Console sign-in methods
A console account signs in with a password or with sign-in providers such as Google, never with both. This page explains what sets the method, what each screen shows, why a provider account gets no password-reset email, and how to get help.
This page is about console accounts. A console account signs in to the SenseCrypt admin console and owns tenants, billing and administrators. This page is not about the end users of your applications. They sign in with a face scan and have no password.
A console account has one sign-in method. It signs in with an email address and a password, or with one or more sign-in providers. It never has both. After the account is verified, the method does not change.
This applies to the account owner. Administrators that you invite to an account always sign in with a password.
The two kinds of console account
| Password account | Provider account | |
|---|---|---|
| Signs in with | Email address and password in the Sign In dialog | A Continue with button, for example Continue with Google |
| Forgot password? | Sends a reset email | Sends no email. The account has no password. |
| More providers | Cannot be added | Can be added. See Sign in with a provider account. |
The console can offer four providers. On screen they appear in this order: SenseCrypt, GitHub, Google and Microsoft. The console shows a button only for a provider that is set up. On a self-hosted deployment, the operator chooses which providers to set up.
What sets the method
Email verification sets the method. Starting to create the account does not set it.
- Create Account with your email address: the console sends you a verification link. The link opens the Set your password page. When you select Set password & continue, the account becomes a password account. The Create Account dialog tells you "You'll set your password when you verify your email."
- A Continue with button: the provider confirms your email address, and the account becomes a provider account.
Do not use both while you create the account. If you use a Continue with button for the same address before you select Set password & continue, the account becomes a provider account. Opening the verification link does not prevent this. The Set your password page then shows an error and sets no password. Sign in with the Continue with button that you used.
The Create Account dialog does not tell you that the method is permanent. Choose the method that you want to keep before you start.
Sign in with a provider account
Start on the SenseCrypt home page and select Sign In. A tenant's subdomain, for example https://<slug>.sensecrypt.com, shows no Continue with buttons. On a self-hosted deployment, ask your operator for the console address.
Then select a Continue with button:
- Your account at that provider (for example, your Google account) must have the same verified email address as your console account. The first time you use a second provider, the console adds it to your console account.
- For GitHub, the console uses the primary email address of your GitHub account when that address is verified. When it is not verified, the console uses another verified address of your GitHub account.
- If you do not remember which provider you used, try the buttons. Use only accounts at the providers that have your console account's email address.
If your account at that provider has a different email address, the console does not sign you in to your console account. It treats the address as a new sign-up:
- For GitHub, Google and Microsoft, the console shows Almost there and asks for your company. Close the dialog. The console creates no account until you complete it.
- For SenseCrypt, the console can create the new account immediately and sign you in to it. If you see a new, empty dashboard, open the user menu and select Sign Out. This is a separate account. To close it, see Account lifecycle and deletion.
- When new sign-ups are paused, the console shows the waitlist instead. Close it.
What you see
| You do this | Account | You see | What it means |
|---|---|---|---|
| Forgot password? | Provider account | "If an account with a password exists, a reset email has been sent" | No email arrives, because the account has no password. Use a Continue with button. |
| Sign In with a password | Provider account | "The email or password you entered is incorrect" | The account has no password. Use a Continue with button. |
| Create Account with the same address | Either kind | Check Your Email | The account exists already, so no email arrives. Sign in instead. |
| Set password & continue, after you used a Continue with button for the same address | Provider account | An error message | The account became a provider account. Use the Continue with button that you used. |
| A Continue with button | Password account | "This email signs in with a password. Use the email and password form instead" | Sign in with your email address and password. If you forgot the password, select Forgot password? in the Sign In dialog. |
| Continue with Microsoft | Either kind | "That Microsoft account's email no longer matches your SenseCrypt account. Sign in with your password or another provider you've used, or contact support" | The email address of your Microsoft account changed after the console added it. A password account signs in with its password. A provider account has no password, so use another provider that you added. If you have none, see Get help. |
| A reset link sent before the account became a provider account | Provider account | "This account signs in with a connected provider, so there's no password to reset. Use that provider on the sign-in page" | This is rare, because a reset link stops working after one hour. Use a Continue with button. |
An account that had both before release 3.3.0
Before release 3.3.0, an account could have a password and a provider at the same time. That account is now a password account. Sign in with your email address and password. If you do not know the password, use Forgot password?. The provider button shows "This email signs in with a password. Use the email and password form instead". Nothing else about the account changes.
Why the reset message says so little
The Forgot Password dialog shows the same sentence for every address. The address can have a password account, a provider account or no account. If the message changed with the account, anyone could type an address and learn how its account signs in. So the sentence states the rule ("with a password") and tells you nothing about the address that you typed.
For the same reason, the sentence does not prove that SenseCrypt sent an email. You also get no email in these cases:
- No account uses the address.
- The address has a typo.
- The request did not go through. For example, you sent too many requests in a short time.
What you cannot change
- No setting adds a password to a provider account or moves a password account to a provider.
- The Security section of Profile tells you to use Forgot password? to set a new password. That applies to password accounts only.
- Change email in Profile asks for the account password. A provider account has no password, so it cannot change its email address.
Get help
If you cannot sign in to the hosted service, email support@seventhsense.ai. While you are signed out of the console, you can also use the contact form on the SenseCrypt home page. You do not have to sign in to use either. Write from the email address of the console account, so that support can find the account. Tell us which Continue with buttons you tried.
On a self-hosted deployment, contact your operator.
Related
- Managing tenants: the console account, its default tenant and its first application.
- Account lifecycle and deletion: how a console account is closed and reopened.
- Support: how to reach SenseCrypt.
- Security: the security model.
Signed requests and responses
JAR request objects at the PAR endpoint (RFC 9101) and JARM signed authorization responses — the signing rules, the claims that are required, where each is accepted, and how to validate the response JWT.
Account lifecycle and deletion
How a SenseCrypt account is closed and reopened — owner-only self-delete with a 30-day grace, the 423 block on the admin console during that window, what reactivation restores, and the crypto-shred and data erasure that happen on final deletion.