Signing In and Account Security

Magic links, passwords, passkeys and connected accounts.

Who this is for

Use this guide if you want to understand every way to sign in to senco and how to manage your own account security: passwords, two-factor authentication, passkeys, social sign-in, email changes, and password resets. senco is a non-diagnostic SEND reasoning support system, so account security protects sensitive pupil information — treat your sign-in details and reset links as safeguarding-relevant.

What it does

senco supports several sign-in methods, side by side, on the same account:

  • Email link (magic link) — a one-click sign-in email; no password needed.
  • Password — email-and-password sign-in for accounts that have set a password.
  • Passkey — Touch ID, Face ID, Windows Hello, or a security key (WebAuthn).
  • Connected account — Google, Microsoft, or Apple, when your organisation has configured them.

You can use whichever methods suit you and add or remove them at any time from Settings. On top of a password you can turn on two-factor authentication: a 6-digit code from an authenticator app on your phone, asked for every time you sign in — with your password, an email link, or Google, Microsoft or Apple. A passkey signs you in in one step.

Where to find it

  • Sign in, create an account, or start a magic link: /auth/sign-in.
  • Forgotten password: /auth/forgot-password (also linked from the Password tab on the sign-in screen).
  • Reset link destination: /auth/reset-password (opened from the email).
  • Manage your account security: /dashboard/settings → Profile section → Account & security card.

Step by step

Create an account with a password

  1. Open /auth/sign-in and choose Create account.
  2. Enter your name, email, and a password: anything from 8 to 128 characters. There are no rules about capitals, numbers or symbols. As you type, a meter under the field says how easy the password would be to guess and what would make it stronger — it is advice, and never stops you. The eye button in the field shows what you have typed.
  3. Select Create account. We email you a verification link.
  4. Open the email and confirm your address. You must verify before your first password sign-in — until then, password sign-in is refused.

Sign in

  1. Open /auth/sign-in.
  2. Choose Email link for a one-click email, Password to use your password, or select Sign in with a passkey / Continue with Google/Microsoft/Apple below the form.
  • Many browsers also offer your saved passkey when you click into the Email field. Pick it, approve it on your device, and you go straight on to where you were going.
  1. If you are already signed in, /auth/sign-in redirects you to the dashboard.

Reset a forgotten password

  1. On the Password tab, select Forgot password? (or open /auth/forgot-password).
  2. Enter your email and select Send reset link. You always see the same confirmation message, whether or not the email matches an account — this is deliberate, so no one can use the screen to discover who has an account.
  3. Open the link in the email (valid for one hour, single use) and choose a new password (8 to 128 characters; the meter under the field is a guide).
  4. Choosing the new password signs your account out on every device — including any device someone else may be using with your old password. Sign in again with the new one.
  5. If the link has expired or was already used, the screen offers to send a fresh one.

Add or change your password (in Settings)

  1. Go to /dashboard/settings → Profile → Account & security.
  2. If you signed up without a password (magic link, passkey, or social), you'll see Set a password: choose and confirm one, then select Set password. A password is a new way into your account, so unless you signed in within the last ten minutes a Confirm it's you box asks you to Sign in again first (with two-factor on, it asks for your code instead); you come back to the password section to finish. We email you when the password is set.
  3. If you already have a password, you'll see Change password: enter your current password, then the new one. Changing your password always signs you out of your other devices; the device you are on stays signed in.

Turn on two-factor authentication

You need a password on the account first — two-factor protects a password, so on an account without one the Set up button is unavailable and the section asks you to set a password.

  1. Go to /dashboard/settings → Profile → Account & security → Two-factor authentication and select Set up.
  2. Confirm your password: enter it and select Continue.
  3. Scan this with your authenticator in any TOTP app (Google Authenticator, 1Password, Bitwarden…). If you can't scan, open Can't scan it? and type the key in by hand.
  4. Enter the 6-digit code the app shows and select Turn on.
  5. Save your backup codes: ten single-use codes, shown only once. Use Copy codes, keep them somewhere safe, then select I've saved them.

Once it is on:

  • Signing in asks for the code on an Enter your code screen — after your password, after an email sign-in link, and after Google, Microsoft or Apple. Once it is accepted you go on to the page you were signing in for — an invitation link, say, or Platform admin — or to the dashboard. I don't have my phone switches to a backup code. Ticking Trust this device skips the code on that device for a while — only do this on a device that is yours alone.
  • Email sign-in links keep working, and so do Google, Microsoft and Apple: each asks for your code too, so a link in your inbox is never enough on its own. Passkeys stay one step — a passkey is already something only your device holds.
  • To turn it off, select Turn off and confirm your password. Your backup codes stop working.

senco platform administrators must have it on. senco's own operators (the Platform admin panel) cannot use any admin page without two-factor, and only from a session signed in with the code or a passkey. Opening the panel without it brings you to Settings → Profile, with a note at the top saying why and a Go to Two-factor authentication link. This does not apply to school owners, SENCOs or anyone else in a school.

Change your email address

  1. In Account & security, enter the new address under Email address and select Change email.
  2. If your current email is verified, we email a confirmation to your current address first. Approve it there, then confirm again from the link sent to the new address. The change only applies after both steps — this stops anyone with a hijacked session from quietly moving your account to their own inbox.
  3. If your current email is unverified, the change applies immediately.

