Sign in without another password.
Sign in with a magic link or a passkey. Use scoped API keys for integrations and manage server-side sessions and account access.
Features in detail
Passwordless magic links
Receive a sign-in link by email without creating or remembering a Claribill password.
Passkey sign-in
Sign in with a registered passkey without requesting a new magic link each time.
24-hour link validity
Magic links expire after 24 hours and can only be used once.
Server-side sessions
Sessions are stored on the server and can be invalidated there.
Account status checks
Suspended or deactivated accounts are blocked during the sign-in flow.
API keys for integrations
Authorise external software using a Bearer token in the Authorization header.
Scoped API access
Choose explicit permissions, such as invoices:read or customers:write, for an API key.
API key management
Create and name keys, copy each secret when created and revoke access when needed.
Last sign-in tracking
Record the last successful sign-in timestamp for a user.
Branded sign-in emails
Magic-link emails use Claribill branding and the selected German or English sign-in language.
Sign out
Invalidate the current server-side session when signing out.
Two-factor authentication (TOTP)
An additional verification step using an authenticator app.
Key rotation and expiry
A workflow for expiring and rotating API keys with reminders.
API usage audit trail
Detailed review of API key usage for investigation and anomaly detection.
Magic-link rate limits
Limit repeated magic-link requests to reduce abuse.
IP allowlist
Restrict access to explicitly approved IP ranges.
Try Claribill for free
Create your first invoice in under 5 minutes. No credit card required.
Start for free