# Signing in and sessions

You sign in to Vintage with the email address and password you created your account with. Once you are in, you stay signed in for as long as you keep using Vintage, and a session left unused for 60 days ends on its own. Signing in, recovering a forgotten password, and how sessions behave are covered below. Creating an account and joining an organization for the first time are covered in [Accounts and organizations](/getting-started/accounts-and-organizations/).

## Signing in

Enter your **Email** and **Password** and press **Sign in**. If either is wrong, the screen says it could not sign you in and asks you to check both and try again.

**Where you land.** Vintage opens on the **Modeling** screen, with two exceptions:

- If you can upload (you are an admin or an editor) and your organization has no loans yet, you land on the **Uploads** page, since there is nothing to model.
- While the Vintage team is setting up your organization's first portfolio, admins and editors land on **Uploads**, and viewers land on a page explaining that the portfolio is being set up. See [Your first upload](/uploading/your-first-upload/).

If you have not finished setting up your account (verifying your email, or creating or joining an organization), signing in returns you to the step you still owe. Every one of those steps shows the account you are signed in as and a **Use a different account** link, which signs you out and returns you to the sign-in screen: the way to sign in as someone else, or start a new sign-up with a different email.

## Signing up with an email that already has an account

If you try to create an account with an email that already has one, Vintage does not stop at saying the sign-up failed. It says **An account already exists with this email** and offers **Sign in instead**, which takes you to the sign-in screen with that email already filled in.

## Forgot your password

1. On the sign-in screen, choose **Forgot password?**

2. Enter your email and press **Send reset link**. The confirmation reads the same whether or not that address has an account ("If that address has an account, a reset link is on its way"), so the page never reveals who has an account.

3. Open the email and follow the link. It **expires after one hour**. A link that is invalid or has expired says so and asks you to request a new one.

4. Choose a new password (at least 8 characters), confirm it, and press **Reset password**.

On success, Vintage **signs you in automatically** and takes you into the app. Resetting a password also **ends every existing session** on your account, everywhere you were signed in; the reset then signs you straight back in on the device you used, so you stay in the product.

## How long you stay signed in

A session lasts **60 days** and is **rolling**: any use of Vintage extends it. Someone who signs in and keeps working is never asked to sign in again. Sixty days with no activity ends the session, and your next visit goes to the sign-in screen.

| What happens | Effect on your sessions |
|---|---|
| You use Vintage | This session's 60 days start again. |
| 60 days pass with no use | This session ends. |
| You sign out | This session ends immediately. |
| You reset your password | Every session on the account ends; the reset signs you straight back in on the device you used. |
| You choose **Sign out of all other devices** | Every session except the one you are using ends. |
| You change your password from your profile | Nothing else ends. Use **Sign out of all other devices** if you also want that. |

**Sign out of all other devices** is in **Settings › Profile**, and is the self-service way to end a session left open on a shared or lost computer. See [Profile and security settings](/account/profile-and-security-settings/).

## When a session ends while Vintage is open

If your session ends while you have Vintage open in a tab (it lapsed, or you pressed Back after signing out), the next thing you do **returns you to the sign-in screen**. Vintage never leaves you inside the app with screens that fail, claim your portfolio is empty, or show errors that will not go away.

Vintage remembers where you were. Once you sign back in, it takes you **straight back to that screen** rather than to the usual landing page, unless you still need to verify your email or create an organization first, in which case you land on the usual screen afterwards.

## When Vintage cannot tell whether you are signed in

Occasionally the check that confirms you are signed in fails outright. Vintage retries quietly a couple of times. If it still cannot confirm, it says so plainly, **We couldn't verify your session**, with a **Try again** button. It never reports you as signed out on a failure it could not confirm: you may well still be signed in.

**Note:** Your organization may restrict which networks can reach it. If you sign in from an address that is not on its list, you see a page explaining that your IP address isn't allowed, showing the address you are connecting from. See [Team and organization settings](/account/team-and-organization-settings/#restricting-which-networks-can-reach-your-organization).

## Related

- [Accounts and organizations](/getting-started/accounts-and-organizations/)
- [Profile and security settings](/account/profile-and-security-settings/)
- [Team and organization settings](/account/team-and-organization-settings/)
- [Security and data protection](/reference/security-and-data-protection/)
- [Emails Vintage sends](/reference/emails-vintage-sends/)