Skip to content

Guides & reference

Creating an account and signing in

Sign up and sign in with GitHub, Google or email: confirming your address, reset codes, where you land, signing out, limits and every sign-in message.
Sculptural study of connected forms and structured ideas

Your flowss account is what ties your work to you rather than to one browser. It lets you open the studios, keeps your figures backed up across devices, carries your plan and AI points, and is the identity that collaborators, teams and classrooms see. This page walks through every way in — GitHub, Google, and email with a password — explains each screen and message you can meet along the way, and covers confirming your address, recovering a forgotten password, two-step verification, changing your password, where you land afterwards, and what happens when you sign out.

At a glance

TopicWhat to know
Sign-in page/signin. The "Sign up free" and "Start free" buttons open it directly on the sign-up form.
Ways inContinue with GitHub, Continue with Google, or email and password.
Passwordless linksNot offered. There is no magic-link sign-in, on purpose (see below).
Password rulesAt least 8 characters. A strength meter and a one-click strong-password generator help you choose.
Email confirmationNew email accounts confirm their address by link or by a six-digit code from the same email.
Forgotten passwordForgot password? on the sign-in form sends a reset email with a link and a six-digit code.
Two-step verificationOptional. Turn it on under Security on your account page to ask for a 6-digit code from an authenticator app after your password, GitHub or Google.
Changing your passwordSecurity → Password on your account page. It asks for your current password and signs out your other devices.
Where you landFrom the sign-up form, the Academy at /learn; from the sign-in form, /account; a link you were following always takes you back to it.
What needs an accountAll nine studios, Scholar and the Live board. Pages such as pricing, templates, docs, your Library and the Flow console open without one.
What your plan opensFree opens the Studio and Sketch. Starter and above open every studio. See Plans and what they include.
Signing outSign out in the account menu. It clears this device's personalisation and any saved AI key, and leaves your documents alone.

What you can do before you sign in

You can explore a good deal of flowss without an account. The marketing site, pricing, the template gallery, this documentation, flowss Academy, your Library and the Flow console all open for a visitor who is not signed in. The command palette (press ⌘K on a Mac or Ctrl+K on Windows and Linux) works on every one of those pages.

The studios themselves require an account. When you open any of the nine — Studio, Study, Evidence, Lab, Weave, Science, Figure, BPMN or Sketch — or Scholar or the Live board while signed out, you are taken to the sign-in page first. Whatever you were trying to open travels with you: a shared diagram link, a template link from the gallery, a project invitation or a deep link into a particular screen is preserved, and after you sign in you arrive exactly where the link pointed rather than on an empty start screen.

Once you are signed in, your plan decides which studios open. The Free plan opens the Studio and the Sketch canvas. Starter, Plus, Ultra and Enterprise open every studio. If you are on Free and follow a link into another studio, you land on the pricing page with a short note at the top naming the studio — for example "Lab is part of Starter" — followed by an explanation that the Studio and the Sketch canvas stay free and that Starter opens every workstation. In the studio switcher, studios your plan does not open show a small lock and the words "Part of Starter" instead of their tagline. For the details of each plan, see Plans and what they include.

The ways to sign in

MethodButton or formGood to know
GitHubContinue with GitHubUses your GitHub name and avatar for your flowss profile. No email is sent, so it works even when email is briefly paused.
GoogleContinue with GoogleAlways shows Google's account chooser, so you can pick or switch the Google account you use. No email is sent.
Email and passwordThe email form under the buttonsYou choose a password; new accounts confirm their email address once.

The GitHub and Google buttons appear only when that provider is switched on for the service, so you never click a button that leads to an error page. If neither appears, use the email form.

Note: flowss deliberately has no "email me a sign-in link" option. A passwordless link creates an account that has no password, and every later attempt to sign in with a password then fails. GitHub, Google and email-plus-password are the three ways in.

Use the same method every time. An account created with Continue with Google is signed into with that button, not with the email form, and the same goes for GitHub. If you try the email form with an address you originally registered through GitHub or Google, the wrong-password message reminds you of this.

Creating an account with email and a password

The sign-up form asks for six things. All of them are required.

