Two-factor authentication, sessions, and what to do if you are locked out.
Sign in at /auth with your email and password, then confirm a code from your authenticator app.
Two-factor is required
Every ProposalKit account uses two-factor authentication. It is not an optional setting you can turn off — proposals carry client contact details, contract values and signatures, so a password alone is not enough to reach them.
-
Step 1: Sign in with your email and password
On your first sign-in you are taken straight to two-factor setup.
-
Step 2: Scan the QR code
Use any authenticator app — Google Authenticator, Authy, 1Password, Bitwarden or similar. ProposalKit shows the code on screen; nothing is emailed or texted.
-
Step 3: Enter the 6-digit code
That confirms the pairing and takes you into your workspace.
-
Step 4: After that, one code per sign-in
Your authenticator shows a fresh code every 30 seconds. Enter the current one.
If a code is rejected
- Make sure you are entering the current code — they rotate every 30 seconds.
- Check your device clock is set automatically. A clock that has drifted produces codes that will not match.
- If setup timed out, sign in again to restart it.
Staying signed in
Your session lasts a while but not forever, so you will be asked to sign in again periodically. Use Sign out on a shared or public computer rather than just closing the tab.
Locked out
Repeated failed sign-in attempts temporarily lock an account, and the message tells you how long is left. Wait it out, or use your password reset if you are not sure of your password.