Signing in

Add your Fineract server, sign in with username and password, and understand the session.

Open Bankayo in your browser and you land on the sign-in screen (if you are already signed in, you go straight to the dashboard). On a large screen the Bankayo letter mark sits on the left with a quiet grid behind it; on smaller screens you see the mark and a short tagline at the top, then the sign-in card below. The sign-in screen always links to this page at docs.bankayo.io. The rest of the app uses the ? button for the matching help page.

Your browser never talks to Apache Fineract. Bankayo’s server signs in on your behalf, holds the session, and sets an HTTP-only cookie. Passwords are not stored in the browser.

Bankayo does not include a banking server. You add the Apache Fineract your institution runs; username and password appear only after that server is saved and selected.

Install Bankayo

On Chrome, Edge, or another Chromium browser, Bankayo can be installed as an app. A prompt appears after a few seconds (or choose Install from the account menu after you sign in). Not now hides it for a week.

On iPhone or iPad, tap Share, then Add to Home Screen. Installed Bankayo opens full-screen, without the browser chrome.

The service worker does not keep banking data offline. You still need a network connection, and your session still ends on idle or sign-out.

Add a server

  1. Select Add server on the sign-in card (unless you already have a server selected in this browser). A panel opens on the side.
  2. Choose Address or Application code.
    • Address — give it a name, its address (starting with https://), and its tenant ID. Just the domain is fine — if you leave off the rest of the path, Bankayo fills in the standard Fineract API path. If your deployment already uses a custom path, type the full URL and it is left as you entered it.
    • Application code — paste the code from Register your server (or your confirmation email). Bankayo looks up the address and tenant on its registry. Identity keys for Self Help stay on Bankayo's server; they never land in this browser.
  3. Save it. Username and password then appear, with that server selected.
  4. To use a different saved server later, select Change. The same panel lists every server you have saved, with pencil and trash icons to edit or remove one, and Add server for another. Picking a row closes the panel and gets you ready to sign in with it.

Your saved servers live only in this browser — they are not shared with anyone else, and nobody else’s servers show up for you. Only https:// addresses with a valid, CA-issued certificate are accepted; a self-signed certificate is rejected and you will see a clear message explaining why. Plain http:// is refused.

Already signed in and want a different server? Sign out, then pick another saved server (or add a new one) from the sign-in screen before entering your credentials again.

Register your server

If you don't have an application code yet, open Register your server from the Add server panel (or go to /register-server). Enter contact details, organization name, country, Fineract tenant ID, and API URL. Bankayo stores that record on the registry and returns an application code. Paste the code on the sign-in screen. A registered server can also carry Self Help identity (Keycloak or the customer platform) so staff can create a mobile-app login from a client's Actions menu.

Sign in

  1. Select the server as above.
  2. Enter your username. It is not an email address.
  3. Enter your password. Use the eye button inside the field to check what you have typed.
  4. Press Sign in. If your account requires two-factor authentication, Bankayo asks how to send a verification code (email or text, from the addresses on your user record), then for the code. After that you arrive at the dashboard.

Two-factor authentication

When the banking server has two-factor authentication on, most logins must confirm with a one-time code after the password. Bankayo never stores that code or the resulting token in your browser — both stay on the server.

  1. Sign in with your username and password as usual.
  2. Choose Email or Text message (only the methods Fineract can actually deliver for your login are listed).
  3. Open the message and enter the code. It expires after a few minutes; Send a new code requests another.
  4. Verify completes sign-in.

If the list of methods is empty, your user record has no email (or no staff mobile number for SMS). An administrator must add one on Admin → Users. A role with the BYPASS_TWOFACTOR permission skips this step.

Signing out tells the banking server to drop the two-factor token as well as ending your Bankayo session.

About your session

  • Your session ends automatically after 30 minutes of inactivity, and in any case after 12 hours — you will simply be asked to sign in again. This protects client data if a workstation is left unattended.
  • Use Sign out (top-right account menu) whenever you leave your desk.
  • Closing the browser also ends your access — reopening requires signing in again.

Trouble signing in?

What you seeWhat it meansWhat to do
"Username or password is incorrect."The credentials didn't match.Check for typos (the eye button helps) and try again. Repeated failures? Ask your administrator to reset your password.
A prompt for a verification codeTwo-factor authentication is on for your account.Choose email or text, then enter the code from that message.
"No way to send a code"Your login has no email or SMS target.Ask an administrator to add an email (or a staff mobile number) on your user record.
"That code is incorrect or has expired."The OTP didn't match, or it timed out.Try again, or send a new code.
"Your sign-in timed out."The two-factor step took too long.Enter your username and password again.
"Your password has expired."Your password must be renewed.Contact your administrator for a reset — self-service renewal is coming later.
"The banking service is unreachable right now."Bankayo couldn't reach the core banking system.Wait a moment and retry; if it persists, tell your administrator.
"Add a server before signing in."No Fineract server is selected.Select Add server and enter an https address and tenant ID.
"This server's certificate isn't trusted."The server's certificate is self-signed, expired, or otherwise not CA-validated.Ask whoever runs that server to install a valid certificate — self-signed certificates are never accepted.

Security notes

  • Bankayo never stores your password (or anything derived from it) in your browser.
  • Nobody can retrieve your password — administrators can only reset it.
  • Saved server addresses live only in this browser’s storage. They are a convenience for the next visit, not a Bankayo account.

This walkthrough matches the written guide on this page.

Was this article helpful?

Yes or no only — no name or email.

On this page