Forgot Password

Reset your password using a secure magic link sent to your email

Co-authored by
Dien BasseyRHEMA Nigeria
Joshua AdamsRHEMA Nigeria

Overview

The Forgot Password feature allows you to regain access to your account if you've forgotten your password. The system sends a secure magic link to your email address, which you can use to sign in and optionally set a new password.

How It Works

Instead of traditional password reset forms, the Partners application uses magic links for password recovery:

  • No Password Required: Magic link signs you in instantly
  • Secure: Unique, one-time use token
  • Time-Limited: Link expires in 1 hour
  • Email Verified: Confirms you have access to account email

Magic links provide secure, passwordless authentication. You can sign in with the link and continue working, or change your password once logged in.

Step-by-Step Process

  1. Navigate to Login Page

    • Go to partners.rhema.app/auth/login
    • See "Forgot your Password?" link
  2. Click Forgot Password Link

    • Located below password field
    • Redirects to forgot password page
  3. Enter Your Email Address

    • Type your registered work email
    • Example: john.doe@rhemanigeria.com
    • Must match account email exactly
  4. Click "Send Magic Link" Button

    • Button shows loading state
    • Wait for confirmation message
    • Don't click multiple times
  5. Confirmation Screen

    • "Check Your Email" message appears
    • Shows email address where link was sent
    • Instructions displayed
  1. Check Your Email Inbox

    • Look for email from RHEMA Apps
    • Subject: "Password Reset" or similar
    • Check spam folder if not in inbox
  2. Open the Email

    • Read the message
    • Verify sender address
    • Note expiration time (1 hour)
  3. Click the Magic Link

    • Blue button or link in email
    • Opens in browser automatically
    • One-time use only
  4. Automatic Sign In

    • Link validates your identity
    • Signs you in automatically
    • Redirects to dashboard or reset password page
  5. Optional: Change Password

    • If redirected to reset password page
    • Set new password if desired
    • Or continue with current password using magic links

Forgot Password Page Features

Email Input Field

What to Enter:

  • Your registered work email address
  • Full email (user@domain.com format)
  • Exactly as registered in system

Validation:

  • Must be valid email format
  • Required field (cannot be empty)
  • Email must exist in system

Error Handling:

  • Invalid format: Prompts for correction
  • Email not found: Still shows success (security)
  • Empty field: Validation error

Even if email doesn't exist in system, success message shown to prevent email enumeration attacks. You'll only receive email if account exists.

Button States:

  • Default: "Send Magic Link"
  • Loading: "Sending..." with spinner
  • Disabled: During processing

After Clicking:

  1. Validates email format
  2. Shows loading state
  3. Sends email if account exists
  4. Displays success screen

Success Screen

After requesting a magic link, you see:

Confirmation Message

Displays:

  • "Check Your Email" heading
  • Email address where link was sent
  • Instructions for next steps
  • Link expiration time (1 hour)

Action Options

Try Different Email:

  • If you entered wrong email
  • Returns to email entry form
  • Allows correction

Return to Home:

  • Button to navigate away
  • If you want to wait elsewhere
  • Can return later

Sign In Link:

  • If you remembered your password
  • Quick link back to login page
  • No need to complete reset

Email Content

Subject Line: "Password Reset" or "Magic Link"

Email Body:

  • Greeting with your name
  • Explanation of magic link
  • Blue "Sign In" button or link
  • Text version of link (backup)
  • Expiration time warning
  • Security reminders

Email Security

What to Check:

  • Sender: official@rhemanigeria.com (or similar)
  • Personalization: Addresses you by name
  • Recent: Sent within minutes of request
  • Professional: Proper formatting and branding

Red Flags (Don't Click):

  • Sender: unknown or suspicious address
  • Content: Requests additional information
  • Timing: Didn't request reset recently
  • Links: Go to unknown domains
  • Errors: Poor grammar or formatting

Never click magic links you didn't request. Contact your administrator if you receive unexpected password reset emails.

Common Scenarios

Forgot Password Before Work

Scenario: Can't remember password at start of workday

Steps:

  1. Go to login page
  2. Click "Forgot your Password?"
  3. Enter work email
  4. Click "Send Magic Link"
  5. Check email on phone or other device
  6. Click magic link
  7. Sign in automatically
  8. Continue working

Time: 2-3 minutes

Multiple Failed Login Attempts

Scenario: Tried several passwords without success

Steps:

  1. Stop trying random passwords
  2. Click "Forgot your Password?"
  3. Request magic link
  4. Use link to sign in
  5. Consider changing password for clarity

Tip: Don't lock account with too many attempts.

