Back to help
21

Account security, QR, and collaboration

Check your profile for the available login methods: password, a one-time code sent by email, or both. If both methods are available, you can disable code login; you can also end other sessions here. For collaboration, assign individual permissions and an access expiry time: QR editing works independently of viewing statistics. In the QR editor, undo and redo changes, update the embedded contact card in the preview, and check the readability of the saved image. The manual and practical course include detailed exercises and instructions for connecting a domain through DNS. Available features and limits depend on your account.

Account, sign-in and profile

An account is needed to return to links, change their settings, view analytics and use management tools. Links created without logging in should not be considered automatically linked to a future account.

Registration and restoration of access

• Select «Login» → «Register», fill in the displayed fields, password and arithmetic check.

• Open the confirmation email and follow the link. The email confirmation link is valid for two days.

• Log in with email or username and password. After logging in, «My links» and «Profile» will appear.

• If the password is forgotten, use «Forgot password?». The reset link is valid for two hours. Set a new password using the form in the letter.

If the entry is incorrect, correct the field indicated by the message and resolve the current security check. Repeated unsuccessful login attempts may be temporarily restricted. If the letter has not arrived, check your address and Spam folder; If you have a delivery problem, contact support at the address in the site header.

The welcome window after registration explains the available options. Close it with the continue button. It does not replace email confirmation.

Login with the code from the email and sessions

If there is «Login with a code from email» on the login page, open it and provide a verified email. Complete the shown security check, request a message, and enter the eight digits from the last message. The service shows the same request notification regardless of whether the account exists. If this method is not available to your account, the message will not be sent.

Usually, the code is valid for ten minutes, a repeat request is possible after one minute, and after five incorrect attempts a new code is required. Available periods and limits may vary; follow the form's message. A new code cancels the previous one. The code is one-time use; do not forward it to others.

In the profile, open «Security» → «Login methods». It indicates what is available: the password, the code from the message, or both methods. If both methods are allowed, you can uncheck «Allow login with a code from email» and save. The change will end other sessions. If login by code is disabled for the service, use the password or its recovery.

The «End other sessions» button keeps the current login active but requires re-login on other devices and cancels previously issued codes. If you suspect unauthorized access, also change your password and check the security of your email. The account login code and the visitor access code to a protected link are different codes for different actions.

Profile settings

In profile, you can update available user data, change the password, set up notifications, grant access to another user, freeze account links, or request account deletion. Email is displayed separately; Do not consider editing your name as changing your email address.

When changing your password, provide your current password, new password, and confirmation. The account password and the specific link password are independent: changing one does not change the other.

Freezing an account pauses redirects for links owned by that account. Select the freeze checkbox and save. To resume redirects, clear that checkbox and save again. Verify the result in a separate window while signed out. Freezing does not delete links or extend an expired link’s lifetime.

Deleting an account requires email confirmation; the confirmation link is valid for two hours. Save any reports and settings you need before confirming. Use freezing when you only want to pause a campaign. The user interface cannot restore a deleted account and all its associated data.

To exit, use the «Logout» button. On a shared computer, log off after work.

Groups and collaboration

Organization of links

• Open «Groups».

• Enter a name of up to 128 characters and select an icon.

• Save the group. Through the group menu you can change the name/icon or delete it.

• In the link card, open the «Groups» tab and configure membership in the desired groups.

One link can belong to several groups. For example, “Client A”, “Fall 2026” and “Printed Materials” at the same time. The group does not add UTM tags or change the target URL of the link.

When deleting a group, carefully check the box for deleting your own links that are only in that group. If you enable this feature, the deletion will affect more than just the list organization. Normally deleting a group without this checkbox preserves the links.

Access to another user

In your profile, find the access control block, enter your colleague's username and select permissions. A colleague needs his own account. A shared account password is not required for collaboration.

Resolution — What it allows View links — See available owner links Create links — Create links on behalf of the owner in an accessible context Changing links — Change allowed basic link data Delete links — Remove owner links View metrics — Open analytics; also required by new verification tools Manage groups — Change the organization of links Manage UTM — Work with tags, campaigns and templates Manage QR — Change design and export QR Targeting management — Configure rules for selecting target URL Manage webhooks — Configure external event handlers Manage settings — Change the corresponding link settings Manage access — Change link access restrictions

Grant only the permissions you need. Permission to view statistics does not mean permission to remove the link. Feature availability settings also remain in effect. Revoke access when the collaboration ends and verify it from the recipient's account.

