Skip to main content
Version: 1.28 (Current)

Create Auto Login Link

Audience: Low-code Engineers

Skill Prerequisites: Actions, Tokens, Users

Creates a link that signs a user in without a password. Whoever opens the link is signed in as that user and sent to a page you choose. You can limit how many times the link works and when it's valid.

The action saves the link in the DnnSharp_UserManagement_AutoLoginLinks database table and puts the URL in an output token, for example to send it by email.

warning

An auto login link works like a password. Anyone who has it can sign in as the user, with no password and no second factor. By default a link never expires and works any number of times. Always set an End Date and a Number Of Logins. See Security.

Typical Use Cases​

  • Send a one-time link in an email so a user can open a task or approve a request without signing in
  • Send a "magic link" to users who don't have a password yet, for example users created with a random password
  • Give a customer a short-lived link to a status or download page

Don't use it to​

  • Sign in a user who has entered their password. Use User Login instead.
  • Let users reset their password. Use Send User Reset Password Email instead.
  • Give long-term access. Links without an end date stay valid forever.
  • Create links for administrators or other powerful accounts. See Security.
Action NameDescription
User LoginSigns a user in with a username and password.
Send EmailSends the link to the user.
Send User Reset Password EmailSends a password reset link.
Load UserLoads the user, for example to get their ID or email.

Input Parameter Reference​

ParameterDescriptionSupports TokensDefaultRequired
UserThe user the link signs in as. It can be a user ID, an email or a username. In forms and listings you pick a field, or switch to an expression and use a token, for example [UserId].Yesempty stringYes
Redirect To PageThe page to open after the user is signed in. Pick a page, or use an expression with a page ID or page path. If it's empty or not found, the user goes to the home page.YesemptyNo
On Error Redirect To PageThe page to open when the link doesn't work, for example when it's expired. If it's empty, the user goes to the home page. The error message is added in the autoLoginError query string parameter. See When the link doesn't work.YesemptyNo
QueryString ParametersNames and values to add to the query string of the Redirect To Page URL, for example TaskId and [TaskId]. Values support tokens. They aren't URL-encoded.YesemptyNo
Number Of LoginsHow many times the link works. 0 or empty means no limit.Yes0No
Overwrite old linkWhen on, the new link replaces a link that already exists for the same user, so the old link stops working. When off, older links keep working.NofalseNo
Validity period input modeHow you set the dates. Date and Time picker (Simple) shows two date pickers. Custom Date and Time values (DateTokens) takes two text values. Start Date and offset (StartAndOffset) takes a start date and a duration.NoDate and Time pickerNo
Start DateWith Date and Time picker: the date the link starts working. If it's empty, the link works straight away.NoemptyNo
End DateWith Date and Time picker: the date the link expires. If it's empty, the link never expires.NoemptyNo
Start DateWith Custom Date and Time values or Start Date and offset: the date the link starts working, for example [DateTime:Now]. For UTC values use the ISO format, for example [DateTime:Now|o].Yesempty stringYes, in these modes
End DateWith Custom Date and Time values: the date the link expires. Same format as Start Date.Yesempty stringYes, in this mode
OffsetWith Start Date and offset: how long the link is valid after Start Date, as a whole number, for example 24.Yes0Yes, in this mode
Offset UnitWith Start Date and offset: the unit of Offset. Minutes (Minute), Hours (Hour) or Days (Day).NoMinutesNo
Output Token NameThe name of the token to save the link in, for example LoginLink.Noempty stringYes

Output Parameters Reference​

TokenDescription
[<Output Token Name>]The link as a relative URL, for example /API/AutoLogin/<code>.
[<Output Token Name>:Absolute]The full link with the current site address, for example https://example.com/API/AutoLogin/<code>. Use this one in emails. It starts with https:// only when SSL is enabled for the site.
  1. The action finds the user and saves a new link record with the user ID, target page, query string, number of logins and dates.
  2. It builds a code from a new random value and the error page, and encrypts it with the site's key. Only a hash of the random value is stored in the table.
  3. When someone opens the link, the site checks the code, the number of logins used, and the dates.
  4. If everything's fine, it signs the visitor in as the user with a persistent login cookie, counts the login, and redirects to Redirect To Page with the query string.

