# Help Center

Get answers to all of your questions regarding Brex

**URL Source:** https://www.brex.com/support

---


## Popular Articles

### [How Brex credit limits work](https://www.brex.com/support/brex-credit-limits)

Brex is built to be your financial platform at every stage of growth. Whether you're just getting started, entering the Commercial or Upmarket space, or leading a global Enterprise, our solutions scale with you to manage the increasing complexity of your finances. This approach helps you spend smarter and move faster, with clear insights and high limits available quickly.




## Overview

Brex is built to be your financial platform at every stage of growth. Whether you're just getting started, entering the Commercial or Upmarket space, or leading a global Enterprise, our solutions scale with you to manage the increasing complexity of your finances. This approach helps you spend smarter and move faster, with clear insights and high limits available quickly.

To provide a credit limit that meets your growing needs, our underwriting process adapts to your unique business model and financial characteristics assessing your company based on the metric that best reflects its strength — be it your cash balance or your sales and performance. The information below can help you understand your Brex credit limit.

## What determines your Brex credit limit

The credit limit for your Brex card account is determined based on either cash-based underwriting and/or revenue-based underwriting. In order to unlock higher limits, we recommend providing complete financial information.

We’ll underwrite your account based on one or a combination of the following:

- **Connected bank funds: **Available for accounts making monthly payments.
   - **Bank statements: **Available for accounts making monthly payments (If you can’t connect your bank account).
- **Brex business account funds: **Required for daily payments and available for qualified accounts making monthly payments.
- **Financial statements: **Available for accounts making monthly payments.

### Connected bank funds

Brex uses Plaid or Finicity to **securely** and **seamlessly** connect to your bank accounts so we can view account transactions and balances. Connecting your bank accounts gives us a complete picture of your financial profile, which we use to determine your credit limit. 

The best way to unlock the highest credit limit is to:

1. Securely connect all bank accounts where you hold cash (our system can see your full financial strength)
2. Maintain a strong payment history by paying your balance on time

Account and card admins can update bank connections or add new ones [from your Brex dashboard](https://dashboard.brex.com/?should-connect-bank=true/). Plaid or Finicity support many bank accounts.  
  
**Note**: If you maintain cash at multiple financial institutions that you cannot connect to Brex, providing us with statements for each account helps us give you the highest limit possible. Upload your two most recent monthly statements for additional accounts [through this secure file uploader](https://www.brex.com) or the [Financial documents](https://dashboard.brex.com/settings/financial-documents) page in your Brex dashboard.

### Bank statements

If you run into issues with connecting your bank account, we can provide a solution by accepting bank statements instead of an account connection.

Similar to connected bank underwriting, we use bank statements to access your cash balance to understand your company’s financial health and determine your limit.

We accept statements that meet these criteria:

- Statements must be official bank PDFs; no screenshots or scanned copies will be accepted.
- Two or sometimes three full months of statements are required each time a new account is introduced.

If you’d like to see instructions on how to upload bank statements, please read [this help article](https://www.brex.com).

### Financial statements

We may review financial statements including income statements and balance sheets to evaluate cash flow and growth trends.

These statements give our underwriting team a comprehensive view of your company’s financial position, including liquidity, profitability, and leverage metrics. Based on this data, we can assign a credit limit that reflects your company’s scale and financial strength.

You may submit standard financial documents, including:

- Balance sheets
- Income (profit & loss) statements
- Cash flow statements

For more information on financial statement underwriting, please read[ this help article](https://www.brex.com)

## Limits by account type

Please read the relevant section below, which will outline how your credit limit is determined for your Brex card based on your product type.



To determine limits with our monthly payments product, we consider your current cash balance, cash flow, and overall financial performance. As your cash balance, cash flow, or financial performance changes, your available limit may change accordingly.

By default, payments to settle your statements are due monthly. If you have a Brex business account in addition to a card with monthly payments, you can switch between a monthly payment cycle and a daily payment cycle.

Your autopay account can be any linked bank account, including Brex business accounts.

If your account makes monthly payments, you're eligible to redeem Brex points for a variety of options listed in[ this article.](https://www.brex.com)

For Brex cards with daily payments, limits are based on the aggregate balance of your Brex business account across your primary checking, treasury, and vault accounts.

Payments to settle your statement are due daily. If your account makes daily payments, you’re eligible to redeem your Brex points for a variety of options listed in[ this article.](https://www.brex.com)

Brex previously offered cards with net 60-day payments to certain customers. Grandfathered accounts may maintain their net 60-day statement periods, but otherwise, Brex no longer supports net 60-day payments.

For accounts that have been grandfathered into this product, your Brex card limit is directly related to your estimated revenue reported in your accounts that are connected to Brex. Your limit depends on the balances of connected bank accounts and/or bank/financial statements, as well as any connected ecommerce platforms such as Amazon or Shopify.

