Guide
Signing in and account security
Every way into Atlas, how to manage your passkeys, and how an administrator sets up single sign-on for a company domain.
Ways to sign in
The sign-in page shows only the ways your Atlas address offers, and marks the one this device used last, such as "You last signed in with Google". That note stays on this device and holds only the name of the method, never your address or a code.
- Password: your email address and password. Forgot password? on the password row emails you a reset link.
- Email code: choose Email me a code under the form and enter the 6-digit code from your inbox. You can ask for another code after 30 seconds.
- Email sign-in link: choose Email me a sign-in link and open the link from your inbox.
- Passkey: choose Sign in with a passkey, or pick a saved passkey from the suggestions in the email field where your browser offers them.
- Google and GitHub: continue with the account you already use there. Each appears when your Atlas address has it turned on.
- Single sign-on: choose Use single sign-on and enter your work email.
Email sign-in link
A sign-in link works once, for 15 minutes. Open it in the browser where you asked for it and you are signed in straight away. Opened in any other browser, the page first asks you to confirm the address it was sent to, shown in part, and signs nothing in until you choose Continue. A forwarded link cannot sign somebody in without that decision.
After you ask for a link, the page shows Check your email with the address it went to. You can send the link again after 30 seconds, or choose Use a different email. A used or expired link says so: choose Request a new link. The answer is the same whether or not the address has an account, so the page never reveals who uses Atlas.
Passkeys
A passkey signs you in with your device's screen lock or a security key instead of a password. It counts as two-step verification on its own, so Atlas does not ask for an authenticator code after a passkey.
Open Passkeys in security settings
Go to Settings, then Security, and find the Passkeys card.
Confirm it is you
Adding a way into your account asks for your current password, or a 6-digit code emailed to your own address.
Create the passkey
Give it a name you will recognise, such as the device it is on, and follow your browser's prompt.
- You can hold up to 20 passkeys. Rename or remove any of them from the same card.
- Passkeys work on the main Atlas sign-in page. On a firm's own client portal address, sign in another way.
- A browser that cannot use passkeys says so when you choose the button. Closing the prompt is not an error: try again, or sign in another way.
Single sign-on
Single sign-on sends you to your company's identity provider, which confirms who you are. Choose Use single sign-on and enter your work email. Atlas finds the workspace that has verified your email domain and turned single sign-on on, and you come back to Atlas signed in.
When single sign-on is not set up for an address
Two-step verification
With two-step verification on, a password sign-in also asks for the 6-digit code from your authenticator app. Without the app, choose Use a backup code instead. Turn two-step verification on and create backup codes in security settings. A passkey already proves both factors, so it skips this step.
Verified domains for administrators
Single sign-on can only find your workspace from a work email whose domain your workspace has proved it owns. Workspace owners and admins manage these in the Verified domains card under Settings, then Security, next to the single sign-on settings.
Add the domain
Enter the part of your people's email after the @ sign, such as example.com: the domain name only. A domain written in another script is shown as you wrote it and stored in its encoded form.
Publish the TXT record
At the company that manages your DNS, add a TXT record named _atlas-sso. followed by your domain, with the value the card shows. Copy both with the buttons beside them.
Verify now
Choose Verify now. A new record can take a while to appear. If the check fails, the card says what it found, and you can try again later.
- A domain can be verified by one workspace at a time. Another workspace that has already verified it blocks the claim.
- A subdomain is a separate domain and must be verified on its own.
- Removing a domain stops single sign-on finding your workspace for that domain. People can still sign in another way.
- Members who are not owners or admins see why they cannot change the list.