Sign-in Troubleshooting

Find your message in the tables below. Everything quoted here is quoted exactly as Leed shows it, so the fastest route through this page is to search it for the words on your screen. Nothing on this page requires an administrator to diagnose — but a few of the outcomes do need one to fix, and those rows say so.

If you cannot quote a message — because nothing arrived, or because a screen is simply refusing to move — start from the symptom instead.

flowchart TD
    S{What is actually happening?} --> A["No email ever arrives"]
    S --> B["A red message on the screen"]
    S --> C["I signed in, then Leed bounced me"]
    S --> D["A terminal or an app is stuck"]

    A --> A1["The email never arrives<br/>+ Too many attempts"]
    B --> B1["Sign-in screen · connecting GitHub ·<br/>sending or entering a code · the challenge"]
    C --> C1["You are signed in but Leed<br/>says you cannot be here"]
    D --> D1["Device and app-authorization messages"]

Messages on the sign-in screen

These five arrive as a redirect back to /login after a GitHub round trip, and render in a red panel above the provider buttons.

The sign-in screen showing a red GitHub error panel above the provider buttons
Message (verbatim)Underlying codeWhat happenedWhat to do
GitHub sign-in only works for existing Leed accounts. If you already have a Leed account under a different email, sign in with a magic link, then connect GitHub from your profile settings. Otherwise, ask your administrator for an invitation.signup_disabledNo Leed account matched this GitHub identity, and GitHub is not allowed to create oneMagic link, then connect GitHub — or ask for an invitation if you have no Leed account at all
More than one Leed account uses a verified email from this GitHub account, so we can’t tell which one you mean. Sign in with a magic link, then connect GitHub from your profile settings — that links this GitHub account to that login for good.github_multiple_accountsTwo or more Leed accounts hold addresses verified on this one GitHub account. Leed refuses to guess rather than picking oneMagic link into the account you actually want, then connect GitHub from it
Your Leed account email hasn’t been verified yet, so we can’t link GitHub to it. Sign in with a magic link once, then connect GitHub from your profile settings.account_not_linkedYour Leed address is not verified, so nothing may be linked to itOne magic-link sign-in verifies the address permanently; then connect GitHub
None of the email addresses on your GitHub account are verified on GitHub. Verify one that matches your Leed account and try again.email_not_foundGitHub reported no verified address at allVerify an address on GitHub — Leed will match any verified address, not only your primary
We couldn’t reach GitHub to read your account details. Please try again in a moment.github_email_fetch_failedGitHub’s API could not be read. Leed fails closed rather than pretending you have no verified addressesRetry shortly; if it persists, use a magic link
Sign-in failed. Please try again.anything elseThe catch-all for a redirect code Leed has no specific copy forRetry; if it repeats, sign in with a magic link and report the message
The raw codes, for searching and for support tickets

The code arrives as an error query parameter on the sign-in URL — /login?error=signup_disabled, and so on. The five Leed renders copy for are signup_disabled, github_multiple_accounts, account_not_linked, email_not_found and github_email_fetch_failed. Anything else falls through to Sign-in failed. Please try again.

Two of those five are Leed’s own: github_multiple_accounts and github_email_fetch_failed are raised by Leed’s GitHub identity matching rather than by the OAuth library, which is why they read as sentences rather than as generic OAuth failures.

Messages while connecting or disconnecting GitHub

These come from the Connected Accounts block on your profile’s Security tab, not from the sign-in screen.

