Prompt
How do I send magic link login emails?
Latest observation
Oct 8, 2026
OpenAI APIWeb search: off
To send magic link login emails, you generally do this:
- User enters email address
- Your backend creates a one-time login token
- Store the token server-side with:
- user/email
- expiration time
- whether it’s been used
- Email the user a link containing the token
- When they click it, your app verifies the token and logs them in
- Invalidate the token after use
Typical flow
1) Generate a secure token
Use a cryptographically random token, for example 32+ bytes.
2) Save a hashed version of the token
Store only a hash of the token in your database, not the raw token.
3) Create a login URL
Example:
https://yourapp.com/magic-login?token=abc123...
4) Send the email
Use an email service like:
- SendGrid
- Postmark
- Amazon SES
- Mailgun
- Resend
5) Verify on click
When the user hits your endpoint:
- look up the token
- check expiration
- check not already used
- mark it used
- create a session/JWT/cookie login
Example email content
Subject: Your login link
Body:
Click this link to sign in to YourApp:
https://yourapp.com/magic-login?token=...
This link expires in 15 minutes and can only be used once.
Important security tips
- Make tokens single-use
- Make them short-lived (10–30 minutes)
- Rate-limit requests to prevent abuse
- Don’t reveal whether an email exists in your system
- Hash tokens in storage
- Use HTTPS only
Simple implementation pattern
If you want, I can provide:
- a Node.js/Express example
- a Python/Django/FastAPI example
- a Ruby on Rails example
- a Next.js + email provider example
If you tell me your stack, I’ll show the exact code.