[{"data":1,"prerenderedAt":947},["ShallowReactive",2],{"navigation":3,"\u002Fgetting-started\u002Frunning-without-email":441,"\u002Fgetting-started\u002Frunning-without-email-surround":942},[4,28,62,92,117,146,185,219,243,279,315,353,382],{"title":5,"path":6,"stem":7,"children":8,"icon":27},"Getting Started","\u002Fgetting-started","1.getting-started\u002F1.index",[9,12,17,22],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Usage","\u002Fgetting-started\u002Fusage","1.getting-started\u002F3.usage","i-lucide-sliders",{"title":18,"path":19,"stem":20,"icon":21},"Signing in on the mobile app","\u002Fgetting-started\u002Fmobile-app-sign-in","1.getting-started\u002F4.mobile-app-sign-in","i-lucide-smartphone",{"title":23,"path":24,"stem":25,"icon":26},"Running without email","\u002Fgetting-started\u002Frunning-without-email","1.getting-started\u002F5.running-without-email","i-lucide-mail-x",false,{"title":29,"icon":27,"path":30,"stem":31,"children":32,"page":27},"Security & Privacy","\u002Fsecurity","10.security",[33,38,43,47,52,57],{"title":34,"path":35,"stem":36,"icon":37},"Security Overview","\u002Fsecurity\u002Foverview","10.security\u002F1.overview","i-lucide-shield-check",{"title":39,"path":40,"stem":41,"icon":42},"Authentication","\u002Fsecurity\u002Fauthentication","10.security\u002F2.authentication","i-lucide-log-in",{"title":44,"path":45,"stem":46,"icon":21},"Two-Factor & Devices","\u002Fsecurity\u002Ftwo-factor-and-devices","10.security\u002F3.two-factor-and-devices",{"title":48,"path":49,"stem":50,"icon":51},"Audit & Monitoring","\u002Fsecurity\u002Faudit-and-monitoring","10.security\u002F4.audit-and-monitoring","i-lucide-scroll-text",{"title":53,"path":54,"stem":55,"icon":56},"Account Deletion & Privacy","\u002Fsecurity\u002Faccount-deletion-and-privacy","10.security\u002F5.account-deletion-and-privacy","i-lucide-user-x",{"title":58,"path":59,"stem":60,"icon":61},"Roles & Permissions","\u002Fsecurity\u002Froles-and-permissions","10.security\u002F6.roles-and-permissions","i-lucide-key-round",{"title":63,"icon":27,"path":64,"stem":65,"children":66,"page":27},"Billing & Plans","\u002Fbilling","11.billing",[67,72,77,82,87],{"title":68,"path":69,"stem":70,"icon":71},"Plans","\u002Fbilling\u002Fplans","11.billing\u002F1.plans","i-lucide-credit-card",{"title":73,"path":74,"stem":75,"icon":76},"Limits & Usage","\u002Fbilling\u002Flimits-and-usage","11.billing\u002F2.limits-and-usage","i-lucide-gauge",{"title":78,"path":79,"stem":80,"icon":81},"Managing Your Subscription","\u002Fbilling\u002Fmanaging-your-subscription","11.billing\u002F3.managing-your-subscription","i-lucide-receipt",{"title":83,"path":84,"stem":85,"icon":86},"Add-ons","\u002Fbilling\u002Fadd-ons","11.billing\u002F4.add-ons","i-lucide-puzzle",{"title":88,"path":89,"stem":90,"icon":91},"Integrations","\u002Fbilling\u002Fintegrations","11.billing\u002F5.integrations","i-lucide-plug",{"title":93,"icon":27,"path":94,"stem":95,"children":96,"page":27},"Settings","\u002Fsettings","12.settings",[97,101,105,109,113],{"title":98,"path":99,"stem":100},"General","\u002Fsettings\u002Fgeneral","12.settings\u002F1.general",{"title":102,"path":103,"stem":104},"Leave Types","\u002Fsettings\u002Fleavetype","12.settings\u002F2.leaveType",{"title":106,"path":107,"stem":108},"Carry Forward","\u002Fsettings\u002Fcarryforward","12.settings\u002F3.carryForward",{"title":110,"path":111,"stem":112},"Department Management","\u002Fsettings\u002Fdepartments","12.settings\u002F4.departments",{"title":114,"path":115,"stem":116},"Public Holidays","\u002Fsettings\u002Fpublicholiday","12.settings\u002F5.publicholiday",{"title":118,"path":119,"stem":120,"children":121,"page":27},"Mcp","\u002Fmcp","13.mcp",[122,127,131,136,141],{"title":123,"path":124,"stem":125,"icon":126},"Overview","\u002Fmcp\u002Foverview","13.mcp\u002F1.overview","i-lucide-bot",{"title":128,"path":129,"stem":130,"icon":91},"Connecting","\u002Fmcp\u002Fconnecting","13.mcp\u002F2.connecting",{"title":132,"path":133,"stem":134,"icon":135},"Tools