Skip to main content

Access Identity FAQs

Access Identity is a unified login system. It is how you access Paytronix and any other Access Group tools or modules. This article answers common questions about how logging in works, how to complete the migration, and what to do if something goes wrong.

Written by Sharon Quill

This article answers common questions about Access Identity, the single sign-on system now used to log in to Paytronix. Find answers about what it is, how logging in works, how to complete migration, and what to expect along the way.

General questions

What is Access Identity?

Access Identity is a unified single sign-on (SSO) system that replaces the standard Paytronix username-and-password login. It gives you a single set of credentials to access Paytronix and any other Access Group tools or modules you use.

Why are we moving to Access Identity?

It is the foundation for how the Access Group is building and expanding its products going forward. Migrating to it is the first step in a broader integration that will make it easier and more secure for all users to access Paytronix and other Access products. A single login means less friction for you as the platform grows and more tools become available.

What are the benefits of Access Identity?

Access Identity gives you:

  • One set of credentials: Use a single email and password to log in to Paytronix and any other Access Group tools or modules you use instead of managing separate logins.

  • Two-factor authentication: Your IT administrator can enable two-factor authentication (2FA) on your account for an extra layer of security.

  • Centralised user management: Administrators can manage all user accounts, permissions, and password policies from one place.

  • A platform built to grow: As new Paytronix products and modules become available, Access Identity gives you access to them without needing a separate login.

Who does this affect?

Access Identity affects all Paytronix merchant users, including administrators, managers, and anyone who logs in to the Paytronix platform. It applies to both new merchants setting up for the first time and existing merchants migrating.


Logging in

How do I log in after migrating to Access Identity?

You log in the same way as before. Go to pxsweb.com (or launch.pxsweb.com for the SMB portal), and enter your email address. That's it. Access Identity handles the rest in the background.

As a new user, how do I set up my login?

You'll receive an email with instructions on how to set your password and complete your Access Identity account setup. Click Set Password in the email, then follow the on-screen steps. When prompted, select No, Paytronix Loyalty is my first Access product to create your account.

📌 Note: Your first name, last name, and email address are all required to create an Access Identity account. Make sure you enter this information correctly when creating your account.

Can I still log in with my username and password after migration?

No. Once your account is migrated, username-and-password login is disabled. All you need to do is enter your email address and click LOG IN. If you have forgotten your password, click the Forgot Password link on the Access Identity login screen, or contact your administrator.


Migration

What is the migration process?

Migration moves your existing Paytronix account from username-and-password login to Access Identity. Your user administrator can move users over individually or in batches.

How will I know it's time to migrate?

When your administrator triggers migration, you'll see a pop-up the next time you log in to Paytronix. The pop-up explains the migration and gives you the option to start. Click Start Migration to begin.

Is migration mandatory?

Yes. While you may be able to select Do it later to delay the prompt during the optional window (which is set by the administrator), migration is mandatory. Once the deadline passes, you can't defer it.

How do I complete the migration?

  1. Click Start Migration when prompted on login.

  2. Select No, Paytronix Loyalty is my first Access product.

  3. Check your email for an activation code sent from Paytronix.

  4. Enter the activation code sent to your email to complete your account setup.

How will I know if I've been migrated successfully?

Once migration is complete, you will see an Access dropdown in the top navigation bar of the Paytronix platform, which confirms you are logged in via Access Identity.

What if I use the same email address to log in to multiple merchants?

Users have the flexibility to share the same email address across multiple merchants, with a maximum of one user account per merchant. However, if you are currently registered with an invalid email address, you must first update it to a valid email address before proceeding. Once your email address has been verified and updated, each user account across different merchants will need to be migrated to EVO individually using the standard migration process.


Multi-Merchant User Migration

This section is for users who access more than one merchant in Paytronix and are migrating to Access Evo. Which steps apply to you depends on how your access is set up today.

Scenario 1: Separate login per merchant, same email address

This applies if you log in to each merchant separately with its own username, but all of those logins use the same email address.

Steps to Migrate:

  1. For each merchant you access, run the standard Access Identity migration using that merchant's username and password.

  2. Repeat the migration once per merchant. For example, if you log in to three merchants today, you'll go through the process three times.

  3. Once all merchants are migrated, you'll have a single Access Identity. Log in once, then use the organization dropdown next to the Evo button to switch between merchants.

📌 Note:

  • Only one login per merchant can be linked to your shared email in Access Evo. If two separate logins in the same merchant use the same email, only one can migrate.

