---
title: Initial access registration
slug: ops-and-admin/org-management-portal/sign-in-and-security
description: Register and set up accounts on Cross River's Identity Server, including MFA setup, password management, IP whitelisting, and troubleshooting.
docTags: 
createdAt: 2024-08-12T13:50:05.403Z
---

:::hint{type="info"}
If you are trying to access COS Explorer, go to [COS Explorer first-time access](docId\:JwSEUG3ELF_gXLhy6T9KI).&#x20;
:::

## Register in the authentication server

Once you are onboarded into the Cross River system you need to register in our authentication server,*&#x20;Identity Server*, to access Cross River applications.

You fill in an enrollment form from your relationship manager where you specify at least 2 admin users for your organization, including their names, phone numbers, and email addresses. These organization admins can then [create and manage](docId:6au9hHoZi9zOPRZmpVPUo) the rest of your organization's users.

:::hint{type="info"}
If you are using the Sandbox environment, you'll need to repeat this process if you need to access the Production environment. Your users can use the same email/username for both environments. We recommend using a different password for each.
:::

The Identity Server endpoints are:

- **Sandbox: &#x20;**[https://idptest.crbcos.com/Account/Login](https://idptest.crbcos.com/Account/Login)
- **Production:&#x20;**[https://idp.crbcos.com/Account/Login](https://idp.crbcos.com/Account/Login)

:::hint{type="warning"}
**IMPORTANT**
**IP allowlisting**

Identity Server IP addresses are:

- 172.67.26.222
- 104.22.40.134
- 104.22.41.134

Organization management portal address:

- 66.206.202.116

The server is proxied via Cloudflare.

You can allow these FQDNs:

- `idptest.crbcos.com`
- `idp.crbcos.com`
:::

## Before you begin

Verify that you received a welcome email from *CrossRiver\_DO\_NOT\_REPLY\@crossriver.com* with a link to create your Cross River account.

:::hint{type="info"}
If you don't see the welcome email in your inbox, check your spam or blocked mail folders.
:::

## Prepare multifactor authentication (MFA)

To protect your identity, your account and information, you must sign in with multifactor authentication. Set up your authenticator app to be able to complete the registration process and to be able to login in the future.

:::hint{type="info"}
If you don't already have an authenticator app on your device, you need to install one.

For both Android and iOS, we recommend using one of these apps:

- Google Authenticator
- Microsoft Authenticator
:::

## Initiate registration

When you click the **Create your Cross River Account** link in the welcome email, the login wizard opens in a browser.&#x20;

If you leave the wizard at any time, click the link in the email to go back to where you left off.

- Navigate through the wizard, following the instructions there.
- In Step 2 of 5, note that if you are using a US-domestic phone number for SMS messages you need to confirm your phone number and give consent to receive an SMS message.
- In Step 4 of 5, if you prefer to manually enter a key instead of using the displayed QR code:
  1. Click **Show key** under the QR code. An alphanumeric string appears below the code. This is the key.
  2. In your authenticator app, enter the key as the *Secret&#x20;*&#x66;or this connection.
  3. Be sure the connection has a meaningful name. If you plan on using more than one environment, check that the name mentions the environment of that connection. For example, *Cross River Sandbox*.
  4. Open the connection to generate a 6-digit code to enter in the wizard.
- Note that Step 5 of 5, Recovery codes, times out after 10 minutes.
  You can only download the recovery codes once.

## Log in to a Cross River application

When you complete your initial login, you'll be redirected to the app you started with.

To access the application after that, navigate to the application URL and log in with your email address and password.

## Support

Email [customer.support@crossriver.com](mailto\:customer.support@crossriver.com).
