Sign-in & security
Create a SutramX account, verify your email, sign in with a password, Google, GitHub or SSO, and protect it with two-factor authentication.
This page covers your SutramX login: creating an account, verifying your email, the ways to sign in, two-factor authentication, password and email changes, sessions, and deleting your account.
Create an account#
- Go to
https://app.sutramx.com/signup. - Enter your Full name, Email, Password and Confirm password.
- Tick I agree to the Terms of Service and Privacy Policy.
- Click Create account.
You can also click Continue with Google or Continue with GitHub instead. By doing so you agree to the same terms.
Every new account starts on the Free plan with its own personal workspace. See Workspaces.
Password rules#
| Rule | Detail |
|---|---|
| Length | 10 to 128 characters |
| Not common | Common passwords and simple variations of them are rejected (letter-for-number swaps, repeated chunks like abcabc, number runs) |
| Not personal | It can't be your email address, the part before the @, or your name |
There are no required character classes, so you don't need upper case, digits or symbols. A strength meter rates your password Too weak, Fair, Good or Strong. A few unrelated words make a strong, memorable password.
Verify your email#
After signing up you're signed in straight away and sent to the verification page. SutramX emails you (subject "Verify your SutramX email address") with both:
- a 6-digit code, valid for 15 minutes, and
- a verification link, valid for 24 hours. The link works even if you're signed out.
Enter the code under Verification code and click Verify email, or click the link. Until you verify, a banner at the top of the dashboard reminds you, with Enter code and Resend.
You must verify your email before you can:
- create or import monitors,
- create API keys,
- set up two-factor authentication,
- invite teammates or accept an invitation.
To get a new code, click Send a new code. You can resend once every 60 seconds, and a new email replaces earlier codes and links. Each code allows 5 wrong attempts. After that, request a new one.
Sign in#
- Go to
https://app.sutramx.com/login. - Enter your Email and Password.
- Leave Keep me signed in ticked to stay signed in after you close the browser. Untick it on shared computers.
- Click Sign in.
A wrong password, an unknown email and a Google/GitHub-only account all return the same message, "Invalid email or password", so nobody can probe which emails have accounts.
Sign-in limits#
SutramX doesn't lock accounts after failed passwords. Instead, it limits attempts to 10 per 15 minutes for each email address (and 60 per 15 minutes per IP address). When you hit the limit, the page shows "Too many sign-in attempts. Try again in mm:ss." and you can try again when the countdown ends.
New-device alerts#
When your account signs in from a browser and operating system it hasn't seen before, SutramX emails you "New sign-in to your SutramX account" with a Review active sessions button. If it wasn't you, sign that session out under Sessions and change your password.
Google and GitHub#
Click Continue with Google or Continue with GitHub on the sign-in or sign-up page.
- The provider must give SutramX a verified email address. For GitHub, SutramX uses your primary verified email.
- If no SutramX account uses that email, a new account is created. Its email counts as verified and it has no password.
- If a verified SutramX account already uses that email, and it doesn't have two-factor authentication, the provider is linked automatically. SutramX emails you "SutramX security: Google sign-in linked" (or GitHub).
- If the existing account isn't verified yet, the sign-in is refused. Verify it, or sign in with your password, first.
- If the account has two-factor authentication, you can sign in with the provider, but you still complete the two-factor step. The provider isn't linked permanently.
Sign-in links from the provider expire after 10 minutes and must be finished in the same browser. Otherwise you'll see "This sign-in link has expired or was started in a different browser. Please try again."
Connected accounts#
Manage providers in Account settings → Connected accounts:
- Link Google / Link GitHub connects a provider account that has the same email as yours.
- Unlink removes it. You can't unlink your only way to sign in. Set a password first.
- The Email and password row shows whether you have a password.
If you signed up with Google or GitHub and want a password too, go to Account settings → Security and click Set a password. SutramX emails you a link to set one. The link is valid for 1 hour.
