Sign in to Slack, Medium, Notion, or a growing pile of newer apps and you'll meet a login form with no password field at all. Type your email address, click the button, and a message lands in your inbox: "Click here to sign in." One click and you're in. That link is a magic link - The most widely deployed form of passwordless login - And it represents a real bet: that your inbox is already the master key to your digital life, so the password ritual on top of it was theater all along.
That bet is more defensible than it first sounds, and more dangerous than its marketing admits. Both halves are worth understanding before you trust a product that offers nothing else.
What happens when you click the button
The mechanics are refreshingly simple. When you submit your email address:
- The server generates a long, unguessable single-use token using a cryptographically secure random generator - Conceptually like the 122 random bits in a v4 UUID (you can see what that much randomness looks like with our UUID generator), though good implementations use dedicated tokens of 128 bits or more.
- The server stores a hash of that token alongside your account, a creation timestamp, and an expiry - Typically 5 to 15 minutes.
- It emails you a URL with the token embedded:
https://app.example.com/auth?token=…. - You click. The server hashes the presented token, finds the match, checks that it hasn't expired and hasn't been used, marks it consumed, and issues you a normal login session cookie.
No password is ever created, so there is no password to forget, reuse, phish, or crack. Notice how much rides on the details, though: tokens must be truly random (not sequential or derived from your email), stored hashed (so a database leak doesn't yield live login URLs), aggressively short-lived, and strictly single-use. A magic link that survives multiple clicks or lives for a day is a bearer credential sitting in the world's most-forwarded medium.
What magic links genuinely fix
The password's greatest weaknesses are all reuse-shaped. Billions of leaked credentials circulate from old breaches - Have I Been Pwned has indexed over ten billion compromised accounts - And attackers replay them everywhere, an attack economy explained in our guide to credential stuffing. A magic-link site is simply not a target for any of it: there's no password database to breach, nothing for users to reuse from elsewhere, and no weak Summer2026! to guess.
For product teams, magic links also dissolve the entire forgot-password apparatus - Which was, if you squint, already a magic-link system. Every password site with email recovery is secretly magic-link authenticated: whoever controls the inbox can reset the password and get in. Magic links just remove the pretense (and the support tickets). Sign-up friction drops too, which is why the pattern thrives in products fighting for the first sixty seconds of a user's attention.
Rule of thumb: any account recoverable by email was always only as strong as the inbox. Magic links don't create that dependency - They make it honest.
What magic links quietly break
Total inbox dependency. Your email account becomes a single point of compromise for every magic-link service you use. An attacker in your inbox doesn't need to phish each account - They log in directly, and the confirmation emails land in the very mailbox they control. This concentration makes your email's own protection the whole ballgame: a unique, high-entropy secret (a random passphrase is ideal for a credential you must sometimes type on other devices) plus the strongest second factor available, per our two-factor authentication setup guide.
Phishing isn't solved - It's relocated. A fake site can trigger a real magic-link email and race you to it, or attackers can send lookalike "sign-in link" emails of their own that lead to token-harvesting pages. Users trained that "login links in email are normal" are easier to phish, not harder - The habits in our phishing protection guide matter more under this model, not less.
Email is a leaky channel. Messages traverse multiple servers, sit in forwarding rules, sync to old tablets, and get scanned by corporate security appliances - Some of which click every link to inspect it, burning single-use tokens or, worse, consuming a login. Delivery is also slow and fallible: the login flow now has a spam-folder failure mode.
No offline factor. Unlike a TOTP code, a magic link requires a network round trip and a functioning inbox at login time.
How the passwordless options stack up
| Magic link | Password + TOTP | Passkey | |
|---|---|---|---|
| Something to remember | No | Yes | No |
| Phishing resistance | Weak - Email links are the phish template | Partial - Codes can be relayed | Strong - Origin-bound cryptography |
| Works offline | No | Codes: yes | Yes (local unlock) |
| Single point of failure | Your inbox | Secret + enrolled device | Platform account / device |
| Login speed | Slow (wait for email) | Medium | Fast |
| Breach exposure at the site | Token hashes (short-lived) | Password + TOTP secrets | Public keys only |
The comparison clarifies where magic links sit: they beat passwords alone, lose to a password with app-based 2FA, and are decisively outclassed by passkeys, which deliver the same "nothing to remember" experience with genuine phishing resistance and no email round trip. Our guide to passkeys and the passwordless future explains why the industry's endgame runs through FIDO2 rather than the inbox. Magic links are best understood as a transitional technology: dramatically simpler than passwords to deploy today, available to literally anyone with email, and destined to be a fallback rather than a flagship.
If you build with magic links
For developers adopting the pattern, the security posture lives in the implementation details: 128+ bits of CSPRNG-sourced token entropy, hashed storage, 10-minute expiry, single use with replay rejection, rate limiting per address, and session issuance only in the browser that initiated the request (bind a short code or cookie to the originating session so a link opened elsewhere - Like a security scanner - Can't hijack the flow; many apps show "confirm this code matches" for exactly this reason). Offer a stronger second factor for accounts that grow valuable - TOTP enrollment can ride on our 2FA API - And treat the magic link as the floor, not the ceiling, of your authentication story.
FAQ
Are magic links safer than passwords?
Safer than the passwords people actually use - Reused, weak, phishable - Yes, because they remove the password attack surface entirely. Weaker than a strong unique password plus app-based 2FA, because a magic link is single-factor: control of the inbox is the whole test. The honest comparison depends on which baseline you're leaving.
What if someone gets into my email?
Then every magic-link account you own falls with it, along with most password accounts via reset flows. This is true of almost all consumer authentication, which is why your email deserves your strongest protection: a unique high-entropy credential, phishing-resistant 2FA if offered, and periodic review of forwarding rules and connected apps that attackers love to plant.
Why do magic links expire so fast?
Because the link is a live credential traveling through an unencrypted-at-rest, widely synced medium. A short lifetime shrinks the window in which a forwarded, intercepted, or database-logged link is useful to anyone else. Fast expiry plus single-use consumption are the two properties that make the pattern defensible; a link that still works tomorrow is a vulnerability, not a convenience.
Why does the link sometimes say "already used" when I never clicked it?
Almost always a security tool got there first: corporate email gateways and some antivirus products follow every link in incoming mail to scan the destination, consuming single-use tokens. Well-built services detect automated clicks or bind login completion to your original browser session. If it recurs, check whether your provider offers an alternative like a typed one-time code.
Can I use magic links and still have 2FA?
Yes, and valuable accounts should. The magic link replaces only the password step; a site can still require a TOTP code or hardware key afterward, turning login into "inbox plus enrolled device" - Genuinely two factors. Services that offer magic links with no option to add a second factor are making a simplicity bet you may not want for anything important.