How do I invite a user and secure their first Nonli sign-in?

Also available in:Français

Invite each person from Users, give them only the roles they need, and let them complete activation and two-factor authentication (2FA) themselves. Never share a password, one-time code, QR secret, or backup code with an administrator or with Nonli support.

1. Before you send the invitation#

  • Use the teammate's individual professional email address. Shared user accounts prevent reliable access control and should not be used.
  • Decide which brands and roles the person needs. A company administrator can change these assignments later.
  • Ask the recipient to install an authenticator app before their first sign-in if they do not already use one.

2. Invite the user#

  1. Open the main menu, select Users, then select Add user.
  2. Enter the recipient's email address and assign the appropriate role or brand access.
  3. Review the access before sending the invitation. Do not grant an administrator role merely to bypass a missing permission.
  4. Send the invitation. The user appears in the list while activation is pending.

Blank user invitation form with email, first name, last name, and role fields

The recipient must open their own invitation link, choose their own password, and follow the displayed enrollment flow. They first verify their phone number with the SMS code requested by Nonli. During 2FA enrollment, they then scan the QR code with their authenticator app, enter the generated one-time code, and store any backup codes somewhere private. A QR code or backup code grants access and must never appear in a support screenshot.

3. If the invitation or code does not work#

First check spam and quarantine folders and confirm that the address in Users is correct. A company administrator can use Resend confirmation link for a pending user. Use only the newest link after a resend.

If mail to the address bounced, or the email address or phone number is wrong, do not redirect an invitation or verification code to another person. Ask the account owner to follow the email or phone update guide, or contact support with the safe details listed below when they cannot sign in. Restart activation from the newest invitation after the correction; old links and codes must not be reused.

Authenticator codes change frequently. If a code is rejected, confirm that the phone's date and time are automatic, wait for the next code, and enter it once. Do not repeatedly retry an expired code. The separate SMS validation code used by some account flows remains valid for 15 minutes.

4. Lost authenticator device or backup codes#

An administrator must not bypass 2FA or ask the user to disclose a code. Contact Nonli support from an address associated with the account and provide only the company name, affected user email, approximate failure time, and the visible error text. Never send a password, one-time code, backup code, QR code, or API key. Support will verify account ownership before explaining the available recovery path.

Was this article helpful?

Book a personalized demo with our team.