Single sign-on (SAML)#
Workspaces can let their team sign in through a SAML identity provider such as Okta, Microsoft Entra ID, Google Workspace, OneLogin or JumpCloud. SAML SSO is included in the Pro plan, and the workspace owner sets it up themselves in the dashboard (see below). For custom identity requirements beyond that, contact support@sutramx.com. (Sign-in for private status pages is a separate feature. See Private pages & SSO.)
Sign in with SSO#
On the sign-in page, click Sign in with SSO, enter your Work email and click Continue. SutramX sends you to your identity provider and back. Two-factor authentication still applies if you've turned it on. If your domain isn't set up, you'll see "Single sign-on isn't set up for this email domain."
Set up SSO (workspace owner)#
Open Account settings → Single sign-on (Account → Settings in the sidebar). Only the workspace owner can configure it, and the workspace must be on the Pro plan.
- Add SutramX to your identity provider. Copy the ACS (reply) URL, Entity ID (audience) and, once step 2 is saved, the SP metadata URL. Use email address as the Name ID format, sign the assertion with SHA-256, and don't encrypt assertions.
- Identity provider. Paste your IdP metadata XML, or choose Enter manually and fill in IdP entity ID (issuer), IdP SSO URL (HTTP-Redirect) (https) and Signing certificate (PEM). Optionally set an Email attribute. It defaults to
email,mailor the NameID. Click Save identity provider. - Verify your email domains. Click Add domain, create the DNS TXT record shown, then click Check DNS. Only people with an address on a verified domain can use SSO. You can verify up to 10 domains, and a domain can be verified by only one workspace.
- Test it. Click Run a test sign-in and sign in through your identity provider with an address on a verified domain. The test checks the whole round trip without signing anyone in, and works before SSO is turned on.
- Turn it on with the switches below.
| Switch | What it does |
|---|---|
| Allow sign-in with SSO | Sign in with SSO sends people with a verified-domain address to your identity provider |
| Create accounts on first sign-in (JIT) | New people from your identity provider with an address on a verified domain join the workspace automatically, with the Role for people who join through SSO: Viewer (read-only, the default) or Member. A pending invitation keeps the role it was sent with. Off: only existing members can use SSO |
| Require SSO | Members with a verified-domain address can no longer use a password, Google or GitHub. Needs SSO on and at least one verified domain |
The saved certificate shows its expiry date. Replace it before it expires, or SSO sign-ins will fail.
Two-factor authentication#
Two-factor authentication (2FA) asks for a one-time code after your password, or after Google, GitHub or SSO. Set it up in Account settings → Security → Two-factor authentication. Your email must be verified first.
You can use either method, or both:
| Method | How it works |
|---|---|
| Authenticator app | Any TOTP app (Google Authenticator, 1Password, Authy…). 6-digit codes that change every 30 seconds |
| Email codes | A 6-digit code is emailed to you at each sign-in. Each code is valid for 10 minutes |
Set up an authenticator app#
- Click Set up app.
- Scan the QR code, or type in the Setup key.
- Enter the 6-digit Code from the app, and your Current password.
- Click Turn on.
To move to a new phone, click Replace app and repeat the steps.
Set up email codes#
- Click Set up email codes.
- Enter the Code from the email. It expires in 10 minutes.
- Click Turn on.
Backup codes#
When you first turn on 2FA, SutramX shows 8 backup codes in the format XXXXX-XXXXX. They're shown only once. Use Copy or Download .txt, store them somewhere safe, then click I've saved them. Each code works once.
The Backup codes row shows how many are unused. Generate new codes replaces the whole set, and the old codes stop working.
Signing in with 2FA#
After your password, enter the code under Verification code and click Verify & sign in. On that screen you can:
- switch with Use your authenticator app instead / Email me a code instead,
- click Resend code (email method),
- choose Can't access your device? Use a backup code,
- tick Remember this device for 30 days to skip the code on this browser for 30 days.
