Strong customer authentication (SCA) on mobile
Strong Customer Authentication (SCA) confirms your identity when you log in or approve a sensitive action, such as a payment or wire transfer. To use it, you link your phone to Spendesk once (called enrollment), then approve actions directly from your phone.
For: All Spendesk users on the mobile app.
Before you start
Requirement | Detail |
App version | Latest version of the Spendesk app (iOS or Android) |
Contact info | A valid phone number or a TOTP authenticator app (e.g., Google Authenticator) set up in your account, so you can receive a one-time code |
Plan | SCA applies to all Spendesk plans and all markets — it is not a plan-specific feature |
Roles | Required for every Spendesk user; Account Owners and Admins also need it to approve wire transfers and expense claim reimbursements |
👥 Roles: Every Spendesk user must complete mobile enrollment. Account Owners and Admins additionally need it to confirm payments and wire transfers.
Enroll your device
You're asked to enroll the first time you log in to the Spendesk mobile app. All users are required to complete this step before using the app.
Go to the App Store or Google Play and search for "Spendesk".
Download or update the Spendesk app.
Open the app and log in using SSO, or your email and password.
Open the identity verification email sent to your inbox, if you logged in with email and password.
Select a one-time code delivery method: TOTP authenticator app or SMS.
Enter the 6-digit one-time code you received.
Create a 4-digit PIN.
Enter the PIN again to confirm it.
Wait for enrollment to complete. This can take a few seconds.
Once enrollment is complete, your device is registered as a trusted device and can receive push notifications for actions that require SCA.
🔒 Access: SCA is a legal security requirement, not a paid feature. It applies to all Spendesk customers worldwide.
Confirm actions with SCA
After enrollment, use your phone to confirm sensitive actions, such as validating a wire transfer or approving an online card payment.
Trigger the action from Spendesk on desktop (for example, validate a wire transfer).
Open the push notification on your enrolled phone, or open the Spendesk app directly.
Enter your PIN when prompted.
Confirm or decline the action in the app.
💡 Tip: If you don't receive a push notification, open the Spendesk app manually — the confirmation screen appears automatically once you're logged in.
Troubleshooting
Symptom: Enrollment doesn't complete, or you're stuck on a loading screen during enrollment.
Cause: A temporary sync issue between the app and Spendesk's authentication provider.
Resolution:
Close the Spendesk app completely.
Uninstall and reinstall the app.
Log in again and repeat the enrollment steps.
If the issue persists, contact Spendesk support.
Symptom: You don't receive the one-time code by SMS or TOTP.
Cause: Your phone number or TOTP authenticator may not be correctly set up in your account.
Resolution:
Check that your phone number is correct in your account settings on desktop.
If you use a TOTP authenticator app, confirm it's correctly linked in your account settings.
Wait a few minutes, as SMS delivery can be delayed.
Contact Spendesk support if you still don't receive a code.
Symptom: You're repeatedly redirected to the PIN screen and can't log in, even after entering the correct PIN.
Cause: Your device's enrollment record may be out of sync with Spendesk's authentication provider (this can happen after reinstalling the app or switching devices).
Resolution:
Uninstall and reinstall the Spendesk app.
Log in again to trigger a new enrollment.
If the loop continues, contact Spendesk support — this requires manual intervention on our side.
FAQs
What if I lose my phone?
Block all your cards first, then enroll your new device by logging in to the Spendesk app.
Can I enroll more than one device?
This depends on your current configuration. Contact Spendesk support if you need to enroll an additional device.