Reference","\u002Fmcp\u002Ftools","13.mcp\u002F3.tools","i-lucide-wrench",{"title":137,"path":138,"stem":139,"icon":140},"Security","\u002Fmcp\u002Fsecurity","13.mcp\u002F4.security","i-lucide-shield",{"title":142,"path":143,"stem":144,"icon":145},"Integrating Your Own MCP Client","\u002Fmcp\u002Fcustom-client","13.mcp\u002F5.custom-client","i-lucide-code",{"title":147,"icon":27,"path":148,"stem":149,"children":150,"page":27},"Data Import & Migration","\u002Fdata-import","2.data-import",[151,155,160,165,170,175,180],{"title":123,"path":152,"stem":153,"icon":154},"\u002Fdata-import\u002Foverview","2.data-import\u002F1.overview","i-lucide-database",{"title":156,"path":157,"stem":158,"icon":159},"Importing a File","\u002Fdata-import\u002Fimporting-a-file","2.data-import\u002F2.importing-a-file","i-lucide-file-up",{"title":161,"path":162,"stem":163,"icon":164},"Supported Platforms","\u002Fdata-import\u002Fsupported-platforms","2.data-import\u002F3.supported-platforms","i-lucide-layout-grid",{"title":166,"path":167,"stem":168,"icon":169},"Direct Connections","\u002Fdata-import\u002Fdirect-connections","2.data-import\u002F4.direct-connections","i-lucide-plug-zap",{"title":171,"path":172,"stem":173,"icon":174},"Custom Templates","\u002Fdata-import\u002Fcustom-templates","2.data-import\u002F5.custom-templates","i-lucide-layout-template",{"title":176,"path":177,"stem":178,"icon":179},"Rollback & Import History","\u002Fdata-import\u002Frollback-and-history","2.data-import\u002F6.rollback-and-history","i-lucide-undo-2",{"title":181,"path":182,"stem":183,"icon":184},"Troubleshooting","\u002Fdata-import\u002Ftroubleshooting","2.data-import\u002F7.troubleshooting","i-lucide-life-buoy",{"title":186,"icon":27,"path":187,"stem":188,"children":189,"page":27},"Leave Management","\u002Fleave-management","3.leave-management",[190,195,200,205,210,215],{"title":191,"path":192,"stem":193,"icon":194},"Leave Management Overview","\u002Fleave-management\u002Foverview","3.leave-management\u002F1.overview","i-lucide-palmtree",{"title":196,"path":197,"stem":198,"icon":199},"Requesting Leave","\u002Fleave-management\u002Frequesting-leave","3.leave-management\u002F2.requesting-leave","i-lucide-calendar-plus",{"title":201,"path":202,"stem":203,"icon":204},"Leave Balances","\u002Fleave-management\u002Fleave-balances","3.leave-management\u002F3.leave-balances","i-lucide-wallet",{"title":206,"path":207,"stem":208,"icon":209},"Group Booking","\u002Fleave-management\u002Fgroup-booking","3.leave-management\u002F4.group-booking","i-lucide-users",{"title":211,"path":212,"stem":213,"icon":214},"Editing and Cancelling Leave","\u002Fleave-management\u002Fediting-and-cancelling","3.leave-management\u002F5.editing-and-cancelling","i-lucide-pencil",{"title":216,"path":217,"stem":218,"icon":184},"Leave Troubleshooting","\u002Fleave-management\u002Ftroubleshooting","3.leave-management\u002F6.troubleshooting",{"title":220,"icon":27,"path":221,"stem":222,"children":223,"page":27},"Approvals","\u002Fapprovals","4.approvals",[224,229,234,238],{"title":225,"path":226,"stem":227,"icon":228},"Approvals Overview","\u002Fapprovals\u002Foverview","4.approvals\u002F1.overview","i-lucide-check-check",{"title":230,"path":231,"stem":232,"icon":233},"Leave Approvals","\u002Fapprovals\u002Fleave-approvals","4.approvals\u002F2.leave-approvals","i-lucide-calendar-check",{"title":235,"path":236,"stem":237,"icon":81},"Expense Approvals","\u002Fapprovals\u002Fexpense-approvals","4.approvals\u002F3.expense-approvals",{"title":239,"path":240,"stem":241,"icon":242},"Time Approvals","\u002Fapprovals\u002Ftime-approvals","4.approvals\u002F4.time-approvals","i-lucide-clock-9",{"title":244,"icon":27,"path":245,"stem":246,"children":247,"page":27},"Time tracking & monitoring","\u002Ftime-tracking","5.Time Tracking",[248,253,258,263,267,271,275],{"title":249,"path":250,"stem":251,"icon":252},"Clocking In & Location","\u002Ftime-tracking\u002Fclock-in-and-location","5.Time Tracking\u002F5.clock-in-and-location","i-lucide-map-pin",{"title":254,"path":255,"stem":256,"icon":257},"Overtime & Pay-Period Lockdown","\u002Ftime-tracking\u002Fovertime-and-lockdown","5.Time Tracking\u002F6.overtime-and-lockdown","i-lucide-lock",{"title":259,"path":260,"stem":261,"icon":262},"Geofencing","\u002Ftime-tracking\u002Fgeofencing","5.Time Tracking\u002F7.geofencing","i-lucide-map",{"title":264,"path":265,"stem":266},"Time & Projects","\u002Ftime-tracking\u002Ftimeandprojects","5.Time Tracking\u002FTime&Projects",{"title":268,"path":269,"stem":270},"Time Tracking","\u002Ftime-tracking\u002Ftime-tracking","5.Time Tracking\u002FTime-tracking",{"title":272,"path":273,"stem":274},"Timeboard","\u002Ftime-tracking\u002Ftimeboard","5.Time Tracking\u002FTimeBoard",{"title":276,"path":277,"stem":278},"Timesheets","\u002Ftime-tracking\u002Ftimesheets","5.Time Tracking\u002FTimesheets",{"title":280,"icon":27,"path":281,"stem":282,"children":283,"page":27},"Expenses","\u002Fexpenses","6.expenses",[284,288,292,296,300,305,310],{"title":285,"path":286,"stem":287},"Expense Claims","\u002Fexpenses\u002Foverview","6.expenses\u002F1.overview",{"title":289,"path":290,"stem":291},"Add & Manage Purchases","\u002Fexpenses\u002Fpurchases","6.expenses\u002F2.purchases",{"title":293,"path":294,"stem":295},"Travel & Mileage Entry","\u002Fexpenses\u002Ftravelentries","6.expenses\u002F3.travelentries",{"title":297,"path":298,"stem":299,"icon":71},"Company Card Expenses","\u002Fexpenses\u002Fcompany-cards","6.expenses\u002F4.company-cards",{"title":301,"path":302,"stem":303,"icon":304},"Per Diems","\u002Fexpenses\u002Fper-diems","6.expenses\u002F5.per-diems","i-lucide-utensils",{"title":306,"path":307,"stem":308,"icon":309},"Receipt Scanning","\u002Fexpenses\u002Freceipt-scanning","6.expenses\u002F6.receipt-scanning","i-lucide-scan-line",{"title":311,"path":312,"stem":313,"icon":314},"Statuses & Submission","\u002Fexpenses\u002Fstatuses-and-submission","6.expenses\u002F7.statuses-and-submission","i-lucide-git-pull-request-arrow",{"title":316,"icon":27,"path":317,"stem":318,"children":319,"page":27},"Documents & E-Signatures","\u002Fdocuments","7.documents",[320,324,329,334,339,343,348],{"title":123,"path":321,"stem":322,"icon":323},"\u002Fdocuments\u002Foverview","7.documents\u002F1.overview","i-lucide-folder-open",{"title":325,"path":326,"stem":327,"icon":328},"Uploading Documents","\u002Fdocuments\u002Fuploading","7.documents\u002F2.uploading","i-lucide-upload",{"title":330,"path":331,"stem":332,"icon":333},"E-Signatures","\u002Fdocuments\u002Fe-signatures","7.documents\u002F3.e-signatures","i-lucide-pen-tool",{"title":335,"path":336,"stem":337,"icon":338},"Audit Trail & Certificate","\u002Fdocuments\u002Faudit-trail","7.documents\u002F4.audit-trail","i-lucide-file-check",{"title":340,"path":341,"stem":342,"icon":174},"Templates & Bulk Send","\u002Fdocuments\u002Ftemplates-and-bulk-send","7.documents\u002F5.templates-and-bulk-send",{"title":344,"path":345,"stem":346,"icon":347},"Onboarding","\u002Fdocuments\u002Fonboarding","7.documents\u002F6.onboarding","i-lucide-user-plus",{"title":349,"path":350,"stem":351,"icon":352},"Offboarding","\u002Fdocuments\u002Foffboarding","7.documents\u002F7.offboarding","i-lucide-user-minus",{"title":354,"icon":27,"path":355,"stem":356,"children":357,"page":27},"People & HR","\u002Fpeople","8.people",[358,362,367,372,377],{"title":359,"path":360,"stem":361,"icon":209},"Directory & Profiles","\u002Fpeople\u002Fdirectory-and-profiles","8.people\u002F1.directory-and-profiles",{"title":363,"path":364,"stem":365,"icon":366},"Managing Users","\u002Fpeople\u002Fmanaging-users","8.people\u002F2.managing-users","i-lucide-user-cog",{"title":368,"path":369,"stem":370,"icon":371},"HR