FieldLabel or placeholderRules
Name"Your full name"Cannot be blank.
Email"you@example.com"Must be an address you can receive mail at; you confirm it in the next step.
Password"Create a password (8+ chars)"At least 8 characters.
Confirm password"Confirm your password"Must match the password exactly.
How you will use flowss"How will you use it?"Choose one: Researcher / academic, Student, Engineer / developer, Educator, Something else.
Terms"I agree to the Terms of Service and Privacy Policy."Tick the box. Both documents open in a new tab from the links in the sentence.

To create the account:

  1. Go to /signin. If the form says Sign in at the bottom, choose Create an account under it to switch to the sign-up form.
  2. Enter your full name and your email address.
  3. Type a password, or choose Suggest strong password under the password field (described below).
  4. Type the password again in the confirmation field. A green tick appears as soon as the two match; "These don't match yet." appears in amber while they differ.
  5. Choose how you will use flowss from the How will you use it? list.
  6. Tick the box to accept the Terms of Service and Privacy Policy.
  7. If a short verification challenge appears above the button, complete it. Until you do, the line "Complete the quick verification above to continue." stays under the button and the button is disabled.
  8. Choose Create account.
  9. Check your inbox and confirm your address, either by opening the link or by typing the six-digit code into the page (see the next section).

If the form finds a problem it tells you in a red box under the form, naming the first thing to fix in the order you read the form: "Enter your email and password." (when either is empty), "Enter your name.", "Use a password of at least 8 characters.", "The two passwords don't match.", "Tell us how you'll be using it.", and "Please accept the Terms of Service and Privacy Policy to continue."

The password strength meter

While you type a password on the sign-up form, a four-segment meter under the field rates it and names the rating. (The meter appears on the sign-up form only, not when you sign in.) The "kinds of character" it counts are lower-case letters, upper-case letters, digits and symbols.

RatingWhat earns it
Too shortFewer than 8 characters, all of one kind.
WeakFewer than 8 characters of mixed kinds; or 8 to 11 characters of a single kind; or any password that is a well-known weak one (such as "password1" or "qwerty"), a single character repeated, or one that starts with a run such as "1234", "abcd" or "qwer" — these are capped at Weak however long they are.
Fair8 to 11 characters using two kinds; 8 or 9 characters using three or more kinds; or 12 or more characters of a single kind.
Good12 or more characters using two kinds; or 10 or 11 characters using at least three kinds.
Strong12 or more characters using at least three kinds.

The meter is guidance, not a gate. The service enforces its own rules when you submit, and it can refuse a password that has appeared in a known data breach however long it is. If that happens you see: "Choose a different password: that one is too weak or has appeared in a known data breach. “Suggest strong password” can make one for you."

Suggest strong password

Suggest strong password (under the password field, on both the sign-in and sign-up forms) generates a random 16-character password that contains at least one lower-case letter, one upper-case letter, one digit and one symbol, and avoids characters that are easy to confuse such as l, I, O, 0 and 1. When you choose it:

  • the password is placed in both the password field and the confirmation field, so you never have to retype it;
  • the password is shown in plain text so you can see it;
  • it is copied to your clipboard, ready to paste into your password manager;
  • if you were on the sign-in form, the page switches to the sign-up form, since a brand-new password only makes sense for a new account.

Save the password in your password manager before you leave the page.

Showing and hiding your password

The eye button at the right of the password field shows or hides what you have typed. Its label changes between Show password and Hide password. It affects both the password and the confirmation field.

Confirming your email address

After you create an email account, the form is replaced by a panel titled Confirm your email: "We sent a confirmation link to your address. Open it to continue — the link expires shortly." You can finish in either of two ways.

Way to confirmHow
Open the linkOpen the email and select its button. You are signed in and taken on to your destination.
Type the codeEvery confirmation email also contains a six-digit code. Type it into Or enter the code from the email on the panel and choose Continue.

The code is there for the cases where a link does not work — most often when an organisation's mail scanner has already "clicked" the link before you did, which uses it up. Spaces in the code are ignored, and Continue stays disabled until you have entered six digits.

