Back to Blog
Guides September 4, 2026 9 min read

Getting Back In: When the Password Is the Problem

There are three ways back into an InnerHaven account, and they are not equivalent. Two of them you already know about. The third arrives in your inbox, signs you in without asking you to remember anything, and is deliberately built to do less than the other two. That last part is the interesting bit, and nobody has ever written it down. Here is all of it: what each route gives you, what one of them refuses on purpose, and why the refusal is a feature rather than a bug you have run into.

The Link in the Email Is a Sign-In

Some of the emails we send carry a link that does not take you to a login form. It takes you into your account, already signed in. No password, no reset, no typing. If you have ever clicked through from one of our emails and found yourself simply in, that is what happened, and it was intentional.

The reason it exists is not cleverness. It is that the most common reason somebody stops using a product is not that they lost interest. It is that they lost the thread, came back weeks later, could not remember which password they had used, and closed the tab. Every step between an email and being back in your conversations is a step somebody gives up on. So we removed them.

And It Is Deliberately Less Than a Full Sign-In

Here is the part worth understanding, because it explains a message you might one day see and mistake for a fault.

A session you got from an email link is marked as such, and it stays marked for as long as it lasts. It can do the things you came back for: read your conversations, keep talking, look around. It cannot do any of these:

What an email-link session refuses

Try any of those from a link session and you will be told, in so many words, that this needs a full sign-in and to come back with your password or with Google. Nothing has broken. That is the design working.

The reasoning, stated plainly

A sign-in link makes access to your inbox into access to your account. That sounds alarming until you notice that password reset already does exactly the same thing, and always has, for every product you use. So the real risk is not that the link grants inbox-level access. It is that the link might grant more than inbox-level access. Everything above is there to make sure it never does.

The One Thing It Can Do That Looks Like an Exception

Checkout is open to a link session. You can start a subscription or buy something from one, and that is deliberate rather than an oversight.

The reason is that checkout does not spend anything you already have on file. Payment details are collected fresh at our payment processor every time, so a link session cannot quietly charge a stored card. It can only reach a page that asks somebody to type in a card. Meanwhile, walling off checkout would have broken the ordinary case this whole feature exists for: reading an email about something new, wanting it, and being made to hunt for a password first.

So the line is not "reading is allowed and spending is not." It is sharper than that: a link session can never touch anything already stored about your money. That one sentence explains every entry on the list above and the exception too.

Fourteen Days, and Reusable, and Why That Is Not an Invitation

A sign-in link works for fourteen days, and within that window it works more than once.

That second part surprises people, so here is the honest reason. Corporate mail filters and inbox scanners follow links in email automatically, before a human ever opens the message, to check them for danger. A link that could only be used once would routinely be spent by a scanner and dead by the time you clicked it, and the person it was for would be locked out by the very system meant to protect them. Reusability is an anti-scanner measure, not a convenience.

Which means: do not forward it

Because the link keeps working, an email carrying one is as sensitive as your password for as long as it lives. Do not forward one of our emails to somebody else, do not paste the link into a chat, and treat a shared screen with your inbox on it the way you would treat a shared screen with a password manager open. If you ever want every outstanding link dead at once, change your password. That single action cancels all of them immediately, including ones in emails you have not opened.

Three Smaller Things That Are Easy to Miss

It will not downgrade a session you already have

If you are already properly signed in on that browser and you click a link from an email, nothing happens to your session. The restricted one does not replace the full one. You stay exactly as signed in as you were.

The link is out of the address bar before the page finishes loading

The token is taken out of the web address and out of your browser history immediately, before anything external to the page is allowed to load, and the page is set never to pass its address to anything it fetches. So it does not sit in your history, it does not travel in the background to anywhere else, and it will not turn up later in a screenshot of your address bar.

Where a link sends you is checked

Emails can point you at a particular page inside the product rather than the front door. That destination is validated against one rule with no exceptions: it must be a path inside InnerHaven. Anything shaped like an outside address is discarded and you land on the normal page instead. A link from us cannot bounce you somewhere else, and neither can a tampered copy of one.

The Other Two Ways In

Password reset

The ordinary route, and still the right one when you want everything back rather than a way to read your conversations. It gives you a full session with no restrictions, and as a side effect it cancels every outstanding sign-in link on your account. If you are worried that an old email of ours is sitting in an inbox you no longer control, this is the button that settles it.

Google

If you set your account up with Google, signing in that way gives you a full session too, with every control above available. It is also the route with nothing to remember, which makes it a reasonable answer to the problem in this article's title.

If None of It Works

The usual cause is the boring one: the address you are trying is not the address the account is under. People sign up with a personal address and later look for the account under a work one. Before assuming anything is broken, try the other address you might have used, and check whether our mail is sitting in a spam folder, which is where sign-in emails most often go to die.

And if you would rather see what is here before solving any of this, you do not need an account at all to start: demo mode gives you five messages with nothing to sign into.

What This Sits Next To

This page is the companion to our full inventory of every email InnerHaven can send you, which was recounted the same day this published and is now correct at twenty-nine senders. Two of the newer ones carry exactly the kind of link described here, which is why the two pages arrived together. If you are going the other direction and want the account gone rather than reopened, the deletion walkthrough is the honest version of that. And once you are back in, the guide to instructions, dials and a greeting covers what to change first.

Come Back In

Password, Google, or the link in your last email from us. Whichever is easiest today.

Sign In
IH

The InnerHaven Team

Connection that understands you.

Previous: Languishing Next: Reading Counts as Being Here →