The Cubewire console at wallet.cubewire.com is where you manage vaults, configure policies, approve transactions, and administer your team.
Note: Every user belongs to at least one organization. You'll either create a new organization during signup or join an existing one via invitation.
Organizations can configure Single Sign-On for centralized identity management.
| Protocol | Compatible providers |
|---|---|
| SAML 2.0 | Okta, Azure AD, OneLogin |
| OIDC | Any OpenID Connect provider |
SSO is configured at the organization level. Contact your admin or support@cubewire.io to set it up.
Add a second layer of security using a time-based one-time password (TOTP) from an authenticator app like Google Authenticator, Authy, or 1Password.
Important: Backup codes are your recovery option if you lose access to your authenticator app. Store them in a password manager or other secure location.
Sessions remain active while you're using the dashboard. Inactive sessions expire after a configurable timeout, and closing your browser ends your session.
Sign out: Click your profile icon → Sign Out.
Review active sessions: Go to Settings → Security → Active Sessions to view and revoke sessions you don't recognize.
If you belong to multiple organizations:
Each organization has its own vaults, policies, users, and settings—switching changes your entire context.
Administrators can add users to the organization:
The invitee receives an email with a link to join your organization.
| Problem | Solution |
|---|---|
| Forgot password | Click Forgot Password on the sign-in page |
| MFA code rejected | Check that your device clock is synchronized—TOTP is time-sensitive |
| Lost MFA device | Use a backup code, or contact support@cubewire.io to reset |
| Account locked | Contact support@cubewire.io |
| Problem | Solution |
|---|---|
| SSO option not appearing | Confirm your email domain is configured for SSO |
| Redirect fails | Contact your IT admin to verify SSO configuration |
| Access denied after SSO | Your account may not be provisioned—contact your admin |
The Cubewire console at wallet.cubewire.com is where you manage vaults, configure policies, approve transactions, and administer your team.
Note: Every user belongs to at least one organization. You'll either create a new organization during signup or join an existing one via invitation.
Organizations can configure Single Sign-On for centralized identity management.
| Protocol | Compatible providers |
|---|---|
| SAML 2.0 | Okta, Azure AD, OneLogin |
| OIDC | Any OpenID Connect provider |
SSO is configured at the organization level. Contact your admin or support@cubewire.io to set it up.
Add a second layer of security using a time-based one-time password (TOTP) from an authenticator app like Google Authenticator, Authy, or 1Password.
Important: Backup codes are your recovery option if you lose access to your authenticator app. Store them in a password manager or other secure location.
Sessions remain active while you're using the dashboard. Inactive sessions expire after a configurable timeout, and closing your browser ends your session.
Sign out: Click your profile icon → Sign Out.
Review active sessions: Go to Settings → Security → Active Sessions to view and revoke sessions you don't recognize.
If you belong to multiple organizations:
Each organization has its own vaults, policies, users, and settings—switching changes your entire context.
Administrators can add users to the organization:
The invitee receives an email with a link to join your organization.
| Problem | Solution |
|---|---|
| Forgot password | Click Forgot Password on the sign-in page |
| MFA code rejected | Check that your device clock is synchronized—TOTP is time-sensitive |
| Lost MFA device | Use a backup code, or contact support@cubewire.io to reset |
| Account locked | Contact support@cubewire.io |
| Problem | Solution |
|---|---|
| SSO option not appearing | Confirm your email domain is configured for SSO |
| Redirect fails | Contact your IT admin to verify SSO configuration |
| Access denied after SSO | Your account may not be provisioned—contact your admin |