Documentation

How clients sign in

Whenever you send a client something private, a shared document, a document to sign, an invoice to pay, or a form filled in for them alone, Esqase asks that person to prove who they are before the page opens. This page explains the sign-in screen your clients see, the three ways they can get past it, and the account they can create for themselves. The other pages in this section link here rather than repeating it.

One rule matters more than the rest, and it is worth knowing before you read anything else: creating an Esqase account grants a client nothing on its own. What they can open is still decided entirely by the email address you sent the link to.

Before you begin

  • There is nothing for your firm to turn on. Sign-in is part of every restricted link you send. You do not configure it, and you cannot switch a client to one method over another.
  • The email you put on the record is the key. A client is let in when the address they sign in with matches the address on the record you shared: the recipient on a document share, the signer on a signature request, the billing contact on an invoice, or a contact on the form's matter. Check that address before you send the link, because it is the only thing that decides access.
  • Sign-in only appears on restricted links. A public document share (Anyone with the link) and a public lead-intake form open straight away, with no sign-in at all. See How clients view shared documents and How clients fill intake forms.
  • Meeting links work differently. The per-meeting page on your booking site still uses its own email sign-in link and nothing else. See How clients book meetings.

The three ways to sign in

Your client lands on a panel headed with the thing you sent them (the document name, the invoice number, or the form title) and a line naming your firm, for example "Acme Law sent you a document. Sign in to continue." Below that are three ways in, in this order.

Email and password

This is the primary method and the one the panel leads with.

  1. The client types the email address your firm has on file in the Email field.
  2. They type their Esqase client account password in the Password field.
  3. They click Sign in. The button reads Signing in... while it checks.

If they do not have an account yet, Don't have an account? Sign up sits under the buttons, and Forgot your password? sits beside the password field. Both are covered further down this page.

Continue with Google

Below the password button, separated by a small or, is a Continue with Google button. The client clicks it, picks their Google account, and comes straight back to the page they were trying to open. Nothing is asked of them beyond choosing the account.

Google sign-in only works when the Google account's own email address matches the address you sent the link to. A client who signs in with a personal Google address when you addressed the invoice to their work address is turned away, exactly as a mismatched password would be.

The passwordless method your clients may already know is still here, unchanged, as the third button: Email me a sign-in link instead.

  1. The client enters their email address and clicks Email me a sign-in link instead. The button reads Sending link... while it sends.
  2. The page confirms with Check your email, naming the address and noting that the link expires in 30 minutes.
  3. The client opens the email on the same device and clicks the link. The page shows Signing you in briefly, then opens what you sent.

They need no account and no password for this route. If they typed the wrong address, Use a different email on the confirmation screen takes them back.

Note: For privacy, the Check your email screen appears whether or not the address is on the record, so nobody can use the link to discover who a document or invoice was sent to. Only the genuine recipient actually receives an email.

📷 Screenshot: The client sign-in panel showing the Email and Password fields, the Sign in button, the "or" divider, the Continue with Google button, and the "Email me a sign-in link instead" button.

Signing in without clicking anything

A client who is already signed in to their client portal in that browser does not see the sign-in panel at all. When they open a shared document, a signature request, or a payment link, the page shows Checking your Esqase sign-in for a moment and then opens the document or invoice by itself. There is no button to press and nothing to teach them.

If they have no portal session, nothing visible happens: the page simply shows the sign-in panel. They are never shown an error for not being signed in.

Note: This shortcut covers shared documents, signature requests, and payment links. A one-time intake form always asks for a sign-in, even for a client who is signed in to the portal.

📷 Screenshot: The "Checking your Esqase sign-in" step, showing the spinner and the line beneath it, before the document opens on its own.

Creating a client account

Clients can now create an Esqase account for themselves, so they can sign in with a password instead of waiting on an email every time.

What your client does:

  1. From any sign-in panel, they click Sign up under Don't have an account?. Their firm's client portal opens on the Create your client account screen.
  2. They enter their Email address. This should be the address your firm has on file for them.
  3. They choose a Password and repeat it in Confirm password. The hint under the fields reads "Use 12+ characters with upper- and lower-case letters, a number, and a symbol."
  4. They click Create account.
  5. They see Check your email, and Esqase sends a confirmation link to the address they entered.
  6. They open that email and confirm the address (see the next section). Once confirmed, they are signed in and taken back to whatever they were trying to open.

The password rules are the same ones your own firm accounts use:

  • At least 12 characters, and at most 128.
  • At least one uppercase letter, one lowercase letter, one number, and one special character.
  • It cannot contain the username part of their email address (everything before the @).

Note: The screen says Check your email whether or not that address already had an account. A brand-new address gets a confirmation link, and an address that already has an account gets a password-reset link instead, so nobody can use the sign-up form to find out who is already a client of yours. Either way the client ends up with a working sign-in.

📷 Screenshot: The Create your client account screen with the Email, Password, and Confirm password fields, the password hint line, and the Create account button.

Confirming an email address

An account cannot be used until the email address on it has been confirmed. Confirming is what proves the person who typed the address actually reads that inbox.

