The portal attempts an automatic sign-in on every load and lets the server decide. /auth admits a platform user whose org owns the link, or platform staff, and skips the password only for them. Everyone else on a passworded link gets a 401 and sees the form. The same internal check suppresses opened_at, the estimate-opened notification and dwell-time recording.
Also called: preview my estimate · see what the customer sees · internal preview
- 1The page posts the link's own contact details to /auth as a best-effort sign-in
- 2The server resolves the caller's platform session and compares org ownership
- 3Internal users bypass the password and are marked as internal viewers
- 4The tracking heartbeat re-checks the real session and records nothing for internal visits
Builders write the estimates, so making them log in to read their own quote was friction with no purpose — and when a customer set a password on the link, the builder was locked out of their own document. Worse, a builder previewing their own send tripped the "your estimate was opened" alert, so the open-tracking numbers counted the builder's own visits and the follow-up call went out on a false signal. Internal users pass straight through and their views are excluded from tracking, checked against the real platform session rather than anything the browser claims, so a customer cannot opt out of tracking by editing a request.
- Builders locked out of documents they created
- Self-previews polluting open tracking and firing false alerts
See it on your own jobs
Twenty minutes, your numbers, no slide deck. We’ll build one of your real buildings in front of you and send you the estimate link at the end — yours to keep either way.
or keep browsing features →