Sign in and secure your account
Sign in to the Orchestrator, reset a password, set up two-step sign-in and passkeys, manage sessions and access tokens, and approve device sign-ins.
Everyone signs in to the Orchestrator web app with a username and password, a passkey, or single sign-on if your administrator set it up. Your profile has two pages: My account and Security, both in the avatar menu at the top right. Sign in# Open your Orchestrator address, for example https://orchestrator.example.com. Enter your Username and Password, then select Sign in. Or select Sign in with a passkey if you added one. Or select Sign in with your provider if your organization uses single sign-on. If you use two-step sign-in, enter the Code from your authenticator app (or a recovery code) and select Verify. If you have a passkey you can select Use a passkey instead. New to the Orchestrator?You need an account first. Ask an administrator for an invitation. When you follow the invitation, choose a Username, enter your Full name and a Password, and select Create account. An invitation is valid for 72 hours. If your organization requires two-step sign-in and you have not set it up, the sign-in asks you to do it now: scan the QR code with an authenticator app, enter the Code from the app, and save the recovery codes it shows. Reset a forgotten password# On the sign-in page, select Forgot password?. Enter your Username or your Email, then select Send reset link. Open the email and follow the link. It is valid for 30 minutes. Enter a New password, repeat it in Confirm new password, and select Update password. Sign in with the new password. For security, the page answers the same way whether or not the account exists. No email? Ask your administrator: the Orchestrator must be able to send mail, and an administrator can also send you a reset link (see Users and roles). Update your profile# Select your avatar (top right) ▸ My account. Under Profile picture, select Upload picture to add a photo. Under Profile details, change your Display name, Preferred timezone or Theme, then select Save changes. Email and Roles are read-only here. Under Notifications, choose how alert emails reach you: One email per alert, Hourly digest or Daily digest, and adjust each category (failed jobs, dead-lettered jobs, offline robots, failed queue items, alert rules). Change your password# Select your avatar ▸ Security. Under Change password, enter your Current password, a New password and Confirm new password. Select Change password. The Last sign-in card at the top shows when your account was last used. Set up two-step sign-in# Select your avatar ▸ Security. Under Two-step sign-in, select Set up. Scan the QR code with an authenticator app (or type the secret shown under it). Enter the 6-digit Code from the app and select Verify. Copy or print the recovery codes, then select Done. Each code signs you in once if you lose your authenticator, and they are not shown again. Later, New recovery codes replaces your codes, and Turn off removes two-step sign-in (both ask for a current code). Turn off is not offered when your organization requires two-step sign-in. Add a passkey# A passkey (Windows Hello, a phone or a security key) can replace your password at sign-in and also works as your second step. Select your avatar ▸ Security and scroll to Passkeys. Select Add passkey. Give it a Name, such as Work laptop, and select Continue. Follow your browser's prompt. To remove a passkey, select the remove button next to it. It stops working at once. Sign out other sessions# The Sessions list on the Security page shows every browser signed in as you, marked This session or Other device. Select Log out other sessions to end all of them except the one you are using. Create a personal access token# Use a personal access token for scripts, CI and the Python SDK. Select your avatar ▸ Security and scroll to Access tokens. Select Create token. Enter a Name (for example Build agent), pick the Tenant, the lifetime in Expires in (30, 90, 180 or 365 days) and the Permissions. Select Create token, then copy the token. It is shown only once. A token can never hold more permissions than you hold in that tenant. To revoke a token, select the revoke button next to it; anything still using it stops working at once. See Authentication. Approve a device sign-in# Studio, the Assistant and the Python SDK sign in through your browser. When one of them shows a code: Open the link it gives you. You sign in to the Orchestrator if you are not already. Check that the Code shown on the device matches what you see on your own screen. If you belong to several tenants, pick the Tenant. Select Approve, or Deny if you did not start this sign-in. Return to the app. It finishes signing in on its own. Only approve your own codesApproving gives that device access as you. Never approve a code someone sends you. The page says what approving grants; a Python SDK sign-in, for example, becomes a personal access token you can revoke under Security ▸ Access tokens. Next steps# Users and roles for sign-in rules, single sign-on and SCIM Sign in to Orchestrator from Studio Manage access
Sign in
Reset a forgotten password
Update your profile
Change your password
Set up two-step sign-in
Add a passkey
Sign out other sessions
Create a personal access token
Approve a device sign-in
Next steps