Manage passkeys

  1. In Account & security → Passkeys, type an optional label (e.g. "MacBook Touch ID") and select Add a passkey.
  2. Confirm it's you. A passkey is a new way into your account, so unless you have confirmed in the last ten minutes senco asks first, in a Confirm it's you box:
  • Two-factor on — enter the 6-digit code from your authenticator app, or select Use a backup code.
  • No two-factor, but a password — enter your password.
  • No password (you sign in by email link, or with Google, Microsoft or Apple) — there is nothing to type: select Sign in again, sign in, and you come back to Passkeys to add it.

Then select Continue and follow your device prompt. After five wrong answers the box says Too many wrong attempts and only Sign in again works.

  1. We email you whenever a passkey is added to your account — its name, if you gave one, and when. If you didn't add it, remove it here and change your password.
  2. Registered passkeys are listed with their type and date added; use the bin icon to remove one. Removing a passkey doesn't ask you to confirm.
  3. On a browser without passkey support, the section explains this instead of showing a broken button.

Join during the private beta

This only applies when your deployment has the private-beta gate switched on (set by an administrator via BETA_GATE_ENABLED=true). When it's off, sign-up is open as normal and you can skip this.

  1. When the gate is on, /auth/sign-in shows a Private beta notice. Existing accounts sign in exactly as before — magic link, password, passkey, or social — and never need a code.
  2. To create a new account, choose Create account, fill in your name, email, and password, then enter the Beta access code you were given.
  3. The code is checked the moment you submit; an invalid code is rejected inline and no account is created. A valid code lets your account be created and is remembered for about 24 hours, so a magic-link sign-up you finish from your inbox shortly after still goes through.
  4. The same gate applies to a brand-new email signing in by magic link or a first-time social login (both create an account): without a valid code, the account is not created.

Connect or disconnect a social account

  1. In Account & security → Connected accounts (shown only when your organisation has configured providers), select Connect next to Google, Microsoft, or Apple, or Disconnect to remove the link.
  2. senco won't let you disconnect your only remaining sign-in method, so you can't lock yourself out.

What each screen shows

  • Sign-in screen — three tabs (Email link / Password / Create account), plus any available passkey and social-sign-in buttons below an "or" divider. The Password tab carries the Forgot password? link.
  • Forgot password — an email field and a generic confirmation after submitting.
  • Reset password — new-password and confirm fields, or a "request a new link" prompt if the link is invalid/expired.
  • Account & security card — Email address (with verified/unverified status), Set/Change password, Two-factor authentication, Passkeys, (when configured) Connected accounts, Where you’re signed in, and Your data.
  • Confirm it's you — shown before a passkey is added: a code box (with Use a backup code), a password box, or Sign in again, depending on how your account signs in.
  • Enter your code (/auth/two-factor) — the second step of any sign-in except a passkey when two-factor is on: after a password, an email link, or Google, Microsoft or Apple.

Tips

  • Magic link and password can both live on the same account — adding a password never removes magic-link sign-in.
  • In local development with the console email provider, sign-in, verification, reset, and email-change links are printed to the dev server log instead of being emailed.
  • Passkeys are tied to the site's domain. A passkey registered on the live site won't work on a different domain, and vice versa.

Troubleshooting

  • "Email not verified" / password sign-in refused — open the verification email and confirm first, or use the magic link to get in.
  • Reset link says invalid or expired — links last one hour and work once; request a new one.
  • Signed out on every device after a reset — that is deliberate: a new password ends every session the account had. Sign in again with the new password.
  • An email link opened "Enter your code" instead of signing you in — that is two-factor at work: enter the code from your authenticator app, or a backup code, and you go on to where the link was taking you.
  • The email link says it is invalid or already used — each link works once and lasts 5 minutes. Some work email systems open links to check them before you do, which uses the link up; ask for a new one, or sign in with your password or a passkey.
  • Sent to Settings when opening Platform admin (senco operators only) — read the note at the top of Profile. Either turn two-factor on, or, if it is already on, this session skipped the code (it began before you turned two-factor on, or on a trusted device): sign out, then sign in with your email and password and enter the code, or use your passkey.
  • "Confirm it's you" when adding a passkey — that is deliberate: a passkey signs you in in one step, so senco checks it's really you first. Enter your code (or a backup code) or your password. If it asks you to sign in again, select Sign in again and you come back to Passkeys afterwards.
  • "Confirm it's you" when setting a password — that is deliberate too: a first password is a new way in. Select Sign in again, then set it.
  • Adding a passkey asks you to sign in again even after confirming — you last signed in more than a day ago, and adding a passkey needs a sign-in from the last day. Select Sign in again.
  • An email says a password was added, and it wasn't you — use Forgot password? on the sign-in page to reset it (that signs every device out), then check Account & security.
  • "Too many wrong attempts" — five wrong codes or passwords in one session. Select Sign in again, then add the passkey.
  • An email says a passkey was added, and it wasn't you — go to Settings → Profile → Account & security → Passkeys, remove it with the bin icon, then change your password (which signs every other device out).
  • Social button missing — that provider isn't configured for your deployment. See .env.example (GOOGLE_CLIENT_ID, MICROSOFT_CLIENT_ID, APPLE_CLIENT_ID, and matching secrets).
  • "An account already exists with this email" — you previously signed in with a different method. Sign in that way first, then link the new provider from Account & security.
  • "This site is in private beta" / "beta access code isn't valid" — the deployment has the private-beta gate on and your code was missing or wrong. Existing accounts are never asked for a code, so this only affects creating a new account; check the code with whoever invited you. (Administrators configure codes via BETA_ACCESS_CODES; the gate itself is toggled with BETA_GATE_ENABLED.)