Account Access — Signing In and Passwords
Four different surfaces change a password in Arcvue, and picking the wrong one is the most common reason somebody gets stuck on their first day. This page says which is which.
Part 0 — Signing in, and your first sign-in
Sign in with Username or email and Password. If you cannot remember either, both Forgot username and Forgot password are on the same page.
Once your account uses an authenticator app, every sign-in asks for the six-digit code from it after your password. Type or paste the code into Authenticator code and press Verify or Enter -- a pasted code works with or without the space in the middle. Verify stays disabled until six digits are in the box, and reads Verifying... while it checks. Back to sign in drops the code and returns you to the password form.
If you cannot remember your username or your password
Both links open the same small panel, and which button it offers tells you which one you picked:
| You chose | The panel asks for | The button reads |
|---|---|---|
| Forgot username | your work email | Send my username |
| Forgot password | your username or work email | Send reset link |
Either button is disabled until the box has something in it, and reads Sending... while it works. The panel then replaces the box with a confirmation line rather than letting you send twice. If you are looking at a button that says the other thing, you are on the other path — Back to sign in, then pick again.
Your first sign-in sets up that authenticator
The first time you sign in, Arcvue walks you through connecting an authenticator app, on a panel headed Set up two-factor authentication. It has two numbered steps:
- Scan this with your authenticator app — or, if your device cannot scan, Add this key to your authenticator app and type the key in by hand. Copy key puts it on the clipboard and changes to read Copied so you know it took. Open in authenticator app hands the key straight to an app on the same device, which saves retyping it.
- Enter the 6-digit code it shows — the rotating code from the app you just added the key to. This proves the key was stored correctly.
Then Finish setup, which stays disabled until all six digits are in and reads Finishing setup... while it works. Back to sign in abandons the enrollment.
The key stays the same until setup finishes. If you sign in again partway through, Arcvue shows the same code to scan, so the Arcvue entry already in your authenticator app keeps working; you do not need to add a second one. If the page says it timed out, select Back to sign in and sign in again.
If the code is refused, it is usually the clock, not the code. The code changes every 30 seconds and is checked against the server's time, so a phone whose clock is set by hand can produce a code that is correct on the phone and wrong here. Wait for the next code, and set the phone's clock to update automatically.
Closing the tab part-way does not cost you the entry you added. Nothing is saved on your machine, but the key is held for you until setup finishes and is shown only after your password is accepted, so your next sign-in brings the same setup panel back. Enter the code your existing entry shows and select Finish setup.
Two buttons, one panel apart — and they are easy to confuse
| Button | Where it is | What it does |
|---|---|---|
| Finish setup | on the setup panel, under the six-digit box | Verifies the code and completes enrollment. This is the one that finishes the setup. |
So if you are still looking at a code field, you have not finished setup yet — the button you want is Finish setup.
Part 1 — Which surface you want
| You are… | Use | Where |
|---|---|---|
| Locked out — you cannot sign in and do not know your password | The reset link from a password-reset email | /reset-password?token=… |
| Signed in and want to change your own password | Change your password | /account/password |
| An administrator setting a password for somebody else | Admin → Users | see Access and Users in the Accounting manual |
| On the mobile app | Settings → Change Password | the app |
| Signing in for the first time | Sign in, set up your authenticator, then choose your own password | the sign-in page — see Part 0 and Part 3 |
The two you will use yourself are the first two, and they are genuinely different things — not two routes to one screen:
- The reset flow proves who you are with a token from an email. It never asks for your old password, because the whole point is that you do not have it.
- The change flow proves who you are with your current password, because you are already signed in.
If somebody sends you to "reset your password" while you are signed in and know it, they mean the second one.
Part 2 — Resetting a password you have lost
Open the link from the password-reset email. It carries a token in the address, and the token is what makes the page work — that is why the link cannot be retyped from memory or forwarded after it has expired.
- New password — at least 8 characters.
- Confirm new password — must match.
- Update password.