## Credit limit increases 

Brex continuously monitors your credit limit to provide the best possible experience. Your credit limit is designed to remain stable and predictable, provided you maintain the following:

- Strong payment history
- Ongoing financial visibility (via connected bank accounts or updated statements)

If your financial profile indicates you qualify for a higher limit, Brex will proactively reach out for an increase. To learn more about requesting limit increases, [please refer to the article here.](https://www.brex.com)

## Disclaimer

_The information you provide is used solely for credit evaluation. Brex treats this data as confidential and complies with rigorous privacy and data handling policies. _Credit limits are calculated in part by Brex’s ongoing account-specific determination of risk. These credit limits are subject to change at any time at our sole discretion in accordance with our rights outlined in the Platform Agreement.


---

### [Two-factor authentication (2FA)](https://www.brex.com/support/two-factor-authentication)

Two-factor authentication (2FA) is an extra layer of security that prevents unauthorized access to your account.

## Overview

Two-factor authentication (2FA) is an extra layer of security that prevents unauthorized access to your account. 2FA is achieved by either setting up SMS authentication or installing a general-purpose authenticator app on your mobile device. 2FA is required for all Brex users.  
  
**We recommend using an authenticator app (see examples below). Authenticator apps provide greater security than SMS, and can be used without a working cell network.   
  
**Brex doesn’t require installation or download of a browser extension to access your account. You should always exercise caution when installing browser extensions.



**Note:** Brex will never call you asking for your 2-Factor Authentication (2FA) code or any one-time passcode.

## How it works

When you sign in to Brex using 2FA, you’ll receive a prompt to provide a verification code in addition to your password. Brex offers two ways to receive a code:

- **[Recommended] **Authenticator app (e.g., Google Authenticator, Twilio Authy, Okta, Duo, 1Password)
- SMS text message

Please read the relevant section below to either set up 2FA for the first time or switch from one method to the other.  
  
**Note:** If you’re using SSO as your preferred sign-in option, you won’t need to complete 2FA during sign-in.

## Setup

**Step 1:** Download an authenticator app.

- Google Authenticator: [iPhone](https://itunes.apple.com/us/app/google-authenticator/id388497605?mt=8/), [Android](https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&hl=en/)
- Twilio Authy: [iPhone](https://apps.apple.com/us/app/twilio-authy/id494168017/), [Android](https://play.google.com/store/apps/details?id=com.authy.authy&hl=en/)
- Okta: [iPhone](https://apps.apple.com/ca/app/okta-verify/id490179405),[ Android](https://play.google.com/store/apps/details?id=com.okta.android.auth&hl=en_US&gl=US)
- Duo Mobile: [iPhone](https://apps.apple.com/us/app/duo-mobile/id422663827https://apps.apple.com/us/app/duo-mobile/id422663827),[ Android](https://play.google.com/store/apps/details?id=com.duosecurity.duomobile&hl=en_US&gl=US&pli=1)

**Step 2:** After downloading your app of choice, ensure that your device's date and time settings are configured to _Automatic_ mode. Authenticator apps generate 2FA codes using the current time on your device, so if the time is set incorrectly, the wrong code will be generated.  
  
**Step 3: **Click your company name at the top left of your dashboard and go to _Personal settings > Security and privacy._  
  
**Step 4: **Under _Personal_, find _Two-factor authentication _and click _Change method_.  
  
**Step 5: **Choose _Authenticator app_ and click _Continue_.  
  
**Step 6: **Open your authenticator app and use it to scan the QR code, then click _Continue_.  
  
**Note: **If you can’t scan the QR code, choose manual entry on your app, and enter the code shown on the screen.  
  
**Step 7:** Enter the six-digit code from your authenticator app and click _Continue _(the code typically expires after 30 seconds).  
  
**Step 8: **Copy or download the recovery codes and save them in a secure place, then click _Continue_.  
  
Once 2FA is enabled, it cannot be disabled.** If you ever lose your phone, you can use your recovery codes to sign in to Brex. Each recovery code can be used once.  
  
**If you do not have access to your recovery codes, you can contact your admin to receive a one-time recovery code via email.

**We strongly recommend using an authenticator app, as this provides greater security and does not require a working cell network to use. However, if you prefer to use SMS messaging, please follow these instructions.  
  
Step 1: **Click your _c_ompany name at the top left of your dashboard and go to _Settings_.  
  
**Step 2: **Under_ Security and privacy_, find _Two-factor authentication_ and click _Change method_.  
  
**Step 3: **Choose _Text Message _and click _Continue_.  
  
**Step 4: **Enter the phone number you want your code sent to and click _Continue_. This phone number will replace any existing phone number on your account and will be used for customer communications and fraud prevention moving forward.  
  
**Step 5: **Enter the six-digit code sent to your phone number and click _Continue_ (the SMS code will typically expire after three minutes).  
  
**Note: **Once 2FA is enabled, it cannot be disabled.  
  
**If you don’t receive your SMS code, your admin can generate a one-time recovery code via email.**

## Reset 2FA

If your 2FA code has stopped coming through, you or your admin can reset your 2FA method

Please contact your Brex admin to reset your 2FA.

If a member of your team is unable to access their account as their phone number has changed, admins have the ability to send a 2FA recovery code by email. To do so, please follow the steps below:  
  
**Step 1:** In your Brex dashboard, go to _Teams.  
  
_**Step 2: **Click on the user who needs to have their 2FA reset.  
  
