Skip to main content

Phone Number Login

Users can now log in with their phone number instead of email. This article goes through what that looks like.

Marisa Crowder avatar
Written by Marisa Crowder
Updated over a week ago

What’s new?

  • Login with Phone Number: Users authenticate using a code sent via SMS.

  • User Creation Without Email: Admins can create or upload users using:

    • ✅ Phone number only

    • ❌ No email required at creation

Note: Users will be prompted to add a personal email after their first login.


How Do I Enable or Disable Phone Number Login?

To enable or disable:

  1. Go to Workspace Settings

  2. Click More Settings

  3. Toggle: “Enable Login with Phone Number”

If disabled:

Phone number login will silently fail


What Does the Phone Login Flow Look Like?

First-Time Login

  1. Select Sign in with Phone

  2. User will enter their phone number

  3. Then receives an SMS code

  4. Then they will enter the code into Nectar

  5. If the user has no real email they will be:

    • Prompted to add one and verify via email

    • Then redirected to the home screen

  6. If the user already has a valid email, they may skip the email step

Future Logins (Without MFA)

  1. Enter phone number

  2. Enter SMS code

  3. Redirected to the platform

No email, no friction.

Future Logins (With MFA)

  1. Enter phone number

  2. Enter SMS code

  3. MFA challenge using:

    • Email or authenticator app

  4. Redirected to platform

⚠️ Admin MFA always uses email or an authenticator app—not SMS with this login option.


How Does User Import Work with Phone Login?

Supported Import Paths

  • Bulk upload (CSV)

  • UserUpsert (via SFTP, ADP, or PAPI)

Import Rules

✅ Allowed: Users can be created with just an email, a phone number, or both

❌ Important: If a user already has a valid email, and the import excludes it, the existing email will not be overwritten by a generated one to prevent accidental data loss during regular imports.


Common Questions

Why is Nectar asking for an email if we wanted phone-only?

  • Some features (like reward redemptions, MFA, device trust, and recovery) require an email. We only ask for it once and store it for future use.

Can users stay phone-only forever?

Yes users can stay phone-only—unless:

  • MFA is enabled

  • Device verification is triggered

In those cases, an email is required for security.

What if we later add emails for everyone?

If you add emails later for all users any import with valid emails will replace the placeholder/generated emails.

Did this answer your question?