Enterprise Open source

Configure passwordless authentication with magic links

Passwordless authentication lets Grafana users authenticate with a magic link or one-time password (OTP) sent via email.

Enable passwordless authentication

Note

Passwordless authentication is an experimental feature. Engineering and on-call support is not available. Documentation is either limited or not provided outside of code comments. No SLA is provided. Enable the passwordlessMagicLinkAuthentication feature toggle in Grafana to use this feature.

To enable passwordless authentication, use the following configuration:

Bash
[auth.passwordless]
enabled = true

Code expiration

By default, the one-time password (OTP) sent to a user’s email is valid for 20 minutes. Use the code_expiration option to change the duration that the OTP is valid.

Bash
[auth.passwordless]
enabled = true
code_expiration = 20m

Enable SMTP server

The SMTP server must be enabled so that Grafana can send emails. The following configuration enables the SMTP server. For more information on configuring the SMTP server, refer to SMTP.

Bash
[smtp]
enabled = true