# Sign in

> How you sign in to sanda with a one-time email link or Google or Apple, how long a session lasts, and how to sign out of every browser.

There is no password to set or lose. You sign in with a one-time link sent to your work email, or with Google or Apple where the sign-in page offers them. If you have turned on [two-step verification](https://docs.sanda-os.com.au/workspace/two-step), sanda then asks for a code from your authenticator app.

## Sign in with an email link

:::steps
1. **Ask for a link.** Go to the [sign-in page](https://console.sanda-os.com.au/signin), enter your **Work email** and press **Email me a sign-in link**.
2. **Open the email.** The link works once and expires in 30 minutes.
3. **Press the button.** The link opens a page headed "Finish signing in". Press **Continue to sanda** to go to your workspace.
:::

You must press the button because the link on its own does not sign anyone in. Some email systems open every link in a message to scan it for threats. If opening the link signed you in, a scanner could use up your link before you did, or someone could send you a link that signs you in to their workspace. Nothing happens until a person presses the button.

### If the email does not arrive

- Check your spam folder, and give it a minute.
- Ask for another link. Each new link cancels every earlier link you have not used, so only the newest works.
- Use the address your workspace knows you by. If that address has no sanda workspace, the page still says a link is on its way and none is sent. This is deliberate: it stops the form being used to find out who is a customer.
- Do not ask for many links in a row. sanda limits how many it sends to one address in an hour, and the page looks the same when it holds one back. Wait and try once.
- If a link has expired or been used, the sign-in page says so and does not send a new one by itself. If you asked for the link in the same browser, your address is already in the field, so pressing **Email me a sign-in link** sends a new one. Otherwise enter your address first.

If your address has no workspace at all, [start a free trial](https://docs.sanda-os.com.au/get-started) instead. An invited teammate signs in for the first time from their invitation. See [Members and roles](https://docs.sanda-os.com.au/workspace/members-and-roles).

## Sign in with Google or Apple

When your sign-in page offers **Continue with Google** or **Continue with Apple**, it shows them above the email field. If you do not see them, use an email link.

- **The address must match.** The first time you use one, sanda links it to your existing account by matching the email address, and only if Google or Apple has confirmed that address is yours. From then on, both the provider and email links work.
- **It does not create a workspace.** If the address has no sanda workspace, you are sent to sign-up with your email filled in.
- **Two-step still applies.** A provider proves your email address. It does not prove your phone, so sanda still asks for your authenticator code if you have one.
- **See what is linked.** **Settings · Security** shows the provider linked to your account under **Connected sign-ins**.

If you see "That account is already connected to a different sanda sign-in", that Google or Apple account belongs to another sanda account. Use your email link instead, or write to sanda support.

## Sessions

Signing in starts a session in your browser. A session ends after 14 days of not being used, or 30 days after you signed in, whichever comes first. Using sanda does not extend the 30 days.

The session lives in a cookie that the browser sends only to the console, only over a secure connection, and that scripts on the page cannot read. sanda stores only a scrambled form of it.

### See where you are signed in

**Settings · Security** has a **Your sessions** panel. It lists every browser you are signed in on, across every workspace you belong to, newest activity first. Each row shows the browser and platform, the first two parts of the network address (the only part sanda stores against a session), when you signed in and when the session was last active. Your current browser is marked **this device**, and sessions in another workspace are marked **another workspace**.

- Press **Sign out** on a row to end that session.
- Press **Sign out everywhere else** to end every session except the one you are using. It also cancels any two-step sign-in that is waiting for a code.

Use these if you left a laptop signed in somewhere. An owner or admin who removes you from a workspace also ends your sessions in it straight away.

### Sign out

Press the **Sign out** icon next to your name at the foot of the left rail. It ends the session in this browser and cancels any two-step sign-in that browser had open.

## If you cannot get in

- Lost your phone or authenticator? See [Two-step verification](https://docs.sanda-os.com.au/workspace/two-step).
- No email, or an address that no longer works? Ask your owner or admin to invite your new address, or write to sanda support at hello@sanda-os.com.au.

:::links
- [Two-step verification](https://docs.sanda-os.com.au/workspace/two-step): Add a code from an authenticator app.
- [Security](https://docs.sanda-os.com.au/workspace/security): How sanda protects sign-in and sessions.
- [Privacy and your data](https://docs.sanda-os.com.au/workspace/privacy): The policy you accept the first time you sign in.
:::
