EIGENN.
docsguidesapichangelogpricingsign in
EIGENN.

Troubleshoot Account Access

Diagnose hosted sign-in, SSO, workspace selection, MFA, subscription, and connection gates with no risk to credentials.

Identity, workspace membership, MFA policy, subscription state, or necessary financial connections can block account access. Find the page and the message that you see before you change a setting.

Protect Credentials First

Never send or paste:

  • password or magic-link contents
  • MFA QR code, manual secret, or six-digit code
  • session cookie
  • OAuth access or refresh token
  • API key or webhook secret
  • bank login credentials
  • full payment-card details

Support can investigate with the sign-in email, organization domain, workspace, time, page URL, and exact non-secret error text.

1. Find the Stage That Blocks You

What you seeLikely stage
Sign-in page repeatsHosted identity start or callback
SSO Setup RequiredOrganization/domain configuration
Create your Eigenn workspaceNo active workspace membership
Set up two-factor authenticationMFA enrollment
Six-digit verification pageWorkspace MFA policy or fresh sign-in verification
Choose the plan or Verifying subscriptionSubscription gate
Non-dismissible Stripe and bank setupNecessary initial connections
Permission error inside SettingsRole does not let you do the requested write

Work the relevant section below. Do not create a second account or workspace until you confirm that the first one does not exist.

2. Retry the Hosted Sign-In Method

Use the same method that you used before:

  • Google
  • Apple
  • GitHub
  • email through the hosted identity flow
  • company SSO

The app remembers the last used provider in the browser and marks it Last used. That hint is local to the browser, not proof of the account's identity provider.

If a protected-page link sent you to sign-in, keep the return_to destination and complete authentication in the same browser. Eigenn rejects unsafe external return destinations.

Rate-limited sign-in

The authentication start endpoint lets you make a limited number of tries in a 15-minute window. Do not try again and again. Wait for the window to clear. Then try one time.

Callback failed

If sign-in returns with an authentication-callback error:

  1. Start again from the Sign-in page.
  2. Use the same provider.
  3. Let the browser use the necessary cookies.
  4. Do not open many callback tabs at the same time.
  5. Record the time and the final URL if it fails again.

3. Resolve SSO Setup Required

The SSO error page appears when domain-based authentication cannot find a team or an organization that you set up.

If you are a member

Contact the organization owner. Send the company domain and the SSO error text. Do not create a separate personal workspace unless the owner directs you to.

If you are the owner

  1. Sign in through an available non-SSO owner identity.
  2. Open Settings → Account → Organizations.
  3. Create or select the organization.
  4. Confirm its company domain.
  5. Open the available identity administration link.
  6. Complete the SSO configuration there.
  7. Test with a non-owner user.

The workspace Security page does not set up SSO.

4. Restore Workspace Selection

Eigenn sends a new user with no membership to workspace creation. A user with more than one membership and no selected workspace must choose one. The server does not guess.

If a current user sees workspace creation unexpectedly:

  1. Open the Teams page if available.
  2. Confirm that the invitation went to the same email that you use to sign in.
  3. Ask an owner to check the membership and the role.
  4. Switch to the intended workspace.
  5. Reload the original page.

Workspace invitations are email-specific. If you sign in with another provider email, Eigenn can create or select a different local identity.

5. Recover MFA Access

You have no enrolled factor

When the workspace needs MFA and no factor exists, the verification flow sends you to setup.

  1. Generate the QR code.
  2. Add it to a TOTP authenticator.
  3. Enter the current six-digit code.
  4. Confirm the code.
  5. Return to the requested page.

Eigenn rejects a valid code

  • confirm that the code belongs to the displayed account
  • turn on automatic time on the authenticator device
  • wait for the next code and enter it one time only
  • do not reuse a code after you generate the enrollment again

You lost a device

Use another enrolled factor if one exists. After you get access again, open Settings → Account → Security. Add a replacement. Confirm it. Then remove the lost factor.

If every factor is unavailable, use public Contact. The current app does not show recovery codes or a self-service factor-reset path.

You cannot remove the last factor

The active membership is subject to the future-member MFA policy. Add another factor first.

6. Resolve Subscription Verification

Eigenn can redirect a new user without active access to plan setup. After successful checkout, subscription activation can take time to synchronize.

  1. Keep the checkout return page open.
  2. Wait for the status poll.
  3. Use Retry status check after its timeout.
  4. Compare hosted billing before you purchase again.

For an established workspace, open Settings → Billing and Manage billing. A billing restriction can permit reads but reject writes across the app.

