Sign-In Help

Everything you need to sign into the Phreesia Dashboard, including two-factor authentication setup and troubleshooting.

Signing into Phreesia

  1. Enter your username
    Navigate to your organization's Phreesia login page and enter your username.
  2. Click Next
    If your organization uses Single Sign-On (SSO), you will be redirected to your identity provider to complete authentication.
  3. Enter your password
    Type your password in the field provided.
  4. Click Sign In
    After clicking Sign In, you will proceed to the next step.
  5. Verify your identity with two-factor authentication
    If your organization has enabled two-factor authentication (2FA), you will be prompted to verify your identity using one of your configured methods, such as an authenticator app, passkey, text message, or email code. See Signing In with 2FA below for details on each method.
  6. You're in!
    Once verified, you will be taken to your Phreesia Dashboard home page.

Signing In for the First Time

  1. Enter your username
    Your Phreesia Administrator will provide you with a username and temporary password.
  2. Click Next, then enter your temporary password
    Use the temporary password provided by your administrator.
  3. Create a new password
    You will be directed to a page where you can create a new password. Your organization may require your password to meet certain conditions. Check that your new password meets the criteria displayed on the screen before submitting.
  4. Set up two-factor authentication
    If your organization has enabled 2FA, you will be prompted to set up your verification method(s) after creating your password. See Setting Up 2FA for step-by-step instructions for each method.
  5. You're all set!
    After setting your new password and completing 2FA setup, click Submit to access the Dashboard.

What is Two-Factor Authentication?

Two-factor authentication (2FA) adds an extra layer of security when signing into the Phreesia Dashboard. In addition to your username and password, you verify your identity using a second method.

Your organization chooses which verification methods are available. You may be able to use one or more of the following:

  • Authenticator App: A time-based code generated by an app on your device. No internet required after initial setup.
  • Passkey: Verify with your fingerprint, face, or device PIN. No codes to enter, and it is fast and phishing-resistant.
  • Text Message (SMS): A one-time code sent to your mobile phone number via text message.
  • Email: A one-time verification code sent to the email address on file for your account.
Setting up more than one method is recommended so you have a fallback if your primary method is unavailable.

Setting Up Two-Factor Authentication

Once 2FA is turned on for your organization, you will be prompted to set up your verification method the next time you sign in. The method(s) shown will reflect your organization's settings.

Setting up an Authenticator App

  • After entering your username and password, you will see a screen displaying a QR code and a manual entry key.
  • Open your authenticator app and scan the QR code, or manually enter the key.
  • Your authenticator app will generate a 6-digit code that refreshes every 30 seconds.
  • Enter the current code from your app and select Next to complete setup.
Your authenticator app does not need an internet or cell connection to generate codes after initial setup.

Setting up a Passkey

  • You will see a screen prompting you to register a passkey. Select Set up Passkey.
  • Your browser will prompt you to choose how to create the passkey: using a built-in method (fingerprint, face recognition, or device PIN) or an external security key.
  • Follow the on-screen prompts from your browser or device to complete registration. This typically takes a few seconds.
  • Once registered, the passkey is stored securely on your device and is ready for future sign-ins.
You can register multiple passkeys. For example, one on your laptop and one on your phone, so you have a backup if one device is unavailable.

Setting up Text (SMS) Verification

  • You will see a screen prompting you to confirm or enter your cell phone number.
  • Enter or update your mobile phone number in the field provided.
  • Phreesia will send a verification code to your phone via text message. You can resend the code up to 5 times.
  • Enter the code and select Next to complete setup.
Phone numbers from outside the United States cannot receive text 2FA due to limitations with our texting vendor.

Setting up Email Verification

  • You will see a screen prompting you to confirm or update your email address.
  • The email address already on file will be pre-filled. You may make a one-time change if needed.
  • Phreesia will send a verification code to your email. You can resend the code up to 5 times.
  • Enter the code and select Next to complete setup.
Verification code emails are sent from Support@phreesia.com. Check your spam or junk folder if you do not receive the code.

