Account Access
Use the account access pages for sign-in, password recovery, email changes, and invitations.
Use this guide for a sign-in, an account recovery, an email change, and an organization invitation.
Purpose#
This page covers these tasks:
- Sign up after you prove that you own the email address.
- Sign in with a password or with a provider account.
- Request and complete a password reset.
- Change the account email address.
- Accept an organization invitation.
Before you start#
- Access to the sign-in page, the password reset page, the email confirmation page, and the invitation page.
- Signup is not always available.
- The confirmation flow, the reset flow, and the invitation flow need a valid link.
Procedure#
A. Create an account#
- Open the signup page and enter a valid email address.
- Open the secure link that PayloadRelay sends to that address. PayloadRelay does not create a user, a password, or an organization before this step.
- Enter your name, set a password, accept the Terms of Service and the Privacy Policy, and create the account. If the signup started with Google, Microsoft, or Apple, sign in with the same provider account and do not create a password.
- PayloadRelay signs you in and sends you to the onboarding page.
The link has one use, and it expires after 24 hours. If the address already has an active account, PayloadRelay sends a notice to that account instead of a signup link. The notice has a link to the sign-in page and a link to the password reset page. For a Microsoft signup, enter the email address for the confirmation. After you open the link, sign in with the same Microsoft account again. This prevents the use of the confirmed email address by a different account.
B. Sign in#
- Open the sign-in page.
- Enter your email address and password, or select a provider button (
Google,Microsoft,Apple) if it is enabled. - After a successful sign-in, PayloadRelay sends you to the app.
A session stays valid for 24 hours after the last request, and for a maximum of 30 days after the sign-in. After that, sign in again. After 10 failed password attempts in 15 minutes, PayloadRelay refuses the password checks for that address from your network address. Wait 15 minutes, then try again.
A sign-in and a signup are different. A provider button on the sign-in page never creates an account, and it never links an account. A provider sign-in uses the selected provider account, and not only the email address of that account.
C. Reset password#
- Open the password reset request page.
- Submit your email address.
- Open the reset link in your email.
- Enter and submit your new password.
Rules:
- A new password has 15 to 128 Unicode characters. You can use spaces and passphrases.
- PayloadRelay rejects a common password. To create a password, use a password manager.
- A reset link has one use, and it expires after 2 hours.
- You can also use the reset flow for a provider-only account. The owner of the confirmed mailbox can create password access. The email inbox is the recovery route for the account, and the usual sign-in method has no effect on this. Protect the mailbox, because the protection of the provider account does not protect PayloadRelay alone. The sign-in method in the list does not change. PayloadRelay adds the password sign-in beside it.
- A successful reset signs out the current sessions. Then sign in with the new password.
- A successful reset also confirms the email address of the account, because the reset link proves that you own the mailbox.
D. Complete an email change#
- Open the confirmation link in the email.
- Read the page, then select
Confirm email. A preview of the link does not consume it. - Sign in with the new email address. An email-change link does not create a session.
To change the account email address, you must give the current password, or you must authenticate with the provider in the last 10 minutes. When the change completes, PayloadRelay ends all the older sessions.
E. Accept organization invitation#
- Open the invitation acceptance link.
- Read the organization invitation details.
- Set a display name and a password.
- Accept the Terms of Service and the Privacy Policy.
- Submit the invitation acceptance form.
Rules:
- The password must have 15 to 128 Unicode characters. It must pass the same common-password test as the signup flow and the reset flow.
- The password and the confirmation must be the same.
Expected result#
- A sign-in gives access to the authenticated pages.
- After the reset flow, you can sign in with the new password.
- The signup creates the account only after you prove that you own the mailbox.
- The email-change confirmation updates the address. It does not sign in the person who opens the link.
- The invitation acceptance creates account access in the organization.
Common issues and fixes#
- A missing-token error: use the most recent link in the email.
- The sign-in says that the email address is not confirmed: select the link under the message to send a new signup link. If you cannot sign in, use the password reset flow, because a completed reset confirms the address.
- The OAuth button is not present: that sign-in method is not available now.
- PayloadRelay rejects the invitation: the token can be expired or revoked. Ask an organization admin to send the invitation again.
- PayloadRelay refuses the sign-in after an account change: delete the old cookies and try again.
- A sensitive change asks for authentication again: sign in with the password or the provider again, then try again in the next 10 minutes.
- The provider email address belongs to an account already: use the existing sign-in method for that account. PayloadRelay never links accounts automatically by email address.
- The provider signup link or the connection-review link expired: start the signup again, or sign in with the same provider. The
Resendaction on the email signup screen sends an email-signup link only. It cannot create a provider signup link or a connection-review link.