Temporary Magic Links Explained

Temporary Magic Links Explained!

May 05, 20252 min read

To strengthen user account protection and eliminate risks associated with permanent login links, temporary magic links have been introduced to the Client Portal. These updates aim to enhance platform security, limit potential unauthorized access, and increase trust by aligning with modern security practices.

What Are Temporary Magic Links?

Temporary magic links are time-sensitive login URLs that allow users to securely access the Client Portal without entering a password. Unlike permanent links, which pose security risks if shared or intercepted, temporary links expire quickly and are harder to misuse.

Key Enhancements

The update brings several significant improvements to how magic links function in the Client Portal:

  • 15-minute time limit: Magic links now expire 15 minutes after being generated, minimizing the chance of unauthorized access.

  • 90-day access window: Users can request magic links for up to 90 days from their last login. After that, login must be re-established manually.

  • Link rate limiting: A limit of 5 to 6 link requests helps prevent abuse or excessive generation of login URLs.

  • Encrypted secret tokens: Each magic link includes a secure, encrypted token, ensuring that login information cannot be intercepted or reused.

  • Backward compatibility: Existing permanent links will continue to work until a user requests a new one. This helps ensure a smooth transition for current users.

Why This Matters

Implementing temporary magic links enhances the security of the Client Portal in several important ways:

  • Prevents unauthorized access by limiting the time a login link remains active.

  • Protects user data with encrypted tokens and tighter request controls.

  • Reduces the risk of misuse, such as replay attacks or link theft.

  • Boosts trust and compliance, showing a commitment to modern security standards.

Additional Update: Language Setting

To streamline user experience, the default language for the Client Portal is now set to English. This simplifies onboarding for most users and ensures consistent communication across the platform.

How to Use the New Magic Links

Here’s how users and admins can start benefiting from the improved system:

  1. Request a login link from the portal as usual.

  2. Use the link within 15 minutes to access your account.

  3. If you haven’t logged in for over 90 days, contact your portal admin to reinitiate access.

Final Thoughts

These updates make the Client Portal not only more secure but also more aligned with today’s expectations for privacy and protection. By adopting temporary, encrypted magic links and removing the vulnerabilities of permanent access URLs, the platform delivers a safer, smarter experience for everyone.

Back to Blog