Client portal - graceful OTP fallback for expired magic links

Client portal - graceful OTP fallback for expired magic links

August 14, 2026

Expired Client Portal magic links no longer lead contacts to a dead end. Contacts are now automatically redirected to the OTP login flow, making it easier to regain access without requesting or regenerating a new magic link.

What changed

Automatic Fallback for Expired Magic Links

When a contact opens an expired Client Portal magic link, they are automatically taken to the OTP verification screen instead of seeing an error or needing to regenerate the link.

OTP Verification with Masked Email

An OTP is automatically sent to the contact’s email address. For added privacy, the email address is masked on the verification screen.

Easier Account Recovery

Contacts can now recover access independently after a magic link expires, reducing login friction and support requests related to expired links.

How it works

  • A contact clicks an expired Client Portal magic link.
  • They are automatically redirected to the OTP verification screen.
  • An OTP is sent to their email address.
  • The contact enters the OTP to complete login and access their account.

No setup is required. The fallback is automatically enabled for Client Portal magic link authentication.

Why this matters

Magic links expire for security reasons, but expired links previously created unnecessary friction for contacts trying to access the Client Portal. With automatic OTP fallback, contacts can securely self-recover access without needing a new link from an admin.

Notes

  • Applies to Client Portal magic links using auth-v2.
  • Expired magic links automatically fall back to OTP-based authentication.
  • Contact email addresses are masked on the OTP verification screen for privacy.

Need help with this?

If you'd like help setting this up or want to know what it means for your account, book a quick call and we'll walk you through it.

EveryCatch • Platform update
Back to Blog