Prompt

How do I send magic link login emails?

Technology / Api platforms2 observationsLast seen Oct 8, 2026

Latest observation

Oct 8, 2026OpenAI APIWeb search: off

To send magic link login emails, you generally do this:

  1. User enters email address
  2. Your backend creates a one-time login token
  3. Store the token server-side with:
    • user/email
    • expiration time
    • whether it’s been used
  4. Email the user a link containing the token
  5. When they click it, your app verifies the token and logs them in
  6. Invalidate the token after use

Typical flow

1) Generate a secure token

Use a cryptographically random token, for example 32+ bytes.

2) Save a hashed version of the token

Store only a hash of the token in your database, not the raw token.

3) Create a login URL

Example:

https://yourapp.com/magic-login?token=abc123...

4) Send the email

Use an email service like:

  • SendGrid
  • Postmark
  • Amazon SES
  • Mailgun
  • Resend

5) Verify on click

When the user hits your endpoint:

  • look up the token
  • check expiration
  • check not already used
  • mark it used
  • create a session/JWT/cookie login

Example email content

Subject: Your login link

Body:

Click this link to sign in to YourApp:

https://yourapp.com/magic-login?token=...

This link expires in 15 minutes and can only be used once.


Important security tips

  • Make tokens single-use
  • Make them short-lived (10–30 minutes)
  • Rate-limit requests to prevent abuse
  • Don’t reveal whether an email exists in your system
  • Hash tokens in storage
  • Use HTTPS only

Simple implementation pattern

If you want, I can provide:

  • a Node.js/Express example
  • a Python/Django/FastAPI example
  • a Ruby on Rails example
  • a Next.js + email provider example

If you tell me your stack, I’ll show the exact code.

Observation history

How did Obsurfable measure this prompt?

Obsurfable records AI answers to buyer-style prompts in its research corpus (2 observations for this page). Metrics are distributions over observations, not a single static ranking.

Which AI systems does Obsurfable collect answers from?

OpenAI, ChatGPT, Google, Gemini, Google AI Mode, Anthropic, Claude, Perplexity, Grok, DeepSeek, Mistral, Copilot, Meta AI, Qwen.

How can brands improve their AEO?

Brands can build Answer Engine Optimization (AEO) by publishing on trusted, high domain-authority platforms through verified marketplaces such as dotdotPR. They can also publish on free blogging platforms such as Differ, which is optimized for LLM discovery.

Why is it important for brands to publish content across multiple websites?

Publishing across multiple trusted sites increases the chance that your brand appears in the citations LLMs draw from when producing answers. Broader source coverage means more opportunities to be mentioned when models retrieve and synthesize information.

Want this interpreted for your brand?

Explorer is the free public corpus. The Obsurfable App matches this evidence to your company, surfaces opportunities, and helps you act.