Account and password recovery
WhizBoard account flows use an email address and password. After sign-in, the browser requests the selected firm’s membership context; authentication alone does not add a user to a firm.
Status: Sign-in and password recovery are implemented in the UI and API. A user still needs a membership in the selected firm to enter that workspace.
Sign in
- Open the firm’s sign-in route.
- Submit the account email and password.
- The UI receives an authentication token and requests the user’s membership for that firm.
- If the user is a member, the firm workspace opens. If not, access is denied or the user must complete the relevant invitation flow.
The API issues a user token. Firm membership and role checks remain server-side, as described in the identity and firm access guide.
Accept an invitation
An invitation link includes an invitation identifier. WhizBoard verifies the invitation, prefills the invited email, and routes the person through account creation or sign-in. The invitation is accepted against that account before firm membership is established; Teams and invitations describes the full lifecycle.
Reset a password
The recovery flow requests a one-time code, verifies that code, then uses the short-lived reset token to set a new password. The request response is designed not to reveal whether an email address has an account. Use the newest valid code and complete the reset before its token expires.
If access still fails
Confirm that the browser is on the intended firm route and that the signed-in email matches the firm’s membership or invitation. A valid account without a firm membership cannot open that firm’s workspace. If an invitation appears invalid, ask the firm owner to verify its status and issue a new one if appropriate.
Code map
- UI login, invitation login, and reset flow: WhizBoard UI,
src/lib/auth-api.ts,src/lib/invite-login.ts, andsrc/lib/password-reset-flow.ts. - API authentication and reset handlers: backend,
src/routers/auth.pyandsrc/controllers/auth.py.