**Step 3: **Click _User actions _> _Send 2FA recovery code_ > _Send code_.  
  
This will send an email to the address your employee has on file that includes the recovery code and instructions to reset their 2FA settings. This code will only be valid for 2 hours. To complete the 2FA reset and to ensure that their 2FA is reset moving forward, the user will need to follow the setup steps listed above.




---

### [Submitting bank statements for your credit limit](https://www.brex.com/support/bank-statement-underwriting)

Statement underwriting is an alternative way for us to underwrite your account limit if you cannot/choose not to connect your bank account. It involves downloading a statement from your bank and manually uploading it to Brex.

## Overview

Statement underwriting is an alternative way for us to underwrite your account limit if you cannot/choose not to connect your bank account. It involves downloading a statement from your bank and manually uploading it to Brex. We’ll then base your limit off of the account balance reflected in the statement.  
  
We allow accounts to move to statement underwriting on a case-by-case basis, often for scenarios such as these:

- Your bank is not supported by Brex.
- You're having persistent issues connecting your bank to Brex.
- You prefer not to connect your bank to Brex.

You can also move to statement underwriting temporarily If you're having issues connecting your bank.

## Statements we can accept

Before making the switch to statement underwriting, you’ll want to make sure that your bank issues statements in a format that we can accept. In order to be used for underwriting purposes, these statements should be:

- **Complete**: Statements with missing pages will not be accepted.
- **Unaltered**: No redacted info and markups such as highlighting or commenting.
- **In PDF format**: Screenshots, spreadsheets, scanned copies, or activity reports will only be considered in exceptional cases.
- **From business accounts only:** Personal bank accounts will not be accepted.
- **From domestic bank accounts only** and with funds denominated in USD.

Outside of standard bank statements, we also accept these formats:

- Consolidated statements (i.e. one single PDF that contains multiple accounts):
   - These will be accepted as long as each account satisfies our general guidelines.
- Certificates of deposits:
   - These are also accepted as long as their maturity is <1 year old.

## Getting started

If you qualify for a move to statement underwriting, our support team will need to set it up for you. Please reach out with the following documents, depending on your company type:



**Note: **The minimum cash balance requirements and/or monthly sales requirements will also increase with this alternative option.

## Submitting statements

Once you're approved for this alternative, we’ll email your Account and Card admins when we require them to upload statements. Once you receive a notification, you can take action by either tapping the notification directly or going to your dashboard to upload documents.

**Step 1: **Click your name in the top left of the dashboard and select _Statements and documents_

**Step 2:** Select Bank Statements on the left pane > Add documents.

**Step 3: **Click Upload documents to follow the prompts to upload new documents.

Moving forward, you’ll use this same page in your dashboard to upload the most recent month’s statements. Please make sure to upload statements at the requested cadence. Since we base your limit on your company’s cash balance, we cannot maintain your credit limit if we don’t receive the required statements for an extended period of time.

If you’re unable to connect your bank to your Brex account, we may instead ask you to manually submit statements.  
  
You can upload your most recent statements at any time by clicking your name in the top right corner of your dashboard > _Statements and documents. _  
  
**Note: **If this is your first time uploading statements for this bank account, you’ll be asked to upload the 2 most recent bank statements for your bank account(s).  
  
Moving forward, please continue uploading your statements to your dashboard in this location when requested. We’ll also send reminder emails to account or card admins with secure upload links.


---

### [Brex travel car bookings](https://www.brex.com/support/brex-travel-car-bookings)

After enabling Brex travel on your account, all employees with access to travel spend limits will have the ability to book a trip.

## Booking a trip

After enabling Brex travel on your account, all employees with access to travel spend limits will be able to book a trip.

  If provisioned by an account or card admin, employees may also use their employee card limit.  
  
Depending on the settings put in place by your admin, you might be able to use a personal card for bookings and request reimbursement later. Otherwise, the card assigned to your limit will be used as a payment method.  
  
**Note: **Per our Platform Agreement, Brex travel can only be used for business-related travel.  
  
You cannot book Black car service or premium transportation—such as limousines, professional chauffeurs, etc.—using Brex travel.

### Rental cars

**Step 1: **In your Brex dashboard or mobile app, click _Trips_ >  _Add new trip_ (if there is no existing trip) or _Add booking _(if there is an existing trip). Go to the _Cars _tab_..  
  
_**Step 2: **If you want to book for a guest (an individual who isn’t a member of your Brex account), change _Booking for myself _to _Book for a guest _using the dropdown arrow.  
  
**Step 3: **Go to the _Cars _tab and fill in the trip details, such as location and dates.  
  
**Step 4: **Select your limit under the _Book with_ dropdown menu and click _Search.  
  
_**Note:** If there is no travel spend limit listed, click _Request a spend limit_. Once your request is approved, you can use that spend limit to book travel.  
  
**Step 5: **Search by places, cities, and more. Fill in the required fields. Checking the box _Return to the same location_ will make the dropoff location the same as the pickup location.  
  
