Most failed Cal.com logins aren't password problems. They're wrong-door problems: you're on the US instance when your team lives on Cal.eu, you're typing a password into an account that was created with Google, or you're on the public site when your company runs its own install. Check those three things first and you'll skip most password resets.
This guide lists the official sign-in addresses, explains the four sign-in methods, and walks through the error messages Cal.com's own interface and help pages describe, in the order that rules out causes fastest. We checked every login-screen detail below directly on the sign-in pages on 2026-09-21.
Key Takeaways
- There's more than one Cal.com login. The hosted product signs in at app.cal.com, the EU-hosted edition at app.cal.eu, and self-hosted installs use their own domain. An account only exists where it was created.
- Your sign-in method has to match how the account was made. Accounts created with Google or Microsoft won't open with an email and password. Cal.com tells you so with a message naming the right provider.
- Ten failed attempts lock the account. Wrong passwords, wrong two-factor codes and wrong backup codes all count. Cal.com's help article describes unlocking by an organization admin, with no self-service option.
- Self-hosted installs need updates you run yourself. Two critical sign-in vulnerabilities were fixed in late 2025 and early 2026. Hosted Cal.com was patched by the vendor; your own install is only safe once you update it.
The Official Cal.com Login Addresses
Cal.com runs two separate hosted environments. Alongside the main product there's Cal.eu, which Cal.com describes as an edition for organizations that need European data residency, with data stored and processed inside the EU. The two look identical but don't share accounts. If your team set up its organization on Cal.eu, app.cal.com won't find you.
| Where you sign in | Address | Who it's for |
|---|---|---|
Cal.com (hosted) | app.cal.com/auth/login | Standard accounts created on cal.com |
Where you sign inCal.com (hosted) Addressapp.cal.com/auth/login Who it's forStandard accounts created on cal.com | ||
Cal.eu (hosted, EU) | app.cal.eu/auth/login | Organizations registered on Cal.eu |
Where you sign inCal.eu (hosted, EU) Addressapp.cal.eu/auth/login Who it's forOrganizations registered on Cal.eu | ||
Short link | cal.com/login | Opens the same sign-in screen as app.cal.com |
Where you sign inShort link Addresscal.com/login Who it's forOpens the same sign-in screen as app.cal.com | ||
Self-hosted | your company's domain + /auth/login | Teams running their own install |
Where you sign inSelf-hosted Addressyour company's domain + /auth/login Who it's forTeams running their own install | ||
Not sure which one holds your account? Open an old booking confirmation or look at your own booking link. The domain in it tells you the environment. We've covered how Cal.eu differs from the main product, and what else is available in Europe, in our piece on the Cal.eu alternative.
One safety note before anything else: only enter your credentials on these domains. A page at a different address that shows a Cal.com-style form isn't Cal.com, no matter how convincing it looks.
The Four Sign-in Methods on the Login Screen
The English sign-in page greets you with a short welcome-back line and offers four ways in:
- A Google button for accounts created with a Google identity.
- A Microsoft button for accounts tied to a Microsoft or Outlook identity.
- Email and password, with a Forgot password link next to the password field.
- Sign in with SAML/OIDC for organizations whose admin has set up single sign-on.
The fourth option is the easiest to miss and the most common source of confusion inside companies. An admin configures SAML or OIDC at the organization level, and after that only users assigned to the Cal.com app in the identity provider can get in that way. If you have a company account but IT never assigned you the app in Okta or Entra ID, you'll fail even though your email and account are correct. That's a ticket for IT, not a password reset.
Cal.com Login Not Working? Five Steps in Order
The order matters. Each step removes one cause before you spend time on the next, more involved one. A password reset is step three, not step one, because every wrong password you type counts toward the lockout limit.
| If you see... | Jump to |
|---|---|
Email or password is incorrect | Step 1, then Step 3 |
If you see...Email or password is incorrect Jump toStep 1, then Step 3 | |
A message naming Google, Microsoft or another provider | Step 2 |
If you see...A message naming Google, Microsoft or another provider Jump toStep 2 | |
Two-factor code is incorrect | Step 4 |
If you see...Two-factor code is incorrect Jump toStep 4 | |
Correct details still rejected after many tries | Step 5 |
If you see...Correct details still rejected after many tries Jump toStep 5 | |
Step 1: Check the instance and domain
Look at the address bar. If it says app.cal.com and your team registered on Cal.eu, the login form simply reports that the email or password is incorrect. It doesn't tell you the account lives somewhere else. The same happens when your company runs its own install and you land on the public site, often through a bookmark saved during a trial.
