Confirm your email and use a Create Password link

Authentication

Confirm your email and use a Create Password link

Finish a new-account email confirmation, use an approved Create Password link, and recover safely when an access message is missing or no longer works.
For: Online Client and studio staff supporting account accessUpdated 2026-07-23

An email-confirmation link and a Create Password link are not interchangeable. One verifies the primary email address. The other changes the account password and signs the recipient in.

#Before you begin

  • Open messages only from the studio and use the Online Client address for that studio.
  • Use the primary account holder's message. A link generated from a related student's record currently targets the primary account.
  • Treat the complete link like a password. Do not forward it, paste it into chat, or include it in a screenshot or support ticket.
  • Use the newest applicable message. A resend or a newly generated Create Password link can invalidate an older one.
  • If the message names an account you do not recognize, do not use the link. Contact the studio using a known phone number or website.

#Identify the access path

Path What starts it What it changes Can the same action be used again? Where it ends
Create Account A visitor submits the studio's registration form Creates an active primary account with the password the visitor chose; the email can remain unconfirmed The registration should not be repeated for the same person or family Confirmation page, sign-in page, or Online Client home, depending on settings
Confirm Email New-account registration when confirmation is required Marks the primary account's email as confirmed The current link expires after 24 hours and is deleted after successful use; a resend replaces it Confirmation success, then sign-in, or automatic sign-in when enabled
Create Password A welcome, registration, or staff message containing a generated access link Sets a password, makes the primary account active, and establishes a client session The link stops working after successful use, a newer link, another password change, or an account lock; the current implementation has no automatic time expiration Online Client home, signed in
Forgot Password The recovery action on the sign-in page Generates a replacement password and emails the username and replacement password Every successful request creates another replacement; the previous password can stop working before the message arrives Return to sign-in; it does not sign the client in
Staff changes password An authenticated staff member uses Change Password on a member record Replaces that record's password immediately Not link-based The client signs in separately; no automatic email or sign-in occurs
Change Password while signed in A client opens Change Password from the account menu Replaces the signed-in primary account's password Can be repeated while signed in The current client session remains open
Sign-in URL A studio message contains a sign-in-page link Changes nothing Yes The ordinary sign-in page; it is not a magic login link

Important: Account activation, email confirmation, and password creation are separate states. A password can be valid while normal sign-in is still blocked because the email is unconfirmed.

#Confirm your email after registration

When the studio requires confirmation, the registration-complete page says that a confirmation message was sent. The account is active, but normal sign-in remains blocked until confirmation succeeds.

  1. Keep the registration-complete page open in the same browser if possible.
  2. Check the primary email inbox and spam or junk folder.
  3. Open the most recent message with a subject similar to Confirm Your Account - Studio Name.
  4. Select Confirm Email once.
  5. Look for one of these results:
    • a success message with a sign-in link; or
    • the Online Client home page, already signed in, when the studio has automatic sign-in enabled.
  6. If you reach the success page, select the sign-in link and use the username and password created during registration.

The confirmation email states that its link expires in 24 hours. A successful confirmation deletes that link, so reopening it later shows the same generic failure used for an expired, replaced, or incorrect link.

#Resend a confirmation message

The resend action is available only while the original browser session still has the pending-registration information.

  1. Return to the registration-complete page in the same browser.
  2. Confirm that the displayed email address is correct.
  3. Select Resend confirmation email once.
  4. Wait for the new message and use only its confirmation action.

Resending removes the account's earlier confirmation link and creates a new 24-hour link. If the page no longer displays the email and resend action, it cannot recover the pending registration from an email address alone. Contact the studio instead of registering the same person or family again.

A studio can place a generated Create Password link in a welcome, registration, or other authorized message. It is separate from the confirmation message.

  1. Open the newest Create Password message for the correct studio and primary account.
  2. Select the link without copying its full address into another application.
  3. Enter a long, unique password in Password.
  4. Enter the same password in Confirm Password.
  5. Complete the reCAPTCHA challenge or the five-character Security Code.
  6. Select Create Password once.
  7. Confirm that Online Client home opens with the account menu visible.

The current form does not display a minimum password length. That is not a recommendation to use a short password. Use a unique passphrase that is not used for email, banking, or another site.

Important: Successful use makes the account active and signs the recipient in, but it does not mark the email as confirmed. If confirmation is still pending, finish it before the next normal sign-in.

The current generated link has no automatic time expiration. It still stops working after it is used, after a newer Create Password link is generated, after the password changes, or when the account is locked. Do not keep an old message as a reusable login method.

#Recover a forgotten password

The Forgot your password? path does not send a choose-your-password link.

  1. On Sign In, select the password-recovery action.
  2. Enter the requested Username or Email. The studio setting chooses which field appears.
  3. Complete the reCAPTCHA challenge or Security Code.
  4. Select Reset Password once.
  5. Check the primary account inbox for a message containing the username and a newly generated password.
  6. Use that password on Sign In.
  7. After signing in, open Change Password and replace the emailed password with a long, unique one.

The recovery controller checks studio mail readiness before changing the password. However, after generation starts, the stored password is changed before the provider accepts the message. If the screen says a new password was generated but the email could not be sent, the old password may already be invalid. Contact the studio rather than submitting repeated recovery requests.

