When an account is needed
Direct native SSH does not require an OmniTerm account just to connect. Managed relay and cloud-account workflows require their own authenticated access, including when a free allowance is offered.
Choose a sign-in method actually offered by your deployment: a passkey, a configured provider such as Google or Apple, or an enabled email-code workflow. A method shown in a guide is not proof that every administrator has configured it.
Sign in
- Open the sign-in flow and choose an available method.
- Complete the provider, passkey or email verification prompt for the intended account.
- If two-factor protection is enabled, enter the authenticator code or an unused two-factor backup code.
- Wait for the completed sign-in state. Passing the first step alone is not a full login when a second factor is required.
- Unlock the relevant vault separately when its workflow asks you to.
Use the original sign-in method for an existing account. A matching email address from another provider does not automatically prove that the identities should be linked.
Set up an authenticator
Open Account security from the available account controls. If prompted, add a passkey before changing sensitive security settings. Choose Set up authenticator, scan the displayed setup information in your authenticator app, and enter its current code under Confirm authenticator.
Save the backup codes privately when shown. Each works once after the primary sign-in step; they are not vault recovery keys. Confirm that you saved them before leaving the screen.
Activating two-factor protection signs out previous sessions. Sign in again and complete both steps to check your setup. If authenticator operations are unavailable, contact the service operator instead of repeatedly retrying setup.
Understand the recovery materials
| Material | Purpose |
|---|---|
| Two-factor backup code | Completes the second factor after a successful primary sign-in. Each code is single-use. |
| Account recovery code | Restores a supported lost-sign-in workflow and can revoke old sign-in methods and sessions. It does not decrypt a vault. |
| Vault recovery material | Supplies the separate authority required to recover protected vault data. Keep what your specific workflow requires. |
Use Create recovery code where available, save it when displayed, and note its stated validity. Do not assume an old code remains reusable after recovery or expiry.
Review signed-in devices
In Account security, inspect Signed-in devices. Use Sign out device for an unfamiliar session or Sign out all devices when appropriate, and check the result. Disabling an authenticator is also a sensitive operation, not a routine fix for a failed login.
OmniTerm's supported account methods are not an ordinary OmniTerm account-password workflow. Reset a Google or Apple password with that provider. A forgotten vault password requires the vault recovery path, not a provider-password reset.
Never share sign-in codes, authenticator setup information or recovery codes with support. An enabled button or successful local setup is not a guarantee that an external email or identity provider is currently available.