Signing in, passwords, and MFA
You always sign in at your own workspace address (your-business.onlot.app), never at onlot.app itself.
Forgot your password?
Use Forgot your password? on your workspace's sign-in page. A reset link goes to the email address on your account. If the email doesn't arrive, your administrator can also set a new temporary password for you from Settings → Users.
Multi-factor authentication (MFA)
OnLot supports a second factor on top of your password:
- Authenticator app (TOTP) — scan a QR code with an app like Google Authenticator or 1Password, then enter the 6-digit code it shows when you sign in.
- Email codes — a one-time code sent to your account email.
- Recovery codes — one-time backup codes you save when you enroll. Keep them somewhere safe; each works exactly once.
You can mark a device as remembered so it isn't challenged on every sign-in. Administrators may be required to enroll in MFA.
Your devices
The Devices & Sessions section on your Profile page lists everywhere you're currently signed in — device, IP, and last activity. Sign out other devices ends every session except the one you're using; do it whenever a device is lost or you forgot to log out somewhere shared.
For administrators: the Security panel
Each user on Settings → Users shows their last sign-in, and the Security button opens the details: recent sign-ins with time, IP, and device; active sessions (with the current one marked); and which MFA methods are set up, including recovery codes remaining and remembered devices. From there, Sign out everywhere ends all of a user's sessions at once — useful for a lost phone or a departure — and Reset MFA rescues someone locked out of their second factor. Both are audited.
Locked out?
- Try a recovery code if you saved them at enrollment.
- Ask another administrator on your workspace — they can help from Settings → Users.
- Still stuck? Email hello@getonlot.com from the address on your account and we'll help verify you.