Security

Access codes and one-time email codes: when do you need them?

An access code is a short code you tell the signer yourself, by phone or message, which they must type before the document will open. A one-time email code is different: it proves whoever used a public signing link really owns the email address they typed.

4 min read

Request Signatures has two different code features, and they do quite different jobs. Mixing them up is easy, so here they are side by side.

Access codes

Tick "Access codes" on the recipients step and each signer gets an optional code box. 4 to 12 letters or digits.

When a signer opens their link, they see a lock and this message: *"The sender protected this document with an access code. They will have given it to you separately. It is not in the email."*

Until they type it, the document does not open.

Why this helps

A signing link arrives by email. Email is convenient and not especially private. It can be forwarded, an inbox can be shared, a laptop can be left unlocked, an address can be typed wrong.

An access code splits the two things a person needs:

  • the link: which arrives by email,
  • the code: which you deliver another way entirely: a phone call, a text message, in person, or through a channel you already use with them.

Now someone who merely gets hold of the email still cannot open the document.

The everyday version

A parcel firm leaves your package with a neighbour and texts you a collection code. The neighbour has the parcel. Only you have the code.

How to hand the code over

Never in the same email. That defeats the entire point, and the tool never emails the code for you: *"Tell them the code yourself (by phone or message) it is never emailed."*

Good ways: ring them, send a text, tell them in the meeting where you agreed to send it, use a chat system you already share.

When to use them

  • Anything confidential: employment terms, salaries, medical or legal documents, anything with financial details.
  • High-value agreements where you want more than "this address received it".
  • When you are not fully certain the address is right, or it is a shared mailbox.

When not to bother

  • Routine internal documents.
  • Low-risk forms where the friction costs more than it protects.
  • Any case where you cannot reliably reach the person another way. A signer who has lost the code cannot get in, and the only fix is for you to tell them again.

One-time email codes

This is a different mechanism, used in a different situation: a public signing link.

A public link is one link you can put on your website, in a newsletter, or as a QR code on a counter. For a document that the same roles always sign, with one role left open for whoever turns up.

Because anybody might open it, the person has to prove something basic: that the email address they typed is really theirs. So they enter their name and address, a one-time code is emailed to that address, and they type it in to continue.

Why this is necessary

Without it, anyone could sign as anyone. Type in your manager's address and sign as them. The one-time code closes that: the code only reaches the real owner of the inbox.

What it does and does not prove

It proves control of that email address at that moment. It does not prove the person's legal identity. Nothing sent by email can. For a newsletter sign-up form or a consent form, that is exactly the right level of check. For a mortgage, it is not.

The two side by side

Access codeOne-time email code
Used onA request you send to named peopleA public signing link
Who sets itYou doGenerated automatically
How it reaches the personYou tell them, separatelyEmailed to the address they typed
What it provesThey know a secret you sharedThey control that inbox
Optional?YesNo, it is built into public links

Other things on the same screen

The recipients step also carries "Allow reassigning" (see reassigning a signature) and "I need to sign too", which simply adds you to the list. And on the review step you set how long the link stays open and how often reminders go out. Both worth setting deliberately for anything sensitive.

Common questions

What is an access code on a signature request?

A short code of 4 to 12 letters or digits that a signer must type before the document opens. You give it to them yourself, separately from the email.

Is the access code emailed to the signer?

No, never. That would defeat its purpose. You tell the signer by phone, message or in person.

What happens if a signer loses their access code?

They cannot open the document until you tell them again. There is no reset link, because the code is exactly what proves they are the right person.

What is a one-time email code used for?

It is used on public signing links. Whoever opens the link types their name and email, receives a code at that address, and enters it. Proving the address really is theirs.

Does a one-time email code prove who someone is?

No. It proves they control that inbox at that moment. It does not verify a legal identity, and no emailed code can.

Should I use access codes on every request?

No. Use them where the content is sensitive or the stakes are high. On routine documents they add friction without adding much.