**Step 6: **Click _Select _on the car you want. Review your booking details including the car’s cancellation policy and loyalty. If you choose to book on behalf of a guest traveler, fill out their information here.  
  
**Note: **The payment method entered at checkout is used only to secure the booking. Actual payment will be taken at the time of pickup. Depending on the settings put in place by your admin, you might be able to use a personal card and request reimbursement later. Otherwise, the card assigned to your limit will be used as a payment method.  
  
**Step 7: **Select _Reserve_** **to confirm your car booking.  
  
Once your car is booked, you can add a flight and/or hotel to your trip by clicking _Add another reservation to the trip.  
  
_**Disclaimer:** _Rental agencies require that the primary driver of the rented vehicle present a physical credit card for payment that matches the driver's name as it appears on their license. Therefore, car rentals cannot be paid with a credit card at the time of booking and drivers should plan to present their credit card, issued in their name, to the rental agency at pickup. Rental agencies will typically place a hold on the card for the cost of the rental, plus any insurance. Contact your rental agency to find out about any additional costs.  
  
If you choose to book a rental car with a personal card, we recommend using a personal credit card instead of a personal debit card. If you book with a debit card, a hold could be placed on your card or it could be denied based on the rules of the rental agency. If you do book with a debit card, please ensure that you review the terms and conditions as well as confirm that the funds linked to your debit card can cover the entire booking._

Brex does not provide rental car insurance. If you pay for a rental with an eligible Brex Mastercard, you may be eligible for Mastercard’s MasterRental Insurance Coverage. This coverage is offered and administered solely by Mastercard, not Brex. For full eligibility requirements, exclusions, and claim instructions, see [Mastercard’s MasterRental Insurance Coverage](https://www.brex.com).

### Rideshares

Brex offers connections with the popular rideshare apps Lyft and Uber within our mobile app. These connections enable you to quickly request rides alongside viewing your trip details.  
  
**Step 1: **In your Brex mobile app, select _Trips_. On your day of travel, find and select your current trip.  
  
**Step 2: **Select either Uber or Lyft for your ride. Once your preferred application is selected, the rideshare app will open, where you can view ride details and request a ride.

## Comparing Prices

To compare prices, you can filter by the car rental company that you would like to compare.  
  
Select the same pickup and drop off time. Wait until checkout, at which point prices will be updated, to compare.

## Viewing booked trip details

You can view upcoming and past trips you’ve booked in your Brex dashboard or app. Outside of your own personal trips, managers can also view trips they manage as a spend limit owner in the dashboard, while account, card, travel admins, and any other users with the [specific product capability](https://www.brex.com) can view all booked trips across your organization.

You can view your upcoming and past travel arrangements in your dashboard under your _Trips _tab. Use the filters at the top of the page to help you find a specific trip. If you’re an account, card, travel admin, spend limit manager, or a user with the [specific product capability](https://www.brex.com), you’ll have additional search options such as trips by user.  
  
When you find the trip you’re looking for, click on it for additional details.  
  
Account, card, travel admins, and any other users with the [specific product capability](https://www.brex.com) can view reports by clicking _Reports _from within the _Travel_ tab, then click _Travel_. This includes information about booked travel spend, and policy compliance.

You can view your travel arrangements in your Brex app by tapping _Trips _at the bottom right of your screen. Tap between _Upcoming, Drafts, Past, _and _All _to view trips in different statuses.

## Travel policy rules and management

Your policy is a set of rules that a manager, account admin, card admin, or travel admin can set for booking travel with Brex.  
  
 Policy admins can set up spending rules_ _that flag travel-related merchant and category expenses (such as car rental) for review if they’re over a certain amount.  
  
 Admins and any other users with the [specific product capability](https://www.brex.com) can customize rules.

### Specify maximum spend

_Specify maximum spend_** **under the car rental policy allows account, card, and travel admins to set the average daily rate, including taxes and fees, that will trigger a review. Maximum spend rules can be configured by toggling the _Specify maximum spend_** **button on.  
  
Example: Car rentals costing more than $100 a day will require the expense to be reviewed.

### Specific vehicle classes

Set the type of car rental that, when booked, will trigger the expense to be reviewed. _Car class _can be used to define a travel policy. Car classes include economy, mini, compact, mid-size, standard, premium, luxury, sport, pickup, and many more. You can also exclude allowed car class rules.  
  
Example: Car rentals in which the car class is not one of "economy," "standard," "mini," "compact,” or "mid-size" will require the expense to be reviewed.

## Manage policy

**Step 1: **Create a policy.  
  
**Step 2: **Under _Add categories_, click _Car rental_ > _Customize_.  
  
**Step 3: **(Optional) Select the _Booking policy enforcement_

- **None: **There will be no users on the booking approval chain.
- **Notification: **Users in the approval chain will be notified of out-of-policy bookings. They will be able to cancel those bookings if needed.
- **Approval: **Users in the approval chain will be asked to review out-of-policy bookings. If not approved, the booking will be automatically canceled after a few hours.

**Step 4:** (Optional) Toggle _specify maximum spend _and enter the dollar amount.  
  
**Step 5: **(Optional) Toggle** **_specify vehicle class_ and choose whether you’d prefer a compact, standard, convertible, economy, full size, luxury, mid size, mini, or minivan.  
  