  1. The client opens the confirmation email and clicks its link.
  2. On the device that asked for the link, the page confirms the address and signs them in automatically, showing Signing you in.
  3. Opened anywhere else, the page shows Confirm your email, names the address, and waits for them to click Confirm my email. This is deliberate: a link that signs someone in silently should only do so on the device that asked for it.
  4. When it works they see Email confirmed and a Sign in button. If the link has already been used or has expired, they see We could not confirm your email and can request a fresh one.

An unconfirmed account cannot sign in anywhere. If a client tries to sign in with the right password before confirming, Esqase sends a fresh confirmation email and shows Check your email instead of letting them through.

📷 Screenshot: The Confirm your email screen naming the address, with the Confirm my email button and the Use a different email button beneath it.

What an account does and does not give a client

This is the part to be clear about if a client, or a colleague, asks whether open registration is safe.

Creating an account grants nothing. It is a credential, not a key. Anyone can create one, in the same way anyone can create an email address, and doing so gives them access to no document, no invoice, no form, and no matter.

Every restricted link makes the same two checks, every time, whichever sign-in method was used:

  1. Is this email address confirmed? An unconfirmed address is refused.
  2. Is this exact address the one the firm sent this to? A document opens only for the recipient you addressed the share to. A signature request opens only for that signer. An invoice opens only for the contact it is billed to. A form opens only for a contact on that record.

A client who signs in with an account you have never heard of gets the same outcome as one who mistypes a password: a single, unhelpful message and no document. They cannot register their way into somebody else's file.

The client portal itself works the same way. A client only reaches a portal session if the confirmed address on their account matches an email address your firm (or another firm on Esqase) holds on a contact record. An account with an address nobody has on file is a valid account that can still never open anything.

Important: None of this changed with the new sign-in methods. The access rules are exactly what they were when email links were the only way in. What changed is how a client proves they own the address, not which address is allowed.

Tip: Because everything hinges on the address on the record, keeping contact emails accurate is the whole of client-access administration. If a client cannot get in, check that address first. See Working with contacts.

Resetting a forgotten password

  1. From a sign-in panel, the client clicks Forgot your password?. The Reset your password screen opens, with the line "We will email you a link to choose a new password."
  2. They enter their email address and click Email me a reset link.
  3. They see Check your email, noting that the link expires in 60 minutes. As everywhere else, this message appears whether or not an account uses that address.
  4. They open the email, land on Choose a new password, fill in New password and Confirm new password (the same rules as above), and click Save new password.
  5. Password updated confirms the change, and a Sign in button takes them back.

Reset links work once. If a client reuses one they see That link is no longer valid with a Request a new link button.

Tip: A client who cannot remember whether they ever made an account does not need to know. Ask them to use Email me a sign-in link instead, which works with no account at all, or to click Sign up and let Esqase sort out which email it sends.

Which methods appear where

Where the client isPasswordGoogleEmail sign-in link
A restricted document shareYesYesYes
A document sent for signatureYesYesYes
A payment linkYesYesYes
A one-time form linkYesYesYes
A one-time form embedded in your websiteYesNoYes
The client portalYesYesYes
A meeting page on your booking siteNoNoYes

A form embedded in your own website offers two methods rather than three. Continue with Google is not available inside an embedded form, because signing in with Google leaves your page and comes back, which an embedded form cannot do cleanly. For the same reason, the Sign up and Forgot your password? links are not shown inside an embedded form either. The password and email-link methods both work there normally, so a client who already has an account can sign in without leaving your page, and a client who does not can use the email link. See Embedding forms on your website.

Common questions

Do clients have to create an account? No, and most will not. Email me a sign-in link instead still opens everything you send, with no account and no password. An account is a convenience for clients who deal with you often.

Can a client use one account with several firms? Yes. One account, one password, and each firm's documents and invoices open according to the address that firm has on file. A client working with two firms on Esqase signs in once.

Does the client's password give them access to our dashboard? No. Client accounts and firm-member accounts are entirely separate, and a client account cannot sign in to your dashboard at all. See Signing up and signing in for the firm side.

A client says they signed in but the document still will not open. The address they signed in with is not the address on the record. Compare the two, correct the contact if needed, and send a fresh link.

Why do we not see whether a client created an account? Because it would tell you nothing useful. Access is decided by the email address on your record, not by whether an account exists, so the account is the client's own business. What you can see is that the document was opened, on the record's activity history. See Activity timelines and audit logs.

Troubleshooting

  • The client is locked out after several tries. Every sign-in method is rate limited. After several failed attempts in a short window the client sees "Too many attempts have been made recently. Please wait a few minutes before trying again." It clears on its own after a few minutes.
  • The client never receives the sign-in or confirmation email. Ask them to check spam, then confirm the address you have on file matches the one they typed exactly. Remember the page shows the same confirmation whether or not the address matched, so checking your own record is the reliable test.
  • The sign-in link says it is invalid or expired. Sign-in links last 30 minutes and work once. The client requests a fresh one from the same panel.
  • Google sign-in is refused. The Google account's email address does not match the address on the record. Ask them to try the address you have on file, or to use the email sign-in link instead.
  • The client confirmed their email but still cannot open the portal. Their address is not on any contact record. Add it to their contact and ask them to sign in again.