Magic Link Login

Magic Link Login

A magic link is a one-time URL emailed to a member that logs them into the Member Portal without a password. Magic links are the primary login method for everyday members -- they don't have to remember a password or set one up. Members can also create a password later if they prefer traditional login.

This article explains how magic links work, how members request them, what happens when they click, and how to troubleshoot common issues.


How It Works (Member Walkthrough)

  1. The member visits your church's portal login page (e.g., https://app.timelychurch.org/c/{your-church}/login).
  2. They enter their email address and click Send Login Link.
  3. The platform generates a unique, single-use link tied to that email and your church.
  4. An email arrives within seconds with a Log In button.
  5. The member clicks the button, the link is validated, and they're logged into the Member Portal automatically.
  6. The link is marked as "used" the moment it's verified -- it cannot be used a second time.

If the member has 2FA enabled, clicking the magic link sends them to the 2FA challenge page instead of logging them straight in.


Expiry

Magic links expire 30 minutes after being generated. After that, clicking the link shows a "Link expired" error page and the member must request a new one.

When a new magic link is generated for the same email, any unused, unexpired magic links for that same email and church are invalidated -- so only the most recently emailed link is valid at any time.


What Happens When You Click

When a member clicks the link, the platform:

  1. Confirms the link matches the church it was issued for.
  2. Rejects the link if it has already been used, has expired, or isn't recognized.
  3. Marks the link as used, then signs the member into their portal session.
  4. Sets up the member's login automatically the first time they click, if they've never logged in before. For a member who was added by their church but has never signed in, the first magic-link click finishes setting up their account and connects it to the church as a member.
  5. Confirms the member's email as verified (since they proved ownership of the inbox by clicking the link).
  6. If the member has 2FA enabled, sends them to the 2FA challenge.
  7. Otherwise, logs them in (keeping them signed in) and takes them to the page they were originally trying to reach, or the portal dashboard if there wasn't one.

For security, members are only ever returned to a page on your church's own portal or custom domain after logging in.


Member Self-Service Registration

If a member doesn't yet have a record in your church, they can register themselves from the portal's Register page:

  1. They enter first name, last name, email, and (optional) phone.
  2. The platform creates their record (marked as a visitor) and emails a magic link.
  3. Clicking the link finalizes their account just like a regular login.

If a record with that email already exists, the registration form skips the create step and just sends them a magic link with a "Welcome back!" message.


Troubleshooting

"I didn't receive the email"

  • Check spam/junk folder -- Magic link emails are time-sensitive and sometimes get filtered.
  • Verify the email address matches your member record -- The platform only sends a link if the email matches a member in the church (to protect members' privacy). If the email doesn't match, the form still shows a generic "If your email is registered, you'll receive a link" message but no email is actually sent.
  • Check whether you've unsubscribed from emails -- If a member has previously unsubscribed from all emails, magic-link emails are typically still delivered (since they're security-related), but it's worth verifying with a church admin.
  • Try requesting again -- The previous link is invalidated, but a fresh email is sent.

"Link expired" error

The link is older than 30 minutes. Request a new one from the login form.

"Invalid link" error

This usually means the link was already used. Magic links are single-use by design. Request a new one.

"No account found" error after clicking

The member's record was deleted or anonymized between when the link was sent and when it was clicked. Contact a church admin to verify account status.

Custom-domain churches

If your church has a custom domain configured, magic links use the custom domain in the URL. After login, members are only ever returned to a page on the platform or the church's own custom domain.


Magic Link vs Password Login

Both options are available on every portal login page:

Magic Link Password
Passwordless -- nothing to remember Requires set-up via "Forgot Password" or registration
One-time, expires in 30 minutes Reusable until the user changes it
Always single-use Protected against repeated guessing attempts
Recommended for casual members Useful for staff who log in frequently

A single member can use either method on any given login -- the platform doesn't lock them into one or the other.


Related Articles

We use cookies to personalize your experience. By continuing to visit this website you agree to our use of cookies

More