**Step 6:** (Optional) Toggle _maximum spend limit outside of Brex travel _and enter the dollar amount of expenses equal or above the amount you entered to require review.  
  
**Step 7:** (Optional) Toggle _specify by merchant_ and enter the merchant name in the dropdown. Choose between _Allow_** **or _Review_** **under the smaller dropdown. Under _What about all other merchants?_ select either _Review_** **to require review for all other spending,** **or _Allow _to allow spending with other merchants in this category.  
  
**Step 8:** (Optional) To add a note, enter in your note in under 250 characters or less.  
  
**Step 9: **Click _Update & review_ > _Next_ > _Save_**.**

## Modifying trips

### Change rental cars

If you need to make a change to your rental car reservation, cancel your existing booking and make a new one.   
  
**Note:** Changes can no longer be made through Brex once you have picked up the rental car. If you need to make a change to the reservation after pickup date/time, please contact the rental car provider directly.

## Canceling your trip

**Note**: You cannot transfer your booked arrangements to another person.  
  
Most rental car reservations are not paid until pickup and, unless otherwise stated, can be canceled prior to pickup without penalty within your Brex app or dashboard.  
  
If you need to cancel your rental car booking on or after the pickup date and time, please contact the rental car provider directly.  
  
If you can't cancel your rental car on your own, or if you’d like help from a travel agent, please contact Brex travel support.


---

### [Brex Community](https://www.brex.com/support/brex-community)

Brex Community is a platform where all Brex users can connect in one digital space. It was built to foster customer connections and provide a space for customers to share feedback with Brex. Your engagement will help us identify areas of improvement and ensure that the platform is a valuable resource for customers like you.

## Overview

Brex Community is a platform where all Brex users can connect in one digital space. It was built to foster customer connections and provide a space for customers to share feedback with Brex. Your engagement will help us identify areas of improvement and ensure that the platform is a valuable resource for customers like you.

## Register for Brex Community

Any active user on a Brex account can join the Brex Community by following these steps:  
  
**Step 1:** Go to [Brex Community](https://community.brex.com/register) and click _Register_ in the top right.  
  
**Step 2: **Fill out the registration form using the email address associated with your Brex account.  
  
**Step 3: **Once you complete the registration form, your community profile will be confirmed within one business day.

## Using community support

Our [support forum](https://community.brex.com/category/support/discussions/support-forum) is a great place to find tips for using Brex, and our [community](http://community.brex.com) can be a helpful resource for answering questions.  
  
**Note: **When participating in the Brex Community, please remember to communicate kindly and respectfully.

## Community discussions

The Brex Community discussion forum is a space where you can connect with other Brex customers. By participating in the community, you can seek answers to your questions or offer up your own experiences, insights, and solutions. If you want to go a step further, consider joining [Brex Blazers](https://www.brex.com), our customer advocate program.

## Posting

### Creating a new post

Before you post, you can use the search feature to see if your question has already been asked and answered. If you do find an existing post about your question, feel free to share your own experience to help other community members.  
  
If you can’t find any existing threads about your topic, you can create a new post by following these steps:  
  
**Step 1: **Draft a clear and concise title that summarizes your issue or question.  
  
**Step 2: **Provide detailed information in the body of your post. Include relevant context, steps you've taken, and any error messages.  
  
**Step 3: **Use [our recommended formatting](https://community.brex.com/kb/using-the-community/contributing-to-the-community/4) to enhance readability. Bullet points, numbered lists, and code formatting can be helpful.  
  
**Step 4: **Respond promptly to any follow-up questions or requests for clarification from other users or moderators

### Using @ mentions

The community supports two types of @mention capabilities — **user mentions** and **content mentions** — that let you tag other community members and community content within a post.

You can use a content mention to link specific posts within the body of a message. This lets you embed a link to other community content quickly.  
  
**Step 1: **Type the @ symbol and any keywords in the subject or body of the message you want to link to. You can enter multiple words, so long as all words are in the subject and/or body.  
  
**Step 2: **As you type, search results appear in the pop-up. Click on the entry you want to tag.

![HC - Brex Community 01](https://brand.brex.com/transform/8dce8f29-cc7a-4f87-9207-821b3816ebb0/HC-Brex-Community-01)

**Step 3:** When you select an item in the list, the post’s subject is highlighted with a hyperlink in the body of your message.  
  
**Note: **When content is mentioned in posts, authors are sent email notifications.

User mentions let you call out specific users in your post and invite them to join the conversation. Here is how to @mention a user within a post:  
  
**Step 1: **After you click _Reply_, type the “@” symbol followed by their username.  
  
For example, to mention the admin, type “@admin.”  
  
**Step 2: **A pop-up menu appears with matching names as you type. You can continue typing the name or select a name from the list.  
  
**Step 3: **If successfully entered, the mentioned username will be written in blue text.

![HC - Brex Community 02](https://brand.brex.com/transform/edc3a65e-b0f8-403d-b917-4f6898b8be4c/HC-Brex-Community-02)

**Note: **When users are mentioned in posts, they receive an email notification.

### Tags and labels

Be sure to tag your post with relevant labels. This helps others locate your post and ensures it's seen by those who can help.  
  
