Account

Lost the phone with your authenticator app?

Start by asking for an ordinary email sign-in link. Many people expect a lock-out and find the link puts them straight into the dashboard. If it does, go to Security and remove the authenticator you no longer have — that needs nothing but being signed in — then set up the new phone.

Do this first

Ask for a sign-in link, then clear the old authenticator

Sign-in here has no password. The six-digit prompt is a separate step that only appears when the sign-in you are completing comes back with two-factor still pending. An email sign-in link does not, so try it before assuming the worst.

1

Request a link and open it

Owners sign in on app.orcalinq.com; team members on agents.orcalinq.com. Type your email, press Send sign-in link, open the email and click once. If the email will not arrive, that is a different problem — see signing in without a password.

2

Remove the authenticator you have lost

Go to Security — under Account in the owner dashboard sidebar, underSettings in the team portal. Find the Two-factor authentication card. Each authenticator is a row with a phone icon and the date it was added. Click the red bin icon on the row for the lost device.

There is no confirmation dialogue and you are not asked for a code to do this — being signed in is enough. The page then says “Authenticator removed”, and when no authenticators remain the badge beside the heading flips from Enabled to Disabled.

If removal fails with “Couldn't reach the auth server…”, hard-refresh the page (Ctrl + Shift + R) and try once more. That message means the request never got through, not that the removal was refused.

3

Set up the new phone

Same card: Enable 2FA. A QR code appears with the secret printed underneath it. Scan the code with the authenticator app on the new phone, type the six digits it shows, and press Verify. The page confirms “Authenticator added.”

In the owner dashboard there is also a “Name this authenticator” box — use it (“Microsoft Authenticator on iPhone”). That name is stored in the browser you typed it in and nowhere else, so it will not follow you to another computer.

If you are asked for a code

Four things that get you past the six-digit prompt

The prompt reads “Verify it's you”, with a link underneath saying“Use another method” that returns you to the sign-in form. Work through these in order.

  • Restore the app itself. Most authenticator apps can bring your codes back on a new phone if their own backup was switched on — Google Authenticator syncs to your Google account, Microsoft Authenticator has its own cloud backup, and 1Password or Authy sign in on any device you own. Install the app on the new phone, sign in to the app's account, and look for a Restore or Import option in its settings. If the app had no backup switched on, the codes are gone and nothing in the app will bring them back.
  • Your second authenticator. The Security page lets you keep two, and showsAdd another while you have fewer than two. If you set one up on a tablet or in a password manager, its code works here.
  • A passkey on a device you still have. On the sign-in page, open“Already set up a passkey? Use it →” and confirm with your fingerprint, face or device PIN. A passkey sign-in completes on its own and does not ask for the six digits. If you see“No passkey found for this site on this device”, you have not registered one here — nothing is broken.
  • Google, Microsoft, Apple or Facebook. Only if those buttons are showing on your sign-in page, and only if you linked one earlier. They are absent unless switched on for your deployment.
Read this before you type anything

Recovery codes: be careful what you expect

The sign-in page has a quiet “Can't sign in?” link. It leads to a menu including“I lost my authenticator app”, which offers Enter recovery code. Two honest warnings about that screen:

  • Switching two-factor on does not give you recovery codes today. The setup screen shows a QR code, the secret, and then “Authenticator added.” — no list of one-time codes to write down. So unless codes were issued for your account specifically, there are none, and that box will reject everything you type. Assume you have none unless you are holding a printed or saved list.
  • Ignore the “recovery key” option. The same menu offers “I lost my recovery key” and aUse recovery key button. That path is not implemented in the current build: the button accepts your text and does nothing. It is not a sign that your key is wrong.

Where recovery codes do exist, they behave as you would expect: ten codes, shown once at the moment they are generated and never shown again, each usable once, and generating a new set kills the old set. Repeated wrong guesses are throttled, so type carefully rather than quickly.

The honest limit

No self-service reset — email us

If you cannot sign in at all and none of the routes above apply, there is no button anywhere that removes two-factor from an account you cannot get into. That is deliberate: a button like that would be a way in for somebody who is not you. We do it by hand after checking who you are.

  • Email support@orcalinq.com, ideally from the email address on the account.
  • Say which site you sign in on — app.orcalinq.com or agents.orcalinq.com.
  • Give the account email address, spelled out, and roughly when you switched two-factor on.
  • Say what happened to the device: lost, stolen, replaced, or the app was deleted. It changes how quickly we should act.
  • Quote the on-screen message you are stuck on, word for word.
  • Never send us a code, a secret, or a photo of the QR code. We do not need them and they must not travel by email.

Team members: your own admin cannot do this for you. There is no control in the owner dashboard that removes a member's authenticator, so writing to us is faster than waiting on them.

Once you are back in

Make the next phone a non-event

  • Register a passkey on the computer you use most: SecurityPasskeysRegister this device. It is the shortest route past a lost phone.
  • Add a second authenticator while you have a working one — on a tablet, or in a password manager that syncs. The page allows two.
  • Use an authenticator app whose own backup is on, so a replacement phone restores your codes without involving anybody.
  • Name each authenticator in the owner dashboard, so a year from now you can tell which row is the phone in your hand.
If that did not work

Still stuck at the code prompt

  • Codes rejected one after another? Check the clock on the phone. Authenticator codes are time-based, and a phone whose time is set by hand and drifting will produce codes that are always wrong. Turn automatic date and time back on.
  • Typed it a few times and now everything fails? Attempts are rate-limited. Wait fifteen minutes before trying again, then enter one code carefully.
  • Code from an app you no longer recognise? If two entries in your authenticator have the same account email, one is a stale enrolment. Try the newest, then remove the extra row from Security once you are in.
  • Nothing above fits? Email support@orcalinq.com with the details listed further up. Do not keep guessing codes — it only extends the throttle.

Try the email link first.

Then Security → Two-factor authentication → bin the lost device → Enable 2FA on the new phone.