Getting into the portal

Signing in, being invited by a colleague, customers registering themselves, a forgotten password, and signing out.

Signing in

The customer sign-in, at /portal/login. The customer sign-in, at /portal/login. "Create an account" is there only while customers may register themselves.

Customers sign in at /portal/login on the business's address. Type your Email address and Password and press Sign in. Tick Keep me signed in on a computer that is yours alone. You land on the overview, or on the portal page you were trying to open.

Give your customers the /portal/login address. Somebody who is not signed in and opens /portal, or a link to a page inside the portal, is sent there too, and taken on to the page they asked for once they have signed in. The staff sign-in at /login does not accept a customer's email and password.

When signing in does not work

You seeWhy
The usual "credentials do not match" messageA wrong email address or password — or an account that has no portal access: no password set, switched off, or a member of staff. All of these get the same answer, so nobody can find out from outside which addresses have accounts.
A message to wait before trying againFive wrong attempts for the same address from the same computer lock it out for a while.
The customer portal is closed at the moment. Please contact us if you need anything.The business has switched off Allow customers to sign in. The message stays on the sign-in page, Google and Facebook refuse too, and anybody already signed in is signed out on their next click. Nothing is deleted.
The Check your inbox pageYou registered and have not yet opened the confirmation link (shown only once the password is right).
Your registration is waiting for approval. We will email you as soon as it is approved.The business approves new registrations by hand, and has not yet.

Each attempt, successful or not, is recorded in the business's login history. Both portal forms also carry a box people never see; a bot that fills in every box is turned away without being told why. reCAPTCHA can be added on top, for the forms ticked under Integrations ("Customer portal sign-in" and "Customer portal registration").

The portal is a separate door. Customers sign in at /portal/login, staff at /login, and neither can use the other's. A member of staff who opens a portal page is sent to their own dashboard; a contact who tries an /admin address is refused.

Who may get in

A contact can sign in once they have a password, are switched on, and, if they registered themselves, have finished registering. There are three ways to get a password:

The switches that decide this are on the Access card of Settings → Customer portal:

SwitchWhat it does
Allow customers to sign inOn as shipped. Off closes the portal to everybody, as described above.
Allow customers to register themselvesOff as shipped. Adds Create an account to the sign-in page. Only works while signing in is allowed.
Require email verificationOn as shipped. A new registration is emailed a link, and cannot sign in until it is opened. The link works for 1 to 168 hours (48 as shipped).
Require approval by staffOff as shipped. New registrations wait in a queue until a member of staff approves or declines them.

Invited by a colleague

Choose your password: the page the invitation link opens. Choose your password: the page the invitation link opens.

When a primary contact adds you under My account → Contacts, you are emailed Invitation to the customer portal. Its link opens Choose your password, with your Email address already filled in.

  1. Type a Password (at least eight characters) and again under Confirm password.
  2. Press Set my password. You are taken to the sign-in page: Your password is set. You can sign in now.

The link works once and for three days. An old, used or mistyped link — or one for a contact who has since been switched off — is answered This link is not valid any more. Ask whoever invited you to send it again.; Send again on their Contacts list emails a fresh one. Opening the link also confirms that the email address is yours.

Registering yourself

Create an account, here asking for a company name, phone and country, with the terms to accept. Create an account, here asking for a company name, phone and country, with the terms to accept.

While the business allows it, Create an account on the sign-in page opens /portal/register; otherwise that address answers "not found". The form always asks for First name, Last name, Email address, Password and Confirm password. The business chooses on the Sign-up form card whether it also asks, or requires, company name, phone, website, VAT number, address, city, state / region, postcode and country; its own custom fields marked visible to the client are added too. When Privacy / GDPR asks for the terms to be accepted, an I accept the terms and conditions. box (with Read them) must be ticked. Press Create my account.

