Easy to sign in.
Hard to impersonate.

How email sign-in links work, how to add a passkey or authenticator app, and what recovery codes are for.

On this page

Email sign-in links

  • Each link works once and expires after 10 minutes. If it expired or was already used, request a fresh one.
  • Up to three links per address are sent every 10 minutes. Extra requests look the same but send nothing, so wait a few minutes and check your spam folder.
  • Sessions last seven days and renew while you use MCPBinder.

Google and GitHub sign-in

Where available, you can sign in with Google or GitHub. Neither attaches to an existing account by matching email; you’ll see that it “isn’t linked to an MCPBinder account yet.” Sign in with an email link, then link it under Account → Security → Sign-in methods.

Linking needs a recent sign-in or verification, and the provider email must be verified with that provider. It can differ from your MCPBinder email. You can unlink a provider as long as another way to sign in remains.

Passkeys and authenticator apps

In Account → Security → Security methods, add a passkey (recommended) or an authenticator app such as Apple Passwords, 1Password, or Google Authenticator. Either one is a second step after you sign in.

They also confirm it’s you before sensitive actions such as changing roles, opening billing, or exporting your data; a check lasts 10 minutes in that browser. Adding your first method signs out your other browser sessions.

Recovery codes

Save the recovery codes from setup somewhere private. Each works once when you can’t use your other methods: on the Confirm it’s you screen, choose Use a recovery code. Generate new recovery codes replaces the whole set.

After 10 failed codes, verification pauses for 15 minutes. If you’ve lost every method and code, contact support.