Create Auto Login Link
Audience:
Low-code EngineersSkill Prerequisites:
Actions,Tokens,Users
Creates a link that signs a user in without a password. Whoever opens the link is signed in as that user and sent to a page you choose. You can limit how many times the link works and when it's valid.
The action saves the link in the DnnSharp_UserManagement_AutoLoginLinks database table and puts the URL in an output token, for example to send it by email.
An auto login link works like a password. Anyone who has it can sign in as the user, with no password and no second factor. By default a link never expires and works any number of times. Always set an End Date and a Number Of Logins. See Security.
Typical Use Cases
- Send a one-time link in an email so a user can open a task or approve a request without signing in
- Send a "magic link" to users who don't have a password yet, for example users created with a random password
- Give a customer a short-lived link to a status or download page
Don't use it to
- Sign in a user who has entered their password. Use User Login instead.
- Let users reset their password. Use Send User Reset Password Email instead.
- Give long-term access. Links without an end date stay valid forever.
- Create links for administrators or other powerful accounts. See Security.
Related Actions
| Action Name | Description |
|---|---|
| User Login | Signs a user in with a username and password. |
| Send Email | Sends the link to the user. |
| Send User Reset Password Email | Sends a password reset link. |
| Load User | Loads the user, for example to get their ID or email. |
Input Parameter Reference
| Parameter | Description | Supports Tokens | Default | Required |
|---|---|---|---|---|
| User | The user the link signs in as. It can be a user ID, an email or a username. In forms and listings you pick a field, or switch to an expression and use a token, for example [UserId]. | Yes | empty string | Yes |
| Redirect To Page | The page to open after the user is signed in. Pick a page, or use an expression with a page ID or page path. If it's empty or not found, the user goes to the home page. | Yes | empty | No |
| On Error Redirect To Page | The page to open when the link doesn't work, for example when it's expired. If it's empty, the user goes to the home page. The error message is added in the autoLoginError query string parameter. See When the link doesn't work. | Yes | empty | No |
| QueryString Parameters | Names and values to add to the query string of the Redirect To Page URL, for example TaskId and [TaskId]. Values support tokens. They aren't URL-encoded. | Yes | empty | No |
| Number Of Logins | How many times the link works. 0 or empty means no limit. | Yes | 0 | No |
| Overwrite old link | When on, the new link replaces a link that already exists for the same user, so the old link stops working. When off, older links keep working. | No | false | No |
| Validity period input mode | How you set the dates. Date and Time picker (Simple) shows two date pickers. Custom Date and Time values (DateTokens) takes two text values. Start Date and offset (StartAndOffset) takes a start date and a duration. | No | Date and Time picker | No |
| Start Date | With Date and Time picker: the date the link starts working. If it's empty, the link works straight away. | No | empty | No |
| End Date | With Date and Time picker: the date the link expires. If it's empty, the link never expires. | No | empty | No |
| Start Date | With Custom Date and Time values or Start Date and offset: the date the link starts working, for example [DateTime:Now]. For UTC values use the ISO format, for example [DateTime:Now|o]. | Yes | empty string | Yes, in these modes |
| End Date | With Custom Date and Time values: the date the link expires. Same format as Start Date. | Yes | empty string | Yes, in this mode |
| Offset | With Start Date and offset: how long the link is valid after Start Date, as a whole number, for example 24. | Yes | 0 | Yes, in this mode |
| Offset Unit | With Start Date and offset: the unit of Offset. Minutes (Minute), Hours (Hour) or Days (Day). | No | Minutes | No |
| Output Token Name | The name of the token to save the link in, for example LoginLink. | No | empty string | Yes |
Output Parameters Reference
| Token | Description |
|---|---|
[<Output Token Name>] | The link as a relative URL, for example /API/AutoLogin/<code>. |
[<Output Token Name>:Absolute] | The full link with the current site address, for example https://example.com/API/AutoLogin/<code>. Use this one in emails. It starts with https:// only when SSL is enabled for the site. |
How the link works
- The action finds the user and saves a new link record with the user ID, target page, query string, number of logins and dates.
- It builds a code from a new random value and the error page, and encrypts it with the site's key. Only a hash of the random value is stored in the table.
- When someone opens the link, the site checks the code, the number of logins used, and the dates.
