tick is written to the car and read back (rule 28).

    A code works once: if you just used it (to sign in), wait for the next one.

    One timing model, owned by the HU. Value = in force (measured); Stored = what was set. A blank Value means nothing can measure it now (rule 14).

    A code works once: if you just used it, wait for the next one.

    SMS wake centre — read only here

    The number whose SMS the modem treats as the telematics centre, read back from modem NV with AT+MBCNTCFG?. This is what wakes the car when it is parked. There is no setting for it on this screen — the modem holds one entry, so writing a new number retires the old one at once, and nothing here can tell a right number from a wrong one. It is not unreachable: an admin can run car-link -ask WAKECFG <number> from the Root tab, which does exactly that write with no validation and no record — see the note below. Reading this panel needs the admin role, because the read puts a command on the car's modem AT channel.

    Runs as root over car-link's recovery exec (the rule-29 sanctioned exception). Direct-to-khroot over the SIM is not deliverable yet and is refused, never faked.

    A code works once: if you just used it, wait for the next one.

    
          

    car-link version is measured from the live session; the rest need a probe (a fixed read-only -version). An HU-side publisher is owed.

    OTA & component versions

    APK hosting

    Hosting only — an upload changes no car. Install is the OTA path's job.

    Operators

    Who may use this plane. iam owns the list and decides every change: the owner invites admins and viewers, an admin invites viewers; nobody acts on themselves or on a higher rank. The owner is created only at the iam host.

    Invite an operator

    Create an operator and hand over a password

    For when email is not configured. You choose the address; this plane generates one password for you to give them IN PERSON. It works ONCE and expires. At that sign-in they must set their own password and scan their own authenticator before the account becomes a live operator — until both are done it can open no session at all.

    Known trade-off: you will know their first password, so in principle you could complete their setup yourself. The emailed invitation above exists to make that impossible. The IP that finishes the setup is recorded.

    Temporary password — shown ONCE, hand it over in person:

    My account

    Recovery codes

    Regenerating retires every previous code. It costs your password and a fresh authenticator code.

      Change password

      Every session is signed out afterwards. If an administrator gave you your first password, change it now.

      Operator audit

      The plane's own actions. iam keeps its own trail for authentication and control tokens; the token id joins the two.

      · Developed by Khalid Aboelmagd