How WorkOS protects your sign-in
WorkOS doesn't use fixed passwords. Every time you sign in, you prove that you control your email account, or your Google account.
Signing in with a code by email
When you type your email, WorkOS sends you a 6-digit code:
- It expires after 10 minutes and can only be used once.
- You get 5 attempts. On the fifth failed attempt the code is blocked and you have to request a new one.
- WorkOS doesn't store the code, only an encrypted fingerprint (hash) that lets it check it. Not even the WorkOS team can read it.
- The response is the same whether or not the email has an account. That way nobody can use the sign-in screen to find out who works at your company.
- There's a limit on code requests per connection and per email, to slow down automated attempts.
Since the code arrives in your email, the security of your sign-in also depends on the security of your mailbox. We recommend protecting your email with two-step verification.
Signing in with Google
If your company uses Google Workspace or Gmail, you can click Continue with Google. That way WorkOS relies on the protection your Google account already has, including two-step verification if you have it turned on.
- WorkOS only asks Google for your identity (name and verified email), never for access to your email this way.
- You can only sign in if that email already has a WorkOS account. Signing in with Google never creates new users.
- Google has to confirm that the email is verified and be the real provider of that mailbox: a Gmail address or a Google Workspace address from your own company. If your Google account was created with another email (for example, a company address that is not on Google Workspace), sign in with the code: that checks that you control the mailbox today.
- If your company uses its own domain for WorkOS, you stay on that domain when you come back from Google.
Signing in with a code is still available as an alternative.
Remembered devices
When you sign in with a code you can tick Remember this device so you aren't asked for one every time. When you sign in with Google, WorkOS remembers the device automatically. In both cases, that remembered device:
- Lasts 60 days from its last use.
- Is stored encrypted: WorkOS only keeps a fingerprint of the identifier, not the identifier itself.
- Is renewed every time it's used and stops working if your user is deactivated.
- Is removed from that device when you click Log out.
On a shared computer, don't tick the box and always log out when you're done.
Secure connections
All traffic between your browser and WorkOS is encrypted with TLS 1.2 or TLS 1.3; older versions are rejected. The same goes for traffic between WorkOS and the services it works with (Notion, Google, Microsoft, AI providers). Details are in “Encryption and credential protection”.