This guide is for anybody who wants a stronger sign-in, and for the administrator who sets up single sign-on for a company. Every task below starts in Settings > Security. Brix always keeps one working way into your account, so no action on this page can lock you out.
What you can do
- Password reset — Send yourself an email link that sets a new password.
- Google and Microsoft — Connect either account as a second way to sign in.
- Passkeys — Sign in with your face, your fingerprint or a security key.
- Two-factor authentication — Add a 6-digit code from an authenticator app to every sign-in.
- Recovery codes — Keep ten one-time codes for the day you lose your authenticator.
- Single sign-on — Route a company email domain to your own identity provider.
- SSO-only sign-in — Drop the password once another sign-in method works.
Read what your account signs in with
- Open Settings > Security.
- Read the Password row under Sign-in methods.
- Read each row below it for a connected Google, Microsoft or single sign-on identity.
- Scroll to Passkeys for the devices that sign in without a password.
- Scroll to Two-factor authentication for the state of the second factor.

Send yourself a password reset link
- Open Settings > Security.
- Find the Password row under Sign-in methods.
- Select Reset password.
- Read the green banner that names your email address.
- Open the email from Brix.
- Follow the link in the email.
- Set a new password.
Connect Google or Microsoft to your account
- Open Settings > Security.
- Select Connect Google or Connect Microsoft under Sign-in methods.
- Sign in at the provider.
- Wait for the browser to return to Settings > Security.
- Read the green banner that confirms the connection.
- Check the new row in the list.
Add a passkey for this device
- Open Settings > Security.
- Scroll to Passkeys.
- Select Add a passkey.
- Type a label such as
MacBook · TouchIDinto Label (optional). - Select Create passkey.
- Approve the prompt from your browser or your device.
- Check that the new row reads
Added just now · never used.
Remove a passkey
- Open Settings > Security.
- Scroll to Passkeys.
- Select the trash button on the passkey row you no longer want.
- Select Remove in the confirmation dialog.
Turn on two-factor authentication
- Open Settings > Security.
- Scroll to Two-factor authentication.
- Select Set up.
- Scan the QR code with your authenticator app.
- Or copy the key under Or enter manually into your app.
- Type the 6-digit code from your app into the Step 2 field.
- Select
Verify & turn on. - Select Copy all to copy the ten recovery codes.
- Store the recovery codes somewhere safe.
- Select
I've saved them.

Turn off two-factor authentication
- Open Settings > Security.
- Scroll to Two-factor authentication.
- Select Turn off.
- Type a current 6-digit code from your authenticator app.
- Select Turn off a second time to confirm.
Set up single sign-on for your company
A single sign-on connection routes every email address in your domains to your identity provider. Brix works with Microsoft Entra ID, Google Workspace, Okta, Auth0 and any other OIDC provider.
- Open Settings > Security.
- Scroll to Single sign-on.
- Select Add SSO connection.
- Type a name such as
Acme Single Sign-Oninto Display name. - Choose your provider in Vendor.
- Paste the issuer URL from your provider into Issuer URL.
- Select Test to check the discovery document.
- Paste the client ID from your provider app registration into Client ID.
- Paste the client secret into Client secret.
- Type your email domains into Email domains.
- Separate two or more domains with a comma.
- Leave
Just-in-time provisioningticked so Brix creates a member at first sign-in. - Leave Enabled ticked.
- Select Create connection.
- Select Copy beside Redirect URL for your IdP.
- Paste that URL into the redirect-URI field of your provider.
- Select Done.

Change an SSO connection
- Open Settings > Security.
- Scroll to Single sign-on.
- Select Edit on the connection row.
- Change the fields you need.
- Leave Client secret empty to keep the stored secret.
- Select Save changes.
Remove an SSO connection
- Open Settings > Security.
- Scroll to Single sign-on.
- Select the trash button on the connection row.
- Select Remove in the confirmation dialog.
Switch your account to single sign-on only
- Add a passkey, or connect Google, Microsoft or your company provider.
- Open Settings > Security.
- Find the Password row.
- Select Use SSO only.
- Read the warning in the Switch to SSO-only? dialog.
- Select Remove password.
- Read the banner that confirms the account now holds no password.
Disconnect a linked account
- Open Settings > Security.
- Find the provider row under Sign-in methods.
- Select the trash button at the end of the row.
- Select Disconnect in the confirmation dialog.
To give an integration its own credential instead of a person, see API keys and integrations. To set what each member can do, see organization, people and roles. To read who changed what, see proof of play and the audit log.