  1. A new customer is created with you as its primary contact. Without a company name, the customer is you, under your own name.
  2. With verification on, you see Check your inbox and are emailed Confirm your email address. Open the link in it.
  3. With approval on, the registration then waits for the business. You see Thank you, your email address is confirmed. We will email you as soon as your account has been approved., and are emailed again when it is approved or declined.
  4. Otherwise you are told You can sign in now. Sign in at /portal/login with the password you chose.
Check your inbox: where a new registration lands, with a button to send the link again. Check your inbox: where a new registration lands, with a button to send the link again.

Check your inbox says how many hours the link works. If nothing arrives, look in the spam folder, or type the address and press Send the link again: If that address is waiting to be confirmed, a new link is on its way. A link that has run out, or was not copied in full, opens This link has run out with the same button. A link that has already been used takes you to the sign-in page: Your email address is already confirmed.

A confirmation link that has run out: ask for a new one. A confirmation link that has run out: ask for a new one.
A registration never joins an existing company. Typing the name of one of the business's customers creates a separate new customer. When a registration looks like a customer already on file — the same company name, or a contact with the same email domain (free mail providers such as Gmail are ignored) — the business is told, and merges the details by hand. If you work for a company that is already a customer, ask its primary contact to add you instead.
The form never says whether an address is already in use. Whatever is typed, the page that follows is the same. Nothing is created for an address that already has an account; instead its owner is emailed "somebody tried to register with your address" (at most once an hour). A registration still waiting for its confirmation link is simply sent the link again.

The registration queue

For the business: Customers → Registrations lists every registration, filtered by Waiting for approval, Email not confirmed, Approved and Declined, and needs the "create customers" permission.

ActionWhat happens
ApproveThe contact can sign in, and is emailed the "Portal registration approved" template with a link to the portal.
DeclineYou give a reason, which is emailed word for word ("Portal registration declined"). The contact and the customer the registration created are then removed — unless the customer has been invoiced or given other contacts since. A registration that never confirmed its address can be declined without a reason, and nobody is written to.

The registration stays on the list as the record of who asked and what was decided. The queue is described in full under Portal registrations.

A forgotten password

  1. On the sign-in page, press Forgot password? beside Password.
  2. On Reset your password, enter your email address and press Send reset link. The page says If that address belongs to an account, a reset link is on its way. whether or not it does, so nobody can use it to find out who has an account.
  3. Open the link in the email within 60 minutes, choose a new password, type it again, and save. You are taken back to the portal sign-in: Your password has been reset. Please sign in.

It is the same page staff use (Resetting a password); Back to sign in on it returns you to the portal. No email is sent for a contact who has been switched off. The business can also set a new password on the contact's record (Customers → the customer → Contacts → edit, under Portal access), and a contact can sign in with Google or Facebook where the business has set them up.

A colleague who was invited and never chose a password is different: the primary contact presses Send again on the Contacts list. Once signed in, anybody can choose a new password under My account → Password.

Signing out

Open the menu under your name at the top right and choose Sign out. You are taken back to the portal sign-in page.

The emails

Five templates are added under Email templates, in the Customer portal group, and can be reworded there: Confirm your email address, Portal registration approved, Portal registration declined, Somebody tried to register with your address and Invitation to the customer portal.

What a contact can do once inside — My account, colleagues and what each may see, privacy — is on Your account and privacy.

Addresses on this page

For reference and for anyone scripting against the panel. Everything here needs a customer contact signed in to the portal; the addresses that open without signing in are marked.

MethodAddressWhat it does
GETportal/loginThe customer sign-in page. Opens without signing in.
POSTportal/loginSigns a contact in. Opens without signing in.
POSTportal/logoutSign out.
GETportal/registerThe Create an account form, while registration is allowed (404 otherwise). Opens without signing in.
POSTportal/registerSends the registration. Opens without signing in.
GETportal/register/check-your-inboxCheck your inbox. Opens without signing in.
POSTportal/register/resendSend the link again. Opens without signing in.
GETportal/register/verify/{registration}/{hash}The confirmation link in the email; signed and timed. Opens without signing in.
GETportal/password/set/{token}Choose your password, from an invitation. Opens without signing in.
POSTportal/password/setSaves the chosen password. Opens without signing in.