Records","\u002Fpeople\u002Fhr-records","8.people\u002F3.hr-records","i-lucide-folder-archive",{"title":373,"path":374,"stem":375,"icon":376},"Performance","\u002Fpeople\u002Fperformance","8.people\u002F4.performance","i-lucide-target",{"title":378,"path":379,"stem":380,"icon":381},"Training","\u002Fpeople\u002Ftraining","8.people\u002F5.training","i-lucide-graduation-cap",{"title":383,"icon":27,"path":384,"stem":385,"children":386,"page":27},"Features","\u002Ffeatures","9.features",[387,391,395,399,404,409,413,417,421,425,429,433,437],{"title":388,"path":389,"stem":390,"icon":11},"Home","\u002Ffeatures\u002Fhome","9.features\u002F1.home",{"title":392,"path":393,"stem":394},"Email Configuration (SMTP)","\u002Ffeatures\u002Femail-configuration","9.features\u002F10.email-configuration",{"title":396,"path":397,"stem":398},"SMTP troubleshoot","\u002Ffeatures\u002Fsmtp-troubleshoot","9.features\u002F11.smtp-troubleshoot",{"title":400,"path":401,"stem":402,"icon":403},"Notifications","\u002Ffeatures\u002Fnotifications","9.features\u002F12.notifications","i-lucide-bell",{"title":405,"path":406,"stem":407,"icon":408},"Reports","\u002Ffeatures\u002Freports","9.features\u002F13.reports","i-lucide-bar-chart-3",{"title":410,"path":411,"stem":412},"Dashboard","\u002Ffeatures\u002Fdashboard","9.features\u002F2.dashboard",{"title":414,"path":415,"stem":416},"Calendar & Leave Overview","\u002Ffeatures\u002Fcalendar","9.features\u002F3.calendar",{"title":418,"path":419,"stem":420},"Calendar Integration","\u002Ffeatures\u002Fcalendar-integration","9.features\u002F4.calendar-integration",{"title":422,"path":423,"stem":424},"Schedules","\u002Ffeatures\u002Fschedules","9.features\u002F5.schedules",{"title":426,"path":427,"stem":428},"Project Management","\u002Ffeatures\u002Fprojects","9.features\u002F6.projects",{"title":430,"path":431,"stem":432},"Expense Settings","\u002Ffeatures\u002Fexpense-settings","9.features\u002F7.expense-settings",{"title":434,"path":435,"stem":436},"Auth0 SSO Integration","\u002Ffeatures\u002Fauth0-integration","9.features\u002F8.auth0-integration",{"title":438,"path":439,"stem":440},"Password & Authentication Policy","\u002Ffeatures\u002Fpolicies","9.features\u002F9.policies",{"id":442,"title":23,"body":443,"description":935,"extension":936,"links":937,"meta":938,"navigation":939,"path":24,"seo":940,"stem":25,"__hash__":941},"docs\u002F1.getting-started\u002F5.running-without-email.md",{"type":444,"value":445,"toc":921},"minimark",[446,450,457,462,465,511,520,524,527,534,541,549,553,564,571,587,598,601,612,622,626,640,643,665,668,672,731,734,738,741,771,774,778,785,791,795,802,805,819,826,841,844,848,851,854,869,882,892,895,898,902,912],[447,448,449],"p",{},"BookYourPTO sends every account email — verification, welcome, password reset, digests, reminders — through an SMTP server you supply. A self-hosted install that has not configured one can still be set up and used: each step that normally arrives by email also exposes a link an administrator can copy and hand over directly.",[447,451,452,453,456],{},"This page covers running a self-hosted install with no SMTP at all. If you do have a mail server and want to connect it, see ",[454,455,392],"a",{"href":393},".",[458,459,461],"h2",{"id":460},"when-the-application-considers-email-unavailable","When the application considers email unavailable",[447,463,464],{},"Before sending anything, BookYourPTO resolves an email configuration in this order:",[466,467,468,480,505],"ol",{},[469,470,471,475,476,479],"li",{},[472,473,474],"strong",{},"The organization's own SMTP settings",", configured under ",[472,477,478],{},"Settings → Email Configuration",". All of host, port, username, password, and from-address must be present.",[469,481,482,485,486,490,491,490,494,490,497,500,501,504],{},[472,483,484],{},"Platform SMTP from the environment"," — ",[487,488,489],"code",{},"SMTP_HOST",", ",[487,492,493],{},"SMTP_PORT",[487,495,496],{},"SMTP_USER",[487,498,499],{},"SMTP_PASSWORD",", and ",[487,502,503],{},"SMTP_FROM_ADDRESS",". All five must be present.",[469,506,507,510],{},[472,508,509],{},"Nothing."," If neither set is complete, the install has no email capability.",[447,512,513,514,516,517,519],{},"A partially filled set counts as nothing. Setting ",[487,515,489],{}," but leaving ",[487,518,499],{}," empty does not give you a half-working mail