  • There's no limit to how many merchants can appear in your dropdown — access is based on how many merchant logins you migrate.


Scenario 2: One login giving access to multiple merchants

This applies if you have a single PXS user account that gives you built-in access to several related merchants, rather than a separate login per merchant.

Your current single login won't carry over its multi-merchant access automatically. Instead, you'll create one user per merchant, each tied to your same email address. You'll end up with one Access Identity and a dropdown covering all your merchants.

Steps to migrate:

  1. Make a list of every merchant you currently access through your merchant login. Do not include your home merchant in this list. If you're not sure of the full list, ask your account contact.

  2. For the first merchant on your list, click your user avatar in the bottom left corner of your home page, then click Manage Other Users and then New User.

  3. Enter your email address when prompted. Use the same email for every merchant so all your logins link to one Access Identity. Specify a unique username for the new user.

  4. If you don't have permission to create a new user in this merchant, ask your administrator to create one for you.

  5. You'll receive an email to finish setting up your login. Click Set Password in that email.

  6. If this is the first time you've used your email address with Access Identity, you'll be asked to verify your email address and set a new password in Access Evo.

  7. If you've already set up a password for your email address in Access Evo previously, enter your existing Access Evo password to log in.

  8. Once this one-time process is complete, log in via SSO using your email address and Access Evo password for all future logins.

  9. Repeat steps 2–8 for each remaining merchant on your list, using the same email each time.

  10. When all merchants are migrated, log in to Paytronix via SSO and use the dropdown next to the Evo button to switch between your managed merchants without logging in again.

📌 Note:

  • Your old merchant login will still exist in PXS but won't be used going forward. No need to delete it — just stop using it once your Access Identity is set up.

  • Permissions (roles and page access) need to be set individually for each new merchant user. This takes a little more setup up front but lets you have different access levels per merchant if needed.

  • If you manage a large number of merchants, ask your account contact for the full list before you start so you don't miss any.


Scenario 3: More than one merchant login, same email address

This applies if you have two or more separate PXS logins — each one a merchant login giving you access to a bundle of merchants — and all using the same email address.

Steps to migrate:

  1. List out all of your merchant logins and every merchant each one gives you access to.

  2. Combine the lists into one. Remove any duplicates — if the same merchant appears under more than one merchant login, keep it in the list once only.

  3. Follow steps 2–10 from Scenario 2 above for every merchant in your combined list, using the same email address each time.

📌 Note:

  • Only one PXS user per merchant can be linked to your email in Access Evo. This matters most where two merchants that share a merchant in common.

  • If you're not sure whether this scenario applies to you, check whether you use two different usernames — tied to two different home merchants — that all use the same email address.


Two-factor authentication

What is two-factor authentication?

Two-factor authentication (2FA) is an optional security feature that your IT administrator can enable for your account to add an extra layer of protection.

What happens if 2FA is enabled for my account?

If 2FA is enabled:

  1. You'll be prompted to set up 2FA during your first login.

  2. Follow the on-screen instructions to configure your preferred 2FA method.

  3. Complete the verification process.

  4. Save your backup codes in a secure location.

If you need help with 2FA setup or run into issues, contact your IT administrator. For detailed guidance, refer to the Two-Factor Authentication article.


For user administrators

Where do I manage Access Identity for my team?

In the Paytronix platform, search for and select Access Identity Migration in the left navigation to open the Access Identity Migration Management page, where you can manage and monitor migration for all users in your organization.

How do I migrate my users?

You can migrate users individually or send a bulk invitation to all users at once. From the Access Identity Migration Management page, you can select users and trigger invitation emails. Users receive an email prompting them to complete their Access Identity setup.

Can I track who has completed migration?

Yes. The Access Identity Migration Management page shows the status of each user's migration so you can see who has completed the process and who has not.

What happens when a user clicks Do it later instead of Start Migration?

There is no option to decline migration. Clicking Do it later only defers the prompt for 24 hours; it reappears on the next login. Once the administrator-set forced deadline passes, the Do it later option is removed entirely, and migration becomes mandatory for that login.

What if our organization already uses SSO with Azure AD, Okta, or another provider?

If your organization uses its own identity provider, such as Azure Active Directory (AD), Okta, or Active Directory Federation Services (AD FS), you can set up federation — a connection between your identity provider and Access Identity — so that your users continue to authenticate through your existing provider, which means your users do not need to create separate Access credentials. Access Identity works seamlessly alongside your existing setup.

