Overview
This article covers login and session failures* in Ottili ONE — what happens when you cannot sign in, keep getting signed out, or a session ends unexpectedly.
All sign-in, sign-out and session activity happens through the Ottili ONE dashboard at [dashboard.ottili.one](https://dashboard.ottili.one). The public website (ottili.one) points to the dashboard for every authentication step.
Feature note:* The baseline email-and-password sign-in is available everywhere. Advanced methods — Google/Microsoft OAuth, Ottili SSO, passkeys (WebAuthn) and multi-factor (MFA) — are available where your workspace has enabled them*. For what the status labels Live, Beta, Private Beta, In Development, Planned and Concept mean, see [Understand feature status labels](/docs/understand-feature-status-labels).
Prerequisites
Before you start troubleshooting, check these points:
- You are on [dashboard.ottili.one/login](https://dashboard.ottili.one/login).
- Your inbox (and spam folder) can receive messages from
no-reply@ottili.one. - Cookies and local storage are enabled for
dashboard.ottili.onein your browser. - You know the email address your account was registered with.
Common login and session failures
"Invalid credentials" (wrong password or email)
The sign-in page reports invalid credentials when the email or password is wrong. For security, the message does not reveal which field is wrong.
What to do:
1. Check the email address for typos.
2. Use Forgot password* on the [sign-in page](https://dashboard.ottili.one/login) to set a new password.
3. Does the account belong to a different company? Ask your administrator whether you should join via an invitation — see [Company and team](/docs/company-and-team).
Account temporarily locked (too many attempts)
For brute-force protection, the platform temporarily locks sign-in when too many login attempts fail. The lock duration increases on repeated failures.
What to do:
- Wait for the lock to expire automatically, or*
- use Forgot password* on the [sign-in page](https://dashboard.ottili.one/login) to set a new password — this clears the lock.
Email not verified
Email verification is required for full platform access. If your address is unconfirmed, access stays limited.
What to do:
1. Check your spam or junk folder for the email from no-reply@ottili.one.
2. Request a new verification link from the sign-in page or the dashboard prompt (Resend verification email*).
3. The verification link expires after 24 hours*; each newly requested email replaces the previous link.
4. The full guide is in [Verify your email](/docs/verify-your-email).
"Please sign in again" — session expired
When your session expires, you are prompted to sign in again. Sessions use two timeout mechanisms:
- Idle timeout:* the session expires after a period of inactivity (configurable by your organization, typically 30 minutes to 8 hours).
- Absolute timeout:* a maximum session lifetime regardless of activity (configurable, typically 7 days).
What to do:
1. Sign in again at [dashboard.ottili.one/login](https://dashboard.ottili.one/login).
2. If you are signed out regularly, review the session timeout settings with your administrator — see [Account and login](/docs/account-and-login).
Cannot stay signed in (cookies/browser)
If the dashboard signs you out immediately, browser settings are often the cause.
What to check:
1. Make sure cookies and local storage are enabled for dashboard.ottili.one.
2. Clear cookies for dashboard.ottili.one and reload.
3. Try a different browser or a private window to test.
4. Disable extensions that block cookies or storage (e.g. strict tracker blockers).
Frequent sign-outs (idle or absolute timeout)
If you are signed out mid-work, a timeout is usually the cause.
What to do:
1. Keep your activity alive: interact with the dashboard regularly instead of leaving it open in the background.
2. Ask your administrator to explain the configured timeout values — see [Account and login](/docs/account-and-login).
3. On shared or public computers, always sign out explicitly.
OAuth or SSO sign-in fails
When you use Continue with Google* / Continue with Microsoft* or Sign in with Ottili*, the provider handshake can fail.
Common cases:
- Sign-in canceled:* you closed the provider window; try again.
- Security check failed (state mismatch):* the OAuth handshake expired; reload and try again.
- Sign-in temporarily unavailable:* this provider is temporarily disabled for this dashboard; use email and password.
- This account uses Google/Microsoft:* use the matching provider button, not the password field.
If the problem persists, sign in with email and password and contact support.
MFA or passkey problems
Where your workspace has enabled it, you can register a second factor (MFA) or a passkey (WebAuthn) under Account → Security*.
What to do:
- MFA code rejected:* sync the clock on your authenticator device; time-skewed codes are rejected.
- Passkey not recognized:* confirm the passkey on the correct device; passkeys are bound to
dashboard.ottili.one. - Lost second factor:* use account recovery on the sign-in page and contact support to re-register — see [Account and login](/docs/account-and-login).
Wrong company context after sign-in
If you belong to multiple companies, the wrong company may be active after sign-in, so data or modules appear missing.
What to do:
1. Click your profile icon in the top right and choose Switch company*.
2. Select the company you want to access.
3. More in [Company and team](/docs/company-and-team) and [Roles and permissions](/docs/roles-and-permissions).
Session ended on another device
If you are signed out on a device without signing out yourself:
- You may have used Forgot password* or changed your password — after a password change, active sessions on other devices are ended for security.
- Someone may have triggered Sign out all devices* under Account → Security*.
- Review active sessions and devices under Account → Sessions* and revoke any device you do not recognize.
When to contact support
Contact support when:
- you cannot sign in despite correct credentials and a verified email,
- your account is locked repeatedly,
- you have no access to your registered email,
- you have lost your second factor (MFA) or a passkey,
- you notice suspicious sessions or devices.
Open support at [ottili.one/support](https://ottili.one/support) and include your workspace domain, the surface, the exact message and the timestamp. For known outages, check the [status page](https://status.ottili.one) first. Report security incidents via [Report a vulnerability](/docs/vulnerability-reporting).
Related articles
- [Account and login](/docs/account-and-login)
- [Troubleshoot first sign-in](/docs/troubleshoot-first-login)
- [Company and team](/docs/company-and-team)
- [Verify your email](/docs/verify-your-email)
- [Roles and permissions](/docs/roles-and-permissions)
- [Understand feature status labels](/docs/understand-feature-status-labels)
- [Missing product access](/docs/missing-product-access)
- [Privacy controls](/docs/privacy-controls)
Was this article helpful?