Confirmation links work even if you open the email on a different device from the one you signed up on — for example, signing up on a laptop and opening the email on your phone. If a link is ever refused because it came back to a different browser, the page tells you so and offers a fresh link (see Troubleshooting).

When you open an emailed link in a browser that did not ask for it (the laptop-then-phone case above), flowss checks with you before signing anyone in. A page titled Continue as your address? explains: "This link was opened in a different browser from the one that asked for it, so we check before signing you in. Continue only if you requested this email yourself…". For a password-reset link the heading reads Reset this account's password? instead.

ButtonWhat happens
Continue as your address (or Continue to set a new password)You are signed in and taken on, exactly as if you had opened the link in the original browser.
I didn't ask for thisNothing is signed in. You return to the sign-in page with the message "Nothing was signed in. If someone sent you that link, you can ignore it. If it was yours, sign in here — or use “Forgot password?” for a fresh link."

If this browser is already signed in to a different flowss account, an amber note warns you that continuing switches this browser to the account the link belongs to. The check protects you from being signed in to someone else's account by a link they sent you. The decision must be made within about ten minutes; after that the page sends you back to sign in with the "That link has expired or was already used" message.

Sending the confirmation email again

The panel carries a Send it again button. Because an email has just been sent, the button starts with a short wait and reads "You can resend in 60s", counting down to zero. When it reaches zero it becomes Send it again. After you use it you see the neutral message "If that address needs confirming, a new link is on its way." The page deliberately does not say whether the address exists or is already confirmed; that protects every account holder's privacy.

Each address can be sent a limited number of confirmation emails per day (see Limits). Before you resend, check your spam or junk folder: the panel reminds you, "Can't find it? Check spam, or try again in a moment."

If you signed in before confirming

If you try to sign in with an email account that was never confirmed, the page opens a panel titled Confirm your email to sign in: "Your password checked out, but your address was never confirmed, so there's no way into the account yet." Your password is fine; you only need a fresh confirmation email. Choose Send it again (there is no wait the first time, because nothing has been sent yet), then confirm with the new link or code.

If you arrive on the sign-in page from a dead confirmation link (expired, already used, damaged, or opened in another browser), a Send a new confirmation link button appears under the red message, with the note "Goes to the address above — a confirmation link, not a password reset." Type your address into the email field and choose the button. A panel titled Check your inbox then says "If your address is waiting on confirmation, a fresh link is on its way." — worded conditionally because the page is never told whether that address exists or is already confirmed. The panel has the same code field and Send it again button as the others.

If the email field is empty you see "Enter your email, then tap “Send a new confirmation link”."; if the address is malformed, "That doesn’t look like an email address — check it and try again."

Choosing Back to sign in

Back to sign in at the bottom of any of these panels returns you to the form with your email address still filled in.

Signing in with GitHub or Google

  1. Go to /signin.
  2. Choose Continue with GitHub or Continue with Google. A spinner replaces the icon while the page hands you to the provider.
  3. Approve flowss at the provider (the first time only). With Google, pick the account you want from Google's chooser.
  4. You are returned to flowss and land on your destination.

The first time you sign in this way, your flowss account is created automatically using the name and picture your provider shares. No confirmation email is needed, because the provider has already verified your address. If you have turned on two-step verification, you are asked for your authenticator code after the provider returns you (see "Two-step verification" below).

If you are on a preview address of the site rather than www.flowss.ai, an amber note above the buttons warns that GitHub and Google may bounce you back, and links to sign in at www.flowss.ai or to use the email form instead.

If you cancel at the provider, or the provider cannot complete the request, you come back to the sign-in page with the message "We couldn't finish that sign-in. You may have cancelled it, or the provider isn't set up yet — try again, or use the email form above." Under it, in smaller type, a line beginning "What the sign-in server said:" may name the exact cause — for example "That identity is already linked to another account" or "The provider has not verified this email address yet".

Signing in with your email and password

  1. Go to /signin. The form opens in sign-in mode, with Email address and Password fields.
  2. Enter your email and password.
  3. Complete the verification challenge if one appears.
  4. Choose Sign in.
  5. If the account has two-step verification on, enter the code from your authenticator app on the next page.

