Find your message in the tables below. Everything quoted here is quoted exactly as Leed shows it, so the fastest route through this page is to search it for the words on your screen. Nothing on this page requires an administrator to diagnose — but a few of the outcomes do need one to fix, and those rows say so.
If you cannot quote a message — because nothing arrived, or because a screen is simply refusing to move — start from the symptom instead.
flowchart TD
S{What is actually happening?} --> A["No email ever arrives"]
S --> B["A red message on the screen"]
S --> C["I signed in, then Leed bounced me"]
S --> D["A terminal or an app is stuck"]
A --> A1["The email never arrives<br/>+ Too many attempts"]
B --> B1["Sign-in screen · connecting GitHub ·<br/>sending or entering a code · the challenge"]
C --> C1["You are signed in but Leed<br/>says you cannot be here"]
D --> D1["Device and app-authorization messages"]
Messages on the sign-in screen
These five arrive as a redirect back to /login after a GitHub round trip, and render in a red panel above the provider buttons.
| Message (verbatim) | Underlying code | What happened | What to do |
|---|---|---|---|
| GitHub sign-in only works for existing Leed accounts. If you already have a Leed account under a different email, sign in with a magic link, then connect GitHub from your profile settings. Otherwise, ask your administrator for an invitation. | signup_disabled | No Leed account matched this GitHub identity, and GitHub is not allowed to create one | Magic link, then connect GitHub — or ask for an invitation if you have no Leed account at all |
| More than one Leed account uses a verified email from this GitHub account, so we can’t tell which one you mean. Sign in with a magic link, then connect GitHub from your profile settings — that links this GitHub account to that login for good. | github_multiple_accounts | Two or more Leed accounts hold addresses verified on this one GitHub account. Leed refuses to guess rather than picking one | Magic link into the account you actually want, then connect GitHub from it |
| Your Leed account email hasn’t been verified yet, so we can’t link GitHub to it. Sign in with a magic link once, then connect GitHub from your profile settings. | account_not_linked | Your Leed address is not verified, so nothing may be linked to it | One magic-link sign-in verifies the address permanently; then connect GitHub |
| None of the email addresses on your GitHub account are verified on GitHub. Verify one that matches your Leed account and try again. | email_not_found | GitHub reported no verified address at all | Verify an address on GitHub — Leed will match any verified address, not only your primary |
| We couldn’t reach GitHub to read your account details. Please try again in a moment. | github_email_fetch_failed | GitHub’s API could not be read. Leed fails closed rather than pretending you have no verified addresses | Retry shortly; if it persists, use a magic link |
| Sign-in failed. Please try again. | anything else | The catch-all for a redirect code Leed has no specific copy for | Retry; if it repeats, sign in with a magic link and report the message |
The raw codes, for searching and for support tickets
The code arrives as an error query parameter on the sign-in URL — /login?error=signup_disabled, and so on. The five Leed renders copy for are signup_disabled, github_multiple_accounts, account_not_linked, email_not_found and github_email_fetch_failed. Anything else falls through to Sign-in failed. Please try again.
Two of those five are Leed’s own: github_multiple_accounts and github_email_fetch_failed are raised by Leed’s GitHub identity matching rather than by the OAuth library, which is why they read as sentences rather than as generic OAuth failures.
Messages while connecting or disconnecting GitHub
These come from the Connected Accounts block on your profile’s Security tab, not from the sign-in screen.
