Accounts, Sign-In and Passkeys
Everything about logging in — passwords, MFA, passkeys, SSO, lockouts, and what to do when you can't get in.
Accounts, Sign-In and Passkeys
How do I sign in?
Visit your tenant URL (typically {your-org}.papyrus.io). Enter your email + password, or click “Sign in with [SSO provider]” if your org uses Microsoft / Google / Okta SSO.
I forgot my password
Click “Forgot password” on the sign-in screen. You'll receive an email with a one-time link to set a new one. The link expires after 60 minutes. If the email doesn't arrive, check spam — it's sent from noreply@papyrus.io.
What's a passkey and why use one?
A passkey replaces your password with biometric (Touch ID, Face ID, Windows Hello) or hardware-key authentication. Faster sign-in, no password to forget, and substantially harder for attackers to phish. Set one up in Profile & Settings → Security.
How do I set up MFA?
In Profile & Settings → Security, click “Enable Authenticator App MFA”. Scan the QR code with Google Authenticator, Microsoft Authenticator, or Authy. Save the backup codes somewhere safe. Done — future sign-ins ask for a 6-digit code from your authenticator.
My account is locked. What now?
After 5 failed sign-in attempts, accounts lock for 15 minutes. If you're sure you have the right credentials, wait 15 minutes and try again. If it persists, ask your Tenant Admin to reset; if you are the Tenant Admin, contact Papyrus support.
Can I sign in on multiple devices?
Yes. Sign in on web, mobile, and desktop simultaneously. Each session is independently revocable from Profile & Settings → Sessions.
What happens when I leave the organisation?
When your Tenant Admin disables your account, you immediately lose access. Documents you uploaded remain in the tenant (they belong to the organisation). Your personal preferences are retained for 90 days in case you rejoin.
Does Papyrus support SSO?
Yes — via OpenID Connect (Microsoft Azure AD, Google Workspace, Okta) on the Business and Enterprise plans. SAML 2.0 is on the Enterprise plan. Configure under Admin → SSO / Identity Providers.