# Signing in

How people get into ToolboxFM — passwords, single sign-on, and the break-glass password for administrators.

ToolboxFM runs at **[app.toolboxfm.com](https://app.toolboxfm.com)**. Everyone signs in at the same
address — your organisation is chosen after you sign in, not by a separate URL.

ToolboxFM always supports a password. There is no deployment-wide switch that turns passwords off,
and the sign-in page accepts a correct password from anyone. Whether a password is enough is decided
by each organisation, when you open it.

## With a password

Anyone with an account can sign in with their email address and password. This is the default for a
new organisation.

## With single sign-on

Once your account is connected to your organisation's identity provider, the sign-in page sends you
to the provider after you enter your email address. If you also have a password, you can choose to
use it instead.

If your organisation **requires** single sign-on and you signed in with a password, opening it shows
a page asking you to continue with your provider. Your password still works in any other
organisation you belong to.

See [Single sign-on](/tenant-setup/single-sign-on/) for how to connect a provider and how to prove it
works before you require it.

## If an administrator is locked out

Requiring single sign-on is not a one-way door. Someone holding the **Head Office** role can always
use their organisation with a password, even when it requires single sign-on.

This is deliberate. If your identity provider is misconfigured or down, the alternative is that nobody
can administer the organisation at all.

## Sessions

Signing in sets a session cookie scoped to the application. Signing out, or an administrator revoking
your access, takes effect immediately — sessions are stored server-side, not in a token that stays
valid until it expires.

## Related

- [Single sign-on](/tenant-setup/single-sign-on/)
- [Users and roles](/tenant-setup/users-and-roles/)