Signing in and multi-factor authentication (MFA)

Last updated: 23 July 2026

Signing in to Smartbox

You sign in to Smartbox with your email address and password, followed by a one-time code from an authenticator app. This second step — multi-factor authentication, or MFA — means that knowing your password alone is not enough to reach your account.

Your account is fully isolated from every other customer's. You only ever see your own organisation's Boxes, documents and Workflows, and there is no way to switch between accounts — if you work with more than one organisation, each has its own separate sign-in.

Setting up MFA the first time

Smartbox uses an authenticator app for MFA — the kind of app that shows a fresh one-time code that changes regularly, such as the authenticator app already on your phone. You do not need a special app from Smartbox.

  1. When you first sign in, Smartbox shows a QR code.

  2. Open your authenticator app and choose to add a new account, then scan the QR code on screen. Your Smartbox account appears in the app straight away.

  3. The app now shows a rotating one-time code for Smartbox. Enter the current code to confirm the pairing.

That is a one-time setup. From then on, your phone and your account are linked.

Scan the QR code with your authenticator app rather than your phone's camera app, so the account is added to the app that generates your codes.

Signing in from then on

  1. Enter your email address and password.

  2. Open your authenticator app, read the current Smartbox code, and enter it.

Each code is only valid for a short time before a new one replaces it, so always enter the one showing right now. If a code is rejected, wait for the next one to appear and enter that, rather than re-typing the same digits.

If codes are still rejected, check that you are reading the code listed under your Smartbox account in the app rather than another entry, and that you are entering the most recent one.

FAQ: I've lost my phone

If you no longer have the phone with your authenticator app, you cannot generate a one-time code, so you will not be able to complete sign-in on your own. This is by design — it is the same barrier that stops anyone else getting in.

The fix is quick: ask an administrator on your account to reset your MFA. Once they do, your next sign-in starts the enrolment step again, showing a fresh QR code that you scan with the authenticator app on your new phone. Your Boxes, Workflows and everything else are exactly as you left them.

If you are the only administrator and you have lost access, or no administrator is available, contact Customer Success so your access can be restored safely.

Good habits

  • Set up MFA on a device you keep. Because a lost or wiped phone means an admin reset, use a phone you rely on day to day.

  • Keep your authenticator app backed up. Many authenticator apps can sync or restore your codes to a new phone — if yours does, turning that on saves a reset later.

  • Treat your codes as private. Smartbox will never ask you to read a one-time code to anyone. A code is for the sign-in screen only.

  • Keep your own admins in mind. Knowing who your account administrators are means you can get an MFA reset quickly if you ever need one.

Related articles

  • Inviting users and managing roles — who can be an administrator and reset MFA for others.

  • Your account and company settings — profile, branding and account-level options.

  • Keeping your account secure — how role-based access, account isolation and audit trails protect your data.


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article