# Passwordless login — magic link, extra code and 2FA — MijnEvent

 Passwordless login

# No password to forget — just your email address

There is no password at MijnEvent, not for you as an organiser and not for your visitors. You type in your email address, click the link you receive and you are in. If we do not recognise your device yet, a six-digit code is added. Want another lock on the door? Then you switch on two-factor authentication.

 [How it works](#how-title) [More on security](https://mijnevent.nl/en/security) 

  How it works

## From email address to dashboard in three steps

Signing in takes about as long as opening your inbox. Nothing to invent, nothing to remember and nothing to reset.

  1

### You type in your email address

On your organisation’s sign-in page you enter your email address. There are no other fields — no password to think up, none to lose. We send a message to that address.

   2

### You click the link in your inbox

That link is valid for fifteen minutes and works exactly once. Request a new one and the previous link is worthless straight away. So always click the most recent email, never yesterday’s.

   3

### You are in

If we recognise your device, you land in your dashboard right away. If we do not, we first ask for the six-digit code we emailed you — and after that we remember this device for ninety days.

   On screen

## Signing in and setting up 2FA, in one clip

From email address to signed in, and how you then switch on two-factor authentication with an authenticator app.

     The whole flow end to end: the link from your inbox, the extra code on an unfamiliar device, and setting up two-factor authentication.    Why no password## The safest password is no password

Passwords get forgotten, reused and leaked. Leaving them out entirely removes the whole category of problems attached to them.

       ### There is nothing to forget

No password means no "forgot your password" detour at the exact moment the doors open. Anyone who belongs to your organisation gets in with the address they already receive mail on — even after six months away.

      ### A breach elsewhere does not reach you

Most break-ins start with a password stolen from another service and tried again here. We never store a password, so there is nothing for anyone to have picked up somewhere else.

       ### An unfamiliar device gets an extra code

If someone arrives on a device we do not know, the link alone is not enough: a six-digit code follows by email. It is valid for ten minutes, and after five wrong guesses the account locks.

       ### Two-factor on top, if you want it

Every account can switch on two-factor authentication with an authenticator app, including eight recovery codes for when your phone goes missing. As an organisation you can make it mandatory for your whole team — then nobody reaches the admin without it.

   Good to know

## The rough edges, told up front

Signing in through your inbox has a flip side too. We would rather be honest now than on the day itself.

## You need access to your inbox

Everything runs through your email, so without access to that mailbox you cannot get in. Use an address you can reach on your phone as well — exactly what you need when something has to change while you are on site.

## A link does not stay valid forever

Fifteen minutes, and then it is spent. That is deliberately short: an old email sitting in your inbox is no longer a key. You can request a fresh one any time, as often as you like.

## Stewards sign in differently

Your stewards get a one-off invitation link and then set their own PIN. At the gate you do not want to open a mailbox before you can start scanning.

   Frequently asked questions

## Frequently asked questions

## How long is a sign-in link valid?

 Fifteen minutes, and it works exactly once. If you are too late or have already used it, you simply request a new one on the sign-in page. The previous link expires at that moment.

## When do I get one of those six-digit codes?

 Only when we do not recognise your device — on a new phone, in a different browser, or after you have cleared your cookies. The code is valid for ten minutes. After five wrong attempts the account is temporarily locked, even if you then enter the right code.

## How long is my device remembered?

 Ninety days. For that long the link from your inbox is enough and you never have to type a code. The marker lives in a secure cookie that JavaScript cannot read; clear your cookies and the clock starts over.

## Is two-factor authentication mandatory?

 Not for you personally — you switch it on whenever you want. An organisation can make it mandatory for its whole team, though: everyone with access to the admin then has to set it up before the dashboard opens. Visitors are never covered by that.

## What if I lose the phone with my authenticator app?

 When you switch on 2FA you receive eight recovery codes. Each one works once and gets you back in. Keep them somewhere other than the phone running the app — a printed sheet in a drawer is fine.

# Get started without a single password

Create your organisation with your email address. Nothing to invent, nothing to remember — your first sign-in email lands within a minute.

 [Start free](https://mijnevent.nl/registreer) [All features](https://mijnevent.nl/en/features)