Email confirmation still applies. Recovering or creating a password does not clear an unconfirmed-email state.

Online Client Reset Password heading Return Back action and empty Username field with the security-code image excluded.
Enter the account username only when you intend to request recovery; complete the separate security check before submitting.

The verified a test studio recovery page currently uses Username plus a built-in Security Code. The public screenshot is intentionally limited to the empty Username field and excludes the generated code image. No recovery request or email was submitted.

#What studio staff must prepare

#Registration and account settings

Review these choices together before opening public registration:

  • whether Online Client account registration is enabled;
  • whether primary email confirmation is required;
  • whether registration or successful confirmation signs the client in automatically;
  • whether password recovery asks for username or email;
  • whether the security check uses reCAPTCHA or the built-in code;
  • which login groups are allowed to use Online Client;
  • whether the primary account is active, confirmed, unlocked, and has a usable email address.

Turning off required confirmation later does not automatically repair an account already stored as unconfirmed. The current sign-in controller rejects an account whose confirmation state is false even when the studio setting has since changed.

#Email delivery

Confirmation, registration, and recovery depend on the current tenant's SMTP and sender settings. Verify the From name/address, Reply-To or notification address, and delivery through a mail sink before testing with fictional accounts. Do not test these flows against a real client or an unrestricted production mailbox.

A confirmation send and a general registration/welcome message are separate sends. A registration can therefore succeed while either message fails or arrives in a different order.

#Welcome and message templates

Use access merge tags deliberately:

  • Sign-in URL inserts only the studio's sign-in-page address. It does not authenticate the recipient.
  • Create Password URL generates a credential-changing link for the primary account. Generating it can make the current password stop working before the recipient uses the link.
  • A test-message path suppresses Create Password URL generation to avoid changing the sample account. A successful preview therefore does not prove the live link workflow.

Do not place a password value in a welcome or registration template. Do not combine a generated Create Password link with a plaintext password. Keep templates limited to the minimum identity and access information the recipient needs.

Warning: The current registration workflow sends the general client registration notification before it sends the dedicated confirmation email. If that notification contains Create Password URL, generating it can replace the password chosen on the registration form. Do not combine the two actions in a live registration template until a fictional, mail-sink test confirms the complete intended sequence.

#Staff-set passwords

The member Change Password action immediately replaces the selected record's password. It does not currently:

  • confirm the account's email;
  • change the account's active or locked state;
  • send a message to the client;
  • sign the client in; or
  • close existing client sessions.

Verify the person's identity using the studio's approved support procedure, restrict this action to authorized staff, communicate the change through an approved channel, and ask the client to choose a private password after sign-in. Do not ask the client to send a password by email or text.

#Session and handoff behavior

Successful action New client session? Confirmation changed? Existing sessions closed?
Create Account with automatic sign-in and no required confirmation Yes Set as confirmed at registration No
Confirm Email with automatic sign-in Yes Yes No
Confirm Email without automatic sign-in No Yes No
Create Password link Yes No No
Forgot Password No No No
Staff changes password No No No
Signed-in client changes password Keeps the current session No No

Because reviewed password-change paths do not revoke existing sessions, staff should treat a suspected account compromise as more than a password-reset task. Follow the studio's incident procedure and escalate for session invalidation or account restriction.

#Troubleshooting without exposing the account

#Sign in says to confirm the email

Use the newest confirmation message. If the original registration-complete page still offers resend, use it once. Otherwise contact the studio; do not create a duplicate account.

The public page intentionally uses one message for an expired, already used, replaced, or incorrect link. Return to the original completion page for a resend if it is still available. Otherwise ask the studio to verify the primary account and confirmation state.

#The Create Password page says the request is bad or the account is locked

Open the newest message and try once. Do not edit the link, account identifier, or address-bar values. If it still fails, close the page and contact the studio.

#The recovery message does not arrive

Check spam or junk mail and wait for the studio's normal delivery window. Do not repeatedly reset the password; each successful request can replace the previous one. If the page reports a provider or delivery failure, the studio must verify the account and mail configuration.

The account can have a valid password while the email remains unconfirmed. Finish the confirmation action or ask the studio to inspect the confirmation state.

#The page shows the wrong studio or person

Stop. Close the page without submitting a password, then contact the studio through a known channel. Do not forward the message to the person you think it belongs to.

#What to send support

Send only:

  • the studio name and Online Client page you were trying to use;
  • the approximate time;
  • whether the message was Confirm Email, Create Password, or Reset Password; and
  • the on-screen error text without the full address bar.

Never send the password, security code, full email link, link parameters, browser history, or a screenshot containing them.

#Confirm the access state

After the intended flow:

  1. Open the correct studio's sign-in page in a private browser window.
  2. Sign in with the primary username or supported email and the current password.
  3. Confirm that the account menu shows the expected primary person.
  4. Open Change Password and set a private password if recovery or staff assistance used a temporary credential.
  5. Sign out when using a shared device.

If the normal private-window sign-in fails after a direct Create Password handoff, ask the studio to verify active, confirmation, login-group, and lock states. Do not solve it by creating another account.

Search article titles, tasks, settings, and troubleshooting.

Screenshot preview

Screenshot