Magic link limits

How login abuse controls work and how operators recover when a link does not arrive.

How the controls work

Magic-link requests always return a generic success response, so callers cannot enumerate which emails exist. Under the controlled demo policy, requests for unknown emails are a silent no-op — no link is created or sent. Tokens themselves are single-use and short-lived, and delivery is asynchronous through the outbox, so repeated clicking does not speed anything up. Separately, the /judge access-code endpoint is rate limited to 10 attempts per 5 minutes per IP (best-effort, in-memory per Worker isolate) and answers 429 when exceeded.

What you should do

Request one link and wait for the outbox drain. Use the latest email only. Do not script login against production without a dedicated test path. Local e2e may use AUTH_DEV_OUTBOX=1 to read links without SMTP — never enable that as a production default.

  1. Stop repeated clicks on Request link for a few minutes.
  2. Check the inbox and spam for the most recent SpeakerOps message.
  3. Open the latest link once in a fresh browser tab.
  4. If still blocked, ask an admin to confirm your account or membership exists and that the host is healthy.

Admin checks

Verify EMAIL provider configuration, queue drain for auth.magic_link jobs, and that BOOTSTRAP_ADMIN_EMAIL matches the operator address (or that the operator already has a user and membership — unknown emails cannot self-register). Check /health on the Worker for basic liveness.