Access term and independent tools

When granting rights, fill in «Access expires (UTC)» or leave the field empty if unlimited access is allowed. The time is set in UTC. After the term expires, the rights are automatically revoked. To correct an existing entry, click «Change rights», check the participant, checkboxes, and term, then save. Unchecked boxes withdraw the corresponding rights; for complete revocation, use a separate button in the row.

The right to the QR editor does not require the right to view statistics. The participant sees the available tools; restricted access settings, domain tokens, and other people's tools do not appear on the card. Full access applies to link functions but does not transfer account ownership and does not allow granting access to others on its behalf. The feature should be available to both participants. If the participant limit is reached, revoke unnecessary rights; if the duration is limited, specify the allowable end time.

Branded domains

Connect your own domain by verifying ownership with a file or TXT DNS record. Configure CNAME, check the connection and HTTPS, then choose this domain for short links.

• Open «Domains», enter the hostname and add it. Do not enter the path to the page instead of the domain.

• Copy the contents of the test file shown by the service. It looks like clk-ms-verify=YOUR_TOKEN.

• Place it on your domain at the path /.well-known/clk-ms-domain-verification.txt, accessible without logging in or blocking requests.

• Click domain verification and wait for confirmation. If there is an error, check the exact hostname, file contents, external accessibility, and HTTPS settings.

• Prepare the direction of domain traffic to the service and the correct TLS certificate together with the serving party. Proof of ownership itself does not create a DNS record or issue a certificate.

• Select a verified and included domain when creating a link or in its routing settings.

• Check the finished short address from another device and network.

Switching a domain affects the published address. Before disabling or deleting a domain, check the links and printed materials that refer to it. If the domain is already occupied in the service, adding it again does not transfer rights to it.

Domain verification example

Let's say you added go.example.com. In your browser, open https://go.example.com/.well-known/clk-ms-domain-verification.txt and compare the text shown with the value from the domain card. What you need is verification text for this domain, not an HTML page with an error message, a login form, or a file that is only accessible on your local network. A token from another added domain is not suitable.

If a regular browser opens a file and the service check fails, check accessibility from the external network, server restrictions, and site security rules. The card displays the result of the last attempt; After correction, repeat the check. Do not replace the contents of the file with the example YOUR_TOKEN from this tutorial - copy your actual value.

Verifying ownership verifies your ability to manage the domain name. The final check of the short link checks another chain: DNS, HTTPS, hit of the request to the service, identifier and target URL. Save both results before bulk domain replacement in placements.

Connecting a domain via TXT and CNAME

Instead of a verification file, ownership can be confirmed via DNS. Add, for example, go.example.com and reveal «TXT record and connection verification». Copy the full TXT record name _clk.go.example.com and the exact value clk-ms-verify=YOUR_TOKEN, replacing YOUR_TOKEN with your token. In the DNS panel, the record inside the zone example.com is usually called _clk.go; some providers expect the full name. Do not add the zone name twice.

Save the TXT record, wait for it to propagate, and click «Verify via DNS». TXT confirms ownership; to direct traffic, create a CNAME for go.example.com with the value specified in section «CNAME target». This is the hostname without https:// and the path. Then click «Check DNS connection». Repeated checks are limited; wait between attempts.

For an address like aa.com/short_link, a root domain aa.com is required. A regular CNAME at the zone root is not supported by all providers; ALIAS, ANAME, or CNAME flattening is required. If this is not possible, use go.aa.com/short_link. When IP addresses match, diagnostics report this separately from the confirmed CNAME chain. DNS provider proxying may hide the CNAME and change addresses; in this case, check its connection settings to the service.

DNS and domain ownership do not yet confirm HTTPS readiness. A certificate must be set up for your domain. If there is a certificate error, contact support; do not publish the link until it is fixed. When HTTPS works, select the domain when creating the link and open the result from another network. Old links on the main domain keep their addresses. Disabling your own domain stops clicks on its links; after enabling a verified domain, check them again.

QR codes, contact cards and printing

Dynamic link and embedded vCard

In link mode, the QR contains the click address on the link /qr/{code}. The crawl accesses the service, so the target URL can be changed without retyping as long as the domain and ID are preserved. Terms, limits, access restrictions and link routing apply. Crawls are counted separately from regular link clicks.

In vCard mode, the QR contains contact information directly inside the image. The phone prompts you to save the contact. Already printed contact information cannot be updated by changing the record in the service: you need to create and distribute a new QR. Reading the built-in vCard does not access the /qr/{code}, so you cannot expect statistics on its scans on the site.

Visual business card and QR content are separate settings. Contacts printed next to a QR do not automatically become the content of the code. Always check the selected content mode.

Working with the editor

• Open the link card → QR.

• Choose your original layout: square, poster, or business card.

