Skip to main content

Get Started With Toast Account & Login Management

Set up individual Toast Web accounts for your staff by creating jobs, building employee profiles, inviting users, and having each person act

Written by Agent Support Bot

Which login topic do you need?

Several account and login terms sound alike but mean different things. Find your situation below, then go to the guide that covers it.

Note: Your password logs you in to Toast Web on a computer or in an app (Toast POS, Toast Now and MyToast). Your POS access code (also called a passcode, PIN, or clock-in number) is the six-to-eight digit code you enter on a Toast POS device. They are different. If you are looking for your Wi-Fi or network password, that is also separate from your login. See Locate Your Toast Wi-Fi Password.

Before you begin

Applies to: Toast Web, Toast Payroll, Toast POS

Permissions needed:

  • 8.X Account Admin or 4.9 Employee Info (to create profiles, invite users, and view or edit POS access codes)

What you'll accomplish: Set up individual Toast Web accounts for the people at your business so each person has their own secure login.

Why individual accounts matter

For the greatest level of security and customization, each person who logs in to Toast Web should have their own account credentials. When individual accounts are set up for each person, you'll have:

  • Flexible permissions, so only necessary individuals get access to sensitive actions.

  • Clear accountability, so actions can be traced back to specific users.

  • Improved security, so if one account is compromised, it doesn't put everyone at risk.

  • Easier, more secure access, so everyone has their own login and security method.

Setting up accounts takes three steps: create jobs, create employee profiles and invite users, and have each user activate their account.

Step 1: Create jobs and set permissions

Create jobs in Toast Web (for example, server, bartender, or manager) and assign the desired permissions for each job. You can assign these jobs to employees in the next step so they receive the right permissions.

Step 2: Create employee profiles and invite users

Create an employee profile for each user, then invite the users who need Toast Web access.

  1. Assign each employee the appropriate job or jobs, which gives them the permissions associated with those jobs. You can override permissions for an individual user if necessary.

  2. Give the user a POS access code if they need to use the POS.

  3. Invite the user to create a Toast Web account if they need back-end access. An email address is required to send the invite.

  4. Assign the employee to multiple locations if necessary.

Note: If your business uses Toast Payroll, add the employee in Toast Payroll first, then invite them to create a Toast Web account. See this section below.

Step 3: Have each user activate their account

Each user you invite receives an email invitation. They need to select the link in that email to activate their account and set their password.

Note: Once a user is invited to create an account, their POS access code will not work until they select the link in their email and accept the invitation.

Expected outcome: Each invited user can log in to Toast Web with their own email address and password, and their POS access code works again once they accept the invitation.

If your business uses Toast Payroll

If your business uses Toast Payroll, add new hires in Toast Payroll instead of Toast Web and assign the employee's primary job. The employee profile information then syncs automatically to Toast Web. For any employees who also need to access Toast Web, you can invite them to create an account.

For step-by-step instructions, see Toast Payroll: New Hire Employees (Employer Guide). Then, see the Create a Toast Web Account section of Log in to Toast: Create an Account for instructions on inviting a Toast Payroll employee to access Toast Web.

Shared account considerations

Each account requires a unique email address. For this reason, some businesses prefer a shared Toast Web account with basic access that multiple people use to log in. If you choose to set up a shared account, limit the permissions assigned to that account.

Accounts with sensitive financial permissions (8.1 Financial Accounts and 8.7 Instant Deposits) are required to enable multi-factor authentication (MFA), which sends an additional code to an individual's device by SMS or an authenticator app.

MFA can make it hard to share a login because the code is set up to send to just one person's phone. For that reason, consider creating individual accounts or limiting the permissions of any shared account.

If you have been using a shared account and want to update your setup, see Separate Your Shared Toast Web Accounts.

Log in to Toast

Once a user activates their account, they can use their email address and password to log in to Toast Web. On a device that supports biometric login, you might see an option to Log in Faster on This Device using your device's fingerprint or face recognition instead of your password. You can select Remind me later or Not on this device to keep using your password.

For instructions on how to log in to any Toast platform, see Log in to a Toast Product or Device.

If you receive an error message or you can't log in, see Log in to Toast: Troubleshoot Login for help with password resets, locked accounts, MFA problems, and POS access code issues.

