Docs / Basics
Passwords & signing in
Signing in with your email address, choosing a password, and the reset link when you have forgotten it.
You sign in to OrderDen with your email address and a password, or with Google where the server offers it. There are no usernames — the address you signed up with is the whole of your identity — so there is nothing to recover except the password itself.
Choosing a password
At least eight characters, and you type it twice wherever you set one: on signup, on the reset page, and in the internal console. The second box is checked on the server, not just in the browser, so a mismatch never gets through.
Length beats cleverness. A phrase you can remember and nobody else would guess is worth more than a short one with punctuation in it — and if you use a password manager, let it generate one and forget about it entirely.
Forgotten password
- On the sign-in page, follow Forgot your password?
- Type the email address you sign in with and press Email me a link.
- The page answers "If that address has an account, we have sent a link to reset the password." — the same sentence either way, deliberately: a page that said "no account found" would tell anybody who asked which addresses are registered here.
- Open the email and follow the link. Type the new password twice, and you are taken to the sign-in page to use it.
The link works once and expires an hour after it is sent. Clicking an old link, or the same link twice, lands on a page that says so and offers to email a new one. Nothing has changed on the account at that point — asking for a link does not disturb the password you already have, so an unexpected reset email is safe to ignore.
Setting a new password signs out every device. That is the point of resetting one: if somebody else had the old password, their session goes with it. You will sign in again on your phone and anywhere else you were signed in.
The reset shows up in your workspace's activity trail — "…reset their password" — for everyone who shares the workspace, in the same way a two-factor change does. Asking for a link is not recorded anywhere a workspace can see it: the person typing an address has not proved they are anybody yet.
If nothing arrives
- Check the spam folder — the message comes from OrderDen itself, not from your workspace's own mail server.
- Make sure you typed the address you actually signed up with. A message is only sent to an address that has an account, and the page says the same thing either way.
- Too many reset links have been requested for that address means exactly what it says: a handful in a quarter of an hour is the limit, and the same cap applies to whoever is asking, whatever addresses they name. Wait a few minutes and try again.
- On a self-hosted OrderDen with no platform mailer set up, the page says so outright — resets need a mail server. Whoever runs the server needs to configure one.
Changing a password you still know
Signed in, there is nothing to reset — but the reset flow works for this too: sign out, ask for a link, and set the new one. Second factors, passkeys and your signed-in devices live in Roles, permissions, two-factor and sessions.
Two-factor authentication
A password is one thing you know. Turning on two-factor authentication adds one thing you have, and it survives a leaked password entirely. If your workspace holds client addresses and money, it is worth the two minutes: set it up.
Everything on this page is in the free tier — one person, the whole product, no card.
Start free