Accounts and account types
There are four kinds of account. Everybody starts with the first one, two of the others are things you turn on when you need them, and the last is made for you by an employer. This page says what each one is, how you get it, and what changes when you do.
Which one you have
| Type | What it is | How you get it |
|---|---|---|
| Personal | One person, one workspace. Your documents, your connections, your workflows. This is what everybody signs up as. | You already have it. |
| Developer | Personal, plus the things you need to call DocButterfly from your own code: an API key, the testbed and the API reference. It comes with a second workspace of its own. | A switch on your Settings page. On and off, whenever you like. |
| Business | A company, with staff accounts on its own email domain, one shared allowance and one set of connections everybody uses. | You create it on Settings and then prove the company exists. Nothing works until you have. |
| Employee | An account a verified business made for you at your work address. It draws on the company's allowance and sees the company's connections. | Someone at the company invites you. You cannot make one yourself. |
You can hold more than one of these at once, and one person often does — a personal account at home and an employee account at work are two separate accounts with two separate sign-ins, and neither can see the other.
Three workspaces, and nothing is shared
One sign-in can hold up to three workspaces: your personal one, a developer one if you turn developer mode on, and your company's if you own or administer a business. Each is a separate store — its own vault, web forms, templates, connections, workflows, allowance and API key — and a document, form or key belongs to exactly one of them. Nothing is shared between them and nothing is copied: the switch at the top of the portal moves you from one to another, it never merges them, and regenerating a key in one leaves the others working.
Personal
The default, and for most people the only one they need. You get a workspace: a vault for documents, somewhere to keep connections to the systems you use, the workflow builder, web forms and templates. Nothing about it needs setting up beyond signing in.
Until you turn on developer mode you are never offered an API key. That is deliberate rather than a restriction — if you never intend to write code against us, a key is one more secret to look after for no benefit. Turn developer mode on the day you want one, and your personal workspace keeps a key of its own from then on, separate from the developer workspace's.
Developer
Developer mode is a switch on your own Settings page. Turning it on adds three things to your menu — your API key, the testbed where you can run any operation against your own account, and the API reference — and it creates a second workspace to keep them in.
Two workspaces, two vaults, two keys
This is the part worth reading twice. Your developer workspace has its own vault. A document written by a test call lands there, not beside your passport, and nothing in your personal vault can be read from the developer side. The separation is not a filter over one store — they are two stores.
Each workspace has its own API key, and the key page always shows the key of the workspace you are in. They are different keys: the developer one reaches the developer vault and nothing else, the personal one reaches your personal vault and nothing else, and regenerating either leaves the other working.
A switch in the portal says which workspace you are looking at. It is a convenience for moving between them; it never merges them, and it grants nothing on its own. The developer workspace is created the first time you switch into it.
Turning it off
Nothing is deleted. The developer workspace, its documents and its key stay exactly as they are, and the menu entries come back the moment you turn the switch on again. An employee account is the one exception: it has no developer mode to turn on, because its API access belongs to the business rather than to the person.
Business
A business account is a company on DocButterfly: a name, the email domains its people sign in on, and staff accounts created on those domains. Everyone in it draws on the same allowance and uses the same connections, so a workflow one person builds against the company's Dataverse works for everybody else without anybody setting it up twice.
You start one from your Settings page with “Make this a business account”. That creates the company and makes you its owner — and that is all it does, until the next part.
The company gets a workspace of its own, separate from yours: its own vault, its own web forms and templates, its own connections and allowance, and its own API key. Your personal workspace is untouched and stays yours. Once the business is verified you switch between the two at the top of the portal, and neither can read the other — a document you put in the company's vault is not in your own, and the company's key cannot open your personal one.
Proving the company exists
To verify it, upload one of the two letters the IRS issues for an Employer Identification Number:
- Form 147C — the EIN verification letter. This is the one you ask the IRS for when you need proof of a number you already have.
- CP-575 — the EIN assignment notice, sent once, when the number was first issued.
A PDF or a photograph is fine. We read four things off it: which of the two letters it is, the number, the legal name, and the date it was printed. If the legal name on the letter matches the name you gave the business, it is verified straight away and nobody at DocButterfly looks at it.
