Release notes
Sign In Where You Started
September 11, 2026
Sign In Where You Started
Start login on your computer, read the email on your phone, and finish with a short code where you began—so the session stays put. Plus clearer sessions, safer mail links, and directory fields that finally land in Skillhabit.
You know the awkward dance: you start Skillhabit on a laptop, open the login email on your phone, and suddenly you’re signed in on the wrong device. We fixed that hand-off for email login—and tightened a few related places so sign-in, sessions, and directory data feel trustworthy.
- Login codes for email sign-in — Under Configure → Connections → Authentication Methods, choose Login code instead of (or as the alternative to) Magic link. We email a 6-digit code with no sign-in link; you type it on the same browser where you started. Codes expire in 10 minutes, lock after 5 wrong tries, are stored hashed, and a resend invalidates earlier unused codes. New workspaces default to login code; existing ones keep Magic Links until you switch. See SSO and Authentication.
- Other emails no longer sign you in — Only the Magic Link login email (and External API sign-in links) authenticate. Everything else uses ordinary deep links: sign in with your workspace method, then continue to the destination.
- Sessions you can see and revoke — On Profile → Active sessions, sign out other devices or everywhere. Admins can do the same from Users & Groups → Sessions. See Users and Profiles.
- How long new sessions last — Under Configure → User Management, pick 1 day through 12 months for newly issued sessions. See Auto Archive.
- Directory fields onto Skillhabit attributes — Map an OpenID Connect claim, Microsoft Entra property, or SCIM attribute under Configure → Connections → Attribute mappings (Match existing only or Create if missing for lists). Release the field from your IdP first—Add Attributes to IdP Tokens and Profiles—then finish in User Provisioning.
- Mail from your domain, your local-part — With a custom email domain active, set Sender address (default
no-reply) so From looks like{local-part}@{your-domain}. See Custom Domains. - Who hears about paid Academy orders — Under Manage Academy → Payment → Order Notifications, choose administrators for new paid orders (free orders stay quiet). See Academy Notifications.
- External API assignments that match Create — Optional or mandatory targets for users or groups, optional start/finish times, plus list and delete. See Assign Content to a Group.
Related: Sign-In & Email Identifiers · Custom Attribute Fields · Supported Payment Options.