One email address and one password open every business you run or work at. Your password is kept by the sign-in service BookNovi uses, never by BookNovi itself, and nobody at your business can see it.
Sign in
Type your email address and password on the sign-in page and choose Sign in.
After five wrong passwords for one email address in fifteen minutes, signing in with that address waits fifteen minutes. Each wait after that, within a day, is twice as long, up to a day. Twenty wrong passwords from one place, such as a salon's Wi-Fi, make that place wait the same way. The page says the same thing whether or not anyone signs in with the address, so it tells nobody who has an account. After a wait, the page may ask you to tick a box to show you are not a program.
Forgot your password
- On the sign-in page, choose Forgot your password?
- Type the email address you sign in with, and choose Email me a link.
- Open the email and choose Set a new password. The link works once, within an hour.
- Type the new password twice, at least 10 characters, and choose Set the password.
Setting it signs you out of your other browsers and phones, and you get an email saying the password changed. If you have two-step sign-in on, you are still asked for its code: a link to your email proves the email, not your phone. An address can be sent three links an hour.
Change your password
Open your menu and choose Password and two-step sign-in. Under Your Password, type your current password and the new one twice, then choose Change the password. Your other browsers and phones are signed out; this one stays signed in. Five wrong current passwords make it wait, as signing in does.
Two-step sign-in
With two-step sign-in on, each sign-in asks for a six-digit code from an authenticator app on your phone as well as your password, so a stolen password alone opens nothing. Any authenticator app works: Google Authenticator, Microsoft Authenticator, 1Password or Authy. It is yours to turn on whatever your business asks, and your business can require it of owners and admins, or of everyone.
To turn it on:
- Open your menu, choose Password and two-step sign-in, then Turn it on.
- We email a six-digit code to your address. Type it. This keeps anyone who only knows your password from putting their own phone on your sign-in.
- Scan the code shown with your authenticator app, or choose Cannot scan? Show the letters to type.
- Type the code the app shows now.
- Keep the eight recovery codes somewhere safe, such as a password manager. Each one signs you in once if you lose your phone, and they are shown only then.
To turn it off, choose Turn it off and type a code from the app or a recovery code. You get an email each time it is turned on, turned off or reset, so a change you did not make shows at once.
Five codes that do not match in ten minutes make it wait, on the web and in the phone app together. Each one is in your business's activity log.
Lost your phone
Sign in with a recovery code in place of the app's code. Then, on Password and two-step sign-in, turn two-step sign-in off and on again with your new phone, which gives you new recovery codes.
With no recovery codes left, ask an owner of your business to reset it. You get an email saying who reset it, and the next time you sign in you set it up again, beginning with a code to your email. Nothing opens until you do, whatever your businesses ask, so a reset never leaves your sign-in with only its password.
For owners
Settings, Team has a Two-Step Sign-In card: who must use it (nobody, owners and admins, or everyone) and how many on the team have it on. It is the same setting as Admin, Compliance, Sign-in (see Compliance), and a login that must have it is sent to set it up at its next sign-in.
To reset a teammate's, when they have lost their phone and their recovery codes:
- In Settings, Team, choose Reset two-step beside their name.
- Say why, in a few words.
- Choose the button that resets their two-step sign-in, which names them.
The reset is in the activity log with who did it and why, and the person is emailed. Your own is turned off on your own page.
Admin, Compliance, Sign-in lists each sign-in, each password or code that did not match, each password set from a reset link or changed, and each sign-out, with who and from where.
Best practices
- Turn two-step sign-in on for yourself, and require it of owners and admins at least.
- Keep your recovery codes away from the phone the app is on.
- If you get an email about a change you did not make, set a new password at once from the sign-in page and tell the owner of your business.
- When someone leaves, pause their login under Settings, Team the same day.