path — it gives you the third case.",[458,521,523],{"id":522},"creating-the-first-organization","Creating the first organization",[447,525,526],{},"Registration is not blocked by the absence of email.",[447,528,529,530,533],{},"When you register an organization, the application tries to send a verification email. If there is no email configuration, or the send throws an error, the new account is marked ",[472,531,532],{},"verified"," instead and the verification step is skipped entirely. You are signed in and taken straight to organization setup — the \"check your inbox\" screen never appears, because there is no message coming.",[447,535,536,537,540],{},"The account created by registration is an ",[472,538,539],{},"Executive"," — the highest role — and it becomes the head of the default department created alongside the organization.",[542,543,546],"callout",{"color":544,"icon":545},"blue","i-lucide-info",[447,547,548],{},"This fallback applies only to the account that creates the organization. Users added afterwards start out unverified and become verified when they complete their setup link.",[458,550,552],{"id":551},"adding-users-and-sharing-the-setup-link","Adding users and sharing the setup link",[447,554,555,556,559,560,563],{},"Open ",[472,557,558],{},"Add User"," from the Users directory. If the install has no SMTP configured, the form shows an ",[472,561,562],{},"SMTP Not Configured"," warning before you submit, telling you the setup email will not go out.",[447,565,566,567,570],{},"Create the user as normal. On the confirmation screen you will see an ",[472,568,569],{},"Account setup link"," field with a copy button:",[572,573,574,581],"ul",{},[469,575,576,577,580],{},"If the welcome email ",[472,578,579],{},"was"," sent, the field holds the same link the email contains. Copy it only if you would rather deliver it yourself.",[469,582,576,583,586],{},[472,584,585],{},"was not"," sent, the field is the only way for the new user to set a password. Send it to them over whatever channel you use — chat, SMS, or in person.",[447,588,589,590,593,594,597],{},"The link points at ",[487,591,592],{},"\u002Fsetup-account"," and is valid for ",[472,595,596],{},"14 days",". New-user invites get a deliberately long window because administrators often create accounts days or weeks before someone actually starts.",[447,599,600],{},"When the invited user opens the link, they choose a password. Completing that step also:",[572,602,603,606],{},[469,604,605],{},"clears the forced password change on their account,",[469,607,608,609,611],{},"marks their email address as ",[472,610,532],{},", which lifts the notification restrictions described below.",[542,613,615],{"color":614,"icon":545},"amber",[447,616,617,618,621],{},"If the 14 days lapse before the user sets a password, do not re-send the invite — use ",[472,619,620],{},"Reset Password"," on their row in the Users directory to issue a fresh link.",[458,623,625],{"id":624},"resetting-a-users-password","Resetting a user's password",[447,627,628,629,631,632,635,636,639],{},"From the Users directory, open a user's action menu and choose ",[472,630,620],{},". The API permits this for ",[472,633,634],{},"administrators and executives"," only, and only an ",[472,637,638],{},"executive"," may reset another executive's password.",[447,641,642],{},"The confirmation dialog states what is about to happen. When you accept:",[572,644,645,652,659],{},[469,646,647,648,651],{},"A new reset link is generated and shown to you in a ",[472,649,650],{},"Password reset link"," copy field, whether or not the email was delivered.",[469,653,654,655,658],{},"The target user's ",[472,656,657],{},"existing sessions are all signed out immediately",". They cannot keep working on another device while you arrange to get them the link.",[469,660,661,662,456],{},"The reset link is valid for ",[472,663,664],{},"1 hour",[447,666,667],{},"The short window is deliberate: unlike a 14-day invite, an admin-initiated reset is something you perform while the