Phone verification
An optional signup check on some installations: enter a mobile number, receive a code, confirm it once.
Browse topics
What it is
Phone verification is an optional signup check that some Agentency installations turn on. You enter a mobile number, receive a one-time code by SMS, and enter it to prove the number is yours.
Two things it is not:
- It is not two-factor authentication. It happens once, around signup — not at every sign-in. App-based two-factor is a separate feature under Settings → Security. See Two-factor authentication.
- It is not the phone field on your profile. That one is a contact detail and has nothing to do with this check. See Update your profile.
Many installations do not use this at all. If you have never seen the /verify-phone page, yours is one of them and nothing is missing.
Why it exists
It is an anti-abuse measure. Free accounts are attractive to people who want dozens of them, and requiring a working mobile number puts a real-world cost on creating each one. Where it is enabled, one number generally means one account.
When you would use it
- Sign-in sends you to
/verify-phoneand the dashboard is out of reach until you finish. - Registration asks for a phone number and a code.
- You are trying to work out why a colleague was asked for a number and you were not.
Where to find it
The page is at /verify-phone. You do not navigate there by choice — you are sent there when it is required.
Before you start
- Have the phone in your hand. Codes are short-lived.
- Use a mobile number that can receive SMS. Landlines and many virtual or VoIP numbers do not work.
- Know your country code.
- Check your signal. A code sent while you are underground arrives after it has expired.
Steps
- If the dashboard redirects you to
/verify-phone, stay on that page. - Enter your mobile number with the country code.
- Request the code and wait for the SMS. Give it up to a minute before assuming it failed.
- Enter the code exactly as received.
- On success you continue to the dashboard.
- If you never see
/verify-phone, your installation does not require this — carry on as normal.
What you will see
A two-step form: the number first, then the code. It looks like a sign-in page but it is a check that happens after your credentials have been accepted, which is why you may briefly feel signed in and then be redirected.
Error messages are deliberately general — "we could not send a code", "that code is not valid" — rather than quoting the SMS provider. Provider messages leak details that are of more use to an attacker than to you.
The rules that trip people up
Codes expire quickly. Around ten minutes. An old code will be refused even if you typed it perfectly.
Wrong attempts are limited. A handful of wrong codes ends that challenge and you have to request a new one. Guessing does not pay.
One number, one account. Where this is enabled, a number that already belongs to an account will usually be refused for a second one. Sharing an office mobile across several signups will not work.
Existing accounts are usually exempt. When an installation switches this on, accounts created before that point are typically grandfathered so nobody is locked out of an account they already had. New accounts must verify. This is why you and a colleague can be treated differently on the same installation — it depends on when each account was created.
Limits and plan notes
- This is an installation-level setting, not a plan feature. Upgrading does not turn it on or off.
- Where it is enabled, some parts of the dashboard stay out of reach until the number is confirmed.
- It is a one-time check at signup. It is not used as an SMS second factor at later sign-ins.
- Accounts created with Google are also covered where the installation requires it — you sign in with Google and are then sent to the verification page.
- SMS depends on your mobile network. Delivery in some countries and on some networks is slower or less reliable, and that is outside Agentency's control.
Common problems
I never got the SMS.
Check the country code first — it is the single most common mistake. Wait a full minute. Request one new code, then stop; repeated requests are rate-limited and will slow you down further. Landlines and VoIP numbers frequently fail outright.
The code is rejected even though I copied it.
It has probably expired, or a newer code has been sent and only the newest is valid. Request a fresh one and enter it immediately.
I ran out of attempts.
Request a new code and enter it carefully. If that also fails, wait a while before trying again.
The site keeps sending me back to /verify-phone after I succeeded.
Give the page a moment to update your session, then use the continue control if one appears. Do not start over with a second number — you will end up chasing two challenges at once. If it persists, sign out fully and sign in again.
My number is already in use.
Where one-number-per-account is enforced, that number is attached to an existing account. Sign in to that account instead, or use a different mobile number.
I do not want to give a phone number.
Where an installation requires it, there is no way around it from inside the product. Contact whoever operates your installation. See Contact Support.
Do I have to do this every time I sign in?
No. It is a one-time check. If you are being asked repeatedly, the session is not recording the success — sign out completely and sign in again, and report it if it continues.
Common questions
Is this the same as two-factor authentication?
No. It happens once around signup, not at every sign-in. Two-factor is an authenticator app you enable yourself under Settings → Security.
Why was my colleague asked and I was not?
When an installation switches this on, accounts created before that point are usually exempt so nobody is locked out. Newer accounts must verify.
The SMS never arrived.
Check the country code first, then wait a full minute. Landlines and many virtual or VoIP numbers cannot receive these codes at all.
Can I use the same number on two accounts?
Usually not. Where this check is enabled, one number generally means one account — that is the entire anti-abuse point of the feature.
Was this article helpful?
Related articles
Sign-in options
Email and password or Continue with Google — same email means the same login. Extra fields appear only when asked for.
Two-factor authentication
Add an authenticator app to your sign-in, so a stolen password alone is not enough to reach your workspace.
I cannot sign in
Match the message you see to its fix: wrong credentials, throttling, a lockout, Google-only sign-in, two-factor, or verification.
Update your profile
Change your display name, photo, company details, and phone on Settings → Account. Your profile follows you everywhere.
Ready to try it on your own content?
Create a free workspace, add a document, and ask the questions your team is tired of answering.