If the email and password do not match, you see "That email and password don't match. Check both and try again, or use “Forgot password?”." When GitHub or Google sign-in is available the message adds "If you signed up with GitHub or Google, use that button above instead." For your security the message never says which of the two was wrong.

If you are on the sign-up form and enter an address that already has an account, the page switches you to the sign-in form with your address still in place and explains: "An account with this email already exists. Sign in instead, or use “Forgot password?”."

Where you land after signing in

How you arrivedWhere you go
You started from the sign-up form (creating an account, or choosing GitHub or Google while the sign-up form is showing)flowss Academy, which welcomes you and walks you through the platform and the studios hands-on.
You started from the sign-in formYour account page.
You were sent to sign in by a studio, a shared link, a template or an invitationStraight back to that studio, link, template or invitation.
You followed a Starter or Plus waitlist buttonThe matching plan on the pricing page.

If the link you followed was a project invitation, you are not added to the project silently: after you sign in, the Studio asks "Join project as you?", tells you the role you would join with, and does nothing until you choose Join project (or Not now). A team invitation works the same way on the Teams page, with a Join team button. See Sharing and permissions and Teams and organisations.

When a plan is offered as a waitlist rather than a checkout, its button brings you to a sign-in page that says so: the heading reads, for example, "Join the Starter waitlist", above the plan's monthly price and a line such as "Sign in once and we'll email you the moment Starter goes live." After you sign in, a one-moment screen reading "Welcome — finishing setup…" records your interest in that plan and then forwards you on.

Resetting a forgotten password

  1. On the sign-in form, type your email address into the email field.
  2. Choose Forgot password? (under the password field, to the right). If the email field is empty you are asked to "Enter your email, then tap “Forgot password?”."; if the address is malformed you see "That doesn’t look like an email address — check it and try again."
  3. Complete the verification challenge if one appears.
  4. A panel titled Password reset requested appears: "We've asked for a password-reset link to be sent to your address." It goes out only if that address has an account and sign-in email is not briefly paused. The page is not told whether it went, which again protects account holders' privacy.
  5. Open the reset email. Either select its link, or type its six-digit code into Or enter the code from the email on the panel and choose Continue.
  6. You arrive on the Set a new password. page. Enter a password of at least 8 characters in New password, enter it again in Confirm new password, and choose Update password.
  7. You see "Password updated. Taking you to your account…" and are taken to your account page a moment later.

A notice is emailed to your account address whenever your password is changed this way, so you would hear about a change you did not make.

The Set a new password. page opens only within 15 minutes of following the reset link or entering its code. Later than that it sends you to Account → Security instead; if you no longer know your password, ask for a fresh link with Forgot password?. If two-step verification is on, you are asked for a code from your authenticator app before the page opens. To change a password you still know while you are signed in, use the Password card in Account → Security (/account#security), which asks for your current password; see Account settings and your data.

If nothing arrives after a few minutes, check spam first. The panel explains the other possibilities: "Nothing after a few minutes? Check spam. If it isn't there, that address may have no account here, or email may be paused." If GitHub or Google sign-in is available, the panel reminds you that those buttons do not need email.

Tip: if you originally signed up with GitHub or Google, you have no flowss password yet — simply sign in with the same button you used to sign up. If you also want to be able to sign in with your email and a password, Forgot password? with the same address is how you create one.

Two-step verification

Two-step verification (sometimes called 2FA or TOTP) is optional and available on every plan. Once it is on, signing in takes your password (or GitHub or Google) and a 6-digit code from an authenticator app such as 1Password, Google Authenticator or Authy. Someone who learns your password, or gets into your inbox, still cannot get into your account. It lives in the Security section of your account page, in the card titled Two-step verification.

