All guides

Start here

Signing in & account security

How to get into Quickie — by magic link, password, a social account (Google/Microsoft/Apple) or a passkey — and how to manage your email, password, two-factor authentication, passkeys and connected accounts.

What it does

Quickie gives you several ways to sign in, so you can pick whatever is easiest and most secure for you:

  • Magic link — we email you a one-click link, no password to remember.
  • Email & password — a classic password sign-in, with a "Forgot password?" recovery flow.
  • Social login — one tap with Google, Microsoft or Apple (whichever your business has set up).
  • Passkey — sign in with Touch ID, Face ID, Windows Hello or a security key — nothing to type.

On top of a password you can turn on two-factor authentication: a 6-digit code from an authenticator app on your phone, asked for after a password, a magic link or a Google, Microsoft or Apple sign-in — so a leaked password or someone else in your inbox is not enough on its own.

From Settings → Account & security you can change your email, set or change your password, turn two-factor on or off, add/remove passkeys, and connect or disconnect social accounts.

Where to find it

  • Sign in: /auth/sign-in (you're sent here whenever you're signed out).
  • Forgot password: "Forgot password?" on the sign-in form → /auth/forgot-password.
  • Reset password: the link in the reset email → /auth/reset-password.
  • Account & security: Header → avatar menu → Settings → the Account & security card (/dashboard/settings).

Step by step

Sign in with a password

  1. Go to the sign-in page and keep the Password tab selected.
  2. Enter your Email and Password.
  3. Click Sign in. You'll land on your dashboard.
  1. On the sign-in page choose the Magic link tab.
  2. Enter your email, then Email me a magic link.
  3. Open the email and click the link (it expires in 15 minutes and works once).

Sign in with Google / Microsoft / Apple

  1. Click Continue with Google (or Microsoft/Apple) on the sign-in page.
  2. Approve in the provider's window. You'll be returned to Quickie, signed in.
  3. If you cancel or it fails, you'll come back to the sign-in page with a short message — just try again.

Sign in with a passkey

  1. Click Sign in with a passkey.
  2. Approve with your device (fingerprint, face or security key).
  • If your browser doesn't support passkeys, the button won't appear — use another method.
  1. Or click into the Email field: many browsers list your saved passkey among the suggestions there. Pick it, approve it, and you go straight into Quickie.

Create an account

  1. On the sign-in page click Create an account.
  2. Enter your name, email and a password of 8 to 128 characters — any mix of letters, numbers, spaces and symbols — then Create account. The bar under the field shows how easy the password would be to guess; a few unrelated words together is hard to guess and easy to remember.
  3. Check your inbox and click the verification link before signing in.

Joining during the private beta

If Quickie is running in private beta, the sign-in page shows a "Private beta" notice and creating a new account needs an access code:

  1. Click Create an account — a Beta access code field appears.
  2. Paste the code your invite gave you, fill in the rest of the form, and continue.
  3. Already have an account? You're not affected — signing in (by password, magic link, social or passkey) works exactly as normal, with no code needed. The code is only required the very first time an account is created.

Reset a forgotten password

  1. Click Forgot password? on the sign-in form.
  2. Enter your email and Send reset link. You'll always see the same confirmation (we never reveal whether an email is registered).
  3. Open the email, click the link, choose a new password and Update password. The link expires in 1 hour and works once.

Change your email

  1. Settings → Account & security → Email address.
  2. Type the new email and Change email.
  3. If your current email is verified, it's a two-step confirmation (this protects you if someone ever got into your account):
  4. We email your current address a confirmation link — click it to approve.
  5. We then email the new address a verification link — click that to finish the switch. Until both are clicked, your email stays the same.
  6. If your current email isn't verified yet, the change applies immediately.

Set a password (for passwordless accounts)

If you only ever signed in by magic link, social or passkey, you'll see Set a password:

  1. Settings → Account & security → Set a password.
  2. Enter a password of at least 8 characters (the bar under it shows how easy it would be to guess), confirm it, then Set password.
  3. Confirm it's you. A password is a new way into your account, so if you signed in more than 10 minutes ago Quickie asks you to Sign in again first (you come straight back here), or for your authenticator code if two-factor is on.
  4. You can now also sign in with email + password, and we email you that a password was added — if it wasn't you, use Forgot password? on the sign-in page to choose a new one, which signs out every device.