Two things are worth knowing about the name test. It ignores the company-type suffix, so Northwind Traders, L.L.C. and NORTHWIND TRADERS LLC are the same company. It is otherwise exact: Northwind Trading LLC is not, and a difference like that sends the letter to a person rather than being waved through on a near-enough score.
What we keep
Not the number. Only a masked form of it — the last few digits — is stored, and the whole number never appears in a record, a log, a notification or an email. The letter itself stays with the business for review, and only the owner and the admins of that business can open it: an employee of the same company cannot, and no other account can see that it exists.
When it does not go through
Every answer comes with a sentence you can act on, and there are three shapes of them.
| Answer | When, and what to do |
|---|---|
| Verified | The letter reads cleanly and the name matches. Nothing else to do. |
| In review | Something was readable but not certain — a name that does not match, a date that could not be read. A person at DocButterfly looks at it and either approves it or refuses it with a reason. The business still does nothing while it waits. |
| Not verified | The document is not one of the two letters, no Employer Identification Number could be read on it, the number already belongs to another verified business here, or the owner signs in at an address that cannot represent a company — a free mailbox provider, or a domain the business has not claimed. You can upload another letter and try again. |
A screenshot, a tax return or a state registration will not do. It has to be one of the two IRS letters, and the words on the page decide which one it is — not what you tell us it is.
Employee accounts
Once a business is verified, an owner or admin invites people from the Business page by typing a work email address. The address has to be on one of the business's own domains; a personal address is refused, which is the whole point of the domain list.
The person joins by signing in with that exact address — registering first if they have never used DocButterfly. What they get is their own account: their own sign-in, their own password, their own two-factor. What makes it an employee account is where its work is billed and stored: it draws on the business's allowance, sees the business's connections, and its usage shows up in the business's records.
A personal account is never taken over
If the same person already had a personal DocButterfly account under a different address, that account is untouched and stays theirs. It is not linked, not merged, and not visible to the company. Somebody who works at a company and also uses DocButterfly at home genuinely has two accounts, and that is the design rather than an oversight.
What an employee sees
Everything the company's workspace holds, plus the list of who else is in the business — deliberately, because their colleagues are spending the same allowance and hiding the roster would make that invisible. What they do not get is the controls: only an owner or an admin invites, removes or changes domains, and only they can open the verification letter.
When somebody leaves, an owner removes them. They lose the company workspace and keep their own personal account exactly as it was.
If the business stops being verified
Sharing the company's allowance is a state, not a one-time event. If a business's verification is taken away, its employee accounts stop drawing on its tokens, templates and connections straight away and work in their own account instead — nobody has to be removed one at a time. Nothing is deleted, everyone stays a member, and the moment the business is verified again every account goes back to it on its next request. Each affected person is told, in a line that says what changed and does not name why the business lost its verification.
Email domains
A business invites people on its domains, so which domains it holds is worth being careful about. There are two ways to add one, and they are not equally strong:
| How it was added | What it takes, and when you can use it |
|---|---|
| Somebody here signs in on it | An owner or admin whose own DocButterfly address is on the domain. That is the strongest evidence there is and the domain is usable straight away. |
| A DNS record | For a domain nobody in the business signs in on. Publish the value the page shows you as a TXT record on that domain, then press Verify. Nobody can be invited on it until the record is found, and it is read again every week. |
Domains are not checked at all until the business itself is verified, and they show no badge before then. A green tick beside a domain would read as the company having been checked, and at that point it has not been.
What each type can do
| Personal | Developer | Business | Employee | |
|---|---|---|---|---|
| Vault, connections, workflows, forms | Yes | Yes | Yes | Yes, the company's |
| API key, testbed, API reference | No | Yes | Yes | No |
| A second, separate workspace | No | Yes | Yes, the company’s | No |
| Creates staff accounts | No | No | Once verified | No |
| You can switch to it yourself | Yes | Yes | You start it; verification decides | No — you are invited |
Setting any of this up is free. Making an account, turning developer mode on, creating a business, verifying it and inviting staff cost nothing, and none of it spends your allowance.