OpenWorldLab

⚠️ Early Preview. This is a work-in-progress version of the site. Features are still being built and things may change or break. Your feedback is welcome!

User Profiles, Identity & Security Guide

Last updated August 2026

1. Academic Presence on OWL

Your OpenWorldLab profile is your public scientific identity. It bridges your verified academic credentials, published preprints and articles, micro-research updates (sparks), institutional affiliations, and group memberships into a single, cohesive academic portfolio.


2. The 15 User Types & Roles

OWL provides 15 tailored user categories ordered roughly by academic career progression:

Career Stage / RoleDescription
StudentStudying at undergraduate or masters level.
PhD CandidateWorking toward a doctorate.
Postdoctoral ResearcherHolding a doctorate and working on a fixed-term research appointment.
Research Staff / TechnicianSupporting research as permanent staff — technicians, engineers, data and lab managers.
Lecturer / Teaching FacultyFaculty whose appointment is primarily teaching.
Assistant ProfessorEarly-career faculty, typically pre-tenure. Equivalent to Lecturer in the UK.
Associate ProfessorMid-career faculty. Equivalent to Reader or Senior Lecturer in the UK.
ProfessorSenior faculty, typically leading a research group.
ResearcherDoing research in a role none of the more specific titles above describes.
Industry ResearcherWorking in research or development outside academia.
ClinicianPractising medicine or allied health, with or without a research role.
Science CommunicatorWriting about, teaching or broadcasting science to a wider audience.
EnthusiastHere out of curiosity rather than professionally.
InstitutionAn account representing an organisation rather than a person.
FunderFunding research — a foundation, agency or individual donor.

3. ORCID OAuth Verification

Cryptographic ORCID Authentication

To eliminate fake profiles and impersonation, OWL integrates directly with ORCID (Open Researcher and Contributor ID) via official 3-legged OAuth authentication.

  • Connect your ORCID iD by editing your public profile header.
  • You authenticate securely through the official ORCID authorization screen.
  • OWL records the cryptographically verified 16-character ORCID iD (e.g. 0000-0002-1825-0097).
  • Uniqueness Constraint: Exactly one OWL account can claim a given ORCID iD.
  • Your profile proudly displays the verified green ORCID badge linking to your official publication record.
1. ORCID OAuth

Researcher Identity

Cryptographic ORCID Integration

Required for group ownership & grant claims

Official 3-Legged OAuth

0000-0002-1825-0097

Verified ORCID Record

Key Guarantees:

  • Eliminates impersonation and automated bots
  • Strict 1-to-1 account uniqueness across the platform
  • Direct link to verified publication record
2. Email Challenge

Institutional Registry

Academic Affiliation Badges

Validated against global institution registries

Active Appointment Oxford
Past Affiliation MIT (2021–2024)

Key Guarantees:

  • Verified .edu / .ac.uk token
  • Automatic transition to 'Past' appointment badge
  • Prevents academic employment misrepresentation
3. 2FA TOTP Auth

Account Security

Two-Factor Authentication

Recommended for securing administrative lab access

Authenticator Code

482 910

2FA Active
1 Emergency Recovery Code

Key Guarantees:

  • Compatible with Google Auth, 1Password & YubiKey
  • Guards financial payout and administrative actions
  • Zero-knowledge recovery code mechanisms

4. Institutional Email Verification

Display verified badges for your current and past academic appointments:


5. Current vs Past Affiliations

Every affiliation is in one of two states, and which one it is decides how it appears to everyone else. The state is not a switch you set independently; it is read from the end date, so it can never disagree with the dates shown next to it.

Ending an affiliation never removes its verification

The tick means one specific thing: at some point you proved control of an address on that institution’s own domain. Leaving does not make that untrue, so the verification is kept and the badge simply changes tone.

  • You do not need access to the old address to mark an affiliation as past.
  • You do not need to re-verify if you later restore it to current.
  • Deleting an affiliation is a different action: it removes the record entirely, and re-adding it means verifying by email again, which is impossible once you lose access to the address. If you have simply left, mark it past rather than deleting it.
StateWhen it appliesHow it appears on your profile
CurrentNo end date, or an end date that has not passed yet (a contract with a known finish date is still current until that day).Emerald badge reading Verified Affiliation. Listed first.
PastAn end date that has already passed.Muted slate badge reading Verified Past Affiliation, with the end date in the tooltip.

How to mark an affiliation as past

  1. 1
    Go to Settings > Affiliations. Affiliations are grouped under Current and Past headings.
  2. 2
    On the affiliation you have left, click I’ve left.
  3. 3
    Confirm the last day you were there. It defaults to today, so if you have just left you can accept it as-is.
  4. 4
    Click Mark as past. The affiliation moves to the Past section immediately, and the badge on your profile changes tone.
Moved institutions and came back? Open the Past section and click I’m here again; this clears the end date and restores the affiliation to Current.

6. Profile Customization & External Links

Your OpenWorldLab profile is your public scientific identity. It gathers your laboratory affiliations, research publications, code repositories, and community channels in a unified header:

  • Avatar Photo: 1:1 square image (up to 1MB, automatically optimized to WebP).
  • Panoramic Cover Banner: 4:1 widescreen header (1920×480px, up to 2MB) for laboratory branding or research visuals.
  • Research Interest Taxonomy: Select up to 8 multi-level discipline paths (e.g. Physics / Quantum / Optics) to power discovery across topic feeds and job recommendations.
Intelligent URL & Handle Normalization

You can paste either a full URL (e.g. https://github.com/torvalds) or a plain handle (e.g. torvalds). OWL automatically extracts and stores the canonical identifier, preventing broken links and displaying crisp, direct links on your profile header.

