Logging In
All ways to log in to Mindora: email, Google, two-factor authentication, and password reset.
Overview
- You can log in to Mindora in two ways: email/password or with your Google account.
- If you have enabled two-factor authentication (2FA), an additional verification code will be requested after login.
- The login page displays rotating informational messages on the left panel.
Email Login
Login is limited to 10 attempts per minute for security. Additionally, more than 20 failed attempts from the same IP address within 15 minutes will be blocked.
Enter your email address and password.
Click the "Log In" button.
If your account is not verified, you cannot log in (email verification is required first).
Google Login
Click the "Continue with Google" button at the bottom of the login page.
Select your Google account.
If you previously signed up with Google, you will log in directly.
If you signed up with email and later log in with Google using the same email, the accounts are automatically linked.
Two-Factor Authentication (2FA)
- If 2FA is enabled, a 6-digit verification code screen appears after login.
- Enter the code from your authenticator app (Google Authenticator, Authy, etc.).
- After 5 failed attempts, you are automatically logged out for security reasons.
- Recovery code option: If you cannot access your authenticator, click "Use recovery code".
- Recovery codes are 16 single-use codes in xxxx-xxxx format.
- You have 5 minutes to enter your 2FA code after login — if the time expires, you need to log in again.
Forgot Password
Click the "Forgot Password?" link on the login form.
Enter your email address.
A reset link is sent to your email (valid for 1 hour).
Click the link to set a new password (the same password rules apply).
Account Lockout
Too many failed login attempts will temporarily lock the account. Lockout durations increase progressively:
5 failed attempts → 15 minute lockout
10 failed attempts → 30 minute lockout
15 failed attempts → 60 minute lockout
You can try again after the lockout period expires.
Security Scenarios
Situations you may encounter at login that Mindora applies automatically for your security:
Mandatory password reset
A password reset may be required due to a security update. In this case, an automatic reset email is sent.
Session timeout
If no activity is detected for an extended period, the session is terminated for security reasons.
New device detection
A notification email is sent when a login is made from a different device or browser.
Account deletion request
If you have submitted an account deletion request, you cannot log in while the deletion process is ongoing.
OAuth errors
If an error occurs during Google login (access denied, state mismatch, etc.), you are redirected to the login page.