Signing in
Accept your invitation, sign in to WAQAF, and learn the everyday ways to get into your dashboard.
This page gets you from your very first invitation email into a working WAQAF dashboard, then covers the everyday ways you'll sign in afterwards. You'll do the first part once, when your organisation adds you; the rest is what you do each time you come back.
Who can do this. Anyone can sign in once they have been invited — there is no role requirement to log in. What you see after signing in depends on the role(s) you were given. You cannot create your own staff account: an Owner or Org Admin invites you by email and assigns your role(s). If you have no invitation, ask whoever runs your organisation to invite you; see Members & roles.
Your first time: accepting an invitation
WAQAF has no public sign-up for staff. When someone with the Owner or Org Admin role adds you, they pick your role(s) at the same time, and the platform emails you an invitation. Accepting it is what actually creates your member record inside that organisation.
Open the invitation email
Find the email from WAQAF inviting you to your organisation and select its button or link. The link already knows which organisation you're joining and which email address it was sent to.
Set up sign-in (or sign in)
- If you've never used WAQAF before, the link opens the Create an account page with your email already filled in. Choose a name and a password (at least 8 characters) and select Create account.
- If you already have a WAQAF account (for example you're a member of another organisation), the link opens the Welcome back sign-in page instead. Sign in as normal.
Accept the invitation
After signing in you land on an invitation card showing the organisation's name and logo. Select Accept to join, or Decline if it wasn't meant for you. Accepting creates your membership and takes you straight into that organisation's dashboard.
Land on your home screen
WAQAF opens on a home screen shaped around your role, so the first thing you see is the work you're responsible for. For a tour of what's on it, see The dashboard.
Invitations expire and are single-use. If your link says it's no longer valid, ask the person who invited you to send a fresh one — you can't reuse an old or already-accepted invitation.
Everyday sign-in
Once you've joined, you sign in from the Welcome back page. Depending on what your organisation allows, you'll see one or more of the methods below.
Where to find it. The sign-in page is the front door of the dashboard. If your organisation has its own branded sign-in page, the web address ends in your organisation's name and shows its logo at the top.
Sign in with email and password
This is the usual way in. Enter your Email and Password and select Sign in. Use the eye icon in the password field to check what you've typed.
Or use a magic link
If your organisation allows it, you can switch from Password to Magic link using the tabs above the form. Enter your Email, select Send magic link, then open the email we send and follow its link — no password needed. Magic-link emails are single-use and time-limited.
Or use a passkey, Google, or Apple
Below the form you may also see Login with passkey and buttons to continue with Google or Apple, when these are switched on. A passkey signs you in with your device's fingerprint, face, or screen lock instead of a password. (To set up a passkey on your account, see Password, passkeys & 2-step verification.)
Why your sign-in page may look different from a colleague's. Each organisation chooses which sign-in methods to allow as part of its login and security policy, so password, magic link, or social buttons can be on for one organisation and off for another. If a method you expected isn't there, that's the policy, not a fault — see Login & security policy.
Two-step verification
If your organisation (or you) have turned on two-step verification, signing in with your password leads to a Verify your account screen. Open your authenticator app, read the current one-time password, and type the six digits. WAQAF verifies them and lets you through. There's a Back to login link if you need to start over.
Two-step verification protects real money and donor data, so keep your authenticator app safe and don't share the codes. To turn it on or manage it on your own account, see Password, passkeys & 2-step verification.
Forgotten your password
On the password sign-in page, select Forgot password?. Enter your email and select Send link; we'll email you a link to set a new password. The reset link is time-limited, so use it soon after it arrives. Magic-link and passkey sign-in don't use a password at all, so there's nothing to reset for those.
Staying signed in
You don't need to sign in on every visit. After a successful sign-in WAQAF keeps you signed in on that browser for a while, so coming back later usually drops you straight into your dashboard. On a shared or public computer, sign out when you're done to protect your organisation's data.
See also
The dashboard
Find your way around the role-aware home screen and the navigation.
Login & security policy
How an organisation chooses which sign-in methods are allowed.
Password, passkeys & 2-step verification
Change your password and manage passkeys and two-step verification.
Why can't I see a button?
How your role decides what appears in the dashboard.