| Message (verbatim) | Underlying code | What happened | What to do |
|---|---|---|---|
| That GitHub account is already connected to a different Leed login. A GitHub account can only sign in to one Leed account — disconnect it there first, or use a magic link here. | account_already_linked_to_different_user | One GitHub account, one Leed login. This one is spoken for | Sign in to the other Leed account and disconnect GitHub there, then connect it here |
| For your security, connecting or disconnecting GitHub needs a recent sign-in. Sign out and back in, then try again. | SESSION_NOT_FRESH | Your session is older than the freshness window that linking requires | Sign out, sign back in with a magic link, and connect immediately |
| GitHub couldn’t be connected to your Leed account. Its email may not be verified on GitHub, or your Leed email may not be verified yet — sign in with a magic link once, then try again. | unable_to_link_account | The link was refused; both ends of the address check are candidates | Verify an address on GitHub, and sign in once with a magic link to verify your Leed address |
| None of the email addresses on your GitHub account are verified on GitHub. Verify one on GitHub and try again. | email_not_found | GitHub reported no verified address | Verify one on GitHub |
| We couldn’t reach GitHub to read your account details. Please try again in a moment. | github_email_fetch_failed | GitHub’s API could not be read | Retry shortly |
| GitHub sign-in isn’t configured on this environment. | PROVIDER_NOT_FOUND | This Leed environment has no GitHub credentials, so there is nothing to connect to | Nothing you can fix from your account; the button should not be offered here |
| Something went wrong. Please try again. | — | The fallback for anything with no specific copy | Retry, then report the message |
Both controls live on the Security tab, which is also where you sign out of a stale session in order to satisfy that requirement.
Failures while sending or entering a code
These six are raised by the browser when a request fails, and each is a single catch-all with no more specific variant behind it — the wording will not narrow down for you.
| Message | Where | What to do |
|---|---|---|
| Failed to send magic link. Please try again. | The sign-in screen, after Send magic link | Retry. If it repeats, wait a minute — repeated attempts are rate-limited |
| Could not send a login code. Please check your email and try again. | The code step, after Send Login Code | Check the address for typos, then retry |
| That code didn’t work. Request a new one and try again. | The code step, after Verify and continue | Codes last five minutes and are single-use. Press Use a different email, then request a fresh code |
| Google sign-in failed. Please try again. | The sign-in screen | Retry; if it persists, use a magic link |
| GitHub sign-in failed. Please try again. | The sign-in screen | Retry; if it persists, use a magic link |
| Failed to create account. The email may already be registered. | Either sign-up form | The address already has a Leed login — sign in instead of signing up. Do not create a second account on another address |
The email never arrives
Nothing on this list is exotic; work down it in order.
- Check the address. Both the Check your email and Check Your Email screens print back the address they used. A typo there is the single most common cause.
- Check spam and quarantine. Sign-in mail comes from a no-reply sender and is exactly the shape a filter distrusts.
- Do not reuse an old email. Magic links and login codes expire five minutes after they are issued and work once. An email from ten minutes ago is not a spare — request a new one.
- Wait a moment between requests. Repeated requests from the same place are rate-limited, and the rate limiter’s refusal looks like nothing happening.
One cause worth knowing about because you cannot see it from the sign-in screen: an address that has hard-bounced is suppressed, and further mail to it is not attempted. If mail to your address used to arrive and now never does, that is a case for an administrator or for support rather than for another retry.
“Please verify you are human” never resolves
The challenge on the sign-up and sign-in forms is a Cloudflare Turnstile widget. The Create account and Send magic link buttons stay disabled until it resolves, and if its token expires while you are still typing, the button goes back to disabled and the widget re-arms. Waiting a few seconds for it to settle is usually the whole fix; a privacy extension or a blocked third-party script is the usual cause when it is not.
If the widget resolves but the request is still refused, the response says which half failed:
| Response | HTTP | Trigger | What to do |
|---|---|---|---|
Captcha verification required | 400 | The request carried no challenge token at all — usually a form submitted before the widget resolved, or a script blocking it | Reload the page, let the widget finish, and submit again |
Captcha verification failed | 403 | A token was sent and Cloudflare rejected it — most often stale, or already used | Reload the page to get a fresh challenge |
Three actions are protected by the challenge: creating an account, signing in by email, and requesting a magic link. Nothing else in Leed asks you to prove you are human.
Too many attempts
Repeated sign-in requests from the same place are rate-limited, and a limited request comes back as 429. There is no counter shown and no countdown — wait, then try once more rather than retrying in a loop.
What is never rate-limited is worth knowing, because it tells you where a stuck loop cannot be coming from: reading your session, listing your sessions, signing out, the device-authorization polling your terminal does, and looking up an invitation. All of those are exempt. A loop that will not clear is therefore always on the credential-sending side — magic links, login codes, sign-ups — and waiting is the remedy.
