Skip to content

Sign in and account recovery

/auth/login·/auth/mfa-challenge

Every later visit starts at my.lexpoint.io/auth/login, where the heading reads Welcome back. The screen offers the same two methods as sign-up, and there is no password field on it.

The sign-in screen, with the Google button above the email field.
The sign-in screen, with the Google button above the email field.

Select Continue with Google. Google opens Choose an accountto continue to Lexpoint.io. Pick the Google account you signed up with. If that is the one on this file, you land back inside Lexpoint.

Google’s account picker, naming Lexpoint.io as the app you are continuing to.
Google’s account picker, naming Lexpoint.io as the app you are continuing to.
  1. Type your address into Email address. The field checks the address as you type and shows a green checkmark when it is valid.
  2. Select Send Magic Link.
  3. A dialog opens: Check your emailWe sent a sign-in link to your address, with the reminder Check spam folder if you don’t see it.
  4. Open the email and select the link.

The dialog stays open while you go and check. Two controls are on it:

ControlWhat it does
Resend in 60s, then ResendSends a fresh link. It is disabled until the countdown finishes, which stops a double-tap from sending two links and confusing which one is current.
Use a different emailCloses the dialog and returns to the form, so you can try another address.
The confirmation dialog after a magic link is sent, with the resend countdown running.
The confirmation dialog after a magic link is sent, with the resend countdown running.

If a link no longer works, nothing is broken and nothing is lost — return to the sign-in screen and send a new one.

If two-step verification is on for your account, signing in is not finished until you clear the challenge at /auth/mfa-challenge. Lexpoint sends you there automatically; you never navigate to it yourself.

The screen is labelled Two-factor authentication and reads Verify your identityEnter the 6-digit code from your authenticator app. Type the six digits into the boxes and select Verify.

Underneath is Sign in with a different account, which abandons the challenge and returns you to the sign-in screen. Use it when you have started signing in as the wrong person, not when the code is being rejected.

Setting this up, and what to do if you lose the authenticator, are covered in two-step verification.

Lexpoint decides where to send you after sign-in:

  • Profile incomplete — straight to /app/onboarding. The dashboard is not reachable until the required answers exist.
  • Profile complete — your dashboard, or the page you were trying to reach when you were asked to sign in. That destination is carried through the whole sign-in flow, including through the two-step challenge.

There is no “remember me” checkbox, because staying signed in is the default. When Lexpoint renews your session it stores it for seven days, alongside a renewal credential good for thirty, and the renewal happens quietly while you use the app. Closing the tab or restarting the browser does not sign you out.

If the session does end while a page is open — it expired, or you signed out in another tab — Lexpoint does not leave you on a dead screen. It sends you to sign in and remembers where you were.

Open the account menu in the app and select Sign Out. That clears the sign-in cookies on the server side, not only in the tab, and returns you to the sign-in screen.

Sign out deliberately on any device that is not yours. A closed browser tab is not a sign-out.

Frequently asked questions

I never chose a password. How do I sign in?

You do not need one. A client account signs in with Google or with a magic link emailed to your address. The sign-in screen has no password field.

The magic link did not arrive. What now?

Check the spam folder first — the confirmation dialog says so for a reason. If it is genuinely missing, wait for the resend countdown to finish and select Resend. Each new link supersedes the last.

Why is Lexpoint asking for a six-digit code?

Two-step verification is switched on for your account. The code comes from your authenticator app, not from an email or a text message.

Does Lexpoint sign me out when I close the browser?

No. A signed-in session survives closing the tab and restarting the browser. Use Sign Out in the account menu when you are finished on a device that is not yours.