Sign-in problems
Fix a rejected password, a magic link that never arrives, bounced social sign-ins and two-factor lockouts.
Last updated
On this page
Symptoms
- Your password is rejected, or you've forgotten it.
- You chose Email me a magic link instead but no email arrives.
- A "Continue with…" button bounces you back to the sign-in page with an error.
- You're asked for a second factor you can no longer provide.
- You're told the account is deactivated.
Likely causes
- A mistyped password — Laya passwords are at least 12 characters.
- The magic link email landed in spam, or you've hit the request limit (5 links per 15 minutes).
- The magic link expired — links are valid for 10 minutes and work exactly once.
- The social provider reported a problem — the error code in the page address says which one.
- Two-factor authentication is on, and once it's on it is asked for on every route in — password, magic links and every "Continue with" button.
- The account was deactivated — deactivation hides the account but keeps its data.
Fix it
Forgotten or rejected password
There is no separate password-reset form. The reset path is a magic link — proving you control the inbox — followed by setting a new password from your account's Security page.
- On the password step, choose Forgot password?Laya emails a sign-in link to your account address.
- Open the link within 10 minutesThe link is single-use. If it has expired, request a fresh one from the sign-in page.
- Set a new passwordOnce signed in, go to Security → Password and choose Change password (or Set password if you never had one). The new password must be at least 12 characters.
Magic link not arriving
- Check spam and junk foldersSearch for recent mail from Laya.
- Confirm you typed the address on the accountThe link only goes to the email address your Laya account uses.
- Mind the limitsYou can request 5 magic links per 15 minutes. If you've been retrying rapidly, wait a few minutes and request one more.
- Request a fresh link if yours is oldLinks expire after 10 minutes and work once. An expired or already-used link shows an error such as "This link has expired. Request a new one." or "This link has already been used." — always open the newest email, and request a fresh link if needed.
- Try another route inIf you have a password or a linked provider, sign in that way and check your email settings later.
Social sign-in bounces back with an error
When a "Continue with…" sign-in fails, Laya returns you to the sign-in page with an error code in the address bar (?social_error=…). The most common codes and their fixes:
| Code | What it means | What to do |
|---|---|---|
social_email_unverified | The email on your provider account isn't verified with that provider, so Laya can't trust it yet. | Verify your email address with the provider you clicked, then try again — or use Email me a magic link instead with the same address. |
invalid_state | The sign-in attempt expired, or finished in a different browser than it started in. | Return to the sign-in page and start again in one browser window. Don't reuse an old consent tab. |
social_sign_in_failed | The provider hand-off didn't complete. | Try the button again. If it keeps failing, sign in with your email (password or magic link) instead and try the provider later. |
account_exists_link_required | A Laya account already exists for this email address, but it can't be linked to the provider automatically. | Sign in with your existing method — password or magic link — then link the provider from your account's Connected apps page. Linking is offered for Google, GitHub and Microsoft. |
access_denied | You cancelled the provider's consent screen, or the provider refused it. | Try the button again and approve the consent screen this time. |
account_deactivated | This Laya account has been deactivated. | Deactivation keeps your data and a workspace admin can restore the account. Ask your workspace admin, or email support@laya.net from the account's address. |
| Any other code | The provider reported a problem, and Laya passes its code through as-is. | Retry once, and if it persists, copy the exact code from the address bar into your email to support@laya.net. |
Locked out by two-factor authentication
Once two-factor is on, every sign-in route asks for a second factor — including magic links and social buttons. Work through your factors in this order:
- Try any enrolled passkeyPasskeys are the primary factor — Face ID, Touch ID, Windows Hello or a security key. A passkey synced across your devices may work on another machine.
- Use your authenticator appEnter the 6-digit code from the authenticator you set up as the fallback.
- Use a recovery codeRecovery codes were shown once when you first enrolled a factor, with Copy codes and Download .txt options (the file is named laya-recovery-codes.txt). Each code works exactly once.
- Once in, top up your codesThe Security page shows how many unused codes remain. Use Generate new codes — Laya asks you to prove a factor before issuing a fresh set.
Verify the fix
- You land signed in on Home.
- On Security → Active sessions, the current browser is listed as "This device".
- If you set a new password, sign out and back in once with it to confirm it took.
If you're still stuck
Email support@laya.net with: the email address you're signing in with, the method you tried (password, magic link, or which provider button), the exact error code from the address bar if there is one, the date and time of the attempt, and whether two-factor is enabled on the account.
Email support@laya.net — include what you expected, what happened, and a link to the affected board or item so we can help quickly.