How it works
The server creates a long random token, stores a hash of it with a short expiry (minutes rather than hours) and emails a link containing it. When the link is opened, the server checks the token, marks it as used and starts a session. Signing in is therefore exactly as safe as the person's email account, which is the same trust that password reset emails already rely on.
Delivery decides the experience: the email must arrive within seconds and stay out of spam, so magic links need a transactional email service with SPF, DKIM and DMARC set up. Two snags are common. Corporate email scanners sometimes open links before the person does, using up a single-use token, and a link opened on another device leaves the original tab signed out. Many apps include a short code in the same email for exactly these cases.
Magic links pros and cons
Pros
- No password to create, remember, reuse or leak
- Simple sign-up: an email address is all it takes
- Every sign-in also proves the email address works
- Cheap to run with any transactional email service
Cons
- Each sign-in means leaving the app to find an email
- Slow or spam-filtered emails lock people out
- Email scanners and second devices can break single-use links
- Only as secure as the person's email account
When to use Magic links
Pick it when
- Tools people open occasionally, such as dashboards and B2B apps
- You want to avoid storing passwords at all
- Your users read email on the same device they use the app on
Skip it when
- People sign in many times a day, where passkeys or long sessions fit better
- You do not yet have a fast, trusted email sender
Magic links pricing
Free
No licence cost. Each sign-in is one transactional email, which email services include in free tiers or bill at a fraction of a cent.
Approximate, checked September 2026.What the other tools cost
Magic links vs the alternatives
Related terms
More in Auth and identity
Ways to sign in