Security (PRO)
How Can I Only Allow Magic Link Logins At Certain Times?
Quick Answer
This is a Pro feature. In Magic Link -> Settings -> Security -> Access Control, use the Time Window settings to control the dates, weekdays, and hours during which a magic link may be used.
Why This Helps
A magic link is valid until it expires. If someone forwards the email, or a laptop is left open, the link still works at three in the morning on a Sunday — and nobody is watching.
A time window closes that gap:
- Staff and back-office accounts. If your team only works Monday to Friday, 9 to 5, a login at 2am is either a mistake or an intruder. Refuse it rather than record it.
- Time-boxed events. Running a course, a launch, or a client review that opens on a date? Set the window and stop managing access by hand.
- Contractors and temporary access. Give someone an end date at the moment you give them the link, instead of remembering to revoke it later.
The point is that this runs whether or not you are paying attention. It is a rule the site enforces on your behalf.
What You Can Set
In Magic Link -> Settings -> Security -> Access Control, under Time Window:
| Setting | What it does |
|---|---|
| Valid From | No magic link works before this date. |
| Valid Until | No magic link works after this date. |
| Allowed Days | Tick the weekdays on which logins are allowed. Leave every day unticked to allow all of them. |
| Start Hour | Earliest hour of the day a link may be used, 0–23. |
| End Hour | Latest hour of the day a link may be used, 0–23. |
Every field is optional. Leave them all empty and magic links work at any time, exactly as they did before. Fill in only the ones you care about — an end date with no hour restriction is perfectly normal.
How To Set A Business-Hours Window
- Go to
Magic Link -> Settings -> Security -> Access Control. - Under Allowed Days, tick Monday through Friday.
- Set Start Hour to
9. - Set End Hour to
17. - Leave Valid From and Valid Until empty.
- Save changes.
Magic links now work on weekdays between 09:00 and 17:59, and are refused at every other time.
Windows That Cross Midnight
If End Hour is lower than Start Hour, the window wraps to the next day. Start 22, end 2 means 22:00 through 02:59 — useful for overnight shifts.
Times Are In UTC
Dates and hours are evaluated in UTC, not your site's local timezone.
If your site runs several hours away from UTC, convert before you enter the values. A team working 9–5 in UTC+5:30 should enter roughly 3 to 12, not 9 to 17. Set the window, then have someone actually test a login at the edge of it before you rely on it.
What The User Sees
When someone opens a link outside the window, they are not logged in. They see a short message explaining that magic links are not allowed at this time, and the link stays unused — so they can try again once the window opens.
Related
- Restrict magic links by IP address — control where logins may happen.
- Limit how many times a link can be used — control how often.
- Set Magic Link expiry — control how long a link stays valid at all.