All releases

Sign In Where You Started

Start login on your computer, read the email on your phone, and finish with a short code where you began—so the session stays put. Plus clearer sessions, safer mail links, and directory fields that finally land in Skillhabit.

You know the awkward dance: you start Skillhabit on a laptop, open the login email on your phone, and suddenly you’re signed in on the wrong device. We fixed that hand-off for email login—and tightened a few related places so sign-in, sessions, and directory data feel trustworthy.

  • Login codes for email sign-in — Under ConfigureConnectionsAuthentication Methods, choose Login code instead of (or as the alternative to) Magic link. We email a 6-digit code with no sign-in link; you type it on the same browser where you started. Codes expire in 10 minutes, lock after 5 wrong tries, are stored hashed, and a resend invalidates earlier unused codes. New workspaces default to login code; existing ones keep Magic Links until you switch. See SSO and Authentication.
  • Other emails no longer sign you in — Only the Magic Link login email (and External API sign-in links) authenticate. Everything else uses ordinary deep links: sign in with your workspace method, then continue to the destination.
  • Sessions you can see and revoke — On ProfileActive sessions, sign out other devices or everywhere. Admins can do the same from Users & GroupsSessions. See Users and Profiles.
  • How long new sessions last — Under ConfigureUser Management, pick 1 day through 12 months for newly issued sessions. See Auto Archive.
  • Directory fields onto Skillhabit attributes — Map an OpenID Connect claim, Microsoft Entra property, or SCIM attribute under ConfigureConnectionsAttribute mappings (Match existing only or Create if missing for lists). Release the field from your IdP first—Add Attributes to IdP Tokens and Profiles—then finish in User Provisioning.
  • Mail from your domain, your local-part — With a custom email domain active, set Sender address (default no-reply) so From looks like {local-part}@{your-domain}. See Custom Domains.
  • Who hears about paid Academy orders — Under Manage AcademyPaymentOrder Notifications, choose administrators for new paid orders (free orders stay quiet). See Academy Notifications.
  • External API assignments that match Create — Optional or mandatory targets for users or groups, optional start/finish times, plus list and delete. See Assign Content to a Group.

Related: Sign-In & Email Identifiers · Custom Attribute Fields · Supported Payment Options.