Send Magic Link
Parameters
Example
React Component
How It Works
- User enters their email
- SDK sends request to Gately API
- Gately sends email with secure link
- User clicks link in email
- Link opens your app (on the
redirectTodomain), which verifies the token - SDK automatically logs user in
Email Template
The magic link email includes:- Your project name/branding
- Login button with secure link
- Link expiry notice (15 minutes)
- Security notice
Link Expiry
Magic links expire after 15 minutes. If a user clicks an expired link:- They see an error message
- They’re prompted to request a new link
Security
Magic links are:- Single-use (invalidated after first use)
- Time-limited (expire after 15 minutes)
- Random, unguessable tokens tied to one member of one project
- Only sent to links on your project’s allowed redirect URLs. A
redirectToon any other domain is rejected and no email is sent, so nobody can trick Gately into emailing your members a login link that points to their site
New vs Existing Users
The response is the same in both cases so the endpoint can’t be used to check which emails have accounts. Create the member first (for example with signup) if they don’t have an account yet.
Error Handling
Rate Limiting
Magic link requests are rate limited to prevent abuse:- 3 requests per email per 10 minutes
- 10 requests per IP per 10 minutes