Home Getting Started

Getting Started

By Jasha Stanberry
4 articles

Collaborator Access — Signing In to a Site You Work On

How is my sign-in different from the site owner's? Site owners access their websites through their Lumio Portal. As a collaborator, you sign in at the website's own login page with the username and password we set up for you. The login page will mention the portal — that part is for owners; your way in is the form itself. Why did a security screen ask me for a code? Every so often — usually when you're signing in from a new device or after some time away — the site's security system adds one extra check: a six-digit code from your phone. If you haven't set up a code app yet, the next sections walk you through it — about two minutes, once. What is two-step verification? Two-step verification asks for one extra thing along with a password: a six-digit code from your phone that changes every 30 seconds. Even if someone got hold of a password, they still couldn't get in without your phone. Security is always a balance between simplicity and protection — the more locked down something is, the harder it tends to be for the people who genuinely need access. Two-step verification is one of the rare measures that adds real protection without adding real complication, which is why it protects every site we manage. Which app should I use for my codes? Any authenticator app works. Here's what we recommend, in order of least effort: If you have an iPhone or Mac: you already have what you need. Apple's built-in Passwords app generates these codes, syncs them across your Apple devices, and fills them in for you. Nothing to install. Apple's own guides show exactly where to find it on iPhone and on Mac. If you use 1Password: add the code there, right alongside your saved passwords. One app for everything, and it fills both in together. Otherwise: Google Authenticator is free for iPhone and Android. One important step: when you open it for the first time, sign in with your Google account. That backs your codes up automatically, so a new phone or a lost phone doesn't lock you out. How do I set it up? You'll do this once, and it takes about two minutes. Have your phone ready. 1. https://yoursite.com/wp-login.php - Enter your username and password 2. A prompt will ask you to setup two factor authentication, click setup now. 3. On the setup screen you'll see a square QR code. 4. Open your authenticator app and choose add (usually a + button), then scan QR code. Point your phone's camera at the square code on your screen. 5. Your app will show a six-digit code. Type it into the box on your screen and confirm. 6. You'll be shown a set of recovery codes. Save them before you finish — the next section explains why. From then on, when the security screen appears, it's a glance at your phone and you're through. What are recovery codes, and where do I put them? Recovery codes are important! These are your spare keys. If your phone is ever lost, broken, or replaced, any one of these codes gets you in — each works once. Save them somewhere that isn't your phone: your password manager, a note in Apple Passwords, or printed and kept wherever you keep important papers. Please don't skip this — it's thirty seconds now that can save you real trouble later. I got a new phone — what do I do? If your codes were backed up (signed in to Google Authenticator, or using Apple Passwords or 1Password), they'll appear on your new phone automatically — nothing to do. If they didn't come across, use one of your recovery codes when the security screen asks, then set up the new phone from the same setup screen. And if you're locked out entirely: message us in the chat or at support@lumio.host. We can securely reset the verification on your account and get you signed back in. You're never stranded.

Last updated on Aug 01, 2026

Passkeys: Sign In without a password

What's a passkey? A passkey lets you sign in to your Lumio Portal with your fingerprint, your face, or your device's PIN — instead of typing a password. It lives on your device (your phone, your Mac, your password manager) and it only works on our sign-in page. A fake page pretending to be us gets nothing, which makes a passkey the most secure way to sign in that exists today. It's also just… nicer. One touch and you're in. Your password doesn't go away — it keeps working as a backup, and everything in the article "signing into your website" still applies to it. How do I add one? The next time you sign in with your password, we'll ask: "Skip the password next time?" One click on Set up my passkey, a touch of Touch ID (or your face, or your PIN), and you're done — about ten seconds. If you use 1Password (or another password manager), it will prompt you and offer to keep the passkey for you instead — this is an even better solution: the same passkey is on every computer where 1Password is signed in, not tied to a single device. Want to add one to another device later — your phone, your other computer? Go to Security in the portal menu and click Add a passkey. What are these recovery codes it just showed me? Save them — this is the important part. The first time you add a passkey, we generate a set of one-time recovery codes and show them exactly once. Please copy and save them right away — you won't see them again. They're your spare keys. If you ever lose the device that holds a passkey AND your password, a recovery code is how you prove it's you. Each code works once. Put them somewhere that isn't the device you just enrolled: your password manager, a note in Apple Passwords, or printed with your important papers. Thirty seconds now, real trouble saved later — same advice as Article 7's verification codes, and just as worth taking. If you need to generate more, the Security page shows how many codes you have left and can generate a fresh set (the old ones stop working). Can I have passkeys on more than one device? Yes — and you should. Add one on each device you actually use: your Mac, your phone, your tablet. They appear as a list on the Security page, each with a name and when it was last used. If your passkeys sync through iCloud Keychain, 1Password, or Google Password Manager, one enrollment may already cover several devices. How do I sign in with it? Go to your portal sign-in page. Depending on how your passkey is stored, you may be prompted right away — if not, click into the email field and your device will offer your passkey. One touch, and you're on your dashboard. If you're on a device that doesn't have your passkey, you can sign in with your email and password. How do I remove one? If you lose, sell, or recycle a device, remove its passkey: on the Security page, click Remove next to that passkey. Removing your last passkey is the one with a seatbelt: we'll ask for your account password first, because that's what you'll be signing in with afterwards. If you have any issues, don't hesitate to message us so we can double-check the account with you. I lost my device — am I locked out? Almost certainly not. In order of likelihood: 1. Another device has a passkey — sign in there, remove the lost one, add the replacement. Done. 2. You know your password — sign in with it like always, then tidy up your passkeys on the Security page. 3. Neither — use the password reset link on the sign-in page. The emailed link will ask for one of your recovery codes along with your new password. That's deliberate: an email inbox alone should never be enough to take over your account. And if you're truly stranded — no passkey, no password, no codes — message us in the chat or at support@lumio.host. We'll verify it's really you (we'll call — a quick voice check, for your protection) and get you back in. You're never stranded. Do I still need two-step verification? When you sign in with a passkey — no. The touch or glance that unlocks it already proves both things a code would: that it's your device and that it's you holding it. That's the whole trick: more security, fewer steps. When you sign in with your password, everything works the way Article 7 describes. I'm stuck, or something isn't working Passkeys are still new — if anything here didn't go smoothly, no worries. Message us in the chat or at support@lumio.host and we'll walk through it together, or hop on a quick call and do it with you.

Last updated on Aug 01, 2026