We shipped passwordless SMS login in March. By June, portal adoption went from 40% to 80%. The lift came from removing a single friction point: password reset emails that never arrived, or arrived three days later, or landed in spam and got forgotten entirely. This is not a feature story. This is a before-and-after account of what actually moved the needle, which platforms supported it natively, which required Zapier wiring, and how to measure whether the shift is real or noise. Why 40% of your users will never reset a password Start with the baseline. In January, 40% of invited users logged into our client portal in the first 30 days. The remaining 60% either never attempted login or abandoned after the first failed attempt. We interviewed 15 of the 60% who never came back. The pattern was identical: User receives invite email with temporary password. User clicks link, lands on login page, enters email and temporary password. System forces immediate password reset on first login. User enters new password, submits form. Page reloads. Login fails. Password reset email sent to user's email address. User checks email. Nothing arrives, or arrives 15 minutes later after they've closed the tab. User abandons. Friction accumulated across four separate steps. The real culprit wasn't complexity. It was latency. Password reset emails are asynchronous—they queue, sometimes they bounce, sometimes they land in promotions. By the time it arrives, the user has context-switched and the portal invite is no longer top-of-mind. Password reset friction doesn't fail loud. It fails silent. Users don't call support; they just leave. SMS OTP vs email reset links vs true passwordless—the friction map We tested three approaches side-by-side across a randomized cohort of 1,200 new users in February: Traditional password reset (control) User logs in with email + temporary password. System forces password reset screen. Email sent asynchronously with reset link. User clicks link in email, enters new password. 30-day adoption: 40%. Median time from invite to first successful login: 2.8 days. SMS OTP on first login User receives invite email with direct login link (no temporary password). User clicks link, enters email. System sends 6-digit OTP via SMS synchronously. User enters OTP on login form. Login completes. No password reset required. 30-day adoption: 62%. Median time from invite to first successful login: 8 minutes. Passwordless SMS link (magic link) User receives invite email with SMS-linked login URL. User clicks link. System sends unique 12-hour login token via SMS. User clicks SMS link in phone directly, or copies token into browser form. Login completes. No password, no reset, no OTP entry. 30-day adoption: 79%. Median time from invite to first successful login: 4 minutes. The magic link won because it collapsed friction from four decision points to one: click the SMS link or type the code. Email reset links were abandoned because users had to hold context across two channels (email + browser). OTP adoption stalled because asking someone to transcribe a 6-digit code is slower than asking them to click a link already in their text app. Platform support: native vs Zapier-glued We tested implementation across five platforms. The results varied wildly: Platforms with built-in passwordless Auth0, Supabase, Firebase Authentication support passwordless SMS links natively. Configuration takes 15 minutes. You set an SMS provider (Twilio, AWS SNS, MessageBird), enable passwordless mode, and the platform handles token generation, SMS dispatch, and link validation. Cost: included in standard pricing, though SMS is metered by message volume. At our scale (1,200 users × 1 SMS per login), SMS cost was $8/month via Twilio. Orin's native embeddable chat widget and authentication layer supports passwordless SMS out of the box. No Zapier required. Login links generate and SMS sends within the platform; no third-party auth service needed. Platforms requiring custom wiring Shopify, WordPress, custom-built portals do not ship passwordless SMS natively. You need to: Use a plugin or custom code to intercept the login form. Wire Zapier (or Make, or custom API calls) to trigger SMS via Twilio or Vonage. Generate and validate tokens yourself, or use a middleware service like Auth0 as a bolt-on. Handle expiration, rate limiting, and token replay attacks manually or through third-party middleware. Zapier wiring added 3 weeks to our implementation timeline because we had to test token collision (could two users generate the same token?), expiration (did old links stop working after 12 hours?), and brute-force protection (could someone spam SMS requests to lock a user account?). If your platform doesn't support passwordless natively, do not attempt it with Zapier alone. Zapier is a task-runner, not a security layer. You'll need to layer Auth0, or hire a dev to build token middleware. Budget at least 2 weeks and $4K–$8K in engineering time. Measuring adopti