person is waiting. Plan to hand the link over straight away. If it lapses, run the action again.",[458,669,671],{"id":670},"link-expiry-at-a-glance","Link expiry at a glance",[673,674,675,691],"table",{},[676,677,678],"thead",{},[679,680,681,685,688],"tr",{},[682,683,684],"th",{},"Link",[682,686,687],{},"Issued by",[682,689,690],{},"Valid for",[692,693,694,707,720],"tbody",{},[679,695,696,703,705],{},[697,698,699,700,702],"td",{},"New user account setup (",[487,701,592],{},")",[697,704,558],{},[697,706,596],{},[679,708,709,715,718],{},[697,710,711,712,702],{},"Administrator password reset (",[487,713,714],{},"\u002Freset-password",[697,716,717],{},"Users → Reset Password",[697,719,664],{},[679,721,722,725,728],{},[697,723,724],{},"Self-service password reset",[697,726,727],{},"Forgot password on the sign-in screen",[697,729,730],{},"15 minutes",[447,732,733],{},"The self-service route still depends on email — nothing is delivered without SMTP — so on an install without a mail server, the administrator reset is the only working path.",[458,735,737],{"id":736},"how-the-links-are-handled","How the links are handled",[447,739,740],{},"The links are safe to use this way, but they are still credentials. Treat them accordingly.",[572,742,743,749,755,761],{},[469,744,745,748],{},[472,746,747],{},"Only a digest is stored."," The database holds a SHA-256 hash of the token, never the token itself. Reading the database does not yield a usable link.",[469,750,751,754],{},[472,752,753],{},"The link is returned once, to you."," It appears in the HTTP response to the administrator who performed the action and nowhere else. It is deliberately kept out of the audit log — which every other administrator in the organization can read — and out of the server logs.",[469,756,757,760],{},[472,758,759],{},"Anyone holding the link can set that account's password"," until it expires or is used. Send it over a private channel, not a shared one.",[469,762,763,766,767,770],{},[472,764,765],{},"The copy field builds the link from the address bar."," It takes a path and prefixes the origin you are currently browsing, so a link copied from ",[487,768,769],{},"http:\u002F\u002F192.168.1.20:3010"," points back at that host rather than at a public address the install does not answer on.",[447,772,773],{},"The audit log still records that a reset was performed, by whom, against which user, and whether an email was sent.",[458,775,777],{"id":776},"what-a-user-should-do-when-no-email-arrives","What a user should do when no email arrives",[447,779,780,781,784],{},"Someone who uses ",[472,782,783],{},"Forgot password"," on an install without SMTP will see the \"check your email\" screen and nothing will ever arrive. That screen now says so, and tells them to ask an administrator to generate a reset link from the Users page.",[447,786,787,788,790],{},"If a user reports this, run ",[472,789,620],{}," for them and hand over the link. Remember that doing so signs them out everywhere and gives them one hour to use it.",[458,792,794],{"id":793},"notifications-you-will-not-receive","Notifications you will not receive",[447,796,797,798,801],{},"Without SMTP, ",[472,799,800],{},"no email leaves the install",". That covers every automated message: leave submissions, approvals, rejections and cancellations, approval requests waiting on someone, low-balance and carry-over warnings, upcoming leave reminders, expense, document, training and onboarding activity, scheduled digests, and the account emails themselves.",[447,803,804],{},"What continues to work:",[572,806,807,813],{},[469,808,809,812],{},[472,810,811],{},"In-app notifications."," Every notification is written to the recipient's notification list regardless of email, so nothing is lost — people just have to look in the application rather than in their inbox.",[469,814,815,818],{},[472,816,817],{},"Organization-wide Slack and Microsoft Teams webhooks",", where your plan includes notification channels. These are addressed to a shared channel rather than to