Skip to main content

Login & OTP FAQ

Use this page when staff login, forgot password, set-password links, patient portal OTP, magic login or workspace switching fails.

Who can do this: staff users, patient portal users, and owners/admins who manage employee accounts. Where: Staff Login (/login), Forgot Password (/forgot-password), patient portal login, and My workspaces.

Why does staff password login say Invalid credentials?​

  1. Check Email Address spelling.
  2. Check Password.
  3. If the login page shows Detected workspace, confirm it is the right clinic.
  4. If no workspace is saved, login still attempts workspace auto-detection by email.
  5. Click Forgot password? if you are unsure.

After 5 failed login attempts in 15 minutes, the API returns Too many failed attempts. Try again in N seconds.

What if the login page detected the wrong workspace?​

The login page can show Detected workspace when a saved tenant is present. Multi-workspace accounts can switch after login.

  1. If you can login, open My workspaces or use the header workspace selector.
  2. Choose the correct workspace.
  3. The app reloads into the new session.
  4. If switching fails, note the message Unable to switch workspace from the selector.
  5. If you cannot login at all, ask the owner to confirm your employee account in that clinic.

A user with missing tenant context can see Tenant context missing for this account. Please contact support.

I forgot my staff password​

  1. Open /forgot-password.
  2. Enter your Email Address.
  3. Click Send Reset Link.
  4. Check email for Reset Your Password ? Achal Technology.
  5. Open the link within 1 hour.
  6. Enter New Password and Confirm Password.
  7. Click Reset Password.

The response is always If an account exists for this email, a password reset link has been sent. so account existence is not revealed.

Reset links expire in 1 hour and can be used once.

Possible messages include:

  • This reset link is invalid or has expired. Please request a new one.
  • This reset link has already been used. Please request a new one.
  • Token is required
  • Password must be at least 6 characters
  1. Click Request a New Link.
  2. Use the newest email only.
  3. After reset, login again because existing sessions are revoked.

Set-password links are for new employees and expire in 72 hours.

Possible messages include:

  • Invalid or expired token. Please contact your administrator.
  • Password has already been set. This link can only be used once.
  • Password has already been set. Please login or contact your administrator.
  1. Ask the owner/admin to resend access if you never set a password.
  2. If you already set it once, use Forgot password?.
  3. Create a password with at least 6 characters.
  4. Click Set Password & Activate Account.

OTP says please wait​

/auth/public/send-otp allows one send per phone per minute. The exact message is Please wait N seconds before requesting a new OTP. OTPs expire after 5 minutes.

  1. Wait for the number of seconds shown.
  2. Request a new OTP only once.
  3. Use the latest code, not an older WhatsApp/SMS.

OTP is wrong, used or expired​

Use the latest code only.

Messages include:

  • OTP not found. Please request a new OTP via WhatsApp or SMS.
  • This OTP has already been used. Please request a new one.
  • OTP has expired. Please request a new one.
  • Incorrect OTP. N attempts remaining before account lockout.
  • Too many failed OTP attempts. Account locked for 24 hours. Contact support for immediate unlock.

After 5 failed OTP attempts on a linked staff account, the account locks for 24 hours.

Patient portal login says patient not found​

The portal matches the verified phone to active patient records.

  1. In the staff app, open the patient record.
  2. Check contactNumber, phone, guardianPhone, alternatePhone or mobileNumber.
  3. Store the correct 10-digit mobile number.
  4. Ask the patient to request OTP again.

Possible messages are No patient record found for this phone number. and No account found with this phone number. Please register first.

What is shared-phone profile selection?​

If multiple active patients share one family phone, OTP or magic link proves phone ownership first, then the portal asks which profile to open.

  1. Patient completes OTP or opens the WhatsApp magic link.
  2. The portal shows Select a profile.
  3. Patient chooses the correct profile.
  4. The session becomes patient-id-bound.

Expired selection returns PROFILE_SELECTION_INVALID; choosing a non-matching patient returns PROFILE_NOT_ALLOWED.

WhatsApp magic login and reset links are one-time and expire.

  1. If magic login says This login link has already been used. Please request a new one., send LOGIN on WhatsApp again.
  2. If it says Login link has expired. Please request a new one via WhatsApp., send LOGIN again.
  3. If reset says Reset link has expired. Please send 'RESET' on WhatsApp for a new link., send RESET.
  4. Use the newest link only.

What if my session expired or membership was suspended?​

A password reset signs you out on all devices. Membership suspension revokes tokens for that tenant user. Workspace lock can also redirect you to subscription billing.

  1. Login again from /login.
  2. If you belong to multiple clinics, use My workspaces after login.
  3. If your workspace is locked, open Subscription Billing (/app/subscription-billing).
  4. If your membership was suspended, contact the clinic owner.

Still stuck?​

Open Help & Support (/app/support) and send your workspace name, login email or masked phone, time, exact error message, and screenshot. Never send OTPs, passwords, reset links, patient records or clinical data in chat.