Skip to main content

Signing in to Riot with a magic link

The magic link is a passwordless sign-in method. The user enters their email address, receives a single-use link together with a 6-digit code, and signs in. No password to remember or reset.

1️⃣ How it works

👉 Step 1: The user enters their email address on the sign-in page.

👉 Step 2: Riot sends them an email containing two things: a magic link, which leads straight to the confirmation page, and a 6-digit code.

👉 Step 3: Sign-in succeeds if both the link and the code are valid.

👍 Good to know: pairing a link with a code is not needless friction. If someone else opens the link — a company email scanning tool, a shared mailbox — they cannot sign in without the code, which is only shown to the person who made the request.

2️⃣ Same device or a different one

  • Link opened on the device it was requested from: sign-in takes one click, with no code to enter.

  • Link opened on another device — requested on the computer, opened on the phone: the 6-digit code must be entered to complete sign-in.

3️⃣ Limits to be aware of

  • A magic link expires after 15 minutes.

  • If the user requests several links in a row without using them, the later requests are ignored. The right reflex is to use one of the links already received, rather than clicking "send me a link" repeatedly.

  • The address entered must be the profile's primary email address. A secondary address will not work.

4️⃣ Two separate journeys: employee portal and admin platform

Riot treats magic link sign-in differently in two places:

  • the employee portal, where your employees take their courses and report emails: the magic link is always available there, with no setting to change;

  • the admin platform, where you manage your workspace: the magic link only works if an administrator has enabled the corresponding option for the workspace.

⚠️ Important: this is the number one cause of "I can't sign in with a magic link" tickets on the admin side. If you see the message "You are not allowed to sign in with a magic link to this workspace", the option is simply disabled on your workspace — that is the default for admin workspaces. An administrator who is already signed in can enable it in the general settings.

5️⃣ Understanding the error messages

👉 "We couldn't find an account associated with this email address"

No active profile has this address as its primary address. The employee may be deactivated or archived, or their address in Riot may differ from the one they entered. Check the primary address on their profile; a secondary address can be promoted to primary.

👉 "This magic link doesn't exist, has expired or has already been used"

The link is more than 15 minutes old, it has already been used, or the 6-digit code was entered incorrectly several times. Simply request a new link.

👉 "You are not allowed to sign in with a magic link to this workspace"

On the admin platform only: the option is disabled for your workspace. See section 4️⃣.

👉 "We couldn't sign you in. Please try again"

A generic message. Most often, the link was opened on a different device from the one that requested it. Request a new link and open it on the same device.

6️⃣ What to check when an employee can't sign in

  1. The profile exists, it is active, and the address entered is indeed the primary address.

  2. For access to the admin platform: magic link sign-in is enabled on the workspace.

  3. The employee requests a new link and opens it on the device they requested it from.

  4. If the email doesn't arrive: check the spam folder, the spelling of the primary address, and that they haven't sent multiple requests.

Key takeaways

  • Link + 6-digit code: the code protects the account if someone else opens the link.

  • Valid for 15 minutes, and the code is required if the link is opened on another device.

  • Only the profile's primary email address works.

  • On the admin side the option must be enabled on the workspace; on the employee portal it is always available.

Did this answer your question?