TrustWixDocs
Console handbook

Signing in

Your first sign-in, your authenticator app, passkeys, and what to do when you are locked out

There is no self-serve sign-up. Somebody already on your team creates your seat and passes you a temporary password, or we create the first owner for a new organization. Your account exists before you ever open the console.

Your first sign-in

Open the sign-in page. It lives on the main site, at trustwix.com/login. If you go straight to app.trustwix.com while signed out, you land there anyway.

Use the temporary password. Either a colleague passed it to you, or an invitation email gave you a link for setting your own. That link works once and expires 30 minutes after it is sent, so ask for another if it has gone stale.

Replace it with a password only you know. This is a required step, not a suggestion you can skip.

Add an authenticator app. Scan the code with whichever app you use, then type the six digits it shows. Save the recovery codes somewhere that is not the same phone.

After that the console opens, and every later sign-in is your email, your password, and a code from the app.

Why the authenticator app is not optional

Every member of every organization uses one. It cannot be switched off, because the console is where your applicants' identity records live, and a password on its own has been proven not to be enough to stand in front of them.

The same app does a second job. When you do something sensitive, creating an API key, revealing an applicant's identity, changing what a colleague can reach, the console asks for a fresh code before it goes through. That is a step-up check. It confirms the person at the keyboard is still you, and it is why nobody can walk up to your unlocked laptop and mint a live key.

Passkeys

A passkey lets you sign in with the fingerprint, face or screen lock on a device you already trust, instead of typing a password and a code. You add one from Settings, on the device you want to use it from.

Your authenticator app stays enrolled either way, and still confirms sensitive actions. A passkey replaces the typing, not the second factor. A passkey that does not check who is holding the device cannot be enrolled at all, because it would be one factor pretending to be two.

When you cannot get in

Forgot your password. Use the link on the sign-in page. If an account exists for that address, a link for setting a new one arrives, works once, and is short-lived. Setting a new password signs out every other session you had open. It does not skip your authenticator app.

New phone, or a phone you no longer have. Open Settings and replace the authenticator app from there. You need your password, and you need the new device with you, because your account is not usable in between.

Out of codes and out of phone. Use one of the recovery codes you saved at setup. If those are gone too, an owner on your team cannot recover it for you and neither can a colleague, so contact us.

"This seat cannot sign in." Your seat has been suspended by somebody on your team. Their reasons are theirs, but the effect is that you are signed out and stay out until an owner reinstates you. Any review cases you were holding went back to the pool.

Nobody at TrustWix will ever ask you for your password or a code

We do not need either one to help you, and we never ask. Treat any message that does as a phishing attempt, whatever address it appears to come from.

Where you land

Signing in takes you to the Overview. Everything else hangs off the sidebar on the left, which collapses to icons with the button at its top, or with Ctrl/Cmd and B. The menu at the bottom of the sidebar holds your profile, the console language, light or dark, and the way out.

On this page