• Adjust the canvas width and height, QR size and position.

• Specify the QR, background, and accent colors. The color of the QR itself and the background should be different; Maintain strong contrast for easy scanning.

• Select a frame: solid, dotted or no frame; adjust the indentation, thickness and rounding.

• Add frame text, signature and text logo. If necessary, adjust their size and position.

• Drag and drop objects in the preview; use resizing handles. Exact coordinates are also specified in the form fields.

• Add decorative blocks, select the one you want from the list and change its position, size, rotation, fill, stroke and transparency. Delete the unnecessary block.

• Turn on Preview mode to see the layout without editing elements. Clicking on the layout returns editing.

• Save the design, then download the desired format and check the finished file.

Available block shapes: rectangle, circle, ellipse, triangle, diamond, rounded block, hexagon, star and line. Up to 40 blocks are supported. Objects can overlap each other: to drag, select a free part of the desired object or use its coordinate fields. Do not cover the service squares and the white field around the QR with decorative elements.

Canvas sizes are limited to 240–2000 pixels on each side; values ​​that are too large or small are normalized by the service. The QR must fit on the canvas. Frame text is limited to 80 characters, signature - 160, logo text - 32. For long text, check the downloaded file, especially before printing.

Background and contact information

For background images, PNG, JPEG and WebP are supported, up to 3,000,000 bytes. Image size - no more than 4096x4096, no more than 16 million pixels. Choose fill with clipping, fit entirely, or stretch, then adjust the opacity from 0 to 100%. To remove, use the separate background removal checkbox and save the form.

In business card mode, name, organization, position, phone, email, website and address are available, as well as design layouts, alignment and text options. For vCard, fill in at least one of the fields: name, organization, phone or email. The email must be correct, the website must be an HTTP/HTTPS address.

Download and print

• SVG is suitable for scaling and vector layout.

• PNG is convenient for inserting into documents and publishing in raster form.

• PDF is convenient for transferring layout and printing.

• The print page offers business card, flyer, menu, and packaging layouts; use the print button and check the options in the browser dialog.

Scan exactly the exported file or proof print on a real device. Check the target URL, sharpness, margins and readability at the intended size. The monitor preview does not guarantee the quality of a particular printer or camera.

If only the target URL of a dynamic link is updated, the old QR is retained. If the domain, ID, content mode, or embedded vCard changes, prepare and distribute a new QR. Expiration or deletion of a link affects old dynamic QRs in the same way as a regular short URL.

Cancel changes and check readability

The «Undo change» and «Redo change» buttons work with the history of the current editor: up to 59 steps are available. Loading a new background file starts the history over; after reloading, the saved layout is used. During vCard data changes, the preview rebuilds the code. If the data does not pass verification or the request fails, correct the fields; do not use an unfinished preview for publishing.

First, save the layout, then open «Checking QR readability». The service tries to read the finished PNG and compares its data with the expected one. The report shows the image size, module size, and contrast. Warnings help identify pale colors, overly small codes, inverted colors, and overlaps with logos, text, or shapes. Values of 4 pixels per module and a contrast of 4.5:1 are practical guidelines for this check, not a guarantee that all cameras will read it.

Download the JSON report if necessary. Changes not yet saved in the editor are not included in the report or export. The check does not create clicks on links. Before running a print run, scan the final file with different devices and perform a test print at the actual size. If the limit for layout size, background file, or number of shapes is reached, reduce the corresponding value. Limits account for the availability of the feature for both the owner and collaborators.

Complete user guide ยท Practical course

How to apply this section

Each topic explains a feature, the user decision behind it, and how to use it without making the link harder to manage. Read the checklist before changing a link that is already shared.

Before you publish or update

  • Start from the visitor experience: who opens the link, from where, on which device, and what should happen next.
  • Check that the destination is correct, opens quickly, and shows the expected page for the intended audience.
  • Choose only the controls that match the goal, such as expiration, password, referrer, QR design, UTM, routing, or analytics sharing.
  • Save a short note for important changes so future review, rollback, or teamwork stays clear.
  • Open the short link in a private browser session and, when relevant, test mobile, desktop, QR scan, and protected access paths.
  • Review analytics after sharing to confirm real visitors, source quality, device mix, and campaign performance.

Practical example

Example: create a test link for an internal page, add a clear slug, set a short expiration, enable preview if the destination is sensitive, scan the QR code from a phone, then check whether the visit appears in the link statistics.

Next step

After this topic is clear, combine it with one adjacent feature. For example, pair UTM with campaigns, QR with print layouts, targeting with fallback, or webhooks with conversion tracking.