Skip to main content

Change email authentication token settings

Adjust how long an email access token stays valid for visitors on secured sites. Covers expiry options and re-send behavior.

Zoomforth provides two email token types for authenticating visitors through Visitor Access Settings:

  • Approved Emails — Visitors authenticate by clicking a Secure Link sent to their approved email address.

  • Multi-Factor — Visitors authenticate using a one-time password (OTP) sent to their approved email address.

The email token provides an additional layer of security by verifying that the person attempting to access the site has access to an approved email address.

The Secure Link or OTP is valid only for the configured expiration period. Once the token expires, it can no longer be used to authenticate the visitor.

Change email authentication token settings

Access Visitor Access Settings

To view or change the email token settings:

  1. Go to the Site Editor.

  2. Hover over the site you want to configure.

  3. Click Details.

  4. Select the Visitor Access tab.

Configure the Email Token Type

The Email token type setting is available only when the site's Visitor Access method is set to Approved Emails or Multi-Factor.

  1. In the Visitor Access settings, scroll to the bottom of the page.

  2. Locate Email token type.

  3. Select one of the available options:

    • Expire after 24 hours — The Secure Link or OTP remains valid for up to 24 hours after it is sent.

    • Expire after single use — The Secure Link or OTP becomes invalid immediately after it has been used successfully.

  4. Save or apply the changes to the site.

How Email Tokens Work

When a visitor attempts to access a site protected by Approved Emails or Multi-Factor, Zoomforth sends an authentication email to the visitor's approved email address.

Depending on the selected Visitor Access method, the visitor must either:

  • Click the Secure Link to authenticate, or

  • Enter the OTP provided in the email.

The visitor must complete authentication before the token expires. If the token has expired or has already been used when Expire after single use is selected, the visitor will need to request a new authentication email.

Note: The email token type controls how long the authentication token remains valid. It does not determine which email addresses are allowed to access the site.

Add Approved Visitor Email Addresses

To learn how to add email addresses that are allowed to access your site, see Adding Allowed Visitor Email Address.

For more information about Secure Links, see Secure Link.


Token settings are one part of email authentication. For more on Zoomforth's full authentication configuration options, visit the security page.

Need Help?

Contact Zoomforth Customer Support through the in-app chat or email support@zoomforth.com.

Did this answer your question?