If your identity provider is down: recovery codes and password windows
Once a workspace registers an identity provider, everyone on its domains signs in through it. That is the point of single sign-on, and it means an identity provider your team can't reach is a workspace your team can't reach. There are two ways back in. Both are narrow, both are time-boxed, and both are written to your audit log.
Path 1 — a tenant admin uses a recovery code
Registering single sign-on issues ten single-use recovery codes and shows them once. Each one buys one Tenant Admin 12 hours of password sign-in: enough to open the SSO card, re-register a metadata URL, or keep working while your identity team sorts out the outage.
- 1Sign in with your email and passwordUse the password step on the sign-in page as normal. Because your domain is SSO-enforced, Current lands you on the "Sign in with single sign-on" page instead of letting you through.
- 2Open "Workspace admin? Use a recovery code"It sits under the Continue with single sign-on button, and only a Tenant Admin sees it. The server checks the role again anyway, so a code redeemed by anyone else is refused, and a code from another workspace means nothing here.
- 3Enter one codeThey are ten characters shown as XXXXX-XXXXX, from an alphabet with no look-alike letters, and a pasted code works with or without the dash. Each is single-use. A wrong one counts against the same lockout as a wrong email code, so five wrong entries lock the account for about 15 minutes.
- 4Finish your normal second factorA recovery code re-opens password sign-in; it doesn't replace the second factor. You still complete the emailed code, your authenticator app, or your passkey.
- 5You have 12 hoursPassword access lasts 12 hours and covers you alone. Everyone else on the domain still needs the identity provider. When it lapses, redeem another code if you still need one.
Path 2 — ITPartners+ opens a password window
When no admin can reach a code — they sit in a password manager that is itself behind the identity provider, or the one admin who saved them is away — ITPartners+ can open a password window for the whole workspace.
- 1Contact ITPartners+The contact form in the Help Center, or your usual channel. Say which workspace, and what has happened.
- 2A super admin opens a window of 1 to 24 hoursIt is opened from the Accounts console with a reason, which is stored beside it. Nobody can open one open-endedly.
- 3Password sign-in works again for the workspaceFor the length of the window, everyone on the claimed domains can sign in with a password, still with their second factor. Trusted devices, apps, passkeys and any provider that is working carry on unchanged.
- 4Close it as soon as you're backThe single sign-on card on Integrations shows the window with its reason and its end time, and a Close window button any Tenant Admin can press. It also closes itself when the time runs out, and the sessions it allowed expire with it rather than outliving it.
What gets recorded
- +Redeeming a code writes an entry to your workspace's audit log: who used it, when, and how many codes are left.
- +Every other Tenant Admin in the workspace gets a notification the moment a code is used, and so does ITPartners+.
- +Opening and closing a password window are both audit entries, with the reason and the length.
- +Your audit log is append-only, so neither your admins nor ours can remove any of it afterwards. See "The audit log: what's recorded and who can read it".
Generate a new set of codes
The single sign-on card on Integrations shows how many are unused, for example "7 of 10 remaining". Generate new codes issues ten fresh ones and kills every old one in the same moment, so have somewhere to put them before you press it. Worth doing after a use you didn't expect, after an admin leaves, and when you are down to the last couple.
