CORE I/O runs in your browser and connects to a CORE I/O server on your network. The first time you open the application, connect to the server and sign in with your account. The browser remembers the server address for future sessions.
The sign-in method depends on your account configuration. You can use a local account, an Active Directory account, or single sign-on (SSO).
Connecting to a server
If no server address is stored, the application first checks the machine from which it was loaded on port 8080. If the server responds, its address is saved and the sign-in page opens. Otherwise, the connection card appears.
- In API Server URL, enter the address of the CORE I/O server, for example
https://10.100.10.10:8080. You can omithttps://; the application adds it automatically. Anhttp://address is changed tohttps://because the server accepts secure connections only. - Click Connect. The button reads Connecting... while the server is checked.
- When the server is ready, its address is stored and the sign-in page opens.
If the connection fails, the card displays one of the following messages:
| Message | What it means |
|---|---|
| Base URL cannot be empty / Please enter a valid URL | The field is empty or does not contain a valid address. |
| Server is reachable but not ready yet. Please try again. | The server answered but is still starting. Wait a moment and click Connect again. |
| Connection timed out. Please check the URL and try again. | Nothing answered within five seconds. |
| API endpoint not found. Please verify the URL. | A service responded at this address, but it is not a CORE I/O server. |
| Cannot connect to server. If the server uses a self-signed certificate, open the URL in a new tab and accept the certificate warning, then try again. | The browser refused the connection. If the server uses a self-signed certificate, open its address in a new tab, accept the warning, return to CORE I/O, and connect again. |
Reconnecting after a restart
If the stored server does not respond during a later visit, for example while the server restarts, the application displays Reconnecting to server... with a counter (Attempt 1..., Attempt 2...) and retries every five seconds.
Click Change API URL to enter a different server instead.
Signing in
The sign-in card identifies the server below the logo. It displays the server name followed by its address, for example stewie - 10.39.1.42:8080. Check this information when you work with more than one server.
- Enter your Username and Password.
- Click Sign In or press Enter. The button reads Signing In... while the server checks your credentials.
Both fields are required; an empty field is flagged with Username is required or Password is required.
If authentication fails, the sign-in card displays one of the following messages:
| Message | What it means |
|---|---|
| Invalid username or password | The credentials were rejected. |
| Account locked after too many failed attempts | The account is locked. Ask an administrator to unlock it. |
| All licensed seats are currently in use. | Every concurrent license seat is in use (see Concepts). Try again later or ask an administrator to release a seat. |
| Network error. Please check your connection. | The server could not be reached. |
| Login failed. Please try again. | Another error prevented sign-in. |
Signing in when another session is active
Each account can have one active session. If your account is already signed in on another browser or device, the card displays You already have an active session elsewhere and a Login anyway button. Click Login anyway, or click Sign In again, to take over the session. You are signed in on the current device, and the other session ends with the message You were logged out because your account logged in from another device.
If another device takes over your session, the same message appears on your sign-in page. If an administrator ends your session, the page displays You were logged out by an administrator. A Session Ended notification shows the reason before the redirect.
Active Directory accounts
When the server is connected to Active Directory, the sign-in card displays Active Directory and the domain name below the form. Enter your Active Directory credentials in the Username and Password fields. After sign-in, the avatar in the app bar carries an AD badge. Active Directory manages the name, email address, and password for this account; you cannot change them in CORE I/O (see Profile and Dashboard Management).
Single sign-on (SAML)
When single sign-on is enabled, the card shows an or divider and a Sign in with SSO button.
- Click Sign in with SSO. The browser opens your identity provider.
- Sign in to the identity provider. It returns you to CORE I/O, which briefly displays Completing sign-in... before opening your dashboard.
If sign-in does not complete, the page explains why and offers Back to sign in:
| Message | What it means |
|---|---|
| You were signed in at the identity provider, but your account has no access to this system (no mapped group). | Your identity provider account does not belong to a group that is mapped to a CORE I/O group. |
| Your account could not be created - the username collides with an existing account. Please contact an administrator. | A local account already uses the same username. |
| Sign-in was rejected by the identity provider. | The identity provider refused the sign-in. |
| The sign-in link is invalid or has expired. Please sign in again. | The return link has already been used or is more than one minute old. Start again with Sign in with SSO. |
| You already have an active session elsewhere | As with a local account, Login anyway sends you through the identity provider again and then takes over the session. |
What you see after sign-in
After sign-in, the application opens the dashboard you last used in this browser. If no dashboard is remembered, it opens the first dashboard in your account. A new account without a dashboard automatically receives one named Default. If CORE I/O cannot create the dashboard, the page displays Could not prepare your workspace, the reason, and a Try again button.
The interface consists of the app bar at the top, the sidebar on the left, and the dashboard in the center. App Bar and Navigation describes the first two areas. Dashboards and Widgets explains how to add widgets to a dashboard. See Concepts for an introduction to hosts, flows, and widgets.
When no license seat is available
The license limits the number of simultaneous user sessions. Your session retains its seat while it remains active. If every seat is in use, a blocking overlay appears.
The overlay displays All licensed seats are in use, followed by the server message and Your session is still valid - you'll be reconnected automatically as soon as a seat frees up. The application retries every 30 seconds and immediately when the server reports an available seat. Click Retry now to check immediately; the button reads Retrying... during the check. Click Sign out to return to the sign-in page. CORE I/O retains your session and tokens while the overlay is open, so your work remains available when a seat is released.
Administrators can view and release occupied seats on the License page.
When the connection to the server is lost
While you are signed in, the application checks the server every five seconds. After two consecutive checks fail, a blocking overlay displays Lost Connection to API and counts down to the next attempt (Retrying in 5s...).
The first retry occurs after 5 seconds, the second after 30 seconds, and each subsequent retry after 60 seconds. The overlay displays the attempt number, for example Attempt 2. Click Retry Now to check immediately; the button reads Reconnecting... during the check. When the server responds again, the overlay closes and the current page remains open.
Activating the license
Flows cannot start on a newly installed server until its license is activated. Open System > License in the sidebar, copy the Machine ID, and request a license key for that machine. Paste the key into Activation Code and click Activate. The paste button reads the clipboard. A License activated. notification confirms the activation. Activation failed. means that the key was not accepted. See License for details.