If you can’t find a relevant tag, you can use the [suggestion box](https://community.brex.com/category/suggest/ideas/suggestion-box) to let us know and we may be able to make it available in the future.

### Monitoring replies and notifications

By [enabling notifications](https://community.brex.com/kb/using-the-community/follows--notifications/6), you’ll receive updates when someone replies to your posts or relevant discussions.  
  
To make sure you don’t miss anything, you’ll want to regularly check your inbox for private messages or updates on your threads.

### Closing the loop

Once your issue is resolved, it’s helpful to update your post and include the resolution in case others have similar issues.  
  
If any community members tried to help, we encourage you to acknowledge them. A positive community encourages collaboration!

### Reporting issues and feedback

You can report any issues with the support forum either from within the forum or by sending the community moderator a message. If you have suggestions for improvement, let us know in the [suggestion box](https://community.brex.com/category/suggest/ideas/suggestion-box). Constructive feedback helps the community platform evolve and meet everyone’s needs.

## Making suggestions

We strongly encourage you to use the Brex Community [suggestion box](https://community.brex.com/category/suggest/ideas/suggestion-box) to submit your ideas, feedback, and suggestions for improving our products, features, and community. Your input is invaluable!  
  
When submitting your suggestion, please use the same guidelines as you would when posting in the Brex community. This includes checking to see if a similar suggestion already exists and tagging your suggestion with relevant labels. Please be specific about your idea and why it will enhance the product experience.  
  
You can also read suggestions from other community members and provide constructive feedback. If you find an idea interesting, you can express this using the voting feature.


---

### [Signing into Brex](https://www.brex.com/support/signing-into-brex)

Depending on what works best for your team, you have several options that they can use to access their Brex account from either the dashboard or mobile app.

## Overview

Depending on what works best for your team, you have several options that they can use to access their Brex account from either the dashboard or mobile app.

## Brex email and password

When signing into either your Brex dashboard on the web or the Brex app on mobile, you have the option to manually enter the email address and password associated with your Brex account.  
  
All Brex users are required to use multi-factor authentication to provide an added layer of security to their account, and this method would require two-factor authentication (2FA) and/or device verification.  
  
We strongly recommend against sharing passwords or MFA devices between Brex accounts. If you need to allow multiple users to share a single Brex account, you can use delegated access features such as[ Pro Access](https://www.brex.com) and [copilot](https://www.brex.com)

## Signing in with Passkeys 

A passkey is a secure credential that replaces your password. Instead of relying on a remembered password, which can be guessed or stolen, you can confirm your identity with the same method you use to unlock your device, such as Face ID, Touch ID a device PIN, or a security key. Passkeys resist credential phishing and can't be reused across sites, which makes them more secure than passwords in most common attack scenarios, though overall account security still depends on how well the device and account recovery process are protected. For eligible users, a passkey can replace both your password and multi-factor authentication (MFA) at sign-in.

**Note:** If your account uses Single Sign-On (SSO), you must continue to authenticate through your identity provider. This feature will be unavailable.

### Setting up a passkey

**Step 1:** In the Brex dashboard, navigate to _Personal settings, then the Security and privacy tab_.

**Step 2:** Select _Create passkey._

**Step 3:** Follow your browser or password manager's prompts to create the passkey, then confirm it on your device using Face ID, Touch ID, fingerprint, device PIN, or a security key.

**Step 4:** Your passkey will be saved to your device or password manager and is ready to use the next time you sign in.

**Note: **Creating a passkey may open a pop-up window to confirm your identity. Make sure pop-ups are allowed for the Brex dashboard, or passkey creation may fail.

### Signing in with a passkey

**Step 1:** Go to the Brex sign-in page.

**Step 2:** Choose the _Sign in with a passkey _option.

**Note:** In beta, this option appears beneath the email sign-in button, near the password option.

**Step 3:** Select your saved passkey if prompted by your browser or password manager.

**Step 4:** Verify using your device security. Once verified, you're signed in.

### Browser and device support

Passkeys work with most current browsers and devices, including recent versions of Chrome, Safari, Edge, and Firefox on desktop and mobile. For the smoothest experience, keep your browser and operating system up to date. If your device or browser doesn't support passkeys, you can still sign in with your password and two-factor authentication.

## Enterprise IdP login

The Enterprise IdP login gives your employees the option to sign into their Brex account using Google or Microsoft logins.

- This will make it easier for your employees to access the Brex dashboard and reduce the number of passwords they need to remember.
- You can leverage the advantages of single sign-on (SSO) without having your own dedicated IdP.

**Note: **The email associated with the Google or Microsoft account must match the email associated with the Brex account.  
  
Any account admin or card admin on your account can enable this feature in their dashboard:  
  
Click your name in the top left corner and go to _Company settings_ > _Company_. Toggle on _Enable logins with Google and Microsoft_.

