The customer portal

Asking a customer to create an account to look at an invoice you sent them is a way of not getting paid.

Two kinds of link

Both are long random tokens. There is no password, because a password is one more reason not to look at the invoice, and the link itself is the credential.

What they can do there

Read the document, download the PDF, pay online if you have payments configured, and accept or decline a quote. Accepting a quote is recorded with the time, so "we never agreed to that" has an answer.

What they cannot do

See anything belonging to another customer, see your internal notes, or change a document. The lookup is by token alone — there is no customer identifier in the URL that someone could increment to find somebody else's invoice, because that is the classic way these pages leak.

Keeping it out of search results

Portal pages carry a no-index header and are excluded in robots.txt. An invoice appearing in a web search would be a serious failure, so it is prevented in two independent places rather than one.

Quotes: accepted or declined, on the record

A quote in the portal has two buttons. Accepting records the time and marks the quote accepted on your side; declining does the same with the outcome reversed. Both are better than an email saying "yeah ok" that nobody can find eight months later, and both show in the document's activity feed next to everything else that happened to it.

Finding and re-sending the link

The per-customer link is on their record, labelled "customer's own link". Copy it into a chat, a text message or an email you write yourself — it does not have to come from us. The per-document link goes out with every send, and sending the document again sends the same link, not a new one. Nothing a customer has bookmarked stops working because you re-sent something.

What it looks like

Your template, your logo, your accent colour — the same renderer as the PDF. You can set what shows on the portal in Settings → Document design. There is no Oltrano branding on the page on a paid plan, and the small grey line on the free plan does not print.

Questions people actually ask

Can a customer see another customer’s invoices?

No. The page is found by its token alone; there is no account identifier in the address to change. Each token resolves to exactly one customer or one document.

What if a customer forwards the link?

Whoever has the link can see that document. Treat it like the invoice itself — which is what it is. For anything more sensitive, use an electronic signature request, which is per person.

Can I turn the portal off?

You can leave the payment button off and not include the link in emails. The page itself stays, because the PDF download and the quote acceptance go through it.

Next

← All guides