← Alle Concepts
pattern·pro·magic_link

Magic-link auth

Email-based passwordless login. User clicks a one-time URL, server exchanges it for an access token.

TTL on the token (we use 10 min). Single-use marker in DB. Token MUST include a code-challenge if part of an OAuth flow. SMTP sender reputation matters — use DKIM + SPF + a clean +tag policy. Brevo + Resend are popular providers.

Beziehungen

Outgoing
authemailpatternpro