Message (verbatim)Underlying codeWhat happenedWhat to do
That GitHub account is already connected to a different Leed login. A GitHub account can only sign in to one Leed account — disconnect it there first, or use a magic link here.account_already_linked_to_different_userOne GitHub account, one Leed login. This one is spoken forSign in to the other Leed account and disconnect GitHub there, then connect it here
For your security, connecting or disconnecting GitHub needs a recent sign-in. Sign out and back in, then try again.SESSION_NOT_FRESHYour session is older than the freshness window that linking requiresSign out, sign back in with a magic link, and connect immediately
GitHub couldn’t be connected to your Leed account. Its email may not be verified on GitHub, or your Leed email may not be verified yet — sign in with a magic link once, then try again.unable_to_link_accountThe link was refused; both ends of the address check are candidatesVerify an address on GitHub, and sign in once with a magic link to verify your Leed address
None of the email addresses on your GitHub account are verified on GitHub. Verify one on GitHub and try again.email_not_foundGitHub reported no verified addressVerify one on GitHub
We couldn’t reach GitHub to read your account details. Please try again in a moment.github_email_fetch_failedGitHub’s API could not be readRetry shortly
GitHub sign-in isn’t configured on this environment.PROVIDER_NOT_FOUNDThis Leed environment has no GitHub credentials, so there is nothing to connect toNothing you can fix from your account; the button should not be offered here
Something went wrong. Please try again.—The fallback for anything with no specific copyRetry, then report the message

Both controls live on the Security tab, which is also where you sign out of a stale session in order to satisfy that requirement.

Failures while sending or entering a code

These six are raised by the browser when a request fails, and each is a single catch-all with no more specific variant behind it — the wording will not narrow down for you.

MessageWhereWhat to do
Failed to send magic link. Please try again.The sign-in screen, after Send magic linkRetry. If it repeats, wait a minute — repeated attempts are rate-limited
Could not send a login code. Please check your email and try again.The code step, after Send Login CodeCheck the address for typos, then retry
That code didn’t work. Request a new one and try again.The code step, after Verify and continueCodes last five minutes and are single-use. Press Use a different email, then request a fresh code
Google sign-in failed. Please try again.The sign-in screenRetry; if it persists, use a magic link
GitHub sign-in failed. Please try again.The sign-in screenRetry; if it persists, use a magic link
Failed to create account. The email may already be registered.Either sign-up formThe address already has a Leed login — sign in instead of signing up. Do not create a second account on another address

The email never arrives

Nothing on this list is exotic; work down it in order.

  1. Check the address. Both the Check your email and Check Your Email screens print back the address they used. A typo there is the single most common cause.
  2. Check spam and quarantine. Sign-in mail comes from a no-reply sender and is exactly the shape a filter distrusts.
  3. Do not reuse an old email. Magic links and login codes expire five minutes after they are issued and work once. An email from ten minutes ago is not a spare — request a new one.
  4. Wait a moment between requests. Repeated requests from the same place are rate-limited, and the rate limiter’s refusal looks like nothing happening.

One cause worth knowing about because you cannot see it from the sign-in screen: an address that has hard-bounced is suppressed, and further mail to it is not attempted. If mail to your address used to arrive and now never does, that is a case for an administrator or for support rather than for another retry.

“Please verify you are human” never resolves

The challenge on the sign-up and sign-in forms is a Cloudflare Turnstile widget. The Create account and Send magic link buttons stay disabled until it resolves, and if its token expires while you are still typing, the button goes back to disabled and the widget re-arms. Waiting a few seconds for it to settle is usually the whole fix; a privacy extension or a blocked third-party script is the usual cause when it is not.

If the widget resolves but the request is still refused, the response says which half failed:

ResponseHTTPTriggerWhat to do
Captcha verification required400The request carried no challenge token at all — usually a form submitted before the widget resolved, or a script blocking itReload the page, let the widget finish, and submit again
Captcha verification failed403A token was sent and Cloudflare rejected it — most often stale, or already usedReload the page to get a fresh challenge

Three actions are protected by the challenge: creating an account, signing in by email, and requesting a magic link. Nothing else in Leed asks you to prove you are human.

Too many attempts

Repeated sign-in requests from the same place are rate-limited, and a limited request comes back as 429. There is no counter shown and no countdown — wait, then try once more rather than retrying in a loop.

