Getting started
Back to section

Sign in and recover access

Use verification, trusted devices, and recovery options to regain access safely.

Registration / Login

Sign in securely without making daily access difficult

You can sign in with a password, magic link, Google, GitHub, or passkeys. Some accounts may also ask for an email code or authenticator-app code before opening the portal.

Login, verification, trusted devices, and recovery

The login system supports several sign-in methods and more than one verification option. Choose the method that gives your team the right balance of speed and security.

Before you start

  • normal sign-in is self-service
  • stronger account recovery may require support review
  • TOTP can replace email codes when it is enabled on the account
  • trusted devices can reduce repeat prompts when policy allows it
  • recovery codes should be stored somewhere secure and reachable
  1. start with the normal sign-in method your team uses most often
  2. complete email OTP or TOTP when the login flow requests it
  3. if the portal still looks logged out, check browser cookies, environment, and email delivery basics
  4. if normal sign-in no longer works, contact support for recovery instead of trying unsafe workarounds

Available sign-in methods

  • email and password
  • Google sign-in
  • GitHub sign-in
  • magic link sent to your email
  • passkey sign-in on supported devices

Verification after login

Some sign-ins continue with an extra verification step. The portal currently supports:

  • email OTP codes
  • authenticator-app based TOTP
  • trusted device handling so you do not have to repeat the same step on every login when policy allows it

If TOTP is enabled on the account, the login flow can go directly to authenticator-app verification instead of email OTP.

Magic links are useful when you want to sign in quickly without typing a password. You enter your email address, request the link, and complete the login from your mailbox.

The flow is deliberately cautious about account discovery. It does not use the magic-link response to reveal whether an address exists.

Sessions and browsers

Customer access is session-based in the browser. That means a successful login gives the portal an active session used for dashboard, services, invoices, settings, and other customer pages.

If sign-in seems to succeed but the portal still behaves as logged out, check these things first:

  1. browser cookies are allowed
  2. you completed the full OTP or TOTP step when prompted
  3. you are signing in on the correct environment
  4. your email provider is not delaying OTP or magic-link delivery

Recovery today

Some recovery cases need support review instead of an instant self-service reset. This protects the account from takeover attempts and gives support a chance to verify ownership correctly.

That means the right expectation today is:

  • normal login is self-service
  • stronger account recovery is handled with support review
  • keep at least one well-controlled owner account for the business
  • enroll passkeys for regular users where possible
  • enable TOTP if you need stronger login protection
  • keep recovery codes somewhere the team can reach during an incident
  • do not treat API keys or service passwords as a workaround for portal recovery
Sign in and recover access | BlazingFast Docs