Teams that built Cal.com into their own apps hit the same wall at API level: keys and endpoints belong to one instance. Our guide to the Cal.com API covers that side.
Step 2: Use the method you signed up with
Cal.com has a dedicated message for this: your account is managed by a different identity provider, so try logging in with the provider it names. If you see it, the password isn't the problem. Click the Google, Microsoft or SAML button instead.
The related settings screen goes further: for accounts managed by an identity provider, email, password and two-factor settings are changed in that provider's account, not in Cal.com.
Step 3: Reset the password
Click Forgot password, enter the address tied to the account, and Cal.com sends a reset link. The confirmation screen is deliberately vague: it says you'll get an email if that address exists in its system. So no email can also mean you typed an address Cal.com doesn't know.
Three places this step gets stuck:
- No email arrives. Check spam and your company's mail quarantine. In Microsoft 365 setups, system mail from outside services often lands in a quarantine only IT can see.
- The account was created with Google or Microsoft. A reset won't help because there's no Cal.com password to reset. Back to Step 2.
- The new password is rejected. The sign-up form's hints ask for at least 12 characters, at least one number, and a mix of upper and lower case. Admin accounts need at least 15 characters.
Step 4: Two-factor codes and backup codes
With two-factor authentication on, Cal.com asks for a six-digit code from your authenticator app after the password. If it says the two-factor code is incorrect, check your phone's clock first. These codes are time-based, so a manually set or drifting device clock produces codes the server won't accept. Switch the phone to automatic time and try again.
Lost the phone? Use one of the backup codes shown when you set up 2FA. Cal.com's interface states that each one works exactly once. If you never saved them, you'll need an organization admin or Cal.com support to get back in.
Worth knowing: Cal.com only allows its built-in two-factor authentication on email-and-password accounts. If you sign in with Google or Microsoft, your second factor lives in that account.
Step 5: Rule out a lockout, then check status
Cal.com's help article on account lockout (checked 2026-09-21) says an account locks after 10 consecutive failed attempts. Wrong passwords, wrong two-factor codes and wrong backup codes all count. Unlocking is done by an organization admin from the admin area, which resets the failed-attempt counter. The help article describes no self-service unlock and asks locked-out users to contact an admin rather than open a new account. Cal.com's Trust Center separately lists a lockout control of at least 30 minutes or until identity is confirmed; if you're a solo user without an organization, support is the route.
Only after all that is it worth opening status.cal.com. When we checked on 2026-09-21, it reported all systems operational.
What the error messages mean
| Message on the login screen | Likely cause | What helps |
|---|---|---|
Email or password is incorrect | Wrong instance, typo or wrong password | Check the domain, then reset the password |
Message on the login screenEmail or password is incorrect Likely causeWrong instance, typo or wrong password What helpsCheck the domain, then reset the password | ||
Account managed by a different identity provider | Account created with Google, Microsoft or SAML | Use the provider button it names |
Message on the login screenAccount managed by a different identity provider Likely causeAccount created with Google, Microsoft or SAML What helpsUse the provider button it names | ||
Two-factor code is incorrect | Device clock drift or wrong authenticator entry | Set time to automatic, use a backup code |
Message on the login screenTwo-factor code is incorrect Likely causeDevice clock drift or wrong authenticator entry What helpsSet time to automatic, use a backup code | ||
An error occurred when logging you in | Interrupted redirect, often during SSO | Go back to the login screen, try a clean browser profile, check your IdP assignment |
Message on the login screenAn error occurred when logging you in Likely causeInterrupted redirect, often during SSO What helpsGo back to the login screen, try a clean browser profile, check your IdP assignment | ||
Correct details keep failing | Lockout after 10 failed attempts | Contact your organization admin or support |
Message on the login screenCorrect details keep failing Likely causeLockout after 10 failed attempts What helpsContact your organization admin or support | ||
Special Case: Self-Hosted Installs
If your company runs its own install, 2026 changed the ground under you. On 15 April 2026 Cal.com moved its production code out of the public repository. The public codebase is now Cal.diy, an MIT-licensed community edition that the project describes as intended for personal, non-production use (checked 2026-09-21). If an older Cal.com install is still running somewhere in your company, find out who's updating it.