Turning it on

  1. Open your account page and scroll to Security.
  2. In the Two-step verification card, choose Turn on two-step verification.
  3. Scan the QR code that appears with your authenticator app. If you cannot scan it, type the setup key shown beside it into the app instead ("Can’t scan? Type this key into the app instead."). The copy button next to the key, labelled "Copy the setup key", puts it on your clipboard.
  4. Save the setup key in your password manager as well. There are no recovery codes: the setup key is how you get back in if you lose your phone.
  5. Type the 6-digit code your app now shows into Code from the app and choose Verify and turn on. Cancel abandons the setup.
  6. The card now shows On, the app's name and the date it was added. Your other devices are signed out, and ask for a code the next time you sign in there.

Signing in with two-step verification on

After your password is accepted (or GitHub or Google returns you), a page titled Enter your verification code appears: "*your address* has two-step verification on. Open your authenticator app and enter the 6-digit code it shows for flowss." Type the code into Verification code and choose Verify (it stays disabled until you have entered six digits; spaces are ignored). You then continue to wherever you were going, including a shared link you followed. The same step appears whichever way you sign in — password, GitHub, Google, an emailed link or an emailed code. Sign in with a different account on that page signs this browser out and returns you to the sign-in form.

Until you enter the code, flowss treats the browser as signed out: every studio and your account page send you back to this step.

If you lose your phone

The code page and the card both explain the way back. If you saved the setup key, add it to an authenticator app on any device (a new phone, or a second device) and enter the code it shows. If you have lost every copy of the key, email support from the address on your account. Proving an account is yours without the code takes time, so keep the key safe.

Turning it off

  1. In the Two-step verification card, choose Turn off.
  2. Read the warning: "Turn off two-step verification? Your account will be protected by your password alone. Enter the code your authenticator app shows now to confirm it is you."
  3. Type the current code into Code from the app and choose Turn off, or choose Keep it on to back out.

A fresh code is required even though you are already signed in, so a browser someone else finds signed in is not enough to remove the protection.

Two-step verification messages

MessageWhat to do
"That code didn’t match. Codes change every 30 seconds — enter the one your app shows now."Enter the code currently on screen. Check that your phone's clock is set automatically.
"That took too long. Enter the current code from your app."Enter the newest code.
"Too many attempts. Wait a few minutes, then try again."Wait, then try again.
"Enter the 6-digit code from your authenticator app."The code must be exactly six digits.
"Confirm a code from your authenticator app first, then try again."The change needs a fresh code; enter one and retry.
"Two-step verification isn’t available on this deployment yet."The feature is switched off for the service. Contact support.
"Couldn’t load your security settings. Check your connection and refresh."Refresh the account page.

Changing your password

You can change your password while signed in, without an email, from the Password card in the Security section of your account page. The card warns: "Changing it signs you out on every other device, and we email you that it changed."

  1. Enter your Current password.
  2. Enter a New password of at least 8 characters, and type it again in Confirm new password.
  3. If two-step verification is on, also enter the Code from your authenticator app.
  4. Complete the verification challenge if one appears.
  5. Choose Change password. You see "Password changed. Other devices have been signed out."
MessageCause
"The two new passwords don’t match."The two new-password fields differ.
"Use a password of at least 8 characters."The new password is too short.
"Enter your current password."The current-password field is empty.
"That is your current password. Choose a new one."The new password is the same as the old one.
"That password was refused as too weak or previously leaked in a data breach. Choose a different one of at least 8 characters."The service refused the new password.
"Complete the verification challenge first."The anti-abuse challenge was not completed.
"Your current password is incorrect. If you sign in with Google or GitHub and never set a password, use “Forgot password?” on the sign-in page to create one."The current password is wrong, or the account has never had a flowss password.
"This account has no email address to sign in with."The account has no email address on record, so it has no password to change.

The emails you will receive

EmailWhenWhat it contains
Confirm your emailAfter you create an email-and-password account, and whenever you choose Send it againA link and a six-digit code. Single use; expires after a short time.
Password resetAfter you choose Forgot password?A link and a six-digit code. Single use; expires after a short time.
WelcomeOnce per account, the first time you sign inAn introduction to flowss. Sent at most once, however many times you sign in.
Password changedAfter a password reset completes, or after you change your password on your account pageA security notice that your password changed.

