Security and sign-in
You sign in to Carteia with a link sent to your email (valid for 15 minutes, usable once) or with Google sign-in. No saved passwords to steal. An email change always goes through a confirmation, so nobody can hijack your account.
Why it's already safe this way
Most account thefts start from a weak password, reused or caught in an attack on some other site. Carteia removes the problem at the root: there's no Carteia password to steal. You sign in with a link sent to your email, or with your Google account. Fewer things to remember, fewer things that can go wrong.

Method 1 — Link by email
It's the default way in.
Go to
carteia.appand type your email.You get an email with a sign-in link just for you.
Click the link within 15 minutes and you're in.
The link works once only: after use it's no longer valid.
The benefits are concrete:
- No password to invent, remember or reset.
- No password that could be stolen from an attack on another service.
- Harder to fall for a scam: even someone who knows your email still has to get into your inbox to use it.
- The old "I forgot my password" becomes a simple "send me the link again".
Method 2 — Google sign-in
Alternatively you can sign in with Continue with Google: you use your Google account's identity, with all the protections you've already set up there (strong password, two-step verification). It's the recommended choice if your venue already uses a Google or Google Workspace mailbox.
The email change is a security control
When you request to change your sign-in email (from the Settings page), the change is not instant: we send a confirmation link to the new address, and the change only kicks in when you click it. Translation: nobody can change your account email without holding the new mailbox. A small extra wait that protects you a lot.
How to spot a real Carteia email
Our genuine emails always have these traits:
- They come from the
carteia.appdomain (for examplenoreply@carteia.app). - The links point only to
https://carteia.app/..., never to other sites. - We never ask for passwords, codes or card details by replying to an email.
If you get a message that looks like Carteia but the link goes elsewhere, don't click: report it to us and we'll check.
If you suspect a sign-in that isn't yours
Suspect someone got into your account? Do this:
Immediately request a new sign-in link from your real email: any pending links from earlier attempts stop working.
If you sign in with Google, change your Google account password.
Write to us describing what happened: we can check the sign-ins from our side and, if needed, lock the account.
Next steps
Frequently Asked Questions
- I got a sign-in link I didn't ask for. What should I do?
- Ignore it. It expires in 15 minutes and works only once. If it happens often, write to us: someone may be trying to get in as you.
- Do I need a password manager?
- No, there are no Carteia passwords to manage. At most, save the email you sign in with in your manager so you find it quickly.
- I lost access to my email. Now what?
- Write to us from another contact (phone, social). We verify it's really you with billing data and your VAT number, then move access to a new email.
- Does Carteia have two-factor authentication?
- A true second factor isn't built into Carteia yet. But if you sign in with Google you already use your Google account's protections (strong password, two-step verification): it's the most solid way to get in today.
Version history
v3.0.02026-05-29— Tone and content update: added the email change with confirmation as a security control, clarified the state of two-factor authentication, aligned the six 2026-Q2 plans. Confirmed the two real methods: link by email (magic link) + Google sign-in.v2.0.02026-05-22— Rewrite: removed sections on 2FA, active sessions and access logs not present in code.v1.0.02026-05-20— First publication.