Ways to sign in

A one-time email code, a passkey, Google, GitHub or Microsoft, or your organization's identity provider.

Four routes, and you can use more than one.

One-time email code

Enter your email address and a short code arrives. Type it in the same browser tab.

The code expires quickly, is bound to the browser session that requested it, and is discarded once used. Repeated wrong entries invalidate it, and you request a fresh one.

The session binding is worth understanding: somebody who reads the code over your shoulder cannot use it from their own device. That is stronger than an authenticator app code, which works anywhere.

This method works for every account however it was created, which makes it the universal fallback. If you cannot remember how you signed up, use this.

A passkey

Your device’s biometrics or a hardware key. Nothing to type and nothing to phish. See Passkeys.

Google, GitHub, or Microsoft

You are redirected to the provider, authenticate there, and return. Your credentials are handled entirely by the provider and never seen or stored by us.

The security of your Screenly account then depends on the security of that account, so strong authentication there protects Screenly too.

If you lose access to the provider, a one-time email code still gets you in.

Your organization’s identity provider

SAML single sign-on, on Enterprise. Your organization’s credentials, session policies, and multi-factor rules apply automatically, and removing somebody in the identity provider removes their Screenly access at the same moment.

Configured per workspace by the Owner, not per account. See Single sign-on.

Using more than one

Sign in a second way with the same email address and Screenly offers to merge the accounts. After merging, every method associated with that address works, so you can use Google one day and a code the next.

Merging is by email address. If your Google address differs from your Screenly address, no merge is offered and you get a second, separate account.

Methods are per person, not per workspace. One colleague can use Google, another Microsoft, another a code, in the same workspace.

Why there are no passwords

Most account compromises come down to a password reused, guessed, or leaked somewhere else. Removing them removes that entire class: there is nothing to stuff, nothing to phish, and nothing to write down.

The trade is that email becomes the trust anchor. That was already true, since email was always the password reset path, so passwordless removes a credential rather than adding an exposure. If you want to strengthen it, strengthen the mailbox.

Type to search the documentation