Features

Roles, two-factor, and a way to suspend somebody

Owner, admin, member and viewer, with two-factor authentication available on every plan including the free one.

The roles

Owner holds billing. Admin manages people and settings. Member creates and edits. Viewer reads reports and changes nothing — which is the role most requests for access actually want.

Suspension rather than deletion

Somebody on leave, or an account you want closed for a fortnight while something is sorted out, can be suspended with an end date. Deleting them takes their work with them, and "remove this person for now" is a far more common need than "erase this person".

Two ways in that are not a password

Sign in with Google or Microsoft is on every plan including the free one: no password for us to hold, none for you to choose, and none to be reused somewhere that gets breached. A work address at your own domain opens a company account; a personal one opens a free personal account that can move onto a domain later without losing anything.

This is not single sign-on. It is a sign-in button, and the difference is who owns the accounts — the section below is your identity provider owning them.

See it happen

Four roles, and the one most access requests actually want is the one that changes nothing.

What you can do with it

Four roles, and one of them is the answer most of the time

Owner holds billing. Admin manages people and settings. Member creates and edits. Viewer reads reports and changes nothing — which is what most requests for access are actually asking for.

Suspension, rather than deletion

Somebody on leave, or an account you want closed for a fortnight while something is sorted out, can be suspended with an end date. Deleting them takes their work with them, and "remove this person for now" is a far more common need than "erase this person".

Two-factor on every plan, including the free one

Authenticator apps, with recovery codes issued once. An account holding a company's printed codes is worth protecting whether or not that company is paying us.

Getting there

  1. Invite by email

    The invitation expires, which is the point of it.

  2. Give the smallest role

    Viewer covers more requests than people expect.

  3. Turn on two-factor

    It is free, on every plan.

  4. Suspend rather than delete

    When somebody is only going away for a while.

More in the same place

Roles Owner, admin, member, viewer.
Suspend With an end date, keeping their work.
Two-factor Every plan, recovery codes included.
Invitations By email, expiring, revocable.
Audit log Who changed what, and when.
A card each Managed centrally, edited by an admin.

Questions

How many people can I have?

One on Free, three on Starter, ten on Business, twenty on Enterprise.

Can somebody see reports without being able to change anything?

Yes — that is exactly what the viewer role is, and it is usually the right one.

Can people sign in with Google or Microsoft?

Yes, on every plan including the free one, for signing up as well as signing in. There is no password for us to hold or for anyone to reuse. A work address at your own domain opens a company account; a personal address opens a free personal account for one person, which can be moved onto a company domain later without losing what you have made. It is a sign-in button rather than single sign-on — that is the next answer.

Can I connect Lynkarr to Claude or another AI assistant?

Yes. Lynkarr runs an MCP server at https://lynkarr.com/mcp. Add it as a remote MCP server in your assistant, authenticate with an API token, and it can list codes, create them, change where a printed one points and read the scan analytics. Every tool is a call to the same REST API, so the token's scopes and limits apply — a read-only token is not even shown the tools that would write.

Do you support single sign-on?

Yes, on Enterprise, over OpenID Connect — Entra ID, Okta, Google Workspace, Auth0, JumpCloud, Keycloak or anything else that speaks it. Your provider owns the accounts: somebody who leaves loses this with everything else, people are created on first sign-in, and you can require it so passwords stop working. Owners keep theirs, so a provider that breaks on a Friday is recoverable without us. Two-factor is on every plan.

Can my directory create and close accounts automatically?

Yes, on Enterprise, over SCIM 2.0 — Entra ID, Okta and Google Workspace all speak it. Assign a group in your directory and the accounts appear here; take somebody out of it and their sign-in stops within minutes. What a directory cannot do is destroy anything: every removal, including an outright delete, suspends the account and leaves its codes, cards and contacts with the company, so a lapsed licence or a mis-clicked filter is a thing you undo rather than restore. It cannot hand out the owner role either. The token is separate from your API tokens, so revoking a misbehaving sync does not take your integrations with it.

Try it with one code

The free plan has no expiry and asks for no card, and the analytics behind it are the same ones a paying customer gets.

Free forever for one person. No card, and 10,000 scans a month included.