Blog
4 min read

Magic Link Login: How Passwordless Email Sign-In Works (and Its Pitfalls)

Magic links let people log in by clicking a link in their email — no password. How they work, when they're a good fit, the security details that matter (expiry, single use, token hashing), and the real-world problems: spam filters, email scanners and phones vs laptops.

A magic link is a login method where, instead of typing a password, you enter your email address and the app sends you a link. Click it, and you're logged in. Slack, Notion, Medium and many newer apps offer it, and auth providers like Supabase make it a single setting.

How it works

  1. The user enters their email on the login page.
  2. The server generates a long, random, single-use token, saves it with an expiry time, and emails a link containing it: https://app.example.com/auth/verify?token=Xk29...
  3. The user clicks the link.
  4. The server checks the token exists, hasn't expired, and hasn't been used. If so, it marks it used and creates a normal login session.

The security idea: only someone with access to that inbox can log in. The email account becomes the "password".

Why people like them

  • No passwords to forget, reset, reuse or leak. Your database holds no password hashes to steal.
  • Faster sign-up — email in, link clicked, done.
  • Email verified automatically — you know the address is real.

The downsides

  • Dependent on email delivery. If the email is slow or lands in spam, the user can't log in at all. Your login is only as reliable as your email setup. (Send email from your app without landing in spam.)
  • Device switching. Request a link on a laptop, open the email on a phone, and you're logged in on the phone. Some apps add a short one-time code in the same email that can be typed on the original device to avoid this.
  • Email scanners click links. Corporate email security tools often "click" every link to scan it — which can use up a single-use token before the person clicks. More on this below.
  • Only as secure as the inbox. Anyone who gets into the email account gets into your app. Offering two-factor authentication or passkeys on top helps for sensitive apps.
  • Friction for frequent logins. Fine if sessions last weeks; annoying if people log in several times a day.

Building it securely

The easiest path: use your authentication provider's built-in magic links (Supabase Auth, Clerk, Auth0, Better Auth and others offer them). If you build it yourself:

  • Long, random tokens from a cryptographically secure generator — at least 32 random bytes. Never a sequential number or anything guessable.
  • Store a hash of the token, not the token itself, so a database leak doesn't hand out working login links. (Password hashing explained — a fast hash like SHA-256 is fine here because the token is already random and long.)
  • Short expiry — 10 to 15 minutes.
  • Single use — mark the token used the moment it's redeemed.
  • Rate-limit requests per email and per IP, so nobody can flood an inbox or your email bill. (What is rate limiting?)
  • Don't reveal whether an account exists. Always reply "If that email is registered, we've sent a link", whether or not it is.
  • Build the link from your configured app URL, not from the request's Host header, which an attacker could spoof to send links pointing to their own site.

Handling email scanners

Because security scanners may open links automatically, a common pattern is to make the link open a page with a "Confirm sign-in" button. Visiting the page (a GET request) does nothing; clicking the button (a POST) redeems the token. Scanners load pages; they don't press buttons. Alternatively, send a short code instead of — or alongside — the link.

Method Passwords to manage Phishing-resistant Depends on email
Password Yes No Only for resets
Magic link No Partly Every login
Email one-time code No No Every login
"Sign in with Google" No Mostly No
Passkey No Yes No

Many apps offer two options — say, "Sign in with Google" plus magic links — so everyone has a route that suits them.

The summary

  • A magic link logs you in via a single-use link emailed to you — no password.
  • Great for sign-up speed and avoiding password risks; dependent on reliable email.
  • Use random tokens, store hashes, expire in minutes, single use, rate-limited.
  • Guard against email scanners with a confirm button or a code.

EasySpawn runs your app's backend with its secrets stored server-side and gives Claude Code a real environment to build and test login flows end to end — including the email that has to arrive. See how it works or join the waitlist.

Related: How to Add Login to an AI-Built App · Password Resets and Email Verification Done Right · Session vs JWT · Cookies Explained

Keep reading