Billing receipts, plan notices and other messages are described in Managing your subscription and Account settings and your data.

Signing out

Where to find Sign out depends on the screen you are on:

  • In the island studios (every studio except Study), open the account button (your avatar at the far right of the top-right island) and choose Sign out, the last row of the menu.
  • On your account page, the Library and other pages that use the header bar, select the small sign-out icon beside your name, labelled "Sign out".

Signing out returns you to the home page. On the device you sign out from it also clears:

  • your on-device personalisation — your profile and role, streak, recent items and the "For you" suggestions in the command palette;
  • any AI provider key you saved in this browser, so the next person to use the device cannot spend it;
  • the cached AI points balance and plan of the account that signed out.

Your documents are deliberately left untouched. Work saved in this browser stays in this browser; work synced to your account stays in your account. If you sign out in one browser tab, other open tabs of flowss in the same browser notice and also stop using your saved key and balance.

Staying signed in, and using several devices

You stay signed in on a browser until you sign out, your session expires, or you clear the site's data. Sessions are refreshed automatically as you move around flowss, so you do not need to sign in again on every visit.

To use flowss on another computer, tablet or phone, sign in there with the same method. Work that syncs to your account appears on every device; work you made while signed out lives only in the browser where you made it. While you are signed out, the header shows a small notice such as "Saved in this browser only — sign in to back up" (or the short form "Not backed up") so you always know where your work lives. The details of what syncs, and when, are in Cloud sync, offline work and devices.

Your account page

/account is your home base once you are signed in. It shows your current plan and how it is billed, your AI points balance and history, a launchpad back into each studio, today's usage meters, your recent agent runs, your own AI key and API keys, links to pricing, docs and support, a Security section for two-step verification and your password, and the controls to export everything or delete your account. Each part is described in Account settings and your data. Opening the account page while signed out takes you to sign-in first and brings you back afterwards.

Tips

  • Use a password manager and Suggest strong password: the generated password is already in your clipboard, ready to save.
  • If your organisation's email filter tends to consume links before you open them, use the six-digit code in the email instead of the link.
  • Sign in with the same method every time. A Google account and an email-and-password account with the same address are not interchangeable from the sign-in form.
  • Follow a share link or invitation even when you are signed out — after you sign in, you land on the shared item rather than on a blank screen.
  • When email is briefly paused, Continue with GitHub and Continue with Google still work, because neither sends email.
  • Turn on two-step verification, and save its setup key in your password manager the moment you see it.
  • If you share a computer, sign out when you finish. It removes your saved AI key and personalisation from that browser.

Limits and known constraints

LimitValue
Minimum password length8 characters. Very weak or breached passwords can be refused even when longer.
Confirmation emails per address3 per day from any one network through Send it again and Send a new confirmation link, and 20 per day across all networks.
Wait between resends on the panel60 seconds, counted down on the button.
Password-reset emails per address3 per day from any one network, and 20 per day across all networks.
Six-digit email-code attempts per address10 per day from any one network.
When the daily counts resetMidnight UTC.
Link and code lifetimeSingle use, and they expire after a short time. A newer email replaces an older one.

Other constraints to be aware of:

  • There is no passwordless or magic-link sign-in.
  • There is no in-app control to change the email address on an account, or to link a GitHub or Google sign-in to an existing account. (An account created with GitHub or Google can gain a password through Forgot password?.) Contact support from your account page if you need a change of address.
  • Two-step verification uses an authenticator app only. There are no SMS codes and no recovery codes; the setup key is your backup.
  • Sign-in email can be briefly paused when a large amount of email has gone out across the service in a short time. GitHub and Google sign-in are unaffected.
  • Signing in backs up most studios' work to your account, but Study courses and Scholar assessments stay in the browser where you made them even when you are signed in. The notice in those studios says "Signing in does not back up work in this studio." See Cloud sync, offline work and devices.

