The SalesThumb mobile app has two completely separate sign-in paths, and they are not interchangeable. Staff sign in with an email and a password. Customers sign in with a phone number and a code sent by text. Handing a front-desk employee a phone and saying "log in" is exactly how someone ends up stuck on the wrong screen, so it's worth knowing which door is which before you start.
One thing up front: the native iOS and Android apps are still in beta and there's no public App Store or Play Store install link yet — see Mobile app access: what's set up today. Everything below describes what happens once you have a build on the phone.
The first screen: "Who's using the app?"
A fresh install opens on an account-type picker with exactly two choices:
- I'm a Teammate — staff sign-in: "Jobs, quotes, schedule, and more"
- I'm a Customer — "Track your job, view invoices & warranties — no password needed"
You can switch later without starting over. The staff sign-in screen has an "I'm a customer, not a teammate" link at the bottom, and the customer screen has "I'm on the team instead."
Staff sign-in — email and password
Tap I'm a Teammate and you get a "Welcome back" card with two fields, Email and Password. These are the same credentials you use on the web app — there is no separate mobile password and no mobile-only account to create. The app trims and lowercases the email for you, so capitalization won't trip anyone up.
On success the app saves your session to the phone's secure storage (Keychain on iOS, Keystore on Android) and drops you straight onto your landing tab — Dashboard if you're an Owner, Admin, or Manager, Today for everyone else. If it fails, you get a "Sign-in failed" alert with whatever the server said, which in practice means a wrong password or a mistyped email.
There is no "forgot password" link on the mobile sign-in screen
This is the most common dead end on this screen, so it's worth stating plainly. The mobile sign-in card has no password-reset link. The only two links under it are "Email me a sign-in link instead" and "I'm a customer, not a teammate," plus a footer that reads "Need access? Contact your shop administrator."
If you've forgotten your password, you have two real options:
- Use Email me a sign-in link instead — it signs you in with no password at all
- Reset your password from the web app in a browser, then come back and sign in with the new one
Magic link — "Email me a sign-in link instead"
Enter your email, tap Send sign-in link, and the screen switches to a "Check your email" card.
Read that confirmation carefully, because it's deliberately vague: it says the link was sent if that address matches a SalesThumb account. The server replies identically whether or not the email belongs to a real account — that's on purpose, so nobody can use the form to discover who has an account. A typo'd address produces exactly the same "Check your email" screen a correct one does. If nothing arrives, re-check the spelling before assuming email is broken.
Three rules that will save you a support ticket:
- The link expires in 5 minutes. Not an hour, not a day. Get distracted and you'll need a new one.
- It's single use. Tapping it a second time fails.
- You must open it on the same phone that requested it. This one is enforced, not advisory.
That last rule surprises people, so here's why it exists. When you tap "Send sign-in link," the app generates a secret and keeps it only in that phone's secure storage — it's never emailed and never included in the link itself. Finishing the sign-in requires both the emailed link and that on-device secret. So forwarding the email to a colleague, or opening it on a laptop or a second phone, cannot work by design. It's what stops another app installed on the device from intercepting the link and stealing the session.
When something goes wrong, the app shows a "Sign-in link didn't work" card with a Request a new link button and one of these exact messages:
- "This sign-in link has expired or was already used. Request a new one." — past 5 minutes, or already tapped once
- "No SalesThumb account uses this email yet. Ask your shop admin for an invite." — there's no account on that address
- "This link is missing information needed to sign you in. Request a new sign-in link." — opened on a different device than the one that requested it, or the app's storage was cleared in between
- "Something went wrong signing you in. Please try again." — the server couldn't create the session
Customer sign-in — phone number and a texted code
Tap I'm a Customer and you get a two-step passwordless flow.
Step one asks for Phone — the number on the customer's account at your shop — and Name (optional). The name is purely a tiebreaker: when one phone number appears on more than one customer record, the name helps pick the right one. Tap Send code.
Step two asks for the 6-digit code from the text, with Resend code and Edit phone number links underneath it.
What actually governs this flow:
- The code expires in 10 minutes
- 5 wrong attempts burns that code entirely — you have to request a fresh one
- Only 3 codes per phone number per hour will go out
- Once verified, the customer session lasts 30 days
- The text names the shop the code is for, so a customer registered at two shops can tell which is which
Now the gotcha: a phone number that isn't on file produces no error at all. The "Send code" step always reports success — same anti-enumeration reasoning as the magic link. The customer just sits there and never gets a text. So when someone says "the code never came," the first thing to check is whether the number they typed matches the number on their customer record, not whether SMS is down.
Customer sign-out lives on the customer Profile tab, and the confirmation is honest about the consequence: "You'll need to request a new code to sign back in."
Two-factor — two different screens, two different reasons
If 2FA comes up, the app sends you to one of two screens. They look similar and they are not the same thing.
"Verify it's you" appears when your account already has 2FA turned on. Every fresh sign-in has to clear the challenge again — a correct password on its own isn't enough. There are three ways through:
- The 6-digit code from your authenticator app
- One of your saved backup codes (the field switches to an xxxxx-xxxxx format)
- Text me a code instead — but only if you have a verified phone number on your account. A TOTP-only account that taps it gets back "SMS verification isn't set up on this account."
