Guide
Signing in & account security
Sign in your way — magic link, password, Google/Microsoft/Apple or a passkey — and recover access if you're locked out.
What it does
Threadwork supports passwordless magic-link sign-in by default, plus optional password, social (Google/Microsoft/Apple) and passkey (Face ID / Touch ID) sign-in. New people get a team of their own created automatically on first sign-in; invited people get a pending invitation to that team, which they accept or decline from the invitations page.
Where to find it
The sign-in page is at /auth/sign-in. Password recovery is at /auth/forgot-password.
Step by step
Sign in with a magic link
- Open /auth/sign-in.
- Enter your email and click Send magic link.
- Open the link within 15 minutes — it's single-use.
Sign in with a password
- On the sign-in page, click Use a password instead.
- Enter your email and password and click Sign in. To check what you've typed, click the eye at the end of the password field (Show password); the password is hidden again when you sign in.
Reset a forgotten password
- Click Forgot password? on the sign-in page.
- Enter your email; if an account exists you'll get a reset link.
- Choose a new password: anything from 8 to 128 characters. The bars under the field show how easy it would be to guess and say why — a few unrelated words together are hard to guess and easy to remember. They are advice; any password of the right length is accepted.
- Sign in with the new password. Resetting it signs you out on every device — including any you don't recognise — so anyone who was signed in as you is signed out too.
Sign in with two-factor authentication
If you've turned on two-factor authentication (see the settings guide):
- Sign in as usual — with your password, an email sign-in link, or Google/Microsoft/Apple.
- On Enter your code, type the 6-digit code from your authenticator app and click Sign in.
- Tick Trust this device only on a device that is yours alone — that device then skips the code for a while.
- No phone? Click I don't have my phone and enter one of your backup codes instead. Each works once.
While two-factor is on, the code is asked for whichever way you sign in — after your password, after an email sign-in link and after Google/Microsoft/Apple — so someone who gets into your inbox or your Google account still can't get in without your phone. Signing in with a passkey stays one step: a passkey is already something only your device has.
Join during the private beta
When Threadwork is running in private beta, the sign-in page shows a "Private beta" notice. What this means:
- Existing accounts sign in exactly as normal — no code needed. Just use your magic link, password, social login or passkey.
- Creating a new account needs a beta access code. If you're signing in with a brand-new email (which creates your account on first sign-in), enter your invite code in the Beta access code field before sending the magic link or signing in. The field is optional and only needed for new accounts.
If you submit a new email without a valid code while the beta gate is on, sign-in is refused with a message explaining a code is required — no account is created.
Manage your sign-in methods (once signed in)
Go to Settings → Account & security → Security to:
- Set a password if you've only ever used a magic link, social login or passkey, or change an existing one. Changing it signs you out on every other device. Setting your first password asks you to confirm it's you first (usually by signing in again), and we email you when it's added.
- Turn two-factor authentication on or off.
- Change your email address.
- Add or remove passkeys. Adding one asks you to confirm it's you first — your authenticator code if two-factor is on, otherwise your password, otherwise signing in again — and we email you whenever a passkey is added.
- Connect or disconnect Google/Microsoft/Apple. Google and Apple can be connected to an existing account just by signing in with them (they confirm your email address). A Microsoft account connects — here or by signing in — only when Microsoft confirms the address is verified; if it doesn't, keep signing in your usual way.
See the settings guide for step-by-step instructions.
What each screen shows
- Sign-in card — email field, magic-link button, a link to switch to password mode, and any configured social providers.
- Check your inbox — confirmation that a link was sent, with an option to use a different email.
Tips
- Social sign-in buttons only appear when an administrator has configured that provider.
- Magic links expire after 15 minutes and can only be used once.
- Think someone else knows your password? Change it (or reset it) — every other device signed in as you is signed out straight away.
- A passkey keeps working after a password reset, so if you get a "passkey was added" email you didn't expect, remove that passkey in Settings → Security as well as changing your password.
- Threadwork administrators (the staff who run the service, not your organisation's owners and admins) must use two-factor authentication to open the admin panel, and must sign in with their password and code, or a passkey.
Troubleshooting
- Link expired — request a fresh one; each link lasts 15 minutes.
- Asked for a code after an email link or a Google sign-in — that's two-factor doing its job. Enter the code from your authenticator app (or a backup code) and you're in.
- Signed out on another device — you (or someone with your password) changed or reset the password. Sign in again; if it wasn't you, reset the password now.
- "A valid beta access code is required to create an account" — during the private beta, new accounts need a code. Enter your invite code in the Beta access code field, then send the magic link / sign in again. Existing accounts never need a code; if you're seeing this on an account you've used before, make sure you're using the exact email it was created with.
- Don't see the team you were invited to — sign in with the exact email the invite was sent to, then accept the pending invitation; use the team switcher (top-left of the header) to move between teams.