The button stays disabled until both boxes have something in them. Then:
| What you see | What it means |
|---|---|
| "Password updated" | Done. Go to sign in takes you to the login page — you are not signed in automatically. |
| "Password must be at least 8 characters." | The minimum. Nothing else is required of the password on this screen. |
| "Passwords do not match." | The two boxes differ. |
| "This reset link is invalid or has expired. Please request a new one." | The token was refused. Request a fresh reset email; do not keep retrying this link. |
| "Invalid reset link — this link is missing its token." | You reached /reset-password without a token at all, usually by typing the address by hand or following a truncated link. Back to sign in, then use the link from the email. |
Part 3 — Changing a password you still know
Account → Change password (/account/password), while signed in.
- Current password
- New password — at least 8 characters
- Confirm new password
- Update password
All three boxes must be filled before the button enables.
| What you see | What it means |
|---|---|
| "Password updated" | Done — and you stay signed in. The new password applies the next time you sign in, so nothing breaks in the session you are in. Back to Arcvue returns you to the dashboard. |
| "Your current password is incorrect." | The first box is wrong. This is not a session problem — you have not been signed out, and signing in again will not help. |
| "Your new password must be different from your current one." | Re-entering the same password is not a change. |
| "Passwords do not match." | The second and third boxes differ. |
Why "your current password is incorrect" is worded that way. The server answers a wrong current password with the same code it uses for an expired session. Arcvue deliberately does not say "please sign in again" here, because that would send you round a loop that cannot fix anything — you are signed in already, and the only thing wrong is the first box.
If you were told to change your password
When your password was chosen by somebody else — the one in your invitation, or one an administrator set for you — Arcvue asks you to choose your own before anything else. Right after you sign in, the panel Choose your own password appears instead of the app:
- Current password — the one you just signed in with
- New password — at least 8 characters, and different from the current one
- Confirm new password
- Set password and continue
When it saves, you land on the page you were going to, and a note confirms Your new password is set. The messages under the form are the ones in the table above. Sign out, under the panel, leaves without changing anything; the same panel appears at your next sign-in.
On the mobile app Change Password opens by itself right after you sign in, with the instruction at the top. Enter the password you signed in with and your new one twice, and the app works normally again. Until you do, a bar across the top of every screen repeats the instruction with a Change password button, and the screens show the same instruction instead of their data. Time and mileage you save on the phone meanwhile wait on the phone and upload once the password is changed. A change made on either the web or the phone counts for both.
An app that has not picked up the latest update shows screens that couldn't load instead, some asking you to check your connection. The fix is the same: Settings → Change Password.
Part 4 — When something looks wrong
| Symptom | What it means → what to do |
|---|---|
| The reset email never arrives | Nothing on this page can tell you why. Check junk mail, then ask an administrator — they can set a password for you directly from Admin → Users without any email involved. |
| The reset link worked yesterday and not today | Reset tokens expire. Request a new email; the old link stays dead. |
| I am signed in and the reset link asks me to sign in again | You are on the wrong surface. Use Change your password instead — the reset flow is for people who cannot get in. |
| An administrator reset my password and I still cannot sign in | An administrator setting a password is immediate — there is no email to wait for. Use exactly the password they gave you, then change it yourself from Account → Change password. |
| I changed my password on my phone and the web still wants the old one | It should not. The password is one account-wide credential; the mobile Settings → Change Password screen and this one write the same thing. If the web genuinely still wants the old password, the change did not save — try it again on the web and read the error. |
| Multi-factor is the thing blocking me, not the password | A password reset does not touch multi-factor enrollment. An administrator resets that separately from Admin → Users. |
One-line summary
Reset proves who you are with a token from an email and never asks for your old password; change proves who you are with your current password and keeps you signed in — an administrator can set a password for you directly with no email at all, and a wrong current password is reported as exactly that rather than as an expired session.
Related
- Creating users, roles, and resetting somebody else's password or MFA → Access and Users (Accounting manual, Admin section)
- First-run tenant setup → First-Run Setup (Accounting manual, Admin section)