Set up Cross River

COS Explorer first-time login

20min

Once you are onboarded into the Cross River system you are ready to login to the COS Explorer.

Access the COS Explorer portal

Welcome email

You will received a welcome email from [email protected]. If you don't see it in your inbox, check your spam or blocked mail folders.

Click Create your Cross River Account.

Document image


If you leave the wizard at any time, click the link in the original email to go back to where you left off.

Terms and Conditions

Read through the terms and conditions, check Accept, and click Next.

SMS (text message) verification

We send you an SMS (text message) to your device to verify your identity. Enter the 6-digit code you receive in the login screen and click Verify Code.

Document image


Create your password

  1. Enter a password that meets the on-screen requirements and re-enter the password.
  2. Click Create Password.
Document image


Multi-Factor Authentication/2-Step Authentication

You must complete this step to continue the registration process and to be able to login in the future

To protect your identity and your account and information, we require you to sign in with multi-factor/2-factor authentication.

If you don't already have an authenticator app on your device, you need to download one before you continue.

For Android and iOS, we recommend using the follow authenticator app:

  • Google Authenticator
  • Microsoft Authenticator

Once you have your authenticator app installed, you need to either scan the QR code or manually enter the key into the authenticator app.

Document image


QR code

  1. Scan the QR code in your authenticator app and, if necessary, enter the 6-digit code in the Multi-Factor authentication page.
  2. Click continue.

Manual

  1. Click Show key
  2. Copy the key as the Secret in your authenticator app.

    Document image
    
  3. Enter the 6-digit code.
  4. Click Continue.

Invalid MFA Code

If you enter an invalid MFA code, a red message notifies you to try again.

Document image


Oops! You entered an invalid MFA code. Here are some things to double check:

  1. Did the code timeout before you clicked Continue? Remaining time is indicated by the countdown circle to the right of the account name and MFA code.

    Document image
    
  2. If you have the authenticator app set up for multiple environments or applications, double check that you entered the correct code.
    1. If it is not clear from the MFA connection names which is correct option, you might need to try different codes until finding the one that works.

      Document image
      
    2. Once you find the correct connection, you can rename the MFA connection in the app. A pencil icon at the top of MFA app screen will bring you to edit mode. In some apps, you will need to first select (or press and hold) the connection that should be edited, and then the icon will appear.

      Document image
      
    3. Once in edit mode, you can rename the connections as needed so that it will be clear which one applies to which environment.

      Document image
      
    4. Save any changes, and next time it should be easier to understand which code to use.

Recovery codes

Use recovery codes to authenticate in case you lose your device.

  1. Download or copy your recovery codes and keep them in a secure place that you will remember.
  2. Confirm that you have stored your recovery codes
  3. Click Create account.

The recovery codes page times out after 10 minutes.

You can only download the recovery codes once.

Document image


Your account is now active and you can use it to login to any of your CR apps.

IP allowlisting

Only a static IP can be used to access COS Explorer. Reach out to your IP Support if you need help with this.

The Identity Server IP addresses are:

  • 172.67.26.222
  • 104.22.40.134
  • 104.22.41.134

The server is proxied via Cloudflare.

You can allow these FQDNs:

  • idptest.crbcos.com

Troubleshooting

Forgot Password

  1. Click Forgot password? and enter your email.
  2. Enter the 6-digit authentication code from your authenticator app.
  3. You get a Forgot Password email. Click Reset Password.
  4. In the Password Reset page, enter a new password, click Reset Password, and Continue to the application.

Reset Multi-Factor Authentication

If you already have MFA configured:

  1. In Identity Server, go to Reset MFA and click Reset your MFA device.
  2. The Multi-Factor Authentication page opens and you can reset your MFA.

You can also create new multi-factor authentication recovery codes.

  1. Click create new multi-factor authentication recovery codes.
  2. The Recovery Codes page opens and you can copy or download your 10 new recovery codes.

If you have not yet configured your multi-factor authentication, you can enable MFA from Account Settings.

  1. Click Reset MFA Method.
  2. Click Configure MFA.
  3. Follow the instruction in Multi-Factor Authentication/2-Step Authentication.

If your current MFA is SMS, you can enable MFA with your authenticator app.

In Account Settings

  1. Click Reset MFA Method.
  2. Click Configure MFA.
  3. Follow the instruction in Multi-Factor Authentication/2-Step Authentication.

Using a recovery code

If you do not have access to your multi-factor (2-factor) authenticator, you can log in using one of your recovery codes.

  1. Log in as usual
  2. On the Multi-Factor Authentication page, you have the option to use a recovery code as your authentication option.
  3. Enter one of your recovery codes in the text box. The recovery code is single-use and cannot be reused. To avoid future confusion, we recommend that you mark the recovery code as used.
Document image


Account lockout

If you enter the wrong password for your username 5 times, the system locks your account for approximately 5 minutes. If after 5 minutes, you are still unable to access your account, contact Cross River Support.

Browser error - Firewall

You log in to COS Explorer and get following error screen:

Document image


You are blocked by a firewall.

  1. Contact your internal IT department to see if your organization enforces firewall rules for outbound traffic. If there are no firewall rules for outbound traffic, then:
  2. Contact your internal IT department to make sure you're connecting to the Cross River COS Explorer Portal from an approved IP address. If you need to register more IP addresses, send an email to COS support.