Signing in
Signing in
One sign-in covers all of STRIDE — Tasks, the team board, OKRs and the admin console. Signing in once is enough; moving between them does not ask again.
Signing in
Go to the sign-in page, enter your email address and password, and press Sign In.
Where are you going?
The sign-in card. The theme buttons are at the top right, beside Back to site; the STRIDE mark at the top left goes to the public website. Admin console sits on its own row under the three tiles because it is not an ordinary destination — see below.
Remember me on this device does two things, and it is worth knowing both. Your email address is filled in next time — the password never is. And your session is kept when you close the browser, so you come back already signed in. Leave it unticked on a shared or borrowed computer: the session then ends with the tab, and nothing about you is left behind for the next person.
Light or dark. The sign-in page has both, as two buttons in the top-right corner of the header, labeled Dark theme and Light theme. (The third, team-colored option lives inside the app; the sign-in page has no team yet, so it offers the two.) If you have never chosen, it follows whatever your device is set to. Whatever you pick here is the same setting the apps use, so choosing light mode or dark mode on the way in is the theme you arrive in — and a choice made inside the app is the one you see next time you sign in.
If your session expires while you are working, the app sends you here and tells the sign-in page which of the four areas you came from — so you land back in that area rather than at whatever you last chose. It returns you to the area, not to the exact card or note you had open; you will need to find that again.
The cursor is already in the right box when the page opens — the email field, or the password field whenever the page already has your address, whether this browser remembered it or you arrived from a link that carried it. Show, at the right of the password box, reveals what you have typed so you can check it before pressing Sign in; press it again to hide it. It changes nothing else, and your password manager still works exactly as it did.
Creating an account
Anybody can create an account here. There is no code to obtain first, nobody to ask, and no approval step to wait for. Open Create account on the sign-in page, fill the form in, and you are through to the last step — proving the email address you typed is one you can actually read.
That last step is the part that matters, so it is worth knowing before you start. What makes an account real on this system is not who invited you; it is a six-digit code emailed to the address you signed up with. Until you enter it, the account exists and reaches nothing — so sign up with an address you can open now, not one you plan to check later.
The sequence is four steps:
- Open Create account on the sign-in page. The form grows two fields: first name and last name.
- Enter your account details — email, password, and your first and last name. The line under the password field states the strength currently required; an administrator sets that, so it may ask for more than you expect. Underneath it is a checklist that ticks each rule off as you type, so you can see what is still missing instead of guessing and being refused. Your name matters beyond the greeting: tasks are assigned to people by full name.
- Press Create account. The account is created immediately.
- Verify your email address. A six-digit code is sent to the address you signed up with, and entering it is the last step — see verifying your email below.
The same card with Create Account chosen: two more fields, and a checklist that turns green as each rule is met. The rules drawn here are an example — an administrator chooses how strong passwords must be, so yours may ask for more.
If somebody invited you
An invitation is a message, not a credential. If a team has invited you by email, the message carries a link that opens this page on Create account with your address already filled in. There is no code in it and nothing in it expires, so an invitation you find a fortnight later works exactly as it would have on the day it was sent.
Use the address the invitation was sent to. People are matched to teams by email address, so registering with a personal address after being invited on a work one leaves you with an account that is not on the team — which looks, from both ends, like the invitation never worked. Filling the address in for you is what the link is for.
The invitation comes from the team's own name and mark, not from this product's, so search your inbox for the team or for whoever asked you to join.
Verifying your email address
Creating the account is not the last step. The address you signed up with has to be shown to be yours before you can use the product, so the moment the account exists the page asks for a code and emails you one. Until that code is entered there is nothing else to do — this is a gate, not a reminder you can put off.
What arrives is a six-digit code, sent to the same address you sign in with. Type it into Verification code and press the button underneath. That is the whole of it: there is no link to click, so it does not matter which device your mail is open on, and nothing is lost if the mail arrives on your phone while you are signing in on a laptop.
- A code lasts 60 minutes. After that it stops working and you need a fresh one. The page tells you how long you have when it sends one.
- You can ask for a new code whenever you like — Send a new code under the box. Asking for one replaces the last one, so the newest code in your inbox is the only one that works. If two mails arrive, use the later. (Ask twice within a minute and the page says so rather than sending twice.)
- Six wrong attempts lock that code. Nothing happens to your account — only that code stops being accepted, and asking for a new one starts you over with a fresh six. This is what stops somebody guessing their way in.
