Access & account · Security
How does magic-link sign-in work, and is it secure?
You book as a guest — no account, no password. To see or manage a booking later you enter your email and we send a single-use link.
The security properties, stated plainly:
- Signed and scoped — the token is signed server-side and bound to that email address and that set of bookings. It cannot be edited to reach anyone else's trip.
- Short-lived — valid 15 minutes.
- Single use — it burns the first time it's opened. A forwarded email is a dead link.
- Bound session — opening it grants a 30-minute session tied to that browser.
- Re-challenged for destructive actions — cancelling or amending requires a fresh link, so an old email in someone else's inbox can't cancel your holiday.
- No enumeration — we return the same "check your email" message whether or not the address has bookings, so nobody can use the form to test who's a customer.
Compared with a password, there is no credential to reuse, phish, breach or forget. The trade-off is that access depends on your email account — so secure that with two-factor authentication.
More on access & account
Still stuck? Talk to a person
Email help@sunnydays.thedigitalcarpenter.com — replies within one business day, most inside four hours.
Travelling in the next 48 hours, or travelling now: the urgent line +1 (555) 018-7742 is staffed 24/7 and answered in under three minutes, or we call you back.
Full contact detail, including postal address, is on the contact page. Please never send card numbers by email — we will never ask for one, and we do not need it to find your booking.