Signing in with a password, and two-factor authentication
Who can use it. Everyone with a Summit Hub account — customers, field accounts, employees, owners, and platform overseers. Password sign-in is an optional extra some businesses may not have turned on yet; two-factor authentication ("2FA") is available to everyone and is required outright for platform overseers.
What it's for
Signing in with an emailed link works well, but some people would rather use a password — especially on a shared or slow-to-check inbox. When your business has password sign-in turned on, you can set one up and use it instead of waiting for an email every time. Two-factor authentication adds a second, much stronger layer of protection: even if someone guessed or stole your password, they still couldn't get into your account without the six-digit code from your authenticator app (or a saved recovery code).
How to use it
Setting a password
- Go to My Account, in the sidebar for every signed-in role.
- If you don't have a password yet, the Password card offers **Set
password** — just choose one (10–128 characters, no other rules) and confirm it.
- Once you have a password, the same card becomes Change password,
which asks for your current password first.
- Either way, you'll see a "Password updated" confirmation once it's saved.
If your business hasn't turned password sign-in on yet, the sign-in page only offers the emailed-link option — that's expected, not a fault.
Forgot your password?
- On the sign-in page, switch to "Use a password instead", then click
Forgot password?
- Enter your email and submit. You'll always see the same "check your
email" message — whether or not that address actually has an account — so nobody can use this form to find out who has one.
- If an account exists, you'll get an email with a link. It's single-use and
expires after 60 minutes.
- Opening the link lets you choose a new password. This also works as a way
to set your FIRST password, if you've never had one.
- Once it's saved, sign in as normal — you'll go through the same two-factor
check as any other sign-in if you have it turned on.
Setting up two-factor authentication
- Go to My Account and find the Two-factor authentication card.
- Click Set up two-factor authentication.
- Scan the QR code with an authenticator app (Google Authenticator, 1Password,
Authy, and similar all work), or type in the code shown underneath if you can't scan.
- Enter the 6-digit code your app shows to confirm it's linked up.
- You'll be shown 10 recovery codes — save these somewhere safe. Each one
can be used once, instead of your authenticator app, if you ever lose access to it. They're only ever shown this one time.
From then on, every time you sign in — whether by emailed link or password — you'll be asked for a 6-digit code (or a recovery code) before you're fully signed in.
Losing access to your authenticator app
Use one of your saved recovery codes in place of the 6-digit code on the verification screen. Once you're back in, go to My Account and regenerate your recovery codes — this replaces your whole set with 10 fresh ones (shown once, same as at setup) and immediately invalidates the old ones, including the one you just used.
If you've lost your authenticator app and your recovery codes, contact whoever manages your Summit Hub account for help — this needs an operator to step in.
Turning two-factor authentication off
From My Account, click Disable two-factor authentication and confirm with a current code (or a recovery code). This option isn't offered at all if your role requires 2FA (see below) — in that case there's no way to turn it off short of no longer needing the requirement.
What it affects
- The sign-in page, when password sign-in is turned on for your business.
- Every sign-in, once you've turned on two-factor authentication — you'll see
an extra verification step after your usual sign-in method.
- My Account, a new page in the sidebar for every role, with the password
and two-factor cards described above.
- Employees and owners who haven't set up 2FA see an occasional reminder
banner suggesting they do — it can be dismissed and comes back after a day.
Good to know
- Password sign-in is optional on top of the emailed link, never a
replacement for it — you can always fall back to the emailed link.
- Two-factor authentication is required, with no way to opt out, for
platform overseers. For everyone else it starts as an encouraged, optional extra — though a business can choose to require it for its employees and owners too, at which point they'll be asked to set it up the next time they sign in and won't be able to use the app until they do.
- Customers and field accounts can turn 2FA on if they'd like the extra
security, but it's never required for them, and they won't see the reminder banner.
- A changed or reset password signs out any OTHER devices/browsers you were
signed into elsewhere, within a few minutes — the device you just changed it from stays signed in.
- Setting, changing, or resetting your password also cancels any other
"reset your password" email link you'd previously requested but not used — only the most recent action wins.
- Recovery codes are shown to you exactly once. If you didn't save them, use
Regenerate recovery codes in My Account (this needs your authenticator app or an existing recovery code) to get a fresh set.