Quick answer
Sign in at go.actionstep.com (this is the same door for every region — there's no personal subdomain to hunt for). If your password fails, use Forgotten password to reset it yourself. If two-factor is the problem, check your authenticator app's clock and code; if you've lost the device, an Actionstep admin at your firm can reset your MFA. If nothing loads at all, check status.actionstep.com for an outage.
WHY IT HAPPENS
It's nearly always the password, the code, or the URL.
Actionstep sign-in trouble usually comes down to one of a few things: an expired or mistyped password; a two-factor code that's rejected because the authenticator app or an old QR link is out of step; the wrong login URL saved as a bookmark; or a browser auto-filling old saved credentials. Genuine outages are rare but easy to rule out. Note one important admin detail: administrators can manage two-factor authentication, but they cannot reset another user's password — each person resets their own.
THE FIX
Work through these in order.
- Use the correct login URLStaff sign in at go.actionstep.com — the same address regardless of whether your firm's data sits in the Australia region. There's no "yourfirm.actionstep.com" staff login to find. (Clients use a separate portal at login.actionstep.com.) If you've bookmarked an old or staging address, replace it with go.actionstep.com.
- Reset your password yourselfOn the sign-in page, click Forgotten password and follow the email that arrives at your registered address. Because admins can't reset passwords for you, this self-service reset is the correct path — check your junk folder if the email doesn't appear quickly.
- Rule out cached logins and the browserIf your details are right but sign-in still fails, your browser may be auto-filling outdated saved credentials. Try a different browser or a private/incognito window, or clear the saved password and cookies for actionstep.com, then sign in fresh.
- Fix the two-factor codeIf your six-digit code is rejected, open your authenticator app and enter the current code before it rolls over. Codes fail most often when the phone's clock has drifted — enable automatic date and time on the device, or use the app's built-in time-sync option, then try again.
- Recover a lost or changed authenticatorChanged phones or lost the device? Ask an Actionstep administrator at your firm to reset or disable your MFA so you can sign in and re-register the authenticator on your new device. If you're the only admin, or none is available, contact Actionstep Support directly.
- Handle an account lockoutRepeated failures usually trace back to the two-factor step rather than the password — check the authenticator first. If you're genuinely locked out and self-service doesn't clear it, an admin reset or Actionstep Support is the way back in.
- Check Actionstep's status pageIf the site won't load for anyone, check status.actionstep.com and watch the "New Zealand, Australia, and South Pacific" component. If it's not showing "operational", the issue is on Actionstep's side — wait and monitor rather than troubleshooting each login.
Don't switch off two-factor to "make it easier". In Australia and New Zealand, Actionstep won't let you disable MFA, and if your system is linked to Xero or has accounting configured, every user without it is prompted to set it up at each sign-in. That's deliberate — MFA is one of the strongest protections your firm has against account takeover, so set it up properly rather than working around it.