7. Complete the Necessary Connections

Protected pages can show a setup modal that blocks you until the active workspace has:

  • Stripe connected
  • at least one bank connection

If one is already connected, the flow skips it. If the modal remains after both appear present:

  1. Confirm that both belong to the same active workspace.
  2. Wait for the bank account selection and the sync to complete.
  3. Refresh one time.
  4. Return to the summary and select Finish setup.
  5. Contact support with provider, institution, time, and page URL if the checker remains stale.

8. Diagnose Settings Permission Errors

Page visibility and write permission are separate.

  • General workspace changes need Owner.
  • Workspace Security changes need Owner.
  • Custom email-domain lifecycle needs Owner.
  • Billing delegates need Owner.
  • Notification writes need Owner or Member.
  • Owner or Member can do plan checkout, portal, and cancellation.
  • Viewer can read team-scoped settings but cannot write them.

It is safer to switch to an owner account than to submit a visible control that the server rejects again and again.

9. Profile Email and Sign-In Identity Differ

A change to Settings → Account → General → Email updates the local Eigenn profile. It does not check or update the hosted identity provider in the same operation.

If sign-in still recognizes the old email, continue with the identity provider's address until its supported update process is complete. Ask an organization administrator for SSO identities.

10. Escalate Safely

When signed in, use Settings → Account → Support. When signed out, use the public Contact page and its published email.

Include:

  • sign-in method
  • profile email and company domain
  • workspace name
  • the page and URL that block you
  • exact error message
  • timestamp and timezone
  • last successful access
  • whether another user can enter the workspace

Do not include secrets even when asked for more detail.

Related Pages

  • Security and Access
  • Onboarding and Support
  • Account Preferences
  • Set Up a Workspace
  • Teams and Organizations
  • Support

Set Up a Workspace

Create, secure, connect, and check a workspace before you invite the team.

Webhook Delivery

Set up and test an app-specific Eigenn automation destination, and account for its current retry and verification limits.

On this page

Protect Credentials First1. Find the Stage That Blocks You2. Retry the Hosted Sign-In MethodRate-limited sign-inCallback failed3. Resolve SSO Setup RequiredIf you are a memberIf you are the owner4. Restore Workspace Selection5. Recover MFA AccessYou have no enrolled factorEigenn rejects a valid codeYou lost a deviceYou cannot remove the last factor6. Resolve Subscription Verification7. Complete the Necessary Connections8. Diagnose Settings Permission Errors9. Profile Email and Sign-In Identity Differ10. Escalate SafelyRelated Pages

Eigenn docs

current product

Overview
Overview
OverviewAccount PreferencesAssistant AutomationAssistant Command CenterBank ConnectionsBilling and UsageBudgets and ForecastCommand CenterCustomer LifecycleCustomer RecordsCustomersDeveloper PlatformDocument Processing and ExtractionDocument VaultFinancial Analytics and ReportsFinancial OverviewInvoice InsightsInvoice ProductsInvoicesMarketplace IntegrationsNotifications and BrandingOnboarding and SupportOverviewReceivablesReceivables AnalyticsReceivables ControlsSecurity and AccessSettings OverviewStress TestsTeams and OrganizationsTone Profiles and ExperimentsTransaction Categories and RulesTransactionsWeekly Finance RitualWorkflow ExecutionsWorkflow PausesWorkflowsWorkspace Inbox and Approvals
OverviewBuild and Review a ForecastBuild Your First WorkflowConfigure Assistant OperationsConfigure Notifications and BrandingConfigure Receivables ControlsConnect Transaction RecordsCreate and Manage CustomersCreate and Send InvoicesDeveloper API SetupFirst Cash ReviewInvoice Collection WorkflowMaintain Transaction RulesManage Security and BillingManage Team AccessManage the Invoice LifecycleMCP WorkflowsMonitor and Recover WorkflowsOrganize and Share DocumentsProcess Inbox ItemsReconcile and Categorize TransactionsReview a Customer Finance RecordRun a Finance Operating ReviewRun a Receivables Tone ExperimentRun a Runway Stress TestRun Your First Command Center ReviewSet Up a WorkspaceTroubleshoot Account AccessWebhook DeliveryWeekly CFO Review
OverviewIntegrationsMCPSDKsWebhooks
OverviewAuthenticationBank Accounts APICustomers APIErrorsForecasts and Stress Tests APIInvoice Payments APIInvoices APIPaginationRate LimitsRemote Tracker API StatusTracker Categories APITracker Entries and Timers APITracker Projects APITransactions APIWebhooks API StatusWorkflows API Status
Overview
Overview