> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.whizcozy.com/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.whizcozy.com/_mcp/server.

# Account and password recovery

> Sign in to a firm, accept an invitation, or reset an account password.

WhizBoard account flows use an email address and password. After sign-in, the browser requests the selected firm's membership context; authentication alone does not add a user to a firm.

**Status:** Sign-in and password recovery are implemented in the UI and API. A user still needs a membership in the selected firm to enter that workspace.

## Sign in

1. Open the firm's sign-in route.
2. Submit the account email and password.
3. The UI receives an authentication token and requests the user's membership for that firm.
4. If the user is a member, the firm workspace opens. If not, access is denied or the user must complete the relevant invitation flow.

The API issues a user token. Firm membership and role checks remain server-side, as described in the [identity and firm access guide](/identity-and-firm-access).

## Accept an invitation

An invitation link includes an invitation identifier. WhizBoard verifies the invitation, prefills the invited email, and routes the person through account creation or sign-in. The invitation is accepted against that account before firm membership is established; [Teams and invitations](/teams-and-invitations) describes the full lifecycle.

## Reset a password

The recovery flow requests a one-time code, verifies that code, then uses the short-lived reset token to set a new password. The request response is designed not to reveal whether an email address has an account. Use the newest valid code and complete the reset before its token expires.

## If access still fails

Confirm that the browser is on the intended firm route and that the signed-in email matches the firm's membership or invitation. A valid account without a firm membership cannot open that firm's workspace. If an invitation appears invalid, ask the firm owner to verify its status and issue a new one if appropriate.

## Code map

* UI login, invitation login, and reset flow: WhizBoard UI, `src/lib/auth-api.ts`, `src/lib/invite-login.ts`, and `src/lib/password-reset-flow.ts`.
* API authentication and reset handlers: backend, `src/routers/auth.py` and `src/controllers/auth.py`.