- If everything's fine, it signs the visitor in as the user with a persistent login cookie, counts the login, and redirects to Redirect To Page with the query string.
If the visitor is already signed in as someone else, they're signed in as the link's user instead.
Links created by older versions, which ended in a plain code, still work.
When the link doesn't work
The visitor is sent to On Error Redirect To Page, or the home page, with the reason in the autoLoginError query string parameter. Read it with the [QueryString:autoLoginError] token to show a friendly message.
| Message | Cause |
|---|---|
Number of logins reached. | The link was used Number Of Logins times. |
The link is not available yet, it will be active from <date>. | Start Date is in the future. |
The link has expired, it has been deactivated on <date>. | End Date has passed. |
Invalid or non-existing login link. | The link was replaced with Overwrite old link, deleted, or never existed. |
Something went wrong while trying to process the used AutoLogin link. | The code couldn't be decrypted, for example because it was cut off or changed. |
Security
- The link is the key. It can't be guessed, but anyone who gets it, for example from a forwarded email, a shared screen or browser history, can sign in as the user. Treat it like a password.
- Set limits. By default there's no end date and no limit on logins. Use a short validity period and set Number Of Logins, usually to
1. - Admin accounts aren't blocked. The help text in the action says you can't log in as an administrator, but that check was removed. The link works for any user it finds. Don't create links for administrators or other powerful accounts.
- Control who picks the user. Any action flow that runs this action can create a link for any user. Never take User from input a visitor can change, such as a query string, a form field or an API parameter. Otherwise anyone could get a link for any account, including yours.
- Old links stay valid. Creating a new link doesn't cancel older ones unless Overwrite old link is on. To cancel links, delete their rows from the
DnnSharp_UserManagement_AutoLoginLinkstable. - Email scanners may open links. Some mail systems open links to check them before the user does. That can use up a one-time link.
- Send the link only to the user. Send it to the email address on the account, not to an address typed into a form.
Considerations
- Dates. In Custom Date and Time values and Start Date and offset modes, the values are converted to UTC before they're saved. A value without a time zone is read as server time. The link is checked against the current UTC time.
- End date in the past. The action fails with
You cannot set the end date in the past.An Offset of0gives an end date equal to the start date, so it fails too. - Invalid dates. In the text modes, a value that isn't a date fails with
Invalid date format for Start Date: ...or... End Date: .... Custom Date and Time values needs both dates. - User not found. The action fails with
Creating login link failed because the specified user does not exist.A number is always looked up as a user ID, then the value is tried as an email, then as a username. - Query string values aren't URL-encoded. Avoid spaces,
&and=in them, or encode them yourself.
Examples
To understand how to use the below examples, please see Running Examples.
1. One-time link valid for 24 hours
This action creates a link for the user in the UserId token. It works once, for 24 hours from now, and opens page 42 with the task ID in the query string. A new link replaces the user's previous one. The full URL is in [LoginLink:Absolute], ready for a Send Email action.
{
"Title": "Create Auto Login Link",
"ActionType": "UserManagement_CreateAutoLoginLink",
"Description": "One-time link to the task page",
"Parameters": {
"User": "[UserId]",
"RedirectToPage": "42",
"QueryString": [
{
"name": "TaskId",
"value": "[TaskId]"
}
],
"NumberOfLogins": "1",
"OverwriteLastLink": true,
"ValidityPeriodInputType": "StartAndOffset",
"StartDateToken": "[DateTime:Now|o]",
"EndDateOffset": "24",
"EndDateOffsetType": "Hour",
"OutputTokenName": "LoginLink"
}
}
2. Link valid between two dates
This action creates a link that works up to three times between two dates taken from tokens, for example the start and end of an event. If the link doesn't work, the user goes to page 43, which can show [QueryString:autoLoginError].
{
"Title": "Create Auto Login Link",
"ActionType": "UserManagement_CreateAutoLoginLink",
"Description": "Link valid during the event",
"Parameters": {
"User": "[Email]",
"RedirectToPage": "42",
"OnErrorRedirectToPage": "43",
"NumberOfLogins": "3",
"OverwriteLastLink": false,
"ValidityPeriodInputType": "DateTokens",
"StartDateToken": "[EventStart]",
"EndDateToken": "[EventEnd]",
"OutputTokenName": "EventLink"
}
}
Revised 09/28/2026