
The Crédit Agricole des Côtes d’Armor (CRCA22) provides its clients with an online space accessible from a browser or the mobile app Ma Banque. The login relies on a multi-digit identifier and a personal code entered on a virtual grid. Since compliance with the European directive DSP2, the authentication process has evolved, adding steps that change the daily login experience.
Sécur’Pass and DSP2: What Has Changed for CRCA22 Login
The European directive on payment services (DSP2) has required French banks, including Crédit Agricole, to strengthen authentication during sensitive operations. The system chosen by the group is called Sécur’Pass, integrated directly into the Ma Banque app.
Read also : Discover how to boost your business with an innovative online service platform
In practice, a CRCA22 client can still check their accounts with their identifier and personal code. However, to make a transfer, add a beneficiary, or sign an electronic document, activating Sécur’Pass on a smartphone has become almost mandatory. This mechanism is gradually replacing the one-time code sent via SMS.
For clients who do not have a compatible smartphone, the situation becomes more complicated. Some operations then require direct contact with the agency, which reduces the autonomy promised by online banking. Feedback from users varies on this point: some report still being able to validate via SMS, while others are denied this option depending on the type of operation.
Further reading : How to Easily Fill Out Your Tax Declaration in LMNP: Step-by-Step Guide
A detailed guide allows users to access crca22 online on Le Comptoir Web and find the steps for first-time login tailored to the Côtes d’Armor branch.

Input Grid for Personal Code: Functioning and Security Limitations
The login page of Crédit Agricole uses a virtual keyboard whose numbers change position with each session. This system prevents a potential keylogger from capturing the typed sequence. The client clicks on the numbers corresponding to their code instead of entering them on a physical keyboard.
This device protects against certain attacks, but it presents accessibility constraints. On a small smartphone screen, the clickable areas can lead to input errors. After several failed attempts, the account is temporarily blocked.
Unlocking After Input Errors
A block generally occurs after three consecutive incorrect codes. The client then has two options:
- Contact the customer support service of the Côtes d’Armor branch to request a reset of the personal code
- Visit the agency with an ID to receive a new temporary code
- Use the “forgot code” feature on the platform, which triggers the sending of a temporary code by postal mail or SMS depending on the account settings
The unlocking time varies depending on the chosen channel: a few minutes by phone, one to several days by mail. This disparity pushes the majority of clients towards phone calls or visiting the agency.
Ma Banque App and Browser Space: Two Distinct Experiences
Crédit Agricole offers two entry points to manage accounts online. The website, accessible from any browser, and the mobile app Ma Banque, available on Android and iOS. Both provide access to the same account data, but the functionalities and level of fluidity differ.
The mobile app now concentrates the most sensitive functions. It hosts Sécur’Pass, making it a necessary step to validate operations subject to strong authentication. Without the app installed and activated, access to advanced services remains limited, even from the website.
What the App Allows That the Browser Does Not Always
- Instant validation of transfers via push notification through Sécur’Pass
- Balance consultation via fingerprint or facial recognition, without entering the code at each opening
- Real-time alerts on account movements (debits, credits, direct debits)
- Check deposits via photo in certain regional branches (availability for the Côtes d’Armor branch is not confirmed in the available data)
The website remains relevant for consultation operations and document management (downloading statements, accessing insurance contracts). For a client who primarily uses a computer, the browser login covers the common needs for account tracking.

Phishing Attempts Targeting CRCA22 Clients: Signals to Spot
The regional branches of Crédit Agricole are among the frequent targets of phishing campaigns. Fraudulent messages imitate official communications and redirect to fake login pages. The Côtes d’Armor branch is not exempt from this trend.
Several elements can help distinguish a legitimate page from a fraudulent copy. The official URL always starts with credit-agricole.fr, followed by the segment corresponding to the regional branch. Any address that deviates from this pattern should alert the client. The padlock in the address bar confirms the encryption of the connection, but does not guarantee the authenticity of the site on its own.
Crédit Agricole never asks via email or SMS for a complete personal code, nor to “confirm” banking data via a clickable link. Any message containing such a request is phishing.
The relationship between security and ease of access remains a constant balancing act for online banks. Strengthening controls through DSP2 and Sécur’Pass protects the data and finances of CRCA22 clients, at the cost of a less direct login process than before. Keeping the Ma Banque app updated and systematically checking the site address before any entry remain the two most effective reflexes to secure daily access.