Some organisations require password sign-in instead of one-time codes. If your organisation has this enabled, you'll use a password to log in, and may also need to complete a multi-factor authentication (MFA) step.
When password sign-in is required
Your organisation owner chooses the authentication method. If password sign-in is enabled:
You'll need a password to sign in on both web and the iOS app
One-time codes (OTP) via phone or email no longer work for your organisation
If you've never set a password, you'll be prompted to create one
Setting or changing your password
Go to Settings > Security on the web app
Under Password, click Change (or Set Password if you don't have one yet)
Enter your current password (if you have one) and your new password
Save - the new password takes effect immediately
Resetting a forgotten password
On the login screen, click Forgot password?
Enter your email address
Check your email for a verification code
Enter the code and create a new password
This works on both web and the iOS app.
Multi-factor authentication (MFA)
If your organisation requires MFA, after entering your password (or OTP) you'll be asked for a 6-digit code from your authenticator app (TOTP).
Setting up MFA: When first prompted, scan the QR code with an authenticator app like Google Authenticator or 1Password
Backup codes: Save the backup codes shown during setup - each can be used once if you lose access to your device
Signing in: Enter your password, then the 6-digit code from your authenticator app
Tips
Use a unique password you don't reuse elsewhere
Save your backup codes somewhere safe - you'll need them if you lose your phone
If your organisation switches to password sign-in, you'll be prompted to set a password on your next login