Contact your Technical Success Manager or Customer Success Manager to get started with federation setup. Initially, the config process will require IT assistance from both the customer and the Access team.

⚠️ Important: Federation requires your identity provider to support OpenID Connect (OIDC) and be publicly accessible via HTTPS. All users must use email addresses on a company-owned domain. Shared domains like gmail.com or outlook.com are not supported.


Troubleshooting

Review a user's migration status

Before troubleshooting a specific issue, check the user's migration status in Access Identity Migration. This gives you a high-level view of where the user is in the migration process and helps you identify the right next step.

  1. In the Search field, type Migration.

  2. Select Access Identity Migration from the results.

  3. Search for the affected user using the Search field within Access Identity Migration.

  4. Review their Access Identity Migration Status.

Once you have confirmed the user's status, continue with the relevant troubleshooting steps below.


Before working through specific troubleshooting questions, run through these checks first. They resolve the most common migration problems and help you narrow down the cause quickly.

  1. Confirm the user completed all migration steps. Ask the user whether they received the migration email, clicked the link, and set a password in Access Identity. Incomplete setup is the most common cause of login failure.

  2. Check the user's email address is valid and consistent. Verify that the email address in Paytronix matches the one the user used to create their Access Identity account exactly, including capitalisation. Any mismatch will prevent login.

  3. Check the user's username does not match their email address. If a user's Paytronix username is in email format (for example, [email protected]) and matches their email address, SSO login will fail. Update the username to something that is not in email format.

  4. Check that Enforce Login Using SSO is enabled. In the user's Paytronix account settings, confirm that Enforce Login Using SSO is turned on. Without this, the user may be attempting to log in through the wrong method.

  5. Check for shared or duplicate email addresses. If more than one user is sharing an email address, or if the same user has accounts across multiple merchants using the same email, each account must have a unique email address before migration can complete successfully.

  6. Check that verification emails are not being blocked. Ask the user to search their inbox and spam folder for emails from [email protected]. If nothing arrives, your IT team may need to allowlist that address.

If the issue persists after working through these steps, continue with the specific troubleshooting questions below.

What should I check when a user does not receive the verification code email during the migration process?

The email verification step is required. Make sure the verification emails, which have a sender of [email protected], are not blocked by your email provider.

⚠️ Important: You may need to work with your IT team or email admin to allowlist the [email protected] address. Email verification is an Evo platform requirement and cannot be made optional.

What should I check when a user is unable to log in after migration?

  • Confirm the user completed all steps in the migration email, including setting a password in Access Identity.

  • Check that Enforce Login Using SSO is enabled on the user's account in Paytronix.

  • Verify the user's email address in Paytronix matches the email address they used to set up their Access Identity account.

  • If the user has used the same email address with more than one merchant, update the user's email address to be different for each merchant they need to access.

  • If more than one person is using the same email address, update each user to use a unique email address.

  • Have the user attempt the SSO login process again. If they are still unable to log in using their Access Identity email and password, have them select the Forgot your password link in the login screen to set a new password

Why can't a user log in with SSO after migration, even though their email address is correct?

If a user's username is identical to their email address, SSO login will fail after migration—even if all other account details are correct.

How to fix this

Update the affected user's username to something different from their email address:

  1. Log in to the Paytronix merchant website.

  2. Enter user in the Search field in the upper left and then select Manage Other Users.

  3. Find the user and change their username to something that doesn't match their email.

  4. Save the changes.

The user should now be able to log in with SSO.

How to identify affected users

Review your user list in Paytronix and look for usernames that match email address format (like [email protected]). Any user whose username looks like an email address will need to be updated.

What should I check if two-factor authentication isn't working?

  • Verify your mobile device's time settings are correct.

  • Check that you're using the correct authenticator app.

  • Contact your IT administrator if you need to reset your 2FA settings.

What should I check if I see an error after logging in with federation?

  • Confirm the redirect URI in your identity provider exactly matches https://identity.us.access-evo.com/auth/oidc/callback.

  • Verify the Authority URL and Client ID are correct.

  • For AD FS, confirm the email claim is configured, and the email scope is permitted.

  • If domain verification failed, allow up to 48 hours for DNS propagation and verify the TXT record is correct.


Additional resources


For additional assistance, please get in touch with your Technical Success Manager or Customer Success Manager, or contact Paytronix Support.

Did this answer your question?