Signing in
Cascade asks for your email address and works out the rest. There is no method to pick before you start: type your address, select Continue, and the sign-in screen shows you the next step for your account.
What happens after Continue
If your account has no password, Cascade emails you a sign-in link and tells you to check your inbox. The link works once and expires in a few minutes. This is the normal way in, and it is what a brand new address gets too: following the link creates your account and takes you to onboarding. Following a link that has already been used, or one that sat in your inbox too long, brings you back to the sign-in screen with a note saying so, so you can ask for a fresh one.
If your account has a password, the password field appears under your address and you sign in with it. Two options sit below:
- Email me a sign-in link instead, if you would rather not type the password.
- Use a different sign-in method, which takes you back to the first step so you can use Google, Microsoft or GitHub.
Editing your address takes you back to the first step as well, since the password field belongs to the address you typed.
Signing in with Google, Microsoft or GitHub
The provider buttons sit under the email field on the first step. They are hidden once the password field is showing, because at that point you have already chosen how to sign in. Which providers appear depends on your deployment.
Two-factor authentication is not asked for on these, because your provider handles it.
The "Last used" label
Whichever way you signed in last on this browser is marked with a small Last used label, next to the email field or on the provider button. It is a reminder, not a restriction: any method your account has still works.
The label is stored in your browser, not in your Cascade account, so it is per device and per browser. Clearing your browser data clears it, and it never appears on someone else's machine.
Two-factor authentication
If you have turned on two-factor authentication under Settings → Security, Cascade asks for a code from your authenticator app after your password or your sign-in link. You can use one of your backup codes instead, and you can trust the device for 30 days so it stops asking on that browser.
A sign-in link always asks for the code, even on a trusted device. Access to your inbox on its own is not enough to get past a second factor.
When something goes wrong
- The link never arrived. Select Resend the link on the confirmation screen, and check your spam folder. Delivery can take a minute.
- You typed the wrong address. Select Start over on the confirmation screen.
- "Too many sign-in attempts from this address." The sign-in screen limits how often it will look up an address from one network. Wait a minute and try again.
- You do not have a password and want one. Sign in with a link, then set a password under Settings → Security. See Settings.