# Finish creating your account {#top}

**Change** · `POST /v1/signups/complete` · MCP tool `complete-signup`

Send the token from your signup link, or the code your identity provider returned, to create your tenant. Your tenant, its organisation and its signing keys are created together. The answer contains your login name and secret for `login`; the secret is shown only once, so store it now. A signup link works once, for a limited time. Completing the same signup again creates nothing and returns the same login with `secret` set to null.

You do not need to sign in.

## Parameters

| Name | In | Required | Description |
|---|---|---|---|
| `signup` | body | yes | The signup ID that `signup` returned |
| `signup_proof` | body | yes | The token from your signup link, or the code your identity provider returned |

## Returns

A JSON object with these keys: `login`, `secret`, `carrier`, `tenant`, `identity_provider`, `scopes`, `tenants`, `organisation`, `organisation_keyid`, `tenant_keyid`, `guarantee`, `caller_authenticated`.

## Example request

```sh
curl -X POST https://api.tarsana.io/v1/signups/complete \
  -H "Content-Type: application/json" \
  --data '{"signup": "c7e7d896876644cf", "signup_proof": "TOKEN-FROM-YOUR-SIGNUP-LINK"}'
```

## Example response

```json
{
  "login": "you@example.com",
  "secret": "YOUR-LOGIN-SECRET",
  "carrier": "the secret field of the login operation",
  "tenant": "acme",
  "identity_provider": "email",
  "scopes": [
    "operate",
    "read",
    "submit"
  ],
  "tenants": [
    "acme"
  ],
  "organisation": "acme",
  "organisation_keyid": "52f4abfbd90c302b88a5e4d5c064359be50df2a216f0d65b2fa20126acd08648",
  "tenant_keyid": "b83885e535fd96136c6225f3faaf71c09ca752830e955da293769cfba0554bda",
  "guarantee": "namespaces are separated, callers are not authenticated",
  "caller_authenticated": false
}
```

## Errors

| Code | HTTP | What it means |
|---|---|---|
| [`invalid_parameter`](/api/errors#invalid_parameter) | 400 | A value in your request does not have the expected format, for example a submission ID that is not a spec hash. Check the value against the field's description and try again. |
| [`signup_refused`](/api/errors#signup_refused) | 400 | Your signup could not be completed: the link was already used or has expired, your identity was not confirmed, your email domain is not accepted, or this identity already has a login. The response says which; start a new signup, or sign in with your existing login. |
| [`tenant_taken`](/api/errors#tenant_taken) | 409 | This tenant ID is already taken. Choose a different ID. |
| [`tenant_refused`](/api/errors#tenant_refused) | 400 | This tenant ID is not allowed, or is not in the expected format. Use a different ID made of lower-case letters, digits, dots, dashes and underscores. |
| [`signup_not_configured`](/api/errors#signup_not_configured) | 503 | This way of signing up is not available on this Tarsana deployment. Choose another way to sign up, or contact Tarsana support. |
| [`rate_limited`](/api/errors#rate_limited) | 429 | You sent too many requests in a short time. Wait for the number of seconds in `retry_after_seconds`, then try again. |
| [`surface_fault`](/api/errors#surface_fault) | 500 | Something went wrong on our side. Try again later, and contact Tarsana support if it keeps happening. |
