Skip to content

Logging in to Orbit

To log in to Orbit, you need the user credentials supplied by your Apteco software account manager or a FastStats administrator.

Log in screen

To log in:

  1. Enter either your username or email address and select Next.
  2. Select a DataView if you have more than one.

    Select a data view

Use the Forgot password option on the login screen to request a password reset email.

Log in after receiving a shared item

You can be invited to view a Collection or Audience via an Orbit Share email. To log in after receiving a shared item: 1. Open the Orbit Share email. 2. If you are an existing user, log in with your existing credentials. If you are new, select the link to register an account. 3. Select Confirm registration in the registration confirmation email. 4. Log in to Orbit using the credentials you registered with.


Multi-factor authentication

Multi-Factor Authentication (MFA), also known as two-step or two-factor authentication, adds a second layer of security to your Orbit account. After entering your password, you confirm your identity using a One-Time Passcode (OTP) generated by an authenticator app on your phone or device. Even if an attacker learns your password, they still can't access your account without that second factor.

Orbit MFA uses the Time-based One-Time Password (TOTP) standard, supported by all major authenticator apps.

For administrators

Make multi-factor authentication available to users

Before users can enable MFA on their accounts, an administrator must enable it at the system level.

To make MFA available:

  • Make sure your system is running the Q2 2026 Apteco software release and Orbit version 2.3.12 or later.
  • Apply the required configuration change to the OrbitAPI in the FS_Config database.

Refer to the admin guide for step-by-step configuration instructions.

Once enabled, you can choose to enforce MFA for all users or let users opt in themselves. If you enforce MFA, users must complete setup before they can log in.

Disable multi-factor authentication for a user who can't log in

If a user loses access to both their authenticator app and their recovery codes, they become locked out. An administrator can then disable MFA on their behalf.

To disable MFA for a user:

  1. Select your avatar in the top-right corner, then select Users/Groups.
  2. Next to a user with MFA enabled, select Edit User.
  3. Expand the Two-step authentication section and select Disable.

    Admin disable

For users

Enable multi-factor authentication on your account

Before setting up MFA, make sure you have:

  • An authenticator app installed on your phone or device. Common options include Microsoft Authenticator, Google Authenticator, 1password, and Apple Passwords.

    Tip

    Choose an authenticator app that supports cloud backup or account recovery. If you lose your phone and have no cloud backup, you will need to use a recovery code to regain access to Orbit.

  • Access to Orbit under the Q2 2026 release (and Orbit version 2.3.12 or later).

  • Confirmation from your administrator that they've configured the OrbitAPI to support MFA.

Tip

If you use a password manager such as 1Password, many support OTP codes natively. Check your password manager's documentation to see if you can store your MFA codes there alongside your Orbit credentials. Some password managers can autofill your OTP at login, making the process seamless.

Set up multi-factor authentication on your account

You can set up MFA from your account settings at any time. Your administrator might also prompt you to do so at login if they've enforced it.

To set up MFA:

  1. Select your avatar in the top-right corner of Orbit, then select Account Settings.
  2. Select Two-Step Authentication.
  3. Select Enable.

    Enable MFA

  4. Open your authenticator app and scan the QR code displayed on screen, or copy the secret key manually and paste it into your app.

  5. Your authenticator app generates a six-digit code. Enter this code into the confirmation field in Orbit.

    Enter code

  6. Select Enable.

  7. Select Copy Codes to copy the recovery codes displayed and store them somewhere secure (for example, in your password manager).

    Note

    You will need these if you ever lose access to your authenticator app.

MFA is now active on your account.

Tip

Open your authenticator app before scanning the QR code, so the entry goes into the correct app. If you scan using your device's camera app without opening the authenticator first, the code might go to the wrong app or password store.

Note

Your system might have multiple Orbit instances, for example a test environment and a production environment. Each instance requires a separate MFA entry in your authenticator app. The QR code embeds your username and the data view name. If multiple instances share the same data view name, rename the entries in your authenticator app manually so you can tell them apart.

Log in with multi-factor authentication

Once you have enabled MFA on your account, the login process now includes an extra step.

To log in:

  1. Enter your username and password as normal.
  2. When prompted, open your authenticator app and find the current six-digit code for Orbit.
  3. Enter the code in the field.

You are now logged in. You will need to complete this step each time you log in. Refreshing the browser during an active session doesn't require re-authentication.

Note

OTP codes are time-sensitive and expire every 30 seconds. If you enter a code that has just expired, wait for the next code to appear in your authenticator app before trying again.

Respond to the multi-factor authentication setup reminder

If your administrator hasn't enforced MFA on your system, you'll see a prompt to set it up the first time you log in.

Note

This reminder is enabled by default. Your administrator can turn it off in Features settings if preferred.

Setup reminder

To respond to the prompt:

  • Select Enable to go directly to the Two-Step Authentication section of your account settings and complete setup.
  • Select Not now to dismiss the prompt. It will reappear after 30 days, or sooner if you use a different browser or device.

Note

Your browser stores the reminder. If you switch to a different browser or device, the prompt reappears regardless of when you last dismissed it, as expected.

Use recovery codes

Recovery codes let you access your account if you lose your authenticator device.

Note

You can only use each code once.

To use a recovery code at login:

  1. On the OTP prompt, select Use a recovery code.
  2. Enter one of your saved recovery codes.
  3. Select Continue.

Once you log in, set up MFA again immediately to generate a new set of codes.

To generate new recovery codes without disabling MFA:

  1. Go to Account Settings > Two-Step Authentication.
  2. Select Generate new.

    Generate new codes

  3. Copy the new codes and store them securely.

Note

Generating new recovery codes immediately invalidates all previous codes. Store the new codes before navigating away.

Disable multi-factor authentication on your account

You can disable MFA yourself from account settings. You will need your current password to confirm this action.

To disable MFA:

  1. Go to Account Settings > Two-Step Authentication.
  2. Select Disable.
  3. Enter your password when prompted.
  4. Select Disable.

MFA is now off. You can re-enable it at any time.

Note

If your administrator has enforced MFA via permissions, you won't be able to disable it yourself. Contact your Apteco administrator if you need MFA removed from your account.


Single sign-on

With Single Sign-On (SSO), you only need one set of credentials to access all your Orbit DataViews. Before using SSO with Orbit, see Single Sign-On.

If you aren't already logged in, your identity provider (IdP) presents a login prompt.

To log in with SSO:

  1. Enter your username and password at your IdP login prompt, then select Continue.
  2. After authentication, your IdP redirects you back to Orbit.

If you have already signed in to your IdP and open a new Orbit instance, Orbit takes you straight in. You don't need to log in again. When you have multiple DataViews, select which one to log in to.

Log in from your IdP portal

Some identity providers offer a portal from which you can launch connected applications.

To log in to Orbit from your IdP portal:

  1. Log in to your IdP portal.
  2. Select Orbit. Orbit redirects you and logs you in automatically.

Multi-factor authentication with single sign-on

If your organisation uses SSO, MFA in Orbit doesn't apply. Your identity provider handles authentication (including any MFA) entirely. This applies to Orbit and to all client applications, including FastStats and PeopleStage.

If you need to configure MFA for SSO users, refer to your identity provider's documentation or contact your administrator.