# Confirming user identities Open **Users → Confirm user IDs**, or **Settings → User identities**. Administrator access is required. 1. Choose **Check all user IDs** to read the live Jellyfin and Seerr directories and check Jellystat user metadata. 2. Search by account name or ID, or filter by status. The results include raw Magent rows that the ordinary user directory may hide as duplicates. 3. Select accounts marked **Ready to review**. Check the Magent account, Jellyfin ID and Seerr ID in **Review selected links**. 4. Choose **Confirm and save links**. Magent checks the live mappings again before saving. If accounts, service settings or mappings changed, run a fresh check. The canonical external identity is the Jellyfin server ID plus Jellyfin user ID. Seerr is matched through its explicit `jellyfinUserId`; Jellystat must return the same user ID. Existing Magent Jellyfin or Seerr links take precedence. For existing Jellyfin sign-in accounts without a stored ID, a unique normalized Jellyfin username provides a **suggestion requiring administrator review**. Emails and email prefixes never establish an identity. Confirmation saves the Jellyfin link, Seerr user ID, Jellyfin server ID, timestamp and confirming administrator. Normal name-based sync cannot replace confirmed links. My Stats uses the saved Jellyfin ID for playback and the Seerr ID for requests. Changes to the authentication token format are outside this feature. Conflicts, duplicate accounts, ambiguous case/whitespace names, absent IDs and unavailable services cannot be confirmed. This workflow does not merge, delete or create user accounts in any platform. It does not rewrite playback or requests. Conflicting mappings need investigation before reconciliation. Jellystat checks cover IDs found in Jellyfin, Seerr and stored Magent links. They do not enumerate historical Jellystat-only users or playback records. Each run supports up to 3,000 identities, fetches complete Seerr pages, limits concurrent Jellystat requests to six, and stops checking Jellystat after 25 seconds. Unfinished checks remain unavailable, never verified. Results are not HTTP-cached and contain no credentials or raw playback history. All selected accounts are saved in one transaction. The server derives the destination IDs from a fresh check and verifies the database snapshot before writing; the browser only supplies the reviewed revision and selected Magent row IDs. ### Resolve a missing link Open **Users > Manage users > Review account links**, then **Check all user IDs**. For an account marked **Missing link**, choose **Resolve missing link**. Select the correct Jellyfin account by name and ID, then **Check selected account**. The preview checks Seerr's explicit Jellyfin ID, Jellystat's matching ID, and every Magent account (including hidden duplicates) for ownership conflicts. Review the IDs and choose **Confirm and save link**. Magent rechecks live services and the local directory before atomically saving both links and the administrator audit record. A changed preview must be checked again. Existing confirmed or conflicting stored identities cannot be replaced using this flow. Missing upstream records must be corrected in their service before confirmation is available. No accounts are created, merged or deleted; emails are not used to infer identity. ### User Management and repairs Identity checks now live at **Config > User management > Account links & repairs**. The old `/admin/identities` link redirects there. Choose **Review repair** on a missing or conflicting account, select the authoritative Jellyfin identity, and preview the current and proposed Magent links. Saving rechecks live service IDs, all local owners, the server identity and concurrent changes. Repairs retain an atomic before/after audit in `user_identity_repairs`. Changing a Jellyfin identity revokes identity-bound email subscriptions; users must opt in again. If a person has never had a Seerr account, explicitly choose the single-account import option and preview again. Confirmation imports only that Jellyfin ID via Seerr's supported API and rechecks its resulting Seerr ID before saving Magent. Seerr and Magent cannot share a transaction: if an import succeeds but the local save fails, the imported account is retained and the administrator must recheck. No automatic deletion or rollback of upstream accounts is attempted. For an existing Seerr account with a different Jellyfin ID, inspect its ID in the preview and reconnect that existing account in Seerr using the account owner's Jellyfin sign-in. Magent cannot rewrite Seerr's Jellyfin ID through the normal admin user-update endpoint. Do not import another account to bypass a mismatch. Duplicate Magent owners remain blocked until the ownership conflict is resolved; this workflow does not merge users, permissions, requests or playback history.