Signing in to Joryio
The Joryio sign-in page supports four ways to get into your account, in the order you'll see them on screen:
- Email + password - the default flow.
- Single sign-on (Google Workspace, Microsoft Entra, Okta) - if your workspace admin has configured it.
- Passkey, email-first - pick your account, then use a passkey instead of typing your password.
- Passkey, usernameless - the browser remembers your account and you sign in with one click.
If 2FA is required for your account, you'll see a 6-digit code prompt after most of these flows. Passkey sign-in skips it (the passkey is already a strong second factor by spec).
Email and password
- Open
https://app.joryio.com(or whatever your workspace URL is). - Enter your email address. Click Continue.
- If your email belongs to more than one workspace, pick which one you want to sign into. The picker remembers your last choice for next time.
- Enter your password. Click Sign in.
- If 2FA is on, enter the 6-digit code from your authenticator app.
- You're in.
If you forgot your password, click Forgot password? at the email step - you'll get a reset link via email.
Single sign-on (SSO)
If your workspace admin has set up SSO with Google Workspace, Microsoft Entra, or Okta, you'll see one or more Sign in with… buttons on the email step.
- Click the provider button (e.g. Sign in with Google).
- Your browser redirects to the provider, you sign in there as you would for any other app, and the provider redirects you back.
- If 2FA is on, complete the prompt.
- Done.
If your workspace has SSO enforcement turned on, the email + password flow is disabled entirely for that workspace. You'll be redirected to the SSO button if you try.
If signing in via SSO is the first time we've seen your email at that workspace, you'll be auto-created as a member there (assuming the admin has enabled auto-create on that SSO provider).
Passkey - email-first
If you've enrolled a passkey on this device, you can use it instead of typing your password.
- Type your email. Continue.
- Pick your workspace (if you're in more than one).
- On the password step, click Sign in with a passkey below the password field.
- Your browser shows the native passkey prompt - Touch ID on macOS, Windows Hello on Windows, face/fingerprint on phones, or a hardware key like YubiKey.
- Authorize the prompt. You're in. No 2FA prompt - the passkey IS the second factor.
If the workspace you picked has SSO enforcement on, this option won't appear (the passkey wouldn't be honored anyway).
Passkey - usernameless
The fastest sign-in flow if your device has a passkey saved.
-
On the very first step of
/login, click Sign in with a passkey (under the email field, after the Continue button). -
The browser shows its account picker. You'll see entries like:
Lior · Acme Corp
Lior · Pennysimlabeled with your name and the workspace each passkey belongs to.
-
Pick one. Touch ID / Windows Hello prompt fires. Authorize.
-
You're signed in to that workspace.
No email typed, no workspace picker, no 2FA prompt.
"Usernameless" works only on devices where you've actually enrolled a passkey. The picker won't show accounts you haven't added.
If you pick a passkey for a workspace that has SSO enforcement on, sign-in fails with a clear message pointing you to the SSO button. The passkey row stays on your account - you can remove it from My account → Passkeys if you don't want it sitting there.
When passkeys are right for you
We recommend passkeys when:
- You're signing in from a personal device with Touch ID / Face ID / Windows Hello.
- You use a password manager (1Password, iCloud Keychain, Google Password Manager) that syncs passkeys across your devices.
- You have a hardware key (YubiKey, Solokey) you want to use as a second factor that replaces the authenticator app entirely.
Stick with password + 2FA when:
- You're on a shared / kiosk machine where you don't want a passkey saved.
- Your workspace requires SSO and you have a personal SSO account that works fine.
You can enroll a passkey at any time from My account → Passkeys - see the Account Security guide.
Troubleshooting
"Invalid credentials" - Wrong password, or the email isn't a member of the workspace you picked. Try the Forgot password? flow or check with your admin.
"Account locked" - Too many failed sign-in attempts. The page tells you when it unlocks; the default is 15 minutes. An admin can unlock you immediately from Workspace → Security → Authentication.
"This workspace requires single sign-on" - SSO enforcement is on. Use the SSO button on the email step instead of typing a password or using a passkey.
Passkey prompt doesn't appear - Make sure the browser tab is focused (some platforms hide the prompt if the tab is in the background). On Safari macOS, ensure System Settings → Passwords → AutoFill is on.
Browser says "no passkeys available" on the usernameless flow - You haven't enrolled a passkey on this device. Sign in the old-fashioned way once, go to My account → Passkeys, and enroll.
"Session ended by sign-out-everywhere" - Someone (likely you) just clicked Sign out everywhere else on the Trusted devices section of My account. Sign in fresh.