Signing in
How staff, customers and partners get into the system, and what to do when they can't. Rules: ACC-060 … ACC-068.
Staff (/auth)
Type your username or your work email, then your password.
- Your username is shown on the Employees screen next to your email (
@sameer). It was made from your email; an administrator can change it. @alhuda.co.inand@alhudatravels.inare the same account. If your address issameer@alhuda.co.in, typingsameer@alhudatravels.inworks too. Capital letters don't matter.- Complete the verification box, then Sign in.
- The eye at the end of the password box shows what you typed; press it again to hide it (UX-021). Every password box has one — customer and partner sign-in, sign-up, reset password and the finance PIN too.
If the details don't match, you see one message — "That username or email and password do not match an active account." It is deliberately the same whether the account doesn't exist, the password is wrong, or the account is switched off, so the page can't be used to find out who works here.
Locked out. Five wrong attempts in 15 minutes locks that account for 15 minutes; the page says how long to wait. Resetting your password does not wait for the lock.
Forgot your password. Use Forgot password? on the sign-in page. Type your username or work email; the link always goes to your @alhudatravels.in mailbox (Google Workspace), even if you type your @alhuda.co.in address (ACC-072). The page always says a link is on its way — even for an address it doesn't know — for the same reason as above.
Opening the link. The link opens Choose a new password on the site you asked from (alhudatravels.in, www.alhudatravels.in or travel.alhuda.co.in). Type the new password twice and press Save New Password. If the link lands on the home page instead, the app moves you to the new-password form itself. If the page says the link is missing or has expired, the link was used already or is too old: ask for a new one and open the newest email. See ACC-072.
Two-step verification
Turn it on in Settings → Security → Two-step verification → Set up. You need an authenticator app on your phone — Google Authenticator, Microsoft Authenticator, 1Password or similar. Scan the QR code, type the 6-digit code, and save the ten backup codes somewhere safe.
From then on every sign-in asks for the code from the app. This is enforced by the database, not the screen: with only your password, your account can see and change nothing until the code is entered.
Lost your phone. At the code screen choose Use a backup code, type one, and complete the verification box. Each code works once. Your old authenticator is removed; set up a new one from Security settings straight away. If you have no backup codes left, ask an administrator to reset your two-step verification.
Running low on codes. Security settings shows how many are left and warns at two. Create new codes replaces the unused ones.
Email and WhatsApp codes are gone
Earlier versions offered a code by email or WhatsApp. It was checked only by the browser, after the password had already signed you in, so it gave no protection. It was removed on 23 September 2026; nobody had it switched on.
Customers and partners (/customer/auth, /partner/auth)
Type your email or your phone number — +91 98450 11111, 98450 11111 and
9845011111 are the same. If two accounts share a phone number, the phone won't sign
either of them in; use the email instead.
The staff page is for staff and the portal pages are for customers and partners; using the wrong one gives the same "do not match" message.
Forgot your password. Forgot password? sends a link to the email address on the account. Open it: the page signs you in from the link and asks for a new password. The link works once and for an hour.
The email didn't come. On the same page choose Get a code on WhatsApp instead. If you typed your phone number, the 6-digit code goes to that number. If you typed your email address, it goes to the WhatsApp number we hold for you (the one on your login, else on your customer record, else on your partner record). Type the code and your new password together. The code works for 10 minutes; five wrong codes and you must ask for a new one; you can ask for one a minute. The page always says the code is on its way — even for an account it doesn't know — for the same reason as above. Rule ACC-069.
If the page says WhatsApp codes are not switched on yet, use the email link or contact the office: the Meta template has not been approved (see operations → WhatsApp).
Signed up with an email address. The confirmation link comes from Alhuda Travels (not from Supabase). Until it is opened, signing in gives the usual "do not match" message; ask for the link again from the app's sign-up screen.
Signed up with a WhatsApp code. A customer who signed up with a code
(TRV-016)
signs in with that mobile number and their password, or with the email they gave when it
was kept on the account. Their sign-in identity is a placeholder address at
signup.alhudatravels.invalid that they never see and that receives no mail. Forgot
password? sends them no email — not even to the email they gave, which nobody has
confirmed is theirs — and answers as always; they use Get a code on WhatsApp instead,
which goes to the number they signed up with.
Signed up by chatting on WhatsApp. A customer who wrote "sign up" to the business number
and filled the form in the chat (TRV-017) gets a one-time link back in the chat:
/customer/set-password, 30 minutes, once. They choose a password there and are signed in.
After that it is the same as a WhatsApp-code sign-up: mobile number and password, and
Forgot password → WhatsApp code (also the way out when the link has expired or was lost).
For administrators (Employees screen)
- New staff get a username automatically from their email. You can type a different one when creating the account.
- Change a username with Change username in the person's ⋯ menu on Employees & staff. Usernames are lowercase, 3–30 characters (letters, digits, dots, dashes, underscores), and unique.
- One person, one account. Creating
sameer@alhudatravels.inwhensameer@alhuda.co.inexists is refused — it's the same person. - Deactivating somebody signs them out and blocks their sign-in; reactivating lets them back in. If blocking the sign-in fails, the screen says so instead of reporting success.
- Reset two-step verification (the shield button) for somebody who has lost both their phone and their backup codes.
Not built yet
- A person who talks to Supabase directly — not through these pages — meets only Supabase's own rate limit, not this system's lock or captcha. Accounts with an authenticator are still protected, because the database requires the code. Closing the gap for everyone means switching on Supabase's own captcha, which also needs customer self-sign-up changed. Planned for V1.1.
- Customer self-sign-up does not yet go through the same server check as sign-in.
- Staff have no WhatsApp backup for a password reset: a code on a phone is not a factor for a staff account. Ask an administrator to reset your password.
- There is no "remember this device" for two-step verification: the code is asked for at every sign-in.