If you close the page before finishing, nothing is lost and nothing is broken. Signing in again with the same email and password brings you straight back to this same step, with the address you are verifying named on screen. Your account exists; the only thing outstanding is the code.
Until you finish this, you are invisible to any team that invited you. An account that has not proved its address matches no invitation, so somebody who added you to a team still sees you as no account yet. That is not a fault at their end or yours — it is the same gate, seen from the other side, and entering the code closes it.
If the mail does not arrive, check the spam folder first — it is a short automated message and filters sometimes take against it. Then check that the address on screen is the one you meant to use. If it is wrong, there is nothing to enter and no way to correct it from here: ask your administrator, who can see the address the account was created with.
Choosing where you land
Under the sign-in form, Where are you going? offers three destinations as tiles — Tasks, Team Board and OKRs — and the Admin console on its own row underneath. Each tile is an icon, a name and a short caption (My work, Teams, Results) rather than a bare word. Pick one and it is remembered on this browser, so the next time you sign in you go straight there.
All three land on the pages this manual describes — one shell across Tasks, Notes, Calendar, Team and OKRs, whichever tile you pick. The Admin console is its own surface with its own layout, so it looks different when you get there.
The Admin console is on its own row because it is not an ordinary destination. Choosing it only says where to go; it grants nothing. Whether you can actually open it is decided after you sign in, by the database, and an account that is not an administrator is turned away there no matter what was picked here.
OKRs opens on your own team — the one you were last working in, preferring a team that actually has objectives switched on. You can change team from the dropdown once you are there.
Bookmark sign-in on a destination. Under the form is a link that carries whichever destination is selected. Bookmark it and that bookmark always opens sign-in on that page — keep one for each if you like. Using a bookmark does not change the destination you last chose by hand.
Resetting a password
Type your email address in the sign-in form first, then press Forgot password? — the button uses the address in the box, so an empty box is answered by being asked to fill it in. The form is then replaced by one panel asking for an eight-digit reset code, and the code is on its way as the panel opens.
It is a code, not a link, and it works the same way as the one that verifies a new account — but it is not the same code. One field, typed on the machine you are actually signing in on. It does not matter which device your mail is open on, there is no second tab, and nothing has to survive being forwarded.
Two codes, two lengths — and it is not a mistake
The code that verifies a new account is six digits. The code that resets a password is eight. They come from two different systems, which is the whole of the reason: the verification code is this product's own, and the reset code is issued by the sign-in service underneath it — the same one that sends the code when you change your password from inside the app, which is also eight.
Count what arrived rather than what you expected. The rules are identical either way — one hour, that address only, a new code replaces the old one — so nothing about using them differs. Only the length does.
- A code lasts 60 minutes, and the panel says so as it sends one.
- It is eight digits — not the six the verification code uses. The box takes what arrives; you do not have to count.
- It works only for the address it was sent to. There is nothing to transfer to another mailbox and nothing another address can do with it.
- Asking for a new one replaces the last — Send a new code is under the box. If two codes are sitting in your inbox, the later one is the only one that works. Press it twice in a minute and the page says so rather than sending twice.
- A wrong code, an expired code and one that has already been used read identically: “That code did not match, or it has expired. Send a new code and try again with the new one.” That is deliberate — see below.
The message you see after asking is always the same — “If that address has an account, a code is on its way to it. It expires in 60 minutes.” It says the same thing whether or not the address is registered, on purpose: a different answer for each would let somebody find out who has an account here by trying addresses. It is also why a refused code never tells you which of the three things went wrong — “expired” is only possible for a code that was really sent.
Sign out and go back under the panel returns you to the sign-in form if you would rather not finish now. Nothing is left behind by that: an unredeemed code is not a session, and your old password keeps working.
The email can take a minute, and it may land in a junk folder. You can ask from any of the apps; wherever you ask, you finish on the sign-in page, because that is where the new password is set.
A reset link already in your inbox still works
Before 6 September 2026 this step was an emailed link rather than a code. Any such link that has not expired still opens the same “choose a new password” panel and finishes exactly as it always did. Nothing sends new ones, so once yours lapses, ask again and you will get a code.
What happens once the code is accepted. The panel hands straight over to one more, and only that one: the two tabs, the “New to STRIDE?” line and the destination picker all stand down, because you are already past them. Until you set a new password the rest of the app stays closed — that is deliberate, so a recovery cannot be used as a way in.
