Browse guides
End user

Web Login

Sign in to web applications with ScrambleID: scan the QR code, type the code, or use a passkey. No password involved.

Updated June 11, 2026

ScrambleID replaces the password box on the web. When an application uses ScrambleID, signing in means approving the login on your phone instead of typing a secret. This guide covers the three ways to do that. If you haven't set up the ScrambleID app yet, start with the Mobile App guide; everything below assumes your phone is enrolled.

What happens when you sign in

Opening a ScrambleID-protected application redirects you to the ScrambleID login page. The page shows a QR code with a countdown timer and a Type option next to it. Pick whichever method suits the moment; they all end the same way: your phone cryptographically approves this specific login, and you're in.

Scan the QR code

  1. Open the ScrambleID app on your phone.
  2. Scan the QR code shown on the login page.
  3. Approve the sign-in on your phone.

The browser picks up the approval and signs you in. If the timer runs out before you scan, click Refresh Code for a new one.

Type the code

Can't scan (for example, the QR is on the same phone you're signing in from, or the screen is hard to capture)?

  1. Click Type on the login page. A six-digit code appears.
  2. Enter the code in the ScrambleID app.
  3. If your account belongs to multiple organizations, pick the one you're signing in to.
  4. Tap Verify. If the login page shows an extra two-digit code, enter that in the app and tap Verify again.

The two-digit step confirms you're approving this screen's login and not someone else's. Codes expire on a short timer; click Refresh Code if yours lapses.

Use a passkey

If you've set up a passkey on the device you're browsing from, choose Passkey on the login page and approve with your device's unlock (face, fingerprint, or PIN). Setup takes a minute and needs your already-enrolled phone once; the Mobile App guide walks through it.

Why there's no password

The approval your phone sends is a one-time cryptographic signature tied to this specific login session. There's no secret to remember, reuse, or type into a fake site: a lookalike login page has nothing to steal, because the signature it would need only works for the real session.

Troubleshooting

  • The code expired. Click Refresh Code on the login page and try again; codes are deliberately short-lived.
  • No organizations listed in the app. Your account isn't connected to your company yet. Add it with your activation code under Manage Organization; the Mobile App guide shows how.
  • Stuck at "waiting for confirmation." Check your phone has a network connection, then re-scan. If it persists, your company's help desk can check your enrollment.