I’d like to lobby hard for a preference to disable the password-less login option to HubSpot customer portals and knowledge bases. While likely well intentioned by HubSpot, it’s causing strife with the users of our own SaaS product.
Our use case: we support special, designated contacts at paying institutional customers of our SaaS service via a HubSpot customer portal and post information just for them behind the customer portal authentication firewall.
If this small subset of authenticated users share links to a resource on our portal, if search engines index the content, or if they even well-intentionally share even share the address of our portal, some users among the millions of end users in our customer orgs start clicking the password-less login button and entering their email address, thinking they’re logging into OUR SaaS service. Even though it’s labeled at the top of the screen “customer portal,” end users can’t be counted on to understand the distinction. They’re at our domain, after all.
This results in three bad outcomes:
It gives the user the false impression OUR service is down when they get a 403 error … because they think they’re logging into our product and are denied -- which is contributing to user dissatisfaction with OUR product
It creates a HubSpot contact … which is flooding our HubSpot instance with undesired contacts, and
These undesired contacts are often the email addreses of children, as many of the end users of our SaaS service are K-12 age students, and we carefully adhere to the policy requirements of many govenments worldwide and do not market to K-12 age students
Please prioritize making password-less login an option that can be disabled per customer portal.
Hi @Edsby,
Thank you for your valuable feedback on the HubSpot Community, it means a lot to us.
I’ve shared it internally for more visibility.
I’m sorry to hear about your experience regarding this.
I would like to apologize for the frustration, data issues, and business impact this has caused.
I understand that you are referring to the password-less authentication feature, which allows end-users to register and login without necessarily setting up a password. Please let me know if that’s not the case @Edsby.
For new feature suggestions, I’d recommend first to search and check if this idea is already present on our Ideas Forum here. If you find a similar idea, give it an upvote and share your unique use case in the comments.
If the idea doesn’t exist already, please consider posting and creating a new Idea on our Ideas Forum here.
And please @Edsby, let me know if there is anything else I can do for you, I’d be delighted to do so!
Have a lovely day!
Best,
Bérangère
Hi @Edsby, after checking internally for you, I’d like to share these options.
There are a couple of options available for membership settings on knowledge base and customer portal, and you can disable and enable based on your use-case.
If it is the password-less authentication that you are finding to be problematic, you can disable the feature in private content settings.
Here is the article about it: “Edit general settings for private content”.
I hope this helps!
And please @Edsby, let me know if there is anything else I can help with, I’d be delighted to do so
Best,
Bérangère
Glad to learn that the feature to disable password-less login already exists. It has been successfully toggled off on our instance and my suspicion is this will solve our problem.