Secure your account and set up single sign-on
Add passkeys and two-factor codes, connect Google or Microsoft, and route your company's email domain through an identity provider.
This guide is for anybody who wants a stronger sign-in, and for the administrator who sets up single sign-on for a company. Every task below starts in Settings > Security. Brix always keeps one working way into your account, so no action on this page can lock you out.
What you can do
- Password reset — Send yourself an email link that sets a new password.
- Google and Microsoft — Connect either account as a second way to sign in.
- Passkeys — Sign in with your face, your fingerprint or a security key.
- Two-factor authentication — Add a 6-digit code from an authenticator app to every sign-in.
- Recovery codes — Keep ten one-time codes for the day you lose your authenticator.
- Single sign-on — Route a company email domain to your own identity provider.
- SSO-only sign-in — Drop the password once another sign-in method works.
Read what your account signs in with
- Open Settings > Security.
- Read the Password row under Sign-in methods.
- Read each row below it for a connected Google, Microsoft or single sign-on identity.
- Scroll to Passkeys for the devices that sign in without a password.
- Scroll to Two-factor authentication for the state of the second factor.

Send yourself a password reset link
- Open Settings > Security.
- Find the Password row under Sign-in methods.
- Select Reset password.
- Read the green banner that names your email address.
- Open the email from Brix.
- Follow the link in the email.
- Set a new password.
Connect Google or Microsoft to your account
- Open Settings > Security.
- Select Connect Google or Connect Microsoft under Sign-in methods.
- Sign in at the provider.
- Wait for the browser to return to Settings > Security.
- Read the green banner that confirms the connection.
- Check the new row in the list.
Add a passkey for this device
- Open Settings > Security.
- Scroll to Passkeys.
- Select Add a passkey.
- Type a label such as
MacBook · TouchIDinto Label (optional). - Select Create passkey.
- Approve the prompt from your browser or your device.
- Check that the new row reads
Added just now · never used.
Remove a passkey
- Open Settings > Security.
- Scroll to Passkeys.
- Select the trash button on the passkey row you no longer want.
- Select Remove in the confirmation dialog.
Turn on two-factor authentication
- Open Settings > Security.
- Scroll to Two-factor authentication.
- Select Set up.
- Scan the QR code with your authenticator app.
- Or copy the key under Or enter manually into your app.
- Type the 6-digit code from your app into the Step 2 field.
- Select
Verify & turn on. - Select Copy all to copy the ten recovery codes.
- Store the recovery codes somewhere safe.
- Select
I've saved them.

Turn off two-factor authentication
- Open Settings > Security.
- Scroll to Two-factor authentication.
- Select Turn off.
- Type a current 6-digit code from your authenticator app.
- Select Turn off a second time to confirm.
Set up single sign-on for your company
A single sign-on connection routes every email address in your domains to your identity provider. Brix works with Microsoft Entra ID, Google Workspace, Okta, Auth0 and any other OIDC provider.
- Open Settings > Security.
- Scroll to Single sign-on.
- Select Add SSO connection.
- Type a name such as
Acme Single Sign-Oninto Display name. - Choose your provider in Vendor.
- Paste the issuer URL from your provider into Issuer URL.
- Select Test to check the discovery document.
- Paste the client ID from your provider app registration into Client ID.
- Paste the client secret into Client secret.
- Type your email domains into Email domains.
- Separate two or more domains with a comma.
- Leave
Just-in-time provisioningticked so Brix creates a member at first sign-in. - Leave Enabled ticked.
- Select Create connection.
- Select Copy beside Redirect URL for your IdP.
- Paste that URL into the redirect-URI field of your provider.
- Select Done.

Change an SSO connection
- Open Settings > Security.
- Scroll to Single sign-on.
- Select Edit on the connection row.
- Change the fields you need.
- Leave Client secret empty to keep the stored secret.
- Select Save changes.
Remove an SSO connection
- Open Settings > Security.
- Scroll to Single sign-on.
- Select the trash button on the connection row.
- Select Remove in the confirmation dialog.
Switch your account to single sign-on only
- Add a passkey, or connect Google, Microsoft or your company provider.
- Open Settings > Security.
- Find the Password row.
- Select Use SSO only.
- Read the warning in the Switch to SSO-only? dialog.
- Select Remove password.
- Read the banner that confirms the account now holds no password.
Disconnect a linked account
- Open Settings > Security.
- Find the provider row under Sign-in methods.
- Select the trash button at the end of the row.
- Select Disconnect in the confirmation dialog.
To give an integration its own credential instead of a person, see API keys and integrations. To set what each member can do, see organization, people and roles. To read who changed what, see proof of play and the audit log.
Ready to get started?
Open Brix Portal