![HC - Sign In Options 02](https://brand.brex.com/transform/71910928-d2a6-4c88-918d-9374329ee708/HC-Sign-In-Options-02)

Once turned on, your employees will be able to _Sign in with Google_ or_ Sign in with Microsoft_ on the Brex sign-in page.  
  
Prior to an account admin or card admin enabling these features, clicking either button will result in an error message.

![HC - Sign In 01](https://brand.brex.com/transform/6cb27a24-45e9-46eb-b5de-0e010fcde219/HC-Sign-In-01)

## Single Sign-On (SSO)



Brex allows your team to utilize an SSO with your Identity Provider (IdP) by leveraging OpenID Connect (OIDC) or Security Assertion Markup Language (SAML). Brex’s SSO integration provides a secure and seamless way to sign in with your own IdPs and also eliminates the need for employees to enter credentials to prove their identities repeatedly. After the initial setup effort, SSO gives you more control to easily turn off employee access and better speed and efficiency with Brex.  
  
Users who are configured to sign in with SSO will not be prompted for MFA by Brex. Disabling SSO for these users will re-enable the MFA requirement automatically. Enterprise IDP sign-in and SSO cannot be configured at the same time.

**Step 1:** As an account admin or card admin, navigate to the _Security _tab of your dashboard.  
  
**Step 2: **Click on Authentication > Setup Single Sign-On.  
  
**Step 3: **Select your integration provider. Your Identity Provider (IdP) (such as Okta, OneLogin, Google Workspace, etc) must support SSO via OIDC or SAML protocols.  
  
**Step 4: **Choose your integration type (OIDC or SAML).  
  
**For OIDC configurations you’ll need:**

- The Client ID and Client Secret from your OIDC application.
- The issuer URL value from your OIDC application. This must be where the /.well-known/openid-configuration endpoint is hosted.

**For SAML configurations you’ll need:**

- Your SAML Identity Provider Single Sign-On URL.
- Your SAML Identity Provider Issuer URL.
- The X.509 Signing Certificate for your application.

Click _Save configuration _to complete setup. To configure your routing mode and add users to the connection, please follow the steps below.

**Step 1:** Once you’ve set up SSO, navigate to the _Security _tab of your dashboard.  
  
**Step 2: **Click on _Authentication_. A details pane will open up.  
  
**Step 3:** Select your routing mode. Here, you can decide whether you want either:

1. Individual users to sign in via your provider.
   1. If you’ve selected this option, you can add or remove users here.
   2. You can use this option to route individual users to SSO. 
2. All users to sign in via your provider.
   1. If you’ve selected this option, you can add users as exceptions and route them through password entry instead.
   2. You can select this option to enable SSO for all users.

To change the routing mode, you’ll first need to ensure the integration is disabled. You can click the disable toggle.  
  
**Note: **If you click disconnect on your integration, you’ll need to set it up again from scratch.

To enable the SSO integration, use the toggle in the _Authentication_ details pane. Users will not be routed to SSO regardless of your routing mode while _Integration status _is _Disabled._

![HC - Sign into Brex 01](https://brand.brex.com/transform/e0930020-469f-4b35-b468-35beee4ffb06/HC-Sign-into-Brex-01)

### 

You can choose to specifically include users in your new SSO integration. This is helpful for testing whether sign-in works as expected on a subset of your Brex users while in the_ Individual users are sent to your provider’s Sign In_ routing mode

This same flow can be used from _All users are sent to your provider’s Sign In _routing mode to exclude users from SSO. These users will use password authentication with MFA.

**Note:** You must toggle the _Integration status_ to _Enabled_ when you’re ready to route users to your configured SSO integration.

1. Navigate to the Security tab
2. Click _Authentication _and add users to the list at the bottom of the SSO settings menu.

### Security Assertion Markup Language 2.0 (SAML) SSO

- **Assertion Consumer Service URL (ACS URL)**: This is the custom URL generated by Brex where users will be redirected and present their SAML assertion.
   - This is sometimes referred to as the “Single sign-on URL” or “SSO URL”.
   - This value can also be used for the “Recipient” and “Destination” URL in a SAML application.
- **Audience**: This identifies the SAML Service Provider managed by Brex and will be included in SAML assertions.
   - This is sometimes referred to as the “Entity ID” or “SP Entity ID”.

- **Identity provider URL**: The URL that Brex will redirect SSO users to when authenticating with SSO.
   - Also known as “Identity Provider Single sign-on URL”.
- **Destination URL**: Used during the SAML process exchange to identify the intended recipient.
   - By default, we’ll make this identical to the Identity provider URL.
- **Identity provider issuer:** The URL that we’ll expect to see SAML assertions issued from.
- **SAML signing certificate: **Provide the X.509 certificate used by your application to sign SAML messages, this is typically in .pem, .cer, or .cert format.

We require that SAML assertions contain an Attribute Statement with the name email containing the email address of the Brex user’s account. This is configured in your SAML Identity Provider.  
  