Manage user accounts and security

It's best practice to periodically review employee access and permissions so only authorized users have access to your business's back-end functions. To make changes to an employee's account, archive an employee, or edit their permissions, see Log in to Toast: Update Your Account, Add and Manage Employees in Toast Web, and Terminate or Archive an Employee in Toast Web or Toast Payroll.

Toast Web has several security features designed to protect your business information.

Multi-factor authentication (MFA)

Multi-factor authentication (sometimes called two-factor authentication or 2FA) adds an extra layer of security by requiring verification beyond your email and password when you log in to Toast. MFA is required for accounts with the 8.1 Financial Accounts or 8.7 Instant Deposits permission. MFA is tied to the account level, so if your account has access to multiple locations and even one of them has the 8.1 or 8.7 permission, MFA is required at every location for that user.

To check your MFA status, select the avatar icon in the top right corner of any page in Toast Web, then select Profile. In the Login and security section, review the Multi-factor authentication setting. If MFA is enabled, you'll see the option to reset your MFA method here. If you don't have the 8.1 or 8.7 permission, you can also disable MFA here.

Note: To reset your MFA method, you complete a password reset, and you will see one delivery option (SMS text or authenticator app). This is expected. If you have lost the phone or device with your authenticator app, you will not be able to log in until MFA is reset. See Log in to Toast: Troubleshoot Login.

Verified phone number

When you access pages in Toast Web with sensitive information, you may be prompted to enter a one-time password sent by SMS to your verified phone number. This is separate from MFA and happens after you log in, not during login.

To check your verified phone number, select the avatar icon in the top right corner of any page in Toast Web, then select Profile. If you have a verified phone number, you'll see it in the Enhanced access section, where you can select Change phone number to update it.

ID verification

In certain circumstances, Toast requires you to verify your identity using an ID verification process before accessing sensitive information in Toast Web.

To check your ID verification status, select the avatar icon in the top right corner of any page in Toast Web, then select Profile. In the Personal information section, you'll see a badge showing your status: Identity verified, Identity verification under review, or Identity verification failed.

To learn more about keeping your account secure, see Protect Your Toast Account From Scammers.

Frequently asked questions

What's the difference between my password and my POS access code?

Your password and your POS access code are different credentials. Your password is what you enter with your email address to log in to Toast Web on a computer or in a Toast app (Toast Now or MyToast). Your POS access code (also called a passcode, PIN, or clock-in number) is the six-to-eight digit code you enter on a Toast POS device to clock in or take orders. For help with either one, see Log in to Toast: Troubleshoot Login.

Also asked as:

    • What is the POS password to log in?

    • How do I find my POS login code?

    • Where do I find my passcode versus my password?

Can each employee have their own Toast login?

Yes, each employee can have their own Toast login. Each account requires a unique email address, and individual accounts give you flexible permissions, clear accountability, and improved security. To set them up, follow the steps in this article or see Log in to Toast: Create an Account.

Also asked as:

    • Can my staff get their own Toast login credentials?

    • How do I create different users on Toast POS?

    • Do all my employees have to use my login?

Why can't a new employee log in yet?

A new employee can't log in until they activate their account from the email invitation. Once you invite a user to create a Toast Web account, they receive an email and must select the link to set their password. Until they accept the invitation, their POS access code will not work either. If they can't find the email, ask them to check their spam and junk folders. For more, see Log in to Toast: Create an Account.

Also asked as:

    • I rehired an employee and they can't log in.

    • My new hire didn't get the invite email.

    • How does an employee activate their Toast account?

How do I reset my password or MFA?

To reset your password, go to your product's login page, enter your email, select Continue, and then select Forgot password? to receive a reset email. To reset your MFA method, you complete a password reset and choose a delivery option. If you didn't receive the reset email, or you lost the device tied to your MFA, see Log in to Toast: Troubleshoot Login.

Also asked as:

    • I never got my password reset email.

    • How do I reset MFA when I changed my phone number?

    • My MFA reset gives an error.

Why does MFA make it hard to share a login?

MFA makes it hard to share a login because the verification code is set up to send to just one person's phone or authenticator app. Accounts with the 8.1 Financial Accounts or 8.7 Instant Deposits permission are required to use MFA, so a shared account with those permissions only works for the one person who receives the code. Consider individual accounts instead. See Separate Your Shared Toast Web Accounts.

Also asked as:

    • Why does my shared account keep asking for a code?

    • Can two people use the same Toast login with MFA?

Related articles

Did this answer your question?