"Set up two-factor authentication" appears when your organization requires 2FA and your account has never enrolled. This screen is authenticator-app only — it does not offer SMS enrollment, and it does not draw a QR code. You get the setup key as selectable text plus a Share button, so you type or paste it into Google Authenticator, Authy, 1Password, or whatever you use. After you verify, 10 backup codes appear with an "I've saved these backup codes" checkbox that has to be ticked before Continue unlocks. That really is the only time they're shown.
Both screens have a "Sign out and use a different account" link at the bottom — your escape hatch if you were handed the wrong phone.
The honest current state: org-wide mandatory 2FA is suspended platform-wide right now while Twilio approval is pending, so the enrollment screen won't appear for anyone yet. The per-account challenge screen is a different story — it keys off your own enrollment rather than org policy, so if you personally turned 2FA on in Settings → Security on the web, the mobile app will still make you clear the challenge on every fresh sign-in. See Securing your account with 2FA for managing the factors themselves.
The nine full-screen lockout messages
When the server rejects your session for a specific named reason, the app doesn't show a small error or a toast — it replaces the entire tab shell with a full-screen message. There are nine of them and the wording is fixed:
- No shop linked to your account — "Your account isn't a member of any shop yet, so there's nothing to load. Ask an owner or admin to add you to the shop, then reopen the app."
- Two-factor authentication required — "Close and reopen the app to continue — you'll be taken to the verification step."
- Account suspended — "This account has been suspended. Contact support to restore access."
- Account frozen — "This shop's account is frozen. Contact support for details."
- Account locked — "This shop's account is locked. Contact support for details."
- Not on your plan — "This feature isn't included in your current plan. An owner can upgrade from the web app."
- You don't have access — "Your role on this shop doesn't include this. Ask an owner or admin if you need it."
- Blocked network — "This account restricts access to approved networks, and this one isn't on the list."
- Couldn't verify your shop — "Something went wrong resolving your shop. Sign out and back in — if it keeps happening, contact support."
In practice, No shop linked to your account is the one you'll actually hit: the person signed in successfully but nobody has added them to a shop yet. It's fixed by an Owner or Admin, not by the person staring at the screen. You don't have access means a screen that's restricted to Owner and Admin, so a Manager or Technician will see it on some management surfaces. Not on your plan comes from plan-tier and add-on gating — HQ features on a shop without the HQ add-on, for example. Account frozen and Account locked are shop-level states set by SalesThumb support, and the message is intentionally generic: the internal reason an admin recorded is never sent to the app. Blocked network comes from the SalesThumb super-admin IP allowlist, so a normal shop user will essentially never see it.
One note if you're on an older beta build: eight of these nine used to fall through to a generic "check your connection" message, which sent at least one real diagnosis chasing WiFi that was working fine. That's fixed. If you see connection-blaming copy for what's obviously an access problem, you're on a stale build.
"No mobile access set up yet" is not one of the nine
If someone signs in fine but the thumb menu opens to a nearly empty panel reading "No mobile access set up yet — Your account hasn't been assigned an Installer or Sales role for the mobile app. Ask your shop owner or manager to set this in Settings → Team, then reopen the app," that's a mobile-access assignment, not a lockout.
It's easy to get this backwards, so be precise: a mobile access level of No access does not stop anyone from signing in. Sign-in succeeds and the session is real — the app just has nowhere to send them. Owners are the exception: an Owner always gets both the Installer and Sales sides regardless of what's set on their own membership.
Fix it at Settings → Team, on the Members tab, in the Mobile App Access card. Full detail in Mobile app access: what's set up today.
Getting signed out on your own
If your staff session is revoked or expires server-side — an admin revokes it from the web app, the account is deactivated, or the token simply ages out — the app notices on its very next request and signs you out cleanly, landing you back on the account-type picker. That's the app working correctly, not a crash. Sign back in normally.
Signing out and running both sides on one phone
Staff sign-out is Profile → Sign out. Customer sign-out is on the customer Profile tab.
The two sessions are stored separately on the device, so an owner can be signed in as staff and as a customer on the same phone at the same time — genuinely useful for checking what your customers see. When both exist the app always routes you to the staff side, so sign out of staff to land in the customer experience.
Common questions
Q: A teammate keeps landing on the customer sign-in screen and their email doesn't work there. What's wrong?
A: Nothing's broken — they picked the wrong door. The customer screen asks for a phone number, not an email, and it only matches customer records, never staff accounts. Tap "I'm on the team instead" at the bottom and use the email-and-password card.
Q: Can I request a magic link and forward it to a teammate so I don't have to share a password?
A: No. Only the phone that requested the link can complete the sign-in — the second half of the credential never leaves that device. The teammate has to request their own link from their own phone.
Q: Why did the code expire before my customer typed it in?
A: SMS codes are good for 10 minutes and the sign-in link is good for 5. If a customer is reading it back to you over the phone, request the code while they're actually holding their phone rather than ahead of time.
Q: Someone entered a wrong code a few times and now nothing works. Did we lock their account?
A: No — 5 wrong attempts burns that one code, not the account. Tap Resend code and try again. The only hard stop is the 3-codes-per-phone-per-hour cap.
Still stuck after all of that? Use the in-app help widget or email info@roffik.com with the exact wording of the message on screen — for these nine lockouts the wording is what identifies the cause.