That matters for sign-in in particular. Two critical vulnerabilities hit exactly this part of the product:
| ID | Published | Affected | Fixed in |
|---|---|---|---|
CVE-2025-66489 | 2025-12-03 | versions before 5.9.8 | 5.9.8 |
IDCVE-2025-66489 Published2025-12-03 Affectedversions before 5.9.8 Fixed in5.9.8 | |||
CVE-2026-23478 | 2026-01-13 | 3.1.6 up to before 6.0.7 | 6.0.7 |
IDCVE-2026-23478 Published2026-01-13 Affected3.1.6 up to before 6.0.7 Fixed in6.0.7 | |||
According to the NVD entries, the first flaw let an attacker skip password verification when a TOTP code was supplied. The second let an attacker take over any account by supplying the target's email address. Neither is a sign of a current incident on hosted Cal.com. Both are a reason to check the version of any install you run. In an 80-comment r/selfhosted thread about the closed-source move, one self-hoster admits their instance is still on the version they first installed, one affected by a login-bypass flaw.
The practical move: note your install's version number, compare it with the table, and schedule the update before someone else tests your login for you.
When the Login Is Only the Symptom
A forgotten password is no reason to change tools. It's different when the same questions keep coming back: accounts split across two instances, a self-hosted install nobody owns anymore, single sign-on your plan doesn't cover, or open questions about where booking data is stored. At that point you're reviewing the whole booking setup, not just access.
One option in that review is meetergo, a German scheduling and client-communication platform used by sales, consulting, HR and healthcare teams. Data sits on servers in Nuremberg, the company has no US corporate parent, and there's a single hosted environment rather than separate regional instances. For companies with central identity management, meetergo's SAML single sign-on connects to Okta, Azure AD and Google Workspace with SCIM provisioning, on the Enterprise plan. Encryption, pen testing and hosting details are on the meetergo security page.
To be straight about it: switching won't fix a login problem you have today, and every migration costs effort. Booking links change, calendars need reconnecting (our guide on how to sync Google Calendar with Outlook shows what that involves), and people need time to adjust. If you want to compare first, see our roundup of Cal.com alternatives, the side-by-side Calendly vs Cal.com comparison, our Cal.com pricing breakdown and a wider look at meeting scheduling software. Plans, including the free-forever tier, are on the meetergo pricing page.
Common Cal.com Login Mistakes
- Resetting the password before checking the instance. A reset on app.cal.com does nothing for an account on Cal.eu. Check the domain in an old booking link first.
- Typing a password into a Google-created account. Every attempt counts toward the lockout limit of 10. The identity-provider message already names the right button.
- Not saving backup codes. They're the only way back in without an admin if your authenticator phone goes missing. Keep them in a password manager, not as a screenshot on the same phone.
- Ignoring the phone clock. Time-based codes fail on a drifting device clock even when the app shows the right entry.
- Treating a self-hosted install as done. Since the move to Cal.diy, updates are on whoever runs the server. The two sign-in CVEs above show why that matters.
If you'd rather keep bookings, calendars and client data behind one sign-in hosted in Europe, you can try meetergo for free, no credit card needed.
Everything Calendly does, plus video, CRM, and GDPR.
Everything Calendly does, plus video, CRM, and GDPR.
Frequently Asked Questions
Can I use my Cal.com account on Cal.eu?
No. Cal.com and Cal.eu are separate environments with separate accounts. Cal.eu mentions support for migrating existing accounts, but one login doesn't work on both addresses.
Why don't I get a password reset email?
Company mail filters often catch it, so check spam and quarantine. Cal.com's confirmation also only sends mail if the address exists in its system. And if the account was created with Google or Microsoft, there's no Cal.com password to reset.
How long does a Cal.com account lockout last?
The help article on lockouts doesn't give a duration. It describes unlocking by an organization admin. Cal.com's Trust Center lists a minimum of 30 minutes or until identity is confirmed. Solo users without an organization should contact support.
Can I use two-factor authentication with Google sign-in?
Not inside Cal.com. Its built-in two-factor authentication only works for email-and-password accounts. With Google or Microsoft sign-in, set up the second factor in that account instead.
Where do teams with single sign-on log in?
Use the Sign in with SAML/OIDC option on the login screen. It only works once your admin has configured SSO for the organization and your account is assigned to the Cal.com app in the identity provider.