Troubleshooting

What you seeWhat it meansWhat to do
"That email and password don't match. …"Wrong email or password, or the account was created with GitHub or Google.Check both fields; try Forgot password?; or use the GitHub or Google button you signed up with.
"An account with this email already exists. Sign in instead, or use “Forgot password?”."You tried to sign up with an address that already has an account.Sign in instead, or reset the password.
Confirm your email to sign in panelYour password is correct but the address was never confirmed.Choose Send it again and confirm with the new link or code.
"That link has expired or was already used — they only work once. …"A confirmation link was opened twice, opened late, or consumed by a mail scanner.Type your email into the field and choose Send a new confirmation link (it sends a confirmation link, not a password reset).
"That sign-in link didn't work. …"The link was damaged or incomplete.Type your email and choose Send a new confirmation link.
"This sign-in came back to a different browser or address than the one it started from, …"The sign-in started in one browser and finished in another.Start again from the sign-in page in this browser, send yourself a fresh link and open it here, or sign in with your password.
"That password-reset link has expired or was already used — …"A reset link was reused or opened too late.Enter your email and choose Forgot password? again.
"This reset link has expired or was already used. Request a new one from the sign-in page."Shown on the set-a-new-password page when the reset session is no longer valid.Request a new reset email from /signin.
"That code has expired. Send yourself a fresh email and use the new code."The six-digit code is too old.Request a new email and use its code.
"That code didn’t match. Check the digits — or send yourself a fresh email and use the new code."A digit is wrong, or the code belongs to an older email.Re-type it, or use the newest email's code.
"Too many code attempts for that address today. …"10 email-code attempts were used from your network.Wait until after midnight UTC, then request a fresh email.
"Too many confirmation emails requested. Check your spam folder, then try again later."The daily resend limit for that address was reached.Check spam; try again after midnight UTC.
"Too many password-reset emails requested. Check your spam folder, then try again later."The daily reset limit for that address was reached.Check spam; try again after midnight UTC.
"Email sign-in is briefly unavailable: too much email has gone out in a short time, …"Sign-in email is temporarily paused across the service. During sign-up this means your sign-up did not finish.Use Continue with GitHub or Continue with Google, or try email again later.
"Choose a different password: that one is too weak or has appeared in a known data breach. …"The password was refused.Pick another, or use Suggest strong password.
"The verification check didn't go through. Complete it again, then retry." or "Complete the verification challenge first."The anti-abuse challenge was not completed or expired.Complete the challenge again; each attempt needs a fresh one.
"Too many attempts from your network in a short time. Wait a little, then try again."Many requests from your network in a short time.Wait a few minutes and retry.
"Couldn't reach the sign-in service. Check your connection and try again."Your device could not reach the sign-in service.Check your connection, VPN or firewall, then retry.
"We couldn't finish that sign-in. You may have cancelled it, …"A GitHub or Google sign-in was cancelled or refused.Try again, read the "What the sign-in server said" line if shown, or use the email form.
"New accounts can't be created at the moment. …"Sign-up is temporarily switched off.If you already have an account, sign in. Otherwise try again later.
"This account can't sign in at the moment. If you think that's a mistake, contact support."The account has been suspended.Contact support.
"Sign-in is temporarily unavailable. Please try again later."The sign-in service is unavailable.Try again later; meanwhile browse templates or the docs. Check status.
You land on pricing with a note such as "Lab is part of Starter"You are on Free and opened a studio Free does not include.Use the Studio or Sketch, or upgrade — see Plans and what they include.
"We couldn't send a reset email just now, so none was sent. Try again in a moment."The reset service was briefly unavailable.Wait a moment and choose Forgot password? again.
"Enter the six-digit code from the email."You chose Continue with fewer than six digits.Type all six digits.
Enter your verification code page after signing inYour account has two-step verification on.Enter the code from your authenticator app, or see "If you lose your phone" above.
You are asked to sign in again unexpectedlyYour session expired or the site's data was cleared.Sign in again; synced work is waiting in your account.

Something unclear or out of date on this page? Tell us from the Support link in any studio — the flowss team reads every report.

© 2026 Voranox Inc. flowss — Flow Systems Studio. All rights reserved.

This documentation, its text and its examples are protected by copyright. Engine and format names are trademarks of their respective owners — see the terms and copyright and licences.