If the visitor is already signed in as someone else, they're signed in as the link's user instead.

Links created by older versions, which ended in a plain code, still work.

The visitor is sent to On Error Redirect To Page, or the home page, with the reason in the autoLoginError query string parameter. Read it with the [QueryString:autoLoginError] token to show a friendly message.

MessageCause
Number of logins reached.The link was used Number Of Logins times.
The link is not available yet, it will be active from <date>.Start Date is in the future.
The link has expired, it has been deactivated on <date>.End Date has passed.
Invalid or non-existing login link.The link was replaced with Overwrite old link, deleted, or never existed.
Something went wrong while trying to process the used AutoLogin link.The code couldn't be decrypted, for example because it was cut off or changed.

Security​

  • The link is the key. It can't be guessed, but anyone who gets it, for example from a forwarded email, a shared screen or browser history, can sign in as the user. Treat it like a password.
  • Set limits. By default there's no end date and no limit on logins. Use a short validity period and set Number Of Logins, usually to 1.
  • Admin accounts aren't blocked. The help text in the action says you can't log in as an administrator, but that check was removed. The link works for any user it finds. Don't create links for administrators or other powerful accounts.
  • Control who picks the user. Any action flow that runs this action can create a link for any user. Never take User from input a visitor can change, such as a query string, a form field or an API parameter. Otherwise anyone could get a link for any account, including yours.
  • Old links stay valid. Creating a new link doesn't cancel older ones unless Overwrite old link is on. To cancel links, delete their rows from the DnnSharp_UserManagement_AutoLoginLinks table.
  • Email scanners may open links. Some mail systems open links to check them before the user does. That can use up a one-time link.
  • Send the link only to the user. Send it to the email address on the account, not to an address typed into a form.

Considerations​

  • Dates. In Custom Date and Time values and Start Date and offset modes, the values are converted to UTC before they're saved. A value without a time zone is read as server time. The link is checked against the current UTC time.
  • End date in the past. The action fails with You cannot set the end date in the past. An Offset of 0 gives an end date equal to the start date, so it fails too.
  • Invalid dates. In the text modes, a value that isn't a date fails with Invalid date format for Start Date: ... or ... End Date: .... Custom Date and Time values needs both dates.
  • User not found. The action fails with Creating login link failed because the specified user does not exist. A number is always looked up as a user ID, then the value is tried as an email, then as a username.
  • Query string values aren't URL-encoded. Avoid spaces, & and = in them, or encode them yourself.

Examples​

tip

To understand how to use the below examples, please see Running Examples.

This action creates a link for the user in the UserId token. It works once, for 24 hours from now, and opens page 42 with the task ID in the query string. A new link replaces the user's previous one. The full URL is in [LoginLink:Absolute], ready for a Send Email action.

{
"Title": "Create Auto Login Link",
"ActionType": "UserManagement_CreateAutoLoginLink",
"Description": "One-time link to the task page",
"Parameters": {
"User": "[UserId]",
"RedirectToPage": "42",
"QueryString": [
{
"name": "TaskId",
"value": "[TaskId]"
}
],
"NumberOfLogins": "1",
"OverwriteLastLink": true,
"ValidityPeriodInputType": "StartAndOffset",
"StartDateToken": "[DateTime:Now|o]",
"EndDateOffset": "24",
"EndDateOffsetType": "Hour",
"OutputTokenName": "LoginLink"
}
}

This action creates a link that works up to three times between two dates taken from tokens, for example the start and end of an event. If the link doesn't work, the user goes to page 43, which can show [QueryString:autoLoginError].

{
"Title": "Create Auto Login Link",
"ActionType": "UserManagement_CreateAutoLoginLink",
"Description": "Link valid during the event",
"Parameters": {
"User": "[Email]",
"RedirectToPage": "42",
"OnErrorRedirectToPage": "43",
"NumberOfLogins": "3",
"OverwriteLastLink": false,
"ValidityPeriodInputType": "DateTokens",
"StartDateToken": "[EventStart]",
"EndDateToken": "[EventEnd]",
"OutputTokenName": "EventLink"
}
}

Revised 09/28/2026