4:1 Panoramic Cover (1920×480)
JD
1:1 (WebP)

Dr. Jane Doe

Associate Professor of Quantum Optics
iD ORCID 0000-0002-1825-0097
Verified Affiliation · Oxford
Topics: Physics / Quantum / Optics Nanophotonics 2D Materials (Up to 8 Paths)

Connected Academic & Social Links:

GitHub @janedoe-lab
Google Scholar Citations 1,420
arXiv 18 Preprints
LinkedIn /in/jane
4 Platforms

Code & Model Hubs

GitHub · GitLab · Hugging Face · Kaggle

Share research datasets, open weights & software repos

Auto-validates username format
9 Networks

Citations & Registries

Scholar · arXiv · Semantic · PubMed · OSF · Zenodo · DBLP

Permanent author bibliography and DOI cross-linking

Permanent author & DOI linking
12 Networks

Social & Discussion

Bluesky · Mastodon · Discord · YouTube · LinkedIn · X · Reddit

Direct public scientific communication and outreach links

Handles full URLs & usernames
4 Platforms

Code & Data Repositories

Connect version control and model weights:

GitHub: Handle or full profile URL

GitLab: Handle or full profile URL

Hugging Face: Organization/user handle or model link

Kaggle: Profile handle or dataset page

9 Networks

Academic & Citation Indices

Connect scientific indices and preprint registries:

Google Scholar: 12-character user ID or citations URL

arXiv: Author identifier (e.g. smith_j_1) or profile URL

Semantic Scholar & PubMed: Author ID or bibliography URL

Open Science Framework (OSF) & Zenodo: Project/DOI IDs

OpenReview & ResearchGate: Profile handle or vanity URL

DBLP: Computer science bibliography handle

12 Networks

Social & Community Channels

Connect public channels and discussion spaces:

Bluesky & Mastodon: Handle or instance account

LinkedIn & Threads: Profile URL or public slug

X (Twitter): Handle or profile link

Discord & YouTube: Server invite or channel handle

Reddit & Telegram: Subreddit, username, or channel


7. Sparks vs Articles

OpenWorldLab supports two primary formats for sharing scientific thought and published research:

Micro-Post

Sparks (Micro-Posts)

Fast, lightweight posts up to 1,024 characters, with up to 20 images or videos and an optional poll. Ideal for preliminary lab data, conference notes, quick questions to the community, or paper announcements. Sparks are not filed under research areas.

Long-Form Publication

Articles (Long-Form)

Full-length rich-text publications supporting formatted typography, LaTeX/mathematical notation, syntax-highlighted code blocks, embedded charts, and downloadable datasets.


8. Notifications & Preferences

Manage incoming alerts across five discrete notification categories in Settings > Notifications:

  • Social: Likes, bookmarks, replies, new followers, group invitations, and group-to-group link requests.
  • Chat: Direct researcher messages and synchronized group messaging channels under Messages.
  • Fundraising: Campaign review decisions, milestone goals, and backer pledges.
  • System: Platform announcements and content moderation notices.
  • Security: New device logins, password resets, and email modifications (mandatory alerts).

9. Security & Two-Factor Authentication (TOTP)

Protect your account and group administrative privileges with optional Two-Factor Authentication:


10. Recovery Codes

Recovery codes are how you get back into your account when your authenticator app is gone (like a lost, wiped, or replaced phone). Enabling 2FA takes you straight to the recovery codes page, where one click issues a set of 10 single-use codes, each looking like ABCDEFGH-IJKLMNOP.

A set rather than one code, because a single code cannot actually be spent: using it would leave the account with no way back in at all. With a set, each lockout costs one code and the remaining count is shown in your settings long before it reaches zero.

  • Single use: A code stops working the moment it signs you in. 10 codes means 10 recoveries before you need a new set.
  • Shown exactly once: They are stored hashed, the same way passwords are, so nobody, including our team, can display them again. Copy or download them when they appear.
  • Counted, not listed: Settings > Security (2FA) shows how many of the 10 remain, and warns you when three or fewer are left.
  • Regenerating replaces the set: Generating new codes invalidates every code you currently hold, including unused ones. Regeneration asks for a code from your authenticator first.
Enabled 2FA before August 2026?

Accounts enrolled under the older scheme hold a single recovery code. It still works, once. Settings > Security (2FA) flags this, and generating a new set replaces it with the full 10.

How to sign in with a recovery code

  1. 1
    Sign in with your email and password as usual.
  2. 2
    On the two-factor screen, click Lost your device? Use a recovery code.
  3. 3
    Type any unused code. Hyphens, spaces, and lower case are all fine: only the letters and digits are compared.
  4. 4
    You land on the recovery codes page, which tells you how many are left and lets you generate a new set.
Signing in this way does not disable two-factor authentication. If you have lost the authenticator for good, re-enrol a new device from Settings > Security (2FA) once you are in.

How to generate a new set

  1. 1
    Go to Settings > Security (2FA) and click Manage recovery codes.
  2. 2
    Enter the current 6-digit code from your authenticator app.
  3. 3
    Click Generate new codes and save the 10 codes shown.
Do this if you think your codes have been seen by someone else, if you are running low, or if you have lost the list.

11. Developer API Keys

Automate publications and integrate lab repositories using the RESTful Content API:

  • Key Format: owl_sk_<id>_<secret>.
  • Zero-Leakage Security: The secret is displayed once upon creation and stored exclusively as a SHA-256 digest in the database.
  • Endpoints: Authorized developers can create, list, and revoke programmatic keys via /api/v1/keys or request developer access via our Contact Form.

12. Profile FAQs