Setting a new password after entering a reset code. The same panel appears when an administrator has reset your account, with a different sentence: Your password was reset by an administrator. Set your own before continuing. Either way the app stays shut until you have chosen one.
After your own reset, your old password keeps working right up until you finish here, which is deliberate: an abandoned reset must not lock you out of an account you could still get into. After an administrator's reset it does not — that is the point of one.
The security check
Sometimes the page asks you to prove you are a person. A small box headed Security check appears just above the button you were about to press. Most of the time there is nothing to do — it settles by itself and you carry on. Occasionally it asks you to click a checkbox. That is all it ever asks.
It shows up in three places, and never when you simply sign in. Signing in with a password you got right is never interrupted.
- Creating an account.
- Asking for a password reset code.
- After several failed sign-in attempts in a row — a correct password on the first try is never challenged.
It is in addition to the emailed code, not instead of it
This is the point to be clear about, because the two arrive close together. The security check does not replace the code we email you. Creating an account still ends with the six-digit verification code, and resetting a password still needs the eight-digit reset code. The check only decides whether the request is worth acting on at all; the code is what proves the mailbox is yours. Passing the check signs nobody in and proves nothing about who you are.
If there is a checkbox, tick it first. When the check wants something from you, the page says Please finish the security check above the button to continue — and pressing the button before you have ticked the box does nothing except repeat that. The box stays exactly where it is and waits for you; nothing you have typed is disturbed, and the button starts working the moment the check settles.
If it fails, try again — nothing is lost. A check that does not pass leaves everything you typed exactly where it was, so you press the button again rather than starting over. It is not a lockout and it is not a mark against your account.
If the box never appears, or never finishes:
- Reload the page and try once more. This clears up most of it.
- Check whether an ad blocker or privacy extension is switched on for this site. The check is served by an outside company, and blockers sometimes stop it loading. Allowing this site, or trying a private window, usually settles it.
- Try a different browser or network — a company VPN or a locked down guest network is the other common cause.
- If the service itself is having a bad day, the page notices. After a few tries it stops asking and lets you continue on the emailed code instead, so an outage somewhere else does not leave you shut out of your own account.
Your administrator can switch it off. It is a setting for the whole application rather than for one person, so if it is causing trouble for a whole team that is the conversation to have — there is no per-person exception, deliberately.
Staying signed in
Your session refreshes itself while you are using the app. Whether it survives closing the browser is decided by Remember me on this device: ticked, the session is kept and you come back already signed in; unticked, it ends with the tab. You are signed out when you press Sign out — which is in the menu under your initials, at the far right of the bar — or if the session goes stale, most often after leaving a tab untouched for a very long time.
Changing your password signs out your other devices. This one stays signed in; everywhere else has to use the new password. Changing your password.
While the app is working out whether you are signed in, you see Checking your sign-in… rather than the sign-in form. If it showed the form first, everybody with a valid session would see a sign-in screen flash on every load.
When you cannot get in
- "Invalid login credentials"
- The email or the password is wrong. Passwords are case-sensitive. If you are sure of both, reset the password rather than retrying — repeated failures are rate limited and will start being refused for a while.
- Nothing happens when I press Sign in
- Check the message under the button; it says what went wrong. If it mentions the connection, the app could not reach the server — try again in a moment.
- I cannot find the invitation email
- Look for the team's name, not this product's. An invitation to join a team arrives from the team that sent it and is headed by the team's own mark, so searching your inbox for the product name may find nothing. Search for the team, or for the name of whoever asked you to join.
- My verification code is refused
- Check that you are using the newest one. Asking for a new code replaces the last, so if two are sitting in your inbox only the later works. A code also stops working 60 minutes after it was sent, and after six wrong attempts that particular code is locked — in every one of those cases the answer is the same: press Send a new code and use what arrives. Nothing happens to your account, and a fresh code starts you over with a fresh six attempts. There is no registration code and never any need to ask anybody for one — the only code this product will ever ask you for is the one it just emailed to you.
- I am signed in but an app says I have no access
- Being signed in is not the same as being granted access. A team administrator grants boards, and OKRs are off until a team switches them on. Teams and boards.
- I keep getting signed out
- Usually a browser set to clear site data on close, or private browsing. Both discard the session every time the window closes.
Keeping the account safe
Use a password you do not use anywhere else. Anyone who can sign in as you can read every task and note on your account — and, if you have saved an AI API key, can read that too. Nobody administering this application will ever ask you for your password.