Support
Help with the co-signer app and the console.
Most questions are answered below. If you are stuck, write to us — and remember that optitor staff will never ask for a passkey, a recovery key or a pairing code.
Co-signer app
Pairing and approving
- 1An administrator opens Users & Devices → Pair device in the console.
- 2You tap Scan pairing code in the app and scan the QR.
- 3An administrator activates your phone; the app then shows Approver active.
The QR code does not scan or says it has expired.
Pairing codes work once and expire after ten minutes. Ask your administrator to show a new code in the console under Users & Devices, then scan it straight away in good light.
My phone shows "Awaiting activation".
Pairing worked. An administrator now has to activate the phone in the console; activation needs your organization’s approval quorum. Tap Check status once they confirm.
Face ID or my fingerprint changed and the app stopped approving.
That is deliberate: the approval key is bound to the biometrics enrolled when it was created. Ask an administrator to revoke the old device in the console, then pair the phone again.
The app refused to approve a policy change.
The phone recomputes the fingerprint of the rules it shows and refuses when it does not match what the server sent. Do not retry — tell your administrators and security team, because something between the console and your phone changed the content.
I have a new phone, or I lost my phone.
Ask an administrator to revoke the old device in the console right away, then pair the new phone with a fresh code. Keys cannot be moved between phones, by design.
Can I use the app without an organization?
To approve real transactions, no: the app is an approver device for organizations that run optitor, and it approves nothing until it is paired with your organization’s console. To see how it works first, tap Explore a demo on the first screen — it shows the approval screens with sample data, and nothing is signed or sent.
Console
Signing in and approvals
The console runs in your browser and uses passkeys only. Each organization’s administrators manage users, roles and devices.
How do I sign in to the console?
With a passkey — Face ID, Touch ID, Windows Hello, an Android phone or a security key. There is no password. Your first passkey is created from an enrollment link sent by your administrator.
My enrollment link expired.
Enrollment links work once and expire after 24 hours. Use “Email me a sign-in link” on the sign-in page, or ask an administrator to issue a new one. Accounts that already hold a passkey never receive links by email.
I lost every passkey.
An administrator starts a sign-in reset after verifying your identity. For privileged roles it also needs the approval quorum, and every reset waits 24 hours with an email notice to you — so a takeover attempt can be stopped. Add a second passkey once you are back in.
A withdrawal says it is waiting for approval.
Your organization’s policy matched a rule that needs approvers. The transaction shows which rule matched and how many approvals each group still needs.
Contact support
Write to hello@optitor.com. Tell us your organization, the app version and platform (iOS or Android), what you expected and what happened. Please never include a pairing code, a screenshot of one, or any key material.
Report a security issue
Write to hello@optitor.com. See our disclosure guidelines for what to include.