AAgentProof

Help · Sign-in and magic links

Sign-in and magic links

AgentProof signs you in with a one-time magic link, not a password. Sign-in emails are sent from [email protected]. Never paste a sign-in link or token into a chat or email - describe what happened in words instead.

  • I requested a magic link but it has not arrived

    What happened

    You entered your email and we showed 'Magic link sent', but the email is not in your inbox. AgentProof signs you in with a one-time link (a magic link) rather than a password, and sign-in emails are sent from [email protected]. 'Sent' means accepted for delivery; it does not guarantee the message reached your inbox, because your mail provider controls the final delivery.

    Why it matters

    You cannot sign in until you click the link, and a silently filtered email can make it look as though sign-in is broken when it is not. This is especially common on Outlook, Hotmail, Live, Microsoft 365, and custom business domains, which filter automated sign-in emails more aggressively than Gmail. If you use one of those and the link does not arrive, that is an email-delivery matter, not a fault with your account or address.

    What to do next

    1. Confirm the email address you entered has no typo; if it is wrong, request a new link with the correct address.
    2. Search your whole mailbox for [email protected] (a rule or filter may have moved it).
    3. Check Junk, Spam, the Outlook Other / Focused Inbox tab, Quarantine (including Microsoft Defender quarantine), Deleted Items, and Archive.
    4. Give it a minute or two; delivery can be slightly delayed.
    5. Review any mailbox rules or forwarding settings that could divert the email before you see it.
    6. If your policy allows, add [email protected] or agentproofhq.com to your safe senders, or ask your IT admin to allow it.
    7. If your organisation mail security is holding it, ask your Microsoft 365 or Google Workspace admin to run a message trace for that sender and recipient around the time you requested the link.

    What information to include

    1. The exact email address you entered (check for typos).
    2. The approximate time you requested the link.
    3. Which browser and device you used.
    4. The on-screen message you saw, described in words, never the link or the token.

    When to contact support

    If you have checked the above and still cannot get a link, email [email protected]. Tell us the email address you tried and roughly when. AgentProof cannot see your provider delivery status, so your own mail admin message trace is the authoritative source, but we can help arrange a secure access link through a trusted channel. Never paste a sign-in link or token into an email.

  • My magic link has expired or was already used

    What happened

    You clicked a sign-in link and saw a message that it had expired or had already been used. Magic links are deliberately short-lived and single-use; once a link is opened, once enough time passes, or once a newer link is requested, the earlier link stops working.

    Why it matters

    This is a security feature, not a malfunction. It ensures an old or intercepted link cannot be reused to access your workspace. The fix is simply to get a fresh link.

    What to do next

    1. Go back to the sign-in page and request a new magic link.
    2. Open the email and click the newest link; requesting a new link invalidates older ones.
    3. Click the link directly from the email, in the same browser where you will be working. Do not copy, edit, or forward the link.
    4. If you see a 'too many login emails' message, wait a few minutes before trying again; this is a rate limit, not an account problem.

    What information to include

    1. The email address on your account.
    2. The approximate time you requested the most recent link.
    3. Which browser and device you opened the link in.
    4. The exact wording of the expired or already-used message, never the link or the token.

    When to contact support

    If freshly requested links keep showing as expired or already used even when you click them immediately, contact [email protected]. Describe what you see; never paste the link or its token.

  • I clicked the link but I am still not signed in (or I am in a loop)

    What happened

    You opened a magic link but ended up back at the sign-in page, or kept being asked to sign in again. This usually happens when a link is reused or forwarded, when it is opened in a different browser or device from where you will be working, or when the link is older than the most recent one you requested.

    Why it matters

    A magic link establishes your session in the browser that opens it. If the session cannot complete, you appear signed out even though the email worked.

    What to do next

    1. Use only the newest link; older links stop working once a new one is requested.
    2. Open the link in the same, standard browser window you intend to use; avoid forwarding it or opening it inside another app in-app browser.
    3. Allow cookies for the AgentProof app domain, then open the newest link again.
    4. If a workspace page tells you to sign in, sign in first and then return to that page.

    What information to include

    1. The email address you used.
    2. Which browser and device you opened the newest link in.
    3. Whether you allow cookies for the AgentProof app domain.
    4. A plain-English description of the loop or the page you ended up on, never the link or the cookie.

    When to contact support

    If a brand-new link still leaves you unable to sign in, email [email protected] with a plain-English description of the steps you took and what you saw. Safe details to share: the email address you used, the approximate time, and which browser. Never send the link, the token, a screenshot of the full link, or any session cookie.

  • I used the wrong email address

    What happened

    You requested a magic link to an address you do not actually have access to, or to a typo of your real address.

    Why it matters

    A link sent to the wrong address cannot be redirected to the right one; only the recipient of that email can use it. Your account is tied to the exact address you sign in with, so the address has to be correct.

    What to do next

    1. Go back to the sign-in page and request a new link to the correct email address.
    2. Double-check the spelling before submitting.
    3. If you have more than one work address, use the one you expect your workspace to be associated with.

    What information to include

    1. The address you signed up or started under.
    2. The correct address you want the account associated with.
    3. Whether you have any saved assessments or reports under the first address.
    4. Your workspace name, if you know it.

    When to contact support

    If you have already started using AgentProof under one email and need it associated with a different address, contact [email protected] and explain the change you need. We will handle it directly rather than asking you to move any link or token.

  • I have a password — can I sign in with that instead?

    What happened

    Magic link is the recommended, default way to sign in. Sign-in also offers an 'I have a password' option for the small number of accounts that have explicitly set a password.

    Why it matters

    If you registered via magic link and never set a password, the password option will not work for you, and that is expected. Magic link remains the primary path; password is only an alternative for accounts that have one.

    What to do next

    1. On the sign-in page, choose 'I have a password' only if you previously set one.
    2. If you see 'Invalid email or password' and you never set a password, switch back to the magic-link option and we will send you a sign-in link instead.
    3. When in doubt, use magic link; it is the most reliable route for any valid account.

    What information to include

    1. The email address on your account.
    2. Whether you ever explicitly set a password (and roughly when).
    3. The exact wording of the sign-in error you saw, never the password itself.
    4. Which browser and device you used.

    When to contact support

    If you believe you set a password but cannot sign in with it, email [email protected]. We may simply direct you back to magic-link sign-in, which is the most reliable route. Your data is stored in the EU.

Still stuck?

Contact our support team. Safe details to include: the email address you used, roughly when you requested the link, and what you saw on screen.

Email support →