Here is an example of a valid email attribute statement:

![HC - Signing into Brex 03](https://brand.brex.com/transform/0cb7026e-a5c0-40d3-895d-5fa692bfadef/HC-Signing-into-Brex-03)

Please ensure that you have the mappings configured according to the example image below: 

![HC - Signing into Brex #8 ](https://brand.brex.com/transform/37898bec-c9cd-4a17-8bcd-c45bdd55c4f8/HC-Signing-into-Brex-8)

Please note that if you are using the Brex app from Okta’s App Catalog, the email attribute will automatically be mapped to user.email. If a different field in Okta maps to the email address of your Brex users’ accounts, you will need to create a custom app instead.

- You must use SHA-256 as the signing algorithm for SAML assertions and responses in your SAML application.
- Ensure that your IDPs clock is accurate.
- For Microsoft ADFS, map “E-Mail-Addresses” to “Name ID” in your LDAP properties, in addition to mapping “E-Mail-Addresses” to “email.”

### OpenID Connect (OIDC) SSO

**Step 1:** Sign in as an account admin or card admin to your IdP console.  
  
**Step 2: **Follow your IdP guidelines to create a Web OIDC application or client.  
  
**Step 3:** Enter this redirect URL: [https://accounts-api.brex.com/oauth2/v1/authorize/callback](https://accounts-api.brex.com/oauth2/v1/authorize/callback). The client must support the authorization_code grant type and expose a well-formatted OIDC discovery document at the standard path _{{issuer}}/.well-known/openid-configuration_.  
  
**Step 4:** Configure the integration in Brex with your application details.

**Step 1: **Sign in to your Okta admin console.  
  
**Step 2: **Create an Application Integration under Applications > Applications. Under Sign-in Method, choose OIDC - OpenID Connect. Under Application Type, choose Web Application. Click Next.  
  
**Step 3: **Name the application integration “Brex” or “Brex Web App” so users can identify it from the app launcher. You can also add the [Brex logo](https://signature-logos.s3-us-west-2.amazonaws.com/Lockup_Logo_Black.png).  
  
**Step 4:** Use https://accounts-api.brex.com/oauth2/v1/authorize/callback as the sign-in redirect URL and your Brex dashboard link (http://dashboard.brex.com/) as the sign-out redirect URL. Add implicit for grant type and leave other optional fields as they are.  
  
**Step 5:** For controlled access, choose either Allow everyone in your organization to access or Limit access to selected groups for a gradual rollout. Click _Save_.  
  
**Step 6: **Edit the app from General settings and change Login initiated by to either Okta or App.  
  
**Step 7: **Check Display application icon to users and Display application icon in the Okta Mobile app. Input your Dashboard link (https://dashboard.brex.com) as the initial sign-in URL.  
  
**Optional: **After the application is created, you can also configure a specific sign-in policy for this application under the Sign-on tab.

**Step 1:** Sign in to your Okta admin console.  
  
**Step 2:** Go to _Applications_ > _Applications_, and browse the app catalog. Search “Brex” and add integration.  
  
**Step 3: **Finish up the _General Settings_ according to your needs and click _Next_.**  
  
Step 4: **Choose OpenID Connect as your sign on methods and select _Email_ as the _Application username_ format. Click _Done_.  
  
**Step 5: **Click Sign On tab and copy the Client ID, Client secret, and OpenID Provider Metadata’s URL into a text file. We’ll send you an email link to collect it.  
  
**Step 6: **We’ll complete the SSO registration and enable both IdP-initiated flow and SP-initiated flow for you. Visit [https://dashboard.brex.com/?iss=[oktaIssuer](https://dashboard.brex.com/?iss=%5boktaIssuer/)] to enter the SP-initiated flow. Please replace [oktaIssuer] with the issuer URL you can find in your OpenID provider metadata.

We currently do not support OIDC with Microsoft Entra ID. Please use SAML for SSO with Microsoft Entra ID.

## Troubleshooting your SSO connection

If your integration is not working as expected, please follow these steps:

- Confirm that the configuration on both sides of the connection have been set up correctly, as per the relevant SSO guides, or navigate to_ Security > Audit trail_ and check for SSO authentication errors
- Check the status to ensure it is enabled. If disabled, please click the _enable and disable_ toggle to enable it again.

If you cannot sign in even though your SSO integration is enabled, please reach out to Brex support.

![HC - Signing into Brex 04](https://brand.brex.com/m/3ff1a3c82f674dcf/webimage-HC-Signing-into-Brex-04.jpg)

This is often coupled with the error “SAML assertion email attribute cannot be mapped to Brex user.” To resolve this issue check that your SAML assertion contains an email attribute.

If using Microsoft Entra, please ensure your attributes and claims match the example shown below:

![Entra image](https://brand.brex.com/transform/af18da48-ee9e-411f-9028-50f7d2646db3/Entra-image)

You may see the below error in the SSO wizard. This is most often because Brex cannot resolve your IDPs OIDC metadata from the constructed URL _{{issuer}}/.well-known/openid-configuration_. Please confirm that a well-formed JSON document adhering to the OIDC discovery specification exists at this path.  
  
You can find the specification requirements here: https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata

![HC - Sign into Brex](https://brand.brex.com/transform/31ad7010-a26a-4294-b84f-9a17560174be/HC-Sign-into-Brex)