an individual, so they fire normally.",[447,820,821,822,825],{},"There is a second restriction worth knowing about, because it applies whether or not you have SMTP. A user whose email address is ",[472,823,824],{},"not yet verified"," — which is every invited user until they complete their setup link — does not receive:",[572,827,828,831,838],{},[469,829,830],{},"non-account email (account email such as the welcome and reset messages is exempt, which is what makes the invite work at all),",[469,832,833,834,837],{},"notifications through their ",[472,835,836],{},"personal"," Slack or Teams webhook,",[469,839,840],{},"mobile push notifications.",[447,842,843],{},"Those resume the moment they complete setup. Organization-wide channels are unaffected, since the rest of the team is still expecting those messages.",[458,845,847],{"id":846},"set-app_url-anyway","Set APP_URL anyway",[447,849,850],{},"The copy fields described above work without any configuration, because they build the link from the address you are browsing. Other links do not have that luxury.",[447,852,853],{},"Emails, notification action links, and OAuth redirects are generated on the server, where there is no address bar to read. They resolve the application's base URL in this order:",[466,855,856,859,866],{},[469,857,858],{},"The organization's verified white-label custom domain, if it has one.",[469,860,861,862,865],{},"The ",[487,863,864],{},"APP_URL"," environment variable.",[469,867,868],{},"The hosted BookYourPTO address, as a last resort.",[447,870,871,872,874,875,877,878,881],{},"On a self-hosted install with ",[487,873,864],{}," unset, that last resort means links pointing at an address your users have no account on. Set ",[487,876,864],{}," in your ",[487,879,880],{},".env"," to the address people actually use to reach your install:",[883,884,889],"pre",{"className":885,"code":887,"language":888},[886],"language-text","APP_URL=\"https:\u002F\u002Fpto.example.com\"\n","text",[487,890,887],{"__ignoreMap":891},"",[447,893,894],{},"It must be a complete origin including the scheme. A bare hostname or a path is rejected and treated as unset.",[447,896,897],{},"This matters as soon as you configure SMTP, and it already matters for Slack, Teams, and push notification links, which carry a link back into the application.",[458,899,901],{"id":900},"adding-email-later","Adding email later",[447,903,904,905,907,908,911],{},"Nothing about the steps above has to be undone. Configure SMTP under ",[472,906,478],{},", or set the platform ",[487,909,910],{},"SMTP_*"," variables, and the next action that sends an email will use it. Existing users keep their accounts, their verification state, and their passwords.",[447,913,914,915,917,918,920],{},"See ",[454,916,392],{"href":393}," for the settings themselves, and ",[454,919,396],{"href":397}," if authentication fails against Microsoft 365.",{"title":891,"searchDepth":922,"depth":923,"links":924},1,2,[925,926,927,928,929,930,931,932,933,934],{"id":460,"depth":923,"text":461},{"id":522,"depth":923,"text":523},{"id":551,"depth":923,"text":552},{"id":624,"depth":923,"text":625},{"id":670,"depth":923,"text":671},{"id":736,"depth":923,"text":737},{"id":776,"depth":923,"text":777},{"id":793,"depth":923,"text":794},{"id":846,"depth":923,"text":847},{"id":900,"depth":923,"text":901},"How to create your organization, invite users, and reset passwords on a self-hosted install that has no SMTP server configured.","md",null,{},{"icon":26},{"title":23,"description":935},"46W6Y0UyEJpzSZF2WSmYkbAaldzhhO4Wbj1waRcxzRA",[943,945],{"title":18,"path":19,"stem":20,"description":944,"icon":21,"children":-1},"The BookYourPTO mobile app signs in with email and password. Google and SSO sign-in are available in your browser.",{"title":34,"path":35,"stem":36,"description":946,"icon":37,"children":-1},"How BookYourPTO protects your account and your organization's data — authentication, encryption, rate limiting, security headers, audit logging, and account guards.",1791444359121]