What to do when a member cannot sign in

A member says they cannot get in. They have asked for a code and nothing came, or the code did not work, and they are waiting on you. This is the most common thing a membership organization gets asked, and almost all of it is answered in one place. This note is the order to check things in, quickest first. If you have not opened the tool before, How to make edits on an Avistra website shows the sign-in.

Looking at somebody's record shows their details, so this needs your passkey. How to set up a passkey on an Avistra website walks through it.

Why you cannot tell from the sign-in page

When somebody types their address, the page says the same thing either way: if that address is on file, a code is on its way. It says that whether or not the address is on file, on purpose, because otherwise anybody could use that page to find out who belongs to your organization.

So a member cannot tell a typo from a missing record, and neither can you by looking at the same page. Do not try to reproduce it. Open the person in the tool instead: everything you need is on their record.

Members sign in with a code. Passkeys are for admins. If you find yourself about to send a member the passkey note, that is the wrong note; there is nothing for them to set up.

Start here: the address you have, and the address they typed

Choose Dashboard in the bar in the lower right, then People, and search for them by name.

Most of the time this is the whole answer. The address on their record is the one the code goes to, and people move jobs, change providers, and have a work address on file and a personal one in their head. A letter wrong at import does it too.

If the address is wrong, change it on their record. There is nothing else to reset: the next code goes to the new address, and their history, their membership and their payments stay exactly where they are.

If you cannot find them at all, they may not be on file. Somebody who registered for an event is a person on your list but not necessarily a member, and somebody who came in on a spreadsheet may have been left out for having no email address at all.

Then: has the code simply run out?

A sign-in code lasts ten minutes and works once. Somebody who opens your email an hour later, or who asks for a second code and then types the first one, gets nothing, and the page will not say why.

Ask them to request a fresh code and use it straight away. That is the fix for more of these than anything else on this page, and it needs nothing from you.

Two more things the page says in the member's own words, neither of them a fault:

  • "Too many codes have been asked for. Try again in an hour." They pressed the button repeatedly while nothing arrived.
  • "Too many tries. Wait an hour and start again." They typed a wrong or stale code too many times.

Both clear by themselves. Nobody has to do anything.

The one that looks like a broken site

If their address has ever hard bounced, or somebody at that address once marked one of your emails as spam, every email to it stops. Not just newsletters: sign-in codes too. Nothing arrives, no error appears anywhere, and it stays that way until somebody looks. This is the cause that runs for weeks and feels like the site is broken.

You can see it on the person's record. Open them, then the Emails tab: the list shows every email your site has sent them, including the sign-in codes, when each went and what happened to it. If the address is stopped, a line at the top says so plainly, with the reason and the date.

The person's Emails tab, which is where this is answered: the list of emails sent to them with what happened to each, a line at the top saying emails to this address bounce, and then Email, Bounced and unsubscribed, where Try this address again clears it.

To clear it, go to Email, then Bounced and unsubscribed, find the address, and choose Try this address again. Mail starts flowing to it from the next send. Two things to know before you do:

  • The member cannot do this from their end. However many times they ask for a code, nothing will come until the address is let through again or changed.
  • A bounce usually means something real. If the address is closed or misspelled, letting it through again just bounces it again. Ask them what address to use and change it on their record instead.

You can see that a code was sent without seeing the code itself. The tool never shows it back to you, which is deliberate, so no one can read somebody else's code out of the record.

And the spam folder

Codes are ordinary email, and an address that has never had mail from your site before is exactly what a spam filter holds. On the person's record, the Emails tab tells you the site sent it and when. If it left us and never arrived, it is sitting in their mail system.

Give them the address your site sends from, which is in Email, then Settings, and ask them to search for it rather than scroll. Ask them to mark it as not spam once, and it stops happening.

Last, and usually not it: the membership itself

Everybody's first guess is that their membership ran out. It is rarely the answer, because somebody whose membership has ended can still sign in. The account stays theirs, and what they see when they get in is an offer to renew.

So if they can reach their account at all, the membership is not what is stopping them. Two things in this area do look like being locked out, and neither is a sign-in problem:

  • A members-only page refusing them. That is about which level reaches what, not about signing in. How people join and pay on an Avistra website covers the level ladder.
  • Somebody on an organization's membership who was never given one of its seats. Their own account works; there is just no membership attached to it. Open the organization and check the seats.

If none of it fits

Send it to us. Choose Support request in the bar and say who the member is, the address they are typing, and roughly when they last tried. Those three things are enough for us to trace it from our side. How to submit a support request on an Avistra website shows how.

If it is you who cannot get in

This note is about a member. An admin who cannot sign in is a different set of answers, because admins also have a passkey: a backup code, another full admin resetting your passkeys, or us. How to give somebody access to your Avistra website covers it.