Change your password

  1. Settings → Account & security → Change password.
  2. Enter your current password, then your new password twice, and Change password.
  3. Every other device is signed out for safety; the one you changed it on stays signed in.

Turn on two-factor authentication

You need a password first — if you only sign in by magic link, Google or a passkey, set one under Set a password.

  1. Settings → Account & security → Two-factor authentication → Set up.
  2. Confirm your password and click Continue.
  3. Scan this with your authenticator — any TOTP app works (Google Authenticator, 1Password, Bitwarden). Can't scan? Open Can't scan it? and type the key in by hand.
  4. Enter the 6-digit code the app shows and click Turn on.
  5. Save your backup codes — ten codes, each works once, shown only this time. Copy codes, keep them somewhere safe, then I've saved them.

Once it's on, you're asked for your code after a password, after a magic link and after a Google, Microsoft or Apple sign-in. A passkey still signs you in in one step — it is already something only you have.

Sign in with two-factor on

  1. Sign in as usual — with your password, a magic link or Google, Microsoft or Apple.
  2. Enter your code — the 6-digit code from your authenticator app — and click Sign in.
  3. Lost your phone? Click I don't have my phone and enter one of your backup codes instead.
  4. On a device that is yours alone you can tick Trust this device so it doesn't ask for a code again for 30 days.

Turn two-factor off

  1. Settings → Account & security → Two-factor authentication → Turn off.
  2. Enter your password and click Turn off. Your backup codes stop working.

Platform operators: two-factor for the admin panel

Quickie's own staff (platform operators) must use two-factor to open the admin panel — business owners and their teams are not affected.

  • An operator without two-factor who opens an admin page is brought here, to Two-factor authentication, with a sentence saying why. Set it up as above; the sign-in you set it up from then opens the panel.
  • The panel also needs the sign-in you're using to have used your code, a backup code or a passkey. If the sentence says this one didn't, sign out and sign in with your email, password and code — or a passkey.
  • On an operator account with two-factor on, turning it off, setting it up again and adding a passkey need that kind of sign-in too.

Add or remove a passkey

  1. Settings → Account & security → Passkeys.
  2. Optionally name it (e.g. "MacBook Touch ID"), then Add a passkey.
  3. Confirm it's you. A passkey is a new way into your account, so Quickie asks first:
  • with two-factor on — the 6-digit code from your authenticator app, or Use a backup code instead;
  • with a password but no two-factor — your password;
  • with neither (you sign in by magic link or Google, Microsoft or Apple) — nothing to type: if you signed in more than 10 minutes ago, Sign in again signs you out and brings you straight back here afterwards.

Once you've confirmed, you can add passkeys for the next 10 minutes without being asked again.

  1. Approve with your device. We email you that a passkey was added, with its name and when — if it wasn't you, remove it here and change your password.
  2. Remove one with the trash icon next to it. Removing a passkey doesn't ask you to confirm.

Connect or disconnect a social account

  1. Settings → Account & security → Connected accounts.
  2. Connect to link Google/Microsoft/Apple, or Disconnect to unlink. (You can't disconnect your only remaining way to sign in.)

What each screen shows

  • Sign-in card — Password/Magic-link tabs, email + password, "Forgot password?", social buttons, the passkey button, and a "Create an account" toggle. Only the social providers your business configured are shown.
  • Account & security card — your current email and whether it's verified; set/change password; Two-factor authentication (on or off, with Set up or Turn off); your registered passkeys and Add a passkey (which asks you to confirm it's you first); your connected social accounts; and Where you're signed in. When the admin panel sent a platform operator here, a sentence above Two-factor authentication says why.

