Authentication overview.
Login methods and security options for all users
Members, partners, staff, and administrators use the same brand-aware sign-in foundation. It follows the installation's color and light or dark theme while keeping each role inside its own portal.
Login methods
One-time passwords (OTP) (recommended)
New members sign in with an email code. Partners, administrators, and staff can also set a password in Account settings. An existing member account that already has a password can still use it.
How it works:
- Enter the email address and select Continue
- Select Send me a login code
- Enter the 6-digit code from the email
- Continue into the correct portal
Why this is the default:
- No password to remember
- Fast onboarding (members most of all)
- Strong rate limiting + short expiration window
Password login (optional)
An account with a password can use password sign-in. After the email check, the page shows the password field and keeps email code sign-in available. New member registration creates an account without a password.
How it works:
- User enters email + password
- System authenticates and starts a session
When an account is not found
Member sign-in offers account creation and carries the entered email into the form. Partner sign-in does the same only when partner self-registration is enabled. Staff and administrator accounts must be created by an authorized user.
User-specific login
Administrators
Access the admin panel at /admin.
- Full platform access
- OTP and password login supported
- Session duration configurable
Partners
Access the partner dashboard at /partner.
- Partner-specific dashboard
- View only their own data
- Manage their loyalty programs
Staff
Access the staff interface at /staff.
- Simplified mobile-friendly interface
- Quick QR scanning access
- Transaction processing only
Members
Access via the main site homepage.
- Can browse without signing in
- Login required to collect cards
- Uses email codes; existing accounts with a password can also use password sign-in
- On a phone, a guest sees the same app-like bottom tab bar: the first tab reads Sign in and leads to login, and More holds sign in and create-account. On a larger screen, sign in sits in the top header.
Anonymous member mode
For businesses where signup friction loses customers, anonymous mode lets visitors take part without signing up.
How it works:
- Visitor arrives at your loyalty program
- The app creates a member account
- They receive a unique code (e.g., "R4K7")
- Full access from the start: earn points, collect stamps, claim rewards
- You can add an email anytime to enable OTP login on any device
- If you already have an account with an email, use Log in with Email in the Switch Account tab to verify your email and switch
Best for: Cafés, quick-service restaurants, pop-ups, events. Anywhere speed matters.
💡 Learn more: Anonymous Members: Full configuration guide
Security features
OTP expiration
One-time passwords expire after 10 minutes. Expired codes require a new request.
Rate limiting
Public sign-in, registration, verification, and recovery requests have limits per account and per IP address. OTP codes also have their own attempt limits and resend cooldown. If you reach a limit, the page tells you how long to wait. See OTP management for the limits and proxy setup if your host uses a reverse proxy.
Blocking access
There is no session list to manage and no per-user remote logout. To shut an account out, deactivate it: clear the account's Active toggle, and the app blocks it on its next request. One exception exists for anonymous members: when you disable anonymous mode in Settings, a one-time Also log out anonymous members option ends all sessions for members who have not added an email address.
Related topics
- Anonymous members: Zero-friction onboarding
- OTP management: One-time password configuration
- Security monitoring: Security settings