# signup Self-service signup uses `POST /api/auth/register` and the `/register` frontend route. It is disabled unless `Auth:AllowRegistration`/`AUTH_ALLOW_REGISTRATION` is enabled. When Cloudflare Turnstile keys are configured, the server validates the widget token through Siteverify before creating the account. Production activation is intentionally blocked until the operator supplies Turnstile configuration; see `BLOCKERS.md`. Email verification can also be required before the first login.