Tips & good to know

  • Forgot password also works if you've never set one. If you only ever used a magic link or social/passkey, requesting a reset still emails you a link — completing it simply creates a password on your account (your inbox is the proof of identity). So "Forgot password?" is also a way to add a password without signing in first.
  • Passwordless is fine. You never have to set a password — magic link, social and passkeys all work on their own.
  • Passkeys are the most secure and the fastest on a phone.
  • Adding a passkey or a first password asks you to confirm it's you, and you get an email. Someone using a computer you left signed in can't quietly add their own way in: they'd need your code, your password or a fresh sign-in, and you'd hear about it.
  • Two-factor covers every way in except a passkey. A magic link or a Google, Microsoft or Apple sign-in is followed by your code, just as a password is. A passkey needs no code.
  • See what you typed. The eye button in any password field shows the password; it hides again when you submit.
  • Keep your backup codes safe. They are the way back in if you lose your phone, and Quickie can't show them again.
  • Verification emails in development print to the server log instead of being sent (when EMAIL_PROVIDER is console).

Troubleshooting

  • "This reset link is invalid or has expired." Links last 1 hour and work once — request a new one.
  • A social button is missing. That provider isn't configured for your deployment (see the admin notes below).
  • No passkey button. Your browser/device doesn't support passkeys — use a password or magic link.
  • "Confirm it's you" when adding a passkey or setting a password. That's expected — see Add or remove a passkey. Enter your code or password, or choose Sign in again.
  • "Sign in again … you signed in more than a day ago" when adding a passkey. Passkeys can only be added from a sign-in less than a day old. Choose Sign in again; you come back to Settings.
  • "Too many wrong attempts — sign in again to continue." After five wrong codes or passwords in a row, adding a passkey or a password needs a fresh sign-in. Choose Sign in again; you come back to Settings.
  • An email says a password was added and it wasn't you. Use Forgot password? on the sign-in page to choose a new one — that signs out every device — then check Passkeys in Settings → Account & security.
  • An email says a passkey was added and it wasn't you. Go to Settings → Account & security → Passkeys, remove it, then change your password and use Sign out everywhere else under Where you're signed in.
  • My magic link (or Google sign-in) asked for a code. Two-factor is on for your account, so the code comes after every way of signing in except a passkey. Enter it, or a backup code, and you carry on to where the link was taking you.
  • "Use at least 8 characters." A new password needs 8 to 128 characters; nothing else is required.
  • "That code didn't match." Codes last 30 seconds. Check your phone's clock is set automatically and try the next code.
  • Set up is greyed out under two-factor. Your account has no password yet — set one first.
  • The admin panel sent me to Settings (platform operators). Read the sentence above Two-factor authentication: turn two-factor on, or sign out and sign in with your code or a passkey. See Admin Panel.
  • Can't disconnect a social account. It's your only sign-in method — set a password or add another method first.
  • "Quickie is in private beta. A valid beta access code is required to create an account." New sign-ups are gated right now — enter the access code from your invite in the Beta access code field. If you already have an account, just sign in instead (no code needed). Ask your administrator if you don't have a code.

For administrators (setup)

  • Environment variables live in .env.local (see .env.example). Key ones: BETTER_AUTH_SECRET, BETTER_AUTH_URL, the email provider settings, and the OAuth *_CLIENT_ID/*_CLIENT_SECRET pairs.
  • Social providers are env-gated: a provider only appears when both its id and secret are set. Add the redirect URI <BETTER_AUTH_URL>/api/auth/callback/<provider> in the provider's console.
  • Passkeys derive their domain (RP ID) and origin from BETTER_AUTH_URL. Locally that's localhost; in production set it to your real, stable domain — passkeys are bound to it.
  • Private-beta gate (optional, OFF by default). Set BETA_GATE_ENABLED=true and BETA_ACCESS_CODES=code1,code2 (server-side only — never NEXT_PUBLIC) to require a valid access code for new account creation. Existing accounts are unaffected (sign-in never creates a row). Leave BETA_GATE_ENABLED unset/false for open sign-up. Codes are checked constant-time by POST /api/beta/verify, which sets a short-lived httpOnly proof cookie that the account-creation hook in auth.ts requires.

Ready to try it yourself?

Sign in with your email — no password, no card — and follow along in the app.