Staff PIN gate

How PIN entry attributes each action to a staff member and which actions require it.

Sensitive actions ask for a four-digit staff PIN. The prompt identifies who is authorising the action, and that name is what gets recorded against it.

The PIN is checked, not just shown

Approving with a PIN issues a single-use token bound to the specific action being authorised. The endpoint performing that action demands the token, so a gated action cannot be carried out by skipping the prompt. Before version 0.46.0 the keypad appeared but nothing on the server required it to have been answered.

If you do not know your PIN

The prompt offers a password fallback: sign the action off with your account password instead of the PIN.

Where your PIN comes from

A PIN is generated for you when your account is created and sent in the welcome email. PINs are stored hashed, never in plain text. See Staff.

Still stuck? We answer every message.Contact support