---
title: "Passwordless sign-in"
description: "Passwordless sign-in is signing in to Fincanva with a single-use link or 6-digit code emailed to you instead of a password. Both expire in 10 minutes."
canonical_url: "https://fincanva.com/docs/account-security/passwordless-sign-in"
last_updated: "2026-09-05"
md_url: "https://fincanva.com/docs/account-security/passwordless-sign-in.md"
---

# Passwordless sign-in

Passwordless sign-in is signing in to Fincanva with a single-use link or 6-digit code emailed to your address, instead of typing a password. It is the route the sign-in screen offers first: you enter your email, press **Continue with email →**, and Fincanva sends one email that carries both a clickable link and a typeable code. Signing in with a password remains available as a second route, and **Continue with Google** as a third.

**Also seen as:** magic link, email link, email code, one-time code, OTP

## How does passwordless sign-in work?

You give Fincanva your email address and it emails you two interchangeable ways to finish the sign-in — click the link, or type the code into the screen you are already looking at. Both are single-use and both stop working 10 minutes after the email is sent; the screen says so verbatim: "Enter the 6-digit code below, or click the link in the email. Both expire in 10 minutes."

If the email hasn't arrived, **Resend code** becomes available again 30 seconds after each send, and the button counts down in the meantime. On the sign-up screen the same email doubles as account creation: `We sent a code to {email} — your first sign-in will create your account.`

## How is signing in without a password different from signing in with one?

The difference is what proves it's you — control of your inbox, or knowledge of a secret you stored yourself.

| | Passwordless (link or code) | Password |
|---|---|---|
| What you supply | your email address | your email address and your password |
| What proves it's you | you can open the email | you know the password |
| What you have to remember | nothing | the password |
| How long the proof lasts | 10 minutes, single use | until you change it |
| Where it can leak | your inbox | anywhere you reused it |
| How you start it | **Continue with email →** | **Sign in with password instead** |

Neither route is a lesser account: the same account can use whichever is at hand on the day, and [two-factor authentication](/docs/account-security/two-factor-authentication) applies to both. A third route, **Continue with Google**, hands the check to your Google account instead — and it can also create the account, not only sign in to one you already have. If Google confirms your identity but you don't have a Fincanva account yet, the sign-in screen shows a consent step, headed **One step to finish**, asking you to accept the Terms and Privacy Policy before it creates one. The checkbox starts unticked and the button stays disabled until you tick it. Tick it, press **Continue with Google** again, and you're in — Google doesn't ask again, and there's no separate signup page and no email to open. A returning user who already has an account never sees this step.

## Why does Fincanva ask me to verify my email address?

Fincanva requires a verified email address before you can sign in with a password, because an unverified address may not belong to the person who typed it. A verification link goes out when you sign up, and until it is opened, a password sign-in stops with "Verify your email before signing in." and the screen switches to "Please verify your email" with a **Resend verification email** button. Opening the link verifies the address and signs you in.

The address matters beyond sign-in: it is the channel every passwordless link, code, reset link, and security notice travels through.

## What if I forget my password, or never set one?

Use **Forgot password?** on the sign-in screen and Fincanva emails you a reset link, which is valid for one hour. Past that, the screen tells you plainly: "For security, password reset links expire after 1 hour." — request a fresh one and the old link stays dead.

If you created your account with Google and never had a password, the same machinery sets your first one. Fincanva shows "You signed in with Google. We'll email you a link to set a password." with a **Send reset link** button; open the emailed link and choose a password.

## How strong does my password have to be?

A Fincanva password must be at least 8 characters long — that is the only rule the app enforces. There is no requirement for capitals, digits, or symbols.

Above that minimum the sign-up and reset-password screens show an advisory strength bar labelled `Strength: {level}`, where the level reads **Weak**, **Fair**, **Good**, or **Strong**. It reacts to length and to the mix of character types, and it never blocks you: a password rated **Weak** is accepted as long as it reaches 8 characters. Treat it as feedback, not a gate.

## Defaults in Fincanva

- Passwordless is the route offered first; password sign-in and **Continue with Google** sit beside it.
- **Continue with Google** also creates an account for a first-time visitor, after a one-tick consent step for the Terms and Privacy Policy.
- One email carries both the link and the code, and both expire 10 minutes after it is sent. Each can be used once.
- **Resend code** unlocks 30 seconds after each send.
- Password reset links expire after 1 hour.
- A verified email address is required before a password sign-in succeeds.
- Passwords must be at least 8 characters; the strength bar is advisory only.
- Changing your password from your account settings signs your other sessions out — see [active sessions](/docs/account-security/active-sessions).

## Worked example

At 09:00 you enter your email and press **Continue with email →**. One email lands with a **Sign in** button and the code `418 205`.

At 09:04 you are on your laptop, where you opened the request, so you type `418205` into the code field and you are in. Had you instead opened the email on your phone, tapping the button would have signed you in there — either one works, whichever device is in your hand.

At 09:11 both are dead. Typing the code returns "That code didn't work. Try again or request a new one.", and the link lands on "This link is invalid or has expired." Pressing **Resend code** issues a fresh pair with its own 10-minute window; the first pair never comes back.