After Setup

Once you complete setup for your first method, you will see a confirmation message. If your organization allows additional methods, you will have the option to set up another method at this time. Selecting Continue will bring you to the Dashboard.

Signing In with Two-Factor Authentication

Once 2FA has been set up, it becomes a required step each time you sign in. After entering your username and password, you will be prompted to verify your identity.

Signing in with an Authenticator App

  • Open your authenticator app and find the entry for Phreesia.
  • Enter the current 6-digit code displayed in your app.
  • Select Next to access the Dashboard.
No internet or cell connection is required on the device running the authenticator app.

Signing in with a Passkey

  • Select the passkey option on the verification screen.
  • Follow the prompt from your browser or device to authenticate using your fingerprint, face recognition, device PIN, or security key.
  • Authentication is completed in a few seconds with no code to enter.
Passkey sign-in is the fastest method. Just scan your fingerprint or use your device PIN and you're in.

Signing in with a Text Message (SMS)

  • If you have set up text verification, select it as your method (or it will be selected automatically if it is your only method).
  • Phreesia will send a verification code to your mobile phone. You can resend the code up to 5 times.
  • Enter the code and select Next to access the Dashboard.

Signing in with an Email Code

  • If you have set up email verification, select it as your method (or it will be selected automatically if it is your only method).
  • Phreesia will send a verification code to your email address on file. You can resend the code up to 5 times.
  • Enter the code and select Next to access the Dashboard.
Codes are sent from Support@phreesia.com. Check your spam or junk folder if you don't see it.

Lockout: After 3 incorrect code attempts (email, text, or authenticator app), your account will be locked. Passkeys have no attempt limit. Contact your Phreesia Administrator to unlock your account.

If You Forget Your Password

  1. Click Reset Password
    On the sign-in page, click the "Reset Password" link below the password field.
  2. Enter your username and security code
    Fill in your username and the security code displayed on the screen.
  3. Check your email
    A password reset link will be sent to the email address on file for your account.
  4. Follow the link and create a new password
    Click the link in the email and follow the instructions to set a new password.
If we do not have an email address on file for your account, we will not be able to reset your password. Contact your organization's Phreesia Administrator for assistance.

If You Forget Your Username

If you have forgotten your username, please contact your organization's Phreesia Administrator. Self-service username recovery is not available at this time.

Frequently Asked Questions

Phreesia supports any authenticator app that uses the TOTP (Time-based One-Time Password) standard. Your organization will provide guidance on which app to use. If you are unsure, contact your Phreesia Administrator.
Passkeys are supported on most modern devices and browsers, including Chrome, Safari, Edge, and Firefox. You can create passkeys using built-in biometrics (such as Touch ID, Face ID, or Windows Hello), a device PIN, or an external hardware security key. If your browser does not support passkeys, you can use another available verification method.
Yes. You can register multiple passkeys. For example, one on your laptop and one on your phone, so you have a backup if one device is unavailable.
Contact your Phreesia Administrator. They can reset your 2FA setup so you can re-enroll with a new device the next time you sign in. If you have another verification method configured (email, text, or another authenticator/passkey), you can continue to sign in using that method in the meantime. Lost passkeys cannot be used by anyone else, as they require your biometrics or device PIN to authenticate.
Yes, if your organization has multiple methods enabled, you can set up more than one. This provides a fallback in case your primary method is unavailable. For example, if you don't have your phone, you can use email instead.
You can have a verification code sent up to a total of 5 times. After that, the resend option will disappear. You can start the process over by refreshing your browser or restarting the sign-in process.
Verification codes are sent from Support@phreesia.com. This is the same email address used for password resets. If you do not receive the code, check your spam or junk folder.
Yes. Email and text verification do not require a smartphone. Passkeys can also be set up on a laptop or desktop using built-in biometrics (such as Windows Hello or Touch ID) or a hardware security key. No smartphone is required for these methods. Authenticator apps do require a mobile device.