Password Changed by Administrator

Scenario: Admin reset your password for security

Steps:

  1. Receive notification from admin
  2. Go to forgot password page
  3. Request magic link
  4. Sign in via link
  5. Set new personal password immediately

Using Shared Computer

Scenario: Need to reset password on public/shared device

Considerations:

  1. Request magic link normally
  2. Check email on your phone (more secure)
  3. Click link on phone
  4. Sign in on shared computer
  5. Remember to sign out when done
  6. Don't save password on shared device

Troubleshooting

Possible Causes:

  • Email in spam/junk folder
  • Wrong email address entered
  • Email delivery delay (up to 10 minutes)
  • Email server issues

Solutions:

Check Spam Folder:

  1. Open email spam/junk folder
  2. Search for "RHEMA" or "magic link"
  3. If found, mark as "Not Spam"
  4. Add sender to contacts

Verify Email Address:

  1. Return to forgot password page
  2. Click "Try Different Email"
  3. Double-check email spelling
  4. Try again with correct email

Wait for Delivery:

  1. Allow 5-10 minutes for delivery
  2. Check email periodically
  3. Don't request multiple times
  4. Only one link needed

Contact Administrator:

  • If still no email after 15 minutes
  • If email domain has issues
  • If account might be locked

Problem: Link no longer works

Message: "Link expired" or "Invalid token"

Cause: Link older than 1 hour

Solution:

  1. Return to forgot password page
  2. Request new magic link
  3. Use new link within 1 hour
  4. Don't save link for later

Magic links expire after 1 hour for security. Request a fresh link if yours expired.

Problem: Link doesn't work

Message: "Link already used" or similar

Cause: Clicked link multiple times or used previously

Solution:

  1. Link is one-time use only
  2. Check if you're already signed in (another tab?)
  3. If not signed in, request new magic link
  4. Use new link only once

Possible Causes:

  • Link incomplete (email client truncated)
  • Special characters encoded incorrectly
  • Browser issues

Solutions:

Copy Full Link:

  1. Right-click link in email
  2. Select "Copy Link Address"
  3. Paste into browser address bar
  4. Ensure complete URL
  5. Press Enter

Try Different Browser:

  1. Copy link
  2. Open different browser (Chrome, Firefox, Edge)
  3. Paste and go
  4. Sometimes browser extensions interfere

Request New Link:

  • If link appears corrupted
  • Start process again
  • New link will work

Wrong Email Used

Problem: Requested link for wrong email address

Display: Shows wrong email on confirmation screen

Solution:

  1. Click "Try Different Email" button
  2. Enter correct email address
  3. Request new magic link
  4. Check correct email inbox

Security Considerations

Safe Usage

Do:

  • ✅ Request magic link only when needed
  • ✅ Use link within 1 hour
  • ✅ Verify email sender before clicking
  • ✅ Sign out after using link on shared devices
  • ✅ Delete email after using link

Don't:

  • ❌ Share magic link with anyone
  • ❌ Click links you didn't request
  • ❌ Save magic links for later use
  • ❌ Forward reset emails
  • ❌ Use links from suspicious emails

Protecting Your Account

If Receiving Unrequested Links:

  1. Don't click the link
  2. Delete the email
  3. Change your password immediately
  4. Report to administrator
  5. May indicate account compromise attempt

Email Account Security:

  • Keep email password secure
  • Enable two-factor authentication on email
  • Don't share email access
  • Your email is the key to password reset

Alternative Options

Option 1: Contact Administrator

  • Request manual password reset
  • Administrator can create new invitation
  • Faster if urgent access needed

Option 2: Use Backup Email

  • If you registered alternate email
  • Request link to alternate email
  • Contact admin to update primary email

Option 3: Visit IT Support

  • In-person assistance
  • Verify identity
  • Reset credentials on-site

Next Steps

  • Received Magic Link? Check your email and click the link
  • Still Having Issues? Contact your administrator
  • Need to Change Password? After sign-in via magic link