Each sign-in code allows 5 wrong attempts. A sign-in attempt must be completed within 15 minutes, in the same browser where you entered your password.
Remembered devices are listed under Sessions → Remembered devices, where you can Forget one or Forget all. All remembered devices are forgotten when you change or reset your password, or turn off 2FA.
Turn off 2FA#
Click Turn off, confirm with your current password, then click Turn off 2FA. This removes both methods and forgets remembered devices.
Changing 2FA (turning on the app, replacing it, turning 2FA off or generating backup codes) asks for your Current password. Accounts without a password confirm with a Code from your authenticator app instead. SutramX emails you whenever 2FA is turned on or off.
Reset a forgotten password#
- On the sign-in page, click Forgot password?.
- Enter your Email and click Send reset link.
- Open the link in the email "Reset your SutramX password". It's valid for 1 hour and works once.
- If your account has 2FA, verify with your authenticator app, an email code or a backup code.
- Enter a New password, confirm it, and click Reset password.
For privacy, the page always says a link was sent, whether or not the email has an account. After a reset, every session is signed out, remembered devices are forgotten, and you get a "Your SutramX password was changed" email.
Change your password#
- Go to Account settings → Security and click Change password.
- Enter your Current password, a New password and Confirm new password.
- Click Update password.
You stay signed in on this device. Every other session is signed out and remembered devices are forgotten.
Change your email#
- Go to Account → Profile and, under Sign-in email, click Change email.
- Enter the New email address and your Current password. Accounts without a password skip the password.
- Click Send confirmation link.
Open the link sent to the new address within 24 hours. Your email doesn't change until you do. While a change is pending, you can click Cancel change. Once confirmed, the new address is marked verified and your old address is notified.
Sessions#
| Lifetime | |
|---|---|
| Session | Up to 30 days from sign-in, then you sign in again. Using SutramX doesn't extend it |
| Without Keep me signed in | Also ends when you close the browser |
| Remembered 2FA device | 30 days |
Review and end sessions in Account settings → Sessions:
- Each session shows the browser and operating system, IP address, when it signed in and when it was last active. Your current one is marked This device.
- Sign out ends one session immediately.
- Sign out all other sessions ends every session except this one.
- Recent sign-ins lists your 20 most recent sign-ins, including ended ones (Active, Expired or Signed out).
To sign out of the current browser, use Log out at the bottom of the sidebar.
Security emails#
SutramX emails you when something security-relevant changes on your account:
- sign-in from a new device or browser,
- password changed or reset,
- two-factor authentication turned on or off,
- Google or GitHub linked,
- email address changed (sent to the old address),
- API key created or deleted.
If you didn't make the change, sign out unknown sessions, change your password and contact support@sutramx.com.
Delete your account#
Deleting is done from Account settings → Danger zone by the workspace owner. If you own only your personal workspace, the card is called Delete account, and your login, profile and connected sign-ins are deleted along with the workspace.
- Click Delete account….
- Confirm with Your password. Accounts without a password type
DELETEinstead. - Click Delete account.
Monitoring stops, you're signed out everywhere, and the data is kept for 30 days before it's permanently purged. To undo, sign in within 30 days and click Cancel deletion. Any paid subscription is cancelled when the data is purged. See Workspaces for details.
Members of someone else's workspace can't delete it. They can leave it instead.
Troubleshooting#
I signed up with Google and now want a password too. Go to Account settings → Security → Set a password, or use Forgot password? on the sign-in page.
"An account with this email already exists. Verify it…" You created a password account with that email but never verified it. Verify it first, then Google or GitHub can link to it.
I lost my phone and my backup codes. Choose Email me a code instead at the 2FA step if email codes are on. Otherwise contact support@sutramx.com from your account email.
"Your organisation requires single sign-on." Your workspace owner turned on Require SSO. Use Sign in with SSO with your work email.
Related
Last updated . Something unclear or missing on this page? Tell us at support@sutramx.com.