What is never rate-limited is worth knowing, because it tells you where a stuck loop cannot be coming from: reading your session, listing your sessions, signing out, the device-authorization polling your terminal does, and looking up an invitation. All of those are exempt. A loop that will not clear is therefore always on the credential-sending side — magic links, login codes, sign-ups — and waiting is the remedy.

You are signed in but Leed says you cannot be here

These four are not sign-in failures. Your login worked; what failed is placing you in a workspace. The first three need an administrator, and the fourth needs you.

Message or behaviorHTTPCauseWho fixes it
User is not registered in this system403Your login exists, but there is no CMS user record for itAn administrator
User is not a member of this organization403You have a CMS user record but no role in this workspaceAn administrator
No organization membership found403You belong to zero workspacesAn administrator, or create your own workspace
Leed sends you to the organization picker422 org_selection_requiredYou belong to several workspaces and none is currently activeYou, by picking one

The last one is not an error at all — if Leed sends you to a list of workspaces, that is the organization picker doing its job. It is skipped entirely when you belong to exactly one workspace, which is why most people never see it. It is also deliberately suppressed on the sign-in screen, the picker itself and the app-authorization screen, because each of those manages the choice itself.

The first three are all the same underlying shape: an account that exists on one side of Leed and not the other. An administrator resolves them from Managing Team Members. The most common way to arrive at them is by accepting an invitation that was never finished on the administrator’s side, which is covered from the invitee’s point of view in Joining and Switching Workspaces.

Two more messages come from the picker screen itself: Failed to load organizations. means the list could not be fetched, and Failed to select organization. means the workspace you clicked could not be made active. Both are retryable; if either persists, sign out and back in.

Invitation messages

Message (verbatim)ScreenCauseWhat to do
This invitation is invalid or has expired.Invalid InvitationThe invitation id in the link does not resolve — revoked, already deleted, or past its expiryAsk the person who invited you to send a new one
This invitation could not be found.Invalid InvitationThe link resolved to nothing at allAs above
This invitation has already been {status}.Invitation Already UsedThe invitation is no longer pending — the status word is filled in with what actually happened to itIf you accepted it already, sign in normally. Otherwise ask for a fresh invitation
Failed to accept invitation.Join {workspace}Accepting the invitation was refusedRetry once; if it repeats, the invitation needs to be reissued
You don’t belong to any organizations yet.No OrganizationsYour login is real but has no workspace membershipAsk an administrator to invite you, or use Create Company to start your own

Device and app-authorization messages

These come from the two approval screens: the device screen a terminal sends you to, and the consent screen an application sends you to. Both are described in Authorizing Devices and Clients.

Message (verbatim)ScreenCauseWhat to do
Failed to authorize device. Check the code and try again.Authorize DeviceThe code did not match a pending request — mistyped, or already expiredRe-read the code in your terminal and retype it, or start the sign-in again from the CLI
This link has expired — Your connection request timed out. Please start the connection again from your app.Sign in to continueThe signed authorization request an application sent you with has passed its short expiryGo back to the application and start the connection again
Could not complete authorization. Please try connecting again from your app.Authorize accessYou approved, but the authorization could not be completedStart the connection again from the application
Could not record your decision. Please try again.Authorize accessYou declined, and the decision could not be recordedRetry; declining again is harmless
None of your workspaces are on a plan that supports connecting AI tools. Ask a workspace admin to upgrade.Authorize accessSee below — this is not really about your planReport it; it is not something an upgrade will fix

A code shown in your terminal is approved on the device screen, and the command-line half of the same flow is in CLI Authentication.

When none of these match

Work through this once, in order — it clears most of what is left:

  1. Open the Security tab and revoke every session except the one you are using.
  2. Sign out.
  3. Sign back in with a magic link, in a normal (non-private) window, with extensions disabled.

If it still fails, the three things that make a support ticket answerable on the first reply are: the exact message, copied rather than paraphrased; the time you saw it, with your timezone; and the address you signed in with. If the message came with a code in the URL — ?error=… — include that too.

Errors from the rest of the product — the CLI, the site build, MCP — are collected in Common Error Messages.

ESC