Your account
Security and two-factor authentication
How two-factor authentication works in Spyral, changing your password, managing active sessions, and what to do if you lose your phone.
Spyral holds client financial records, so it is stricter about sign-in than most tools your firm uses. This page explains what that means in practice.
Every sign in needs a second factor
There is no "remember this device" option and no way to switch this off. Every sign in asks for a six digit code.
If you have set up an authenticator app, the code comes from your phone. If you have not, Spyral emails you one at each sign in, which works but means every sign in waits on an email.
Setting up an authenticator app
- Go to Settings, then Account, then the Security section.
- Choose Two-factor authentication.
- Install an authenticator app if you do not have one. Google Authenticator, Microsoft Authenticator, Authy and 1Password all work.
- Scan the QR code, or use Can't scan? Enter this code manually and type the key in.
- Enter the six digit code your app shows, to confirm the pairing.
Enabling two-factor authentication gives you no backup codes. Spyral does not issue any. If you lose the phone holding your authenticator app, you cannot recover access on your own and resetting your password will not clear it either. The only route back is to contact us: see How to get help.
Before you finish setup, copy the manual key from the QR screen and keep it somewhere safe, such as your firm's password manager. With that key you can set the same account up on a new phone yourself.
If you open the setup screen, walk away, and come back later, the QR code will have expired and a fresh one is generated. A code you already scanned into your app then stops working. Scan the new one.
Turning it off
The same Two-factor authentication entry in settings offers to disable it, and asks for a current code to prove it is you. Your account then falls back to emailed codes at each sign in. It is not switched off entirely, because there is no way to sign in without a second factor.
Two-factor authentication is a personal setting. There is no way for a firm to require it of everyone.
Changing your password
Settings, then Account, then Change password. You need your current password.
Changing your password signs you out on every other device. The tab you are working in stays signed in. Everything else, including your phone and any other browser, is signed out immediately.
If you have forgotten your password, use Forgot your password? on the sign-in screen. Spyral emails a six digit code that is valid for 10 minutes and can be used once.
The screen after you request a code looks identical whether or not an account exists for that address. This is deliberate, so nobody can use the form to discover who has an account. If no email arrives, check the address you typed.
Resetting a password signs you out everywhere, including the device you reset from, so you sign in again straight afterwards.
Active sessions
Settings, then Privacy, then View active sessions. You get one row per device you are signed in on, showing the browser, the operating system, the network address it connected from, and when it was last active. Your current session is badged.
You can sign out any individual session, except the one you are using. To clear everything at once, use Sign out all other sessions.
Sessions last 24 hours and are extended while you are working.
If you think someone else has your password, change the password rather than only revoking sessions. Changing it invalidates everything in one move.
Too many attempts
If you enter a wrong password or a wrong code several times in a row, Spyral stops accepting attempts from you for 15 minutes. The message names the wait.
The 15 minutes people mention is this lockout, not a session timeout. Spyral does not sign you out after 15 minutes of inactivity. A successful sign in clears the counter, so fumbling a couple of codes and then getting it right leaves you with nothing to wait for.
Verification of codes is also limited per office network, so several colleagues failing at the same time in the same office can hold each other up. If a whole room is locked out at once, that is why. Wait it out.
A code Spyral will not accept twice
An authenticator code cannot be reused within 90 seconds, so if you sign in twice in quick succession, wait for your app to roll over to a new code.
Exporting your data needs two-factor authentication
Downloading a copy of your data asks for a code from your authenticator app, and is not available at all to accounts using emailed codes. See Your data and where it is hosted.