Trusted Terminals and Quick-Switch PIN let multiple employees share a counter or bay device in 1sixty8 Manifold without retyping email and password every time. Sign in once with full credentials, mark the device as trusted, then swap between staff with a 4-digit PIN until the daily reset.

What a trusted terminal is

A device (a counter desktop, a bay tablet, the shop laptop) that a manager has explicitly trusted. Trust is stored as a long-lived signed cookie in the browser; the server only sees a SHA-256 hash of the token. A trusted terminal allows the PIN-swap shortcut; an untrusted terminal always requires full credentials.

Designating a trusted terminal

Sign in on the device. Open the user-menu dropdown in the top right and click "Trust this device". (You will only see this option if your role is Owner or Store Manager and you are not already on a trusted terminal.) Give the device a name (e.g. "Front counter Mac" or "Bay 2 tablet") and confirm. The device now appears in the Trusted Terminals table at Settings > Security.

Revoking a trusted terminal

Go to Settings > Security and find the Trusted Terminals card. Click Revoke next to any device that is retired, moved, or compromised. The next request from that browser is forced back to full credentials, and the daily-login history for that device is cleared.

Fast-switch settings (also at Settings > Security)

  • Idle timeout (minutes): 1 to 30, default 5. After this much inactivity, the trusted terminal locks and asks for the active user's PIN to resume.
  • Daily reset time: a clock time (your store's local time) at which every trusted terminal forces a full credentials sign-in. Typical setting is about an hour after closing time so no one is signed in overnight.

Quick-switch PIN

A 4-digit PIN that lets you swap from one signed-in employee to another on a trusted terminal without retyping a password. Each employee sets their own PIN.

Setting or changing your PIN: open Account > Profile and find the Quick-switch PIN card. Type your current password (required to prove it is you), then your new 4-digit PIN twice. Constraints:

  • Exactly 4 digits
  • Cannot be a weak pattern: blocklisted PINs include all-same digits (1111, 2222, etc.), straight sequences (1234, 4321, 9876), and obvious patterns (1212, 0101). The system rejects with "That PIN is too easy to guess."
  • Must be unique across all employees at your store. The system rejects with "That PIN is already used by another employee at this store."

Lockout after 5 wrong attempts

If someone types the wrong PIN 5 times in a row on the mobile app, the device is revoked and the session destroyed. The employee must sign in with full credentials again. On desktop trusted terminals, persistent wrong attempts force a credentials prompt the same way. The lockout event appears in the audit log.

Mobile passkey interaction

If your shop has "Require passkey unlock for all phones" enabled at Settings > Security, PIN unlock is disabled on phones until the user has enrolled a passkey (Face ID, Touch ID, iCloud Keychain, 1Password, or any platform credential). On desktop trusted terminals, PIN unlock continues to work as normal regardless of this setting.