Understanding Magic Links
Tabletop Time uses a passwordless authentication system. Instead of usernames and passwords, we use secure "Magic Links" sent to your Telegram or Discord to verify your identity.
Why no passwords?
We believe you shouldn't need another password for a tool you use once a week. By verifying ownership of your Telegram/Discord account, we can prove it's you without storing sensitive credentials.
Use Case 1: Sync & Recover (My Events)
Best for: Logging in to view all your events at once.
If you are on a new device or your cookies have been cleared, you can recover access to your entire event history via the My Events (Profile) page.
The header of that page always shows two status pills. Already synced with a platform? You'll see a solid "Telegram Synced" or "Discord Synced" pill, and clicking it lets you disconnect this browser (a simple sign-out: your events and votes are kept, and you can reconnect anytime). Not synced yet? You'll see a dashed "Connect" pill instead.
- Navigate to the My Events page.
- Click "Connect Telegram" (opens a private chat with the bot and sends
/start login, so the bot DMs you a login link) or "Connect Discord" (starts the Discord sign-in). - For Telegram, the bot will DM you a Global Magic Link, valid for 15 minutes. Click it to log in. You can also send
/start loginto the bot yourself, in a private chat only. Discord logs you in directly once you authorize.
This will restore your Event List and your Voting Identity (allowing you to edit votes you linked to that Telegram or Discord account).
Use Case 2: Per-Event Sync Badges
Best for: seeing at a glance which events follow you across devices, and fixing the ones that don't.
Every card on My Events also carries its own badge, separate from the header pills: a colored "Telegram Synced" / "Discord Synced" badge means that event's vote is tied to your verified identity, while a gray "This Device Only" badge means it only exists in this browser's local history.
Events you manage also show a separate indigo "Manager" badge alongside any sync badges, marking your role there. It doesn't by itself mean your identity is linked, a managed event with no linked participant still just shows "Manager" (never "This Device Only", since it's already tied to the event on the server).
Click a badge to act on it: a gray badge opens a menu to link the event to whichever platform(s) you're synced with, and a colored badge opens a menu to unlink it. Linking requires you to have already voted on that event from this browser (so there's a participant row to stamp, and this browser can prove the vote is yours), and you can only unlink your own identity, never someone else's.
Use Case 3: Linking While You Vote
Best for: getting a new vote linked automatically instead of fixing it afterward.
If your browser is already synced when you vote, the vote form shows a "Will link to Telegram/Discord" indicator next to a checkbox, checked by default. Leave it checked and your vote is stamped with your synced identity automatically. Uncheck it if you'd rather that particular vote stay anonymous and device-only.
Voted before syncing, or opted out and changed your mind? The event page shows a dismissible banner offering to link that event whenever your browser is synced but your participant row on it isn't linked yet.
Use Case 4: Manager Recovery
Best for: Quickly switching devices for a specific event.
Viewing your event's Manage Page and want to switch to your phone?
- On the Manage Page, look for the Manager Recovery box. If you have not linked an account there yet, click "Register for Magic Links" (Telegram) or "Recover with Discord" first.
- Click "Send Magic Link".
- The bot DMs a login link, valid for 15 minutes, to each account linked as this event's manager, along with a link to the Manage Page.
- Opening the login link signs that browser in with your Telegram or Discord identity, which unlocks the Manage Page of the events that identity manages. Nothing is reset: your existing manager access keeps working.
Use Case 5: I'm Locked Out
Best for: Recovering access when cookies are gone.
If you are viewing an event you created but appear as a Participant (no admin controls):
- Scroll to the bottom of the Vote Page, under "Are you the organizer?".
- Click the small link: "Lost Manager Link?".
- Choose Telegram or Discord and enter your Telegram handle or Discord username.
- If it matches the manager account linked to this event, the bot sends a login link to that account's DMs. Typing a handle never links anything by itself: this works only if you linked your Telegram or Discord account as the manager beforehand.
Technical Insight
We use two layers of storage: Cookies (signed, HTTP-only server auth that stays valid for 400 days and refreshes each time you visit) and LocalStorage (to auto-fill your name and remember your specific votes on a device). Magic Links restore your signed identity cookie, which brings back your linked events and votes.