Skip to content

Your first sign-in

Sign in from the app for the first time, verify once, and set up a Passkey.

After creating the account, your administrator gives you the login name and the OTP for your first sign-in. You cannot register or activate an account yourself.

  • Install the client app required by your organization
  • Get the login name from your administrator
  • Get the latest OTP issued by your administrator

The sign-in page with the sample login name docs-demo@zitadel.localhost entered

Enter the login name from your administrator, then select Next.

  1. Open the app and go to sign-in.
  2. The app brings up the sign-in page, with “Wea SSO” at the top.
  3. Enter the login name your organization gave you in Login Name, then select Next.
  4. The One-Time Password page appears. This is the only verification method available on a first sign-in; Passkey, verification with another device, and the OKTA option are not shown yet.
  5. Enter the latest OTP issued by your administrator, then select Verify.

The One-Time Password page with the OTP field, Verify button, and Try another way link

The Try another way link has no usable alternative on a first sign-in, so continue with OTP.

During sign-in, you may see Confirm this sign-in? or a User Consent page. Allow only an app you intentionally opened. See Sign in from an app for the difference.

Set up a Passkey immediately after OTP verification

Section titled “Set up a Passkey immediately after OTP verification”

After OTP verification, Setup Passkeys (Biometrics) appears before you return to the client app. It highlights Smooth login without passwords and Keep your account safe.

The Setup Passkeys Biometrics page with Skip and Next buttons

Select Next to register a Passkey. Use Skip only when you must postpone setup.

We strongly recommend selecting Next and completing registration immediately. As long as you still have that device and its Passkey, you can usually verify with your fingerprint, face, or screen lock instead of asking SSOSupport Bot for another OTP.

If you select Skip, a warning appears: “Without a Authentication method enrolled. You will be required to ask for an OTP from your administrator to sign in to your account next time.” After skipping, the next sign-in still requires a new OTP from SSOSupport Bot.

The warning shown before skipping Passkey setup, explaining that the next sign-in requires an administrator-issued OTP

Skip only if you can reach SSOSupport Bot before your next sign-in.

For the steps, see Passkey.

After you complete Passkey registration or skip it, the page shows Success. Use the button on that page to return to the client app.

  • The app no longer sends you to the sign-in page
  • The client app shows your account, and your messages and files load normally