You are signed in but Leed says you cannot be here
These four are not sign-in failures. Your login worked; what failed is placing you in a workspace. The first three need an administrator, and the fourth needs you.
| Message or behavior | HTTP | Cause | Who fixes it |
|---|---|---|---|
User is not registered in this system | 403 | Your login exists, but there is no CMS user record for it | An administrator |
User is not a member of this organization | 403 | You have a CMS user record but no role in this workspace | An administrator |
No organization membership found | 403 | You belong to zero workspaces | An administrator, or create your own workspace |
| Leed sends you to the organization picker | 422 org_selection_required | You belong to several workspaces and none is currently active | You, by picking one |
The last one is not an error at all — if Leed sends you to a list of workspaces, that is the organization picker doing its job. It is skipped entirely when you belong to exactly one workspace, which is why most people never see it. It is also deliberately suppressed on the sign-in screen, the picker itself and the app-authorization screen, because each of those manages the choice itself.
The first three are all the same underlying shape: an account that exists on one side of Leed and not the other. An administrator resolves them from Managing Team Members. The most common way to arrive at them is by accepting an invitation that was never finished on the administrator’s side, which is covered from the invitee’s point of view in Joining and Switching Workspaces.
Two more messages come from the picker screen itself: Failed to load organizations. means the list could not be fetched, and Failed to select organization. means the workspace you clicked could not be made active. Both are retryable; if either persists, sign out and back in.
Invitation messages
| Message (verbatim) | Screen | Cause | What to do |
|---|---|---|---|
| This invitation is invalid or has expired. | Invalid Invitation | The invitation id in the link does not resolve — revoked, already deleted, or past its expiry | Ask the person who invited you to send a new one |
| This invitation could not be found. | Invalid Invitation | The link resolved to nothing at all | As above |
| This invitation has already been {status}. | Invitation Already Used | The invitation is no longer pending — the status word is filled in with what actually happened to it | If you accepted it already, sign in normally. Otherwise ask for a fresh invitation |
| Failed to accept invitation. | Join {workspace} | Accepting the invitation was refused | Retry once; if it repeats, the invitation needs to be reissued |
| You don’t belong to any organizations yet. | No Organizations | Your login is real but has no workspace membership | Ask an administrator to invite you, or use Create Company to start your own |
Device and app-authorization messages
These come from the two approval screens: the device screen a terminal sends you to, and the consent screen an application sends you to. Both are described in Authorizing Devices and Clients.
| Message (verbatim) | Screen | Cause | What to do |
|---|---|---|---|
| Failed to authorize device. Check the code and try again. | Authorize Device | The code did not match a pending request — mistyped, or already expired | Re-read the code in your terminal and retype it, or start the sign-in again from the CLI |
| This link has expired — Your connection request timed out. Please start the connection again from your app. | Sign in to continue | The signed authorization request an application sent you with has passed its short expiry | Go back to the application and start the connection again |
| Could not complete authorization. Please try connecting again from your app. | Authorize access | You approved, but the authorization could not be completed | Start the connection again from the application |
| Could not record your decision. Please try again. | Authorize access | You declined, and the decision could not be recorded | Retry; declining again is harmless |
| None of your workspaces are on a plan that supports connecting AI tools. Ask a workspace admin to upgrade. | Authorize access | See below — this is not really about your plan | Report it; it is not something an upgrade will fix |
A code shown in your terminal is approved on the device screen, and the command-line half of the same flow is in CLI Authentication.
When none of these match
Work through this once, in order — it clears most of what is left:
- Open the Security tab and revoke every session except the one you are using.
- Sign out.
- Sign back in with a magic link, in a normal (non-private) window, with extensions disabled.
If it still fails, the three things that make a support ticket answerable on the first reply are: the exact message, copied rather than paraphrased; the time you saw it, with your timezone; and the address you signed in with. If the message came with a code in the URL — ?error=… — include that too.
Errors from the rest of the product — the CLI, the site build, MCP — are collected in Common Error Messages.