Signing in and keeping your account safe
Sign in with an email code, Google, Microsoft, Facebook or Apple, or a passkey. Add passkeys and two-factor authentication in Settings → Security, and what to do when sign-in fails.
There are no passwords on CoreLoop. You sign in with something you already have — your email, an account you use elsewhere, or the device in your hand — and you can make it stricter whenever you like.
Ways to sign in
- Email code. Enter your address and we send a 6-digit code. Type it in and you’re in. If the code doesn’t arrive, check spam, then use Resend code.
- Google, Microsoft, Facebook or Apple. One tap on the button, no code to type. When you first sign up with Google you may see Google’s own one-tap prompt offering to create the account in a single step.
- Passkey. Your device’s fingerprint, face or screen lock, once you’ve added one (below). Sign in with passkey appears on the sign-in screen on devices that support it.
Whichever you use, it’s the same account — signing in with Google today and an email code tomorrow lands you in the same dashboard.
Passkeys: sign in with your device
A passkey lets your phone or computer vouch for you — fingerprint, face or the screen lock you already use — with nothing to remember and nothing that can be phished. Add one at Settings → Security with Add passkey, follow your device’s prompt, and give it a name you’ll recognise (“Work laptop”). You can add several, rename them, and remove one you no longer use.
Two-factor authentication
For a second check at every sign-in, turn on Two-factor authentication in the same place. Scan the code with an authenticator app (Google Authenticator, 1Password, Authy and the like); from then on, sign-in asks for the six-digit code from the app after your usual method. Get your backup codes while you’re there and keep them somewhere safe — each works once, and they’re your way in if you ever lose the app.
Owners and managers are the ones who can change billing, team and exposure settings, so for them especially, two-factor is worth the thirty seconds.
When sign-in doesn’t work
- “No account found with this email” — you may have signed up with a different address, or with Google, Microsoft, Facebook or Apple. Try those buttons before creating a new account.
- “Invalid code” or “Too many attempts” — codes expire quickly; request a fresh one, and give it a moment if you’ve tried several times in a row.
- “Passkey authentication failed” — the device you’re on may not hold that passkey. Use another method to get in, then add a passkey for this device.
- “This account is scheduled for deletion” — you, or an owner, asked to delete the account. It can be restored during the 7-day window by writing to support@coreloop.so; after that it’s gone for good. See Deleting your account.
If you’re locked out entirely — lost the authenticator app and the backup codes — contact us and we’ll verify you another way.