I cannot sign in
Match the message you see to its fix: wrong credentials, throttling, a lockout, Google-only sign-in, two-factor, or verification.
Browse topics
What it is
Sign-in can fail for about a dozen different reasons, and the message you see usually tells you which. This article maps each message to its fix, in the order they are most likely to happen.
Before anything else, two checks that resolve a surprising share of cases:
- Are you on the real Agentency sign-in page? Type the address yourself rather than following a link from an email you were not expecting.
- Are you using the right email? If you normally sign in with Google, a password on the same address may simply not exist. If you were invited to a team, the invitation was sent to one specific address and only that one works.
Where to find it
The sign-in page. Once you are in, Dashboard → Settings → Security is where two-factor authentication is managed, and Dashboard → Accounts is where a team member finds the workspace they were invited to.
Match the message to the fix
"These credentials do not match our records."
Wrong password, or no account on that address. It is deliberately the same message either way, so that a stranger cannot use the sign-in page to discover which of your colleagues has an account.
Fix: use Forgot password. See Reset your password.
"Too many login attempts. Please try again later."
You have hit the throttle after repeated failures from the same place. It clears on its own after a short wait — around a quarter of an hour.
Fix: stop guessing, wait, then use Forgot password rather than trying a thirteenth variation. Each extra attempt extends the problem.
"Account temporarily locked due to too many failed attempts. Try again later."
The account itself is now locked, not just throttled. Same cause, one level up.
Fix: wait out the lock — it lifts by itself after a short period — then reset the password. A successful sign-in clears the counter completely.
"This account uses Google sign-in. Please sign in with Google instead."
There is no password on this account because it was created through Google.
Fix: use the Google button, with the same Google account. See Google sign-in.
"A two-factor authentication code is required." / "The two-factor authentication code is invalid."
Your password was accepted and the second step is now needed.
Fix: open your authenticator app and enter the current code. If it is rejected, check your phone's clock — a device several minutes out of sync generates codes the server will not accept. If you no longer have the app, use one of your backup codes; each works once. See Backup codes.
Note that failed two-factor attempts count towards the same lockout as failed passwords, so do not brute-force it.
"Please verify your email address to continue."
Your installation requires a verified email and yours is not.
Fix: open the verification email and follow the link, or request a new one. See Verify your email.
A phone code is requested
Your installation requires a verified phone. You will be asked for a code sent by SMS.
Fix: enter it. If it does not arrive, wait for the resend cooldown and request another; there is a limit on both wrong attempts and resends per challenge. A voice-call option is available where SMS will not reach you. See Phone verification.
"You must set a new password before signing in."
Your password has been marked as needing replacement.
Fix: use Forgot password to choose a new one. There is no way around this step.
"This account is not allowed to sign in. Please contact support."
The account is suspended.
Fix: this one cannot be resolved from your side. Write to support from the address on the account, and say when you last signed in successfully — see Contact Support.
"Sign-in is temporarily unavailable. Please try again shortly."
A platform-side problem rather than anything to do with your credentials.
Fix: wait a few minutes and try again. If it persists for more than about half an hour, report it with the time.
Signed in, but the dashboard looks wrong
You are through the door and the problem is now something else:
Empty dashboard after joining a team. You are in your own workspace. Open Dashboard → Accounts and switch — see Switch accounts.
Google signed me into an empty account. That Google address is a different login from the one that owns your workspace. Sign out and sign in with the correct address.
Billing and Developer have vanished. You are switched into somebody else's workspace. Switch back — see Why Billing is missing.
Limits and plan notes
Two-factor authentication uses an authenticator app, not SMS. Phone verification, where it is enabled, is a separate identity check rather than your second factor.
Backup codes are single-use and you get a fixed set when you enable two-factor. Regenerate them once you are down to a couple — see Backup codes.
A password reset link expires after about half an hour. Request a fresh one rather than reusing an old email.
The reset page always says a link has been sent, even for an address with no account. That is deliberate anti-enumeration behaviour, and it means "I got the confirmation" does not prove the address is registered.
Sign-in requirements vary by installation. Email verification, phone verification, and captcha challenges are configurable and are not all on everywhere.
If nothing here works
Write to support with:
- the email address you are trying to sign in with,
- the exact message you see, copied not paraphrased,
- the time of your most recent attempt, with your timezone,
- whether you use Google or a password,
- whether two-factor is enabled, and whether you still have the app or any backup codes,
- what you have already tried from this article.
Never include your password, a two-factor code, or a backup code in the message. Support will not ask for any of them. See Contact Support.
Common problems
I lost my phone and my backup codes.
Support is the only route. Write from the address on the account and expect identity questions — this is exactly the situation two-factor is designed to make hard, so it will not be instant.
My authenticator codes are always rejected.
Your device clock is out of sync. Turn on automatic time on the phone and try again. This is by far the most common cause.
The reset email never arrives.
Check spam, confirm the address is spelled correctly, and confirm the account exists on that address rather than another. Remember the page shows the same confirmation either way.
It works on my phone and not my laptop.
A browser extension, a saved wrong password, or a stale session. Try a private window before you suspect the account.
A teammate cannot sign in and I want to reset it for them.
You cannot. Password resets go to the account holder's own inbox, and no role in Agentency can change another person's password — that is a deliberate boundary, not a missing feature.
Common questions
Does a wrong password lock me out permanently?
No. Repeated failures throttle you, then lock the account for a short period, and both clear on their own. Stop guessing and use Forgot password — every extra attempt extends the wait.
My authenticator codes are always rejected. Why?
Almost always a device clock that is out of sync. Turn on automatic time on your phone and try again. Note that failed two-factor attempts count towards the same lockout as failed passwords.
I got the reset confirmation but no email arrived.
The page shows the same confirmation whether or not an account exists on that address — that is deliberate, so nobody can use it to discover who has an account. Check spam, then check you are using the right address.
How long is a password reset link valid?
About half an hour. Request a fresh one rather than reusing an older email.
I signed in fine but the dashboard is empty.
You are in your own workspace rather than the team's. Open Dashboard → Accounts and switch. Accepting an invitation grants access but does not move you.
Was this article helpful?
Related articles
Sign-in options
Email and password or Continue with Google — same email means the same login. Extra fields appear only when asked for.
Reset your password
Request a one-time link from /forgot-password. The page says the same thing whether or not the address is registered.
Two-factor authentication
Add an authenticator app to your sign-in, so a stolen password alone is not enough to reach your workspace.
Backup codes
You get 8 single-use codes in the form XXXXX-XXXXX, shown once. They are your way in when the phone is gone.
Ready to try it on your own content?
Create a free workspace, add a document, and ask the questions your team is tired of answering.