Magic link sign-in

No password at all: the member receives a one-time link by email. Everything then rests on their mailbox.

  • Intermediate
  • 5 min read
  • Applies to 2.0

Turn it on

User Access → Authentication, select Magic link. The default validity is 15 minutes, which you can change.

The magic link settings, with the expiry field.

  • Email delivery is tested and arrives in the inbox, not the spam folder
  • You have signed in with a test account, end to end
  • Your emergency access link is saved outside the site

How a sign-in goes

The member enters their email address and receives a link. Opening it signs them in and consumes the link: it cannot be used twice, and it expires on its own after the validity you set.

Nobody types a password, and no password needs to be remembered.

What this makes your mailbox

Passwordless means the mailbox is the credential. Two consequences follow, and both belong in your decision:

  • Anyone with access to the mailbox can sign in. A shared team inbox becomes a shared account.
  • A mail provider outage is a sign-in outage. There is no fallback for members — only administrators have the emergency link.

Test delivery before switching, not after. With magic link active, an email that does not arrive is not a degraded experience: it is a door that does not open.

Requests for addresses that do not exist

A request for an unknown address is recorded and no link is sent, but the visitor is told the same thing either way — otherwise the form would answer whether an address has an account here.

Related articles

Something missing or out of date? Tell support.