Set client portal sign-in rules
Choose when client login codes expire and how long client sessions last.
Use Company Settings → Client Portal Security to set client sign-in rules for your branded portal. Clients use an email code. These rules do not change team sign-in.
The company owner can save these rules. Owners and admins can view them.
Before you change the rules
Clients may need to sign in again. Saving expires unused codes. Shorter limits may end a client’s current sign-in. The client can ask for a new code. Longer limits apply only to new sign-ins.
Choose a security profile
- Open Company Settings → Client Portal Security.
- Stay on the Settings tab.
- Under Security profile, choose Recommended, Maximum Security, or Custom.
- Review the code and session settings below the profile.
- Select Save and confirm the change.
- Use the code asked for on the page. It may come from an app, a backup code, or email.
Recommended is the starting choice for new companies. Codes expire after 10 minutes. A client is signed out after 7 days with no portal use or 30 days from sign-in, whichever comes first. Up to five sign-ins can stay valid for each client email.
Maximum Security uses codes that expire in 5 minutes. It signs clients out after 15 minutes with no portal use or 12 hours from sign-in. Each client email can have two valid sign-ins. Clients sign in more often.
An existing company may have older rules. Check the values on your page before you save a new choice.
Adjust individual settings
Choosing Custom lets the owner set:
- Code lifetime: how long a sent code works.
- Expire earlier codes on resend: whether a new code ends older unused codes once the email is sent.
- Sign out after inactivity: how long a client can go without using the portal. None turns off this limit.
- Require sign-in again after: a set time from sign-in, even if the client keeps using the portal.
- Session limit per client: how many sign-ins can stay valid for one email. A new sign-in ends the oldest one when the limit is reached.
These limits cover the whole branded portal. A client may open more than one account with one sign-in. The limit is per email.
What clients see
Clients still open your branded portal with their email. The sign-in page sends a six-digit code. The email button can also sign them in. A client may need a new code after you save rules or end a sign-in.
Fix a common problem
If Save is not shown, check your role. Only the owner can change these rules.
If the check expires or the rules changed, refresh the page. Review the values and try again. You may need to wait a short time before you can ask for another email code.