Skip to main content
The Client Portal is the public-facing side of Commerce — a branded web surface where clients view their invoices, pay outstanding balances, see contract status, and download statements without ever needing to log in to your dashboard. Sign-in is passwordless: clients enter their email address and receive a branded sign-in link, so there is no password to create and none to reset. You control the portal — contacts, permissions, branding, and emails — from a dedicated page at Commerce → Settings → Client portal, organized into five sections: Contacts & activity, Access & permissions, Appearance, Emails, and Advanced. Every field in the settings form shows the live value the portal is using right now, including system defaults, and live previews of the portal, the sign-in email, and the invite email render as you edit.

What clients see

When a client signs in (or clicks the link in an invoice email), they land in a portal session scoped to their record. They see:
  • Outstanding invoices — All unpaid invoices, with payment buttons and a Download PDF link on each invoice
  • Payments — A searchable history of every payment they’ve made, exportable to CSV (shown when you enable it — see Payment history)
  • Contracts — Status of any contracts they’re a signer on (pending, executed, voided)
  • Subscriptions — Active recurring services with next billing dates
  • Statements — Downloadable account statements (PDF) for any date range
  • Saved payment methods — Cards or ACH on file, with edit/remove controls
  • Live chat — Your helpdesk chat launcher, already signed in as them (shown when you enable it — see Live chat)
The invoice, payment, estimate, and contract lists are full data tables: a search box, a status filter, sortable column headers, and pagination, with an Export CSV button that downloads exactly what the current search and filter show. What they don’t see: any other client’s data, your internal notes, your team’s messages, or any non-billing surfaces.

How clients sign in

Sign-in is passwordless. No passwords exist anywhere in the flow, so there is nothing for clients to forget and nothing for you to reset.
1

The client enters their email

On the portal sign-in page, the client types the email address you have on file for them. You can also send them a sign-in link directly from the dashboard (see Managing client contacts).
2

They receive a branded email

The sign-in email carries your branding and contains a sign-in link. The link is single-use and expires after 15 minutes.
3

One click and they're in

Clicking the link signs them in to the portal, scoped to their own records only.
Each sign-in link is single-use, short-lived, and tied to the client’s email address — there is no password for anyone to forget, reuse, or phish.

Appearance

The Appearance section of portal settings controls how the portal looks and what contact details clients see:
The logo itself comes from Settings → Branding (your account logo). The Appearance section controls everything around it, and the live portal preview shows the result as you edit.
To serve the portal and your payment pages from your own subdomain, like billing.youragency.com, see Use Your Own Domain for Billing.

Sign-in and invite emails

The Emails section of portal settings lets you make both portal emails your own:
  • Customize the subject and body of the sign-in email and the invite email, with merge tags for personalization
  • Send a test to yourself before any client sees the result
  • Choose the sender: Hiveku’s address, or your own verified email domain

Choosing what clients can do

Every portal capability is a toggle under Commerce → Settings → Client portal → Access & permissions, grouped by what it lets clients do: With estimates enabled, clients can also accept and sign estimates from the portal. The portal’s navigation adjusts automatically — a tab only appears when the matching capability is on, so clients never see a page they can’t use.

Editing saved cards

Clients can update a saved card’s expiry date and billing address from Payment methods (the pencil icon on the card); this is on by default, and you can turn it off under Self-service. Changes are verified with the card processor immediately.
The card number and security code (CVV) are never editable and never stored. If a client has a new card number, they remove the old card and add the new one.

Paying an invoice through the portal

For the client, paying an invoice looks like:
  1. Click the link in the invoice email
  2. Land on the portal showing their outstanding invoice
  3. Click Pay Now
  4. Pick a saved payment method or enter a new card
  5. Submit — payment processes through Stripe or Authorize.Net
  6. See the invoice flip to paid immediately, with a receipt emailed to them
If their first attempt fails (insufficient funds, incorrect CVC), the portal shows a friendly error and lets them retry without restarting from the email link.

Payment history in the portal

Turn on See their payment history under Commerce → Settings → Client portal → Access & permissions to add a Payments tab to the portal. It’s a searchable, sortable, paginated list of every payment the client has made — amount, date, method, and the invoice it paid. Like the other portal lists, it has an Export CSV button. The export honors the client’s current search and status filter, so the file matches what’s on screen — handy when their accountant asks for “all payments this year” and they can pull it themselves instead of emailing you.

Saved payment methods

Clients can save a card or ACH (where supported) for future use. Saved methods are stored at the processor (Stripe Customer or Authorize.Net Customer Profile) — Hiveku stores only the reference, not the card data. This keeps your PCI scope minimal. Clients can:
  • Add a new payment method
  • Set a default
  • Remove a method
  • See the masked last-4 digits of each saved card
You can also add a payment method on a client’s behalf from their record, but the portal is the safer path — ask clients to enter card details there themselves rather than sending card numbers over email.

Subscriptions in the portal

For clients with active subscriptions, the portal shows:
  • The subscription’s plan and price
  • Next billing date
  • Upgrade/downgrade options (if you’ve enabled self-serve plan changes)
  • Cancel option (if you’ve enabled self-serve cancellation)
Self-serve changes are off by default — most B2B service businesses prefer plan changes to go through their account manager. Toggle on per-account if your business is more self-serve.

Contracts in the portal

If a client is a signer on a sent contract, the portal shows it under Documents. They can:
  • Open the contract and see where every signer stands
  • Click Review & sign when it is their turn
  • Resume signing if they started but didn’t finish
  • Download the executed PDF once all signers complete
  • See the audit trail for any executed contract
This is useful even for clients who already signed — they can pull the signed PDF anytime without emailing you.

Statements

The portal supports downloadable statements:
  • Date range — Custom from/to dates
  • Format — PDF or CSV
  • Contents — Invoices issued, payments received, current balance
Useful for clients’ year-end accounting close or expense reporting.

Live chat in the portal

If your account uses the helpdesk, you can put your live-chat launcher inside the portal. Turn on Show the live-chat widget under Commerce → Settings → Client portal → Access & permissions. What makes portal chat better than a chat widget on your website:
  • No identify step. The client is already signed in to the portal, so the chat opens as them — no “enter your name and email” form, no anonymous visitors.
  • Conversations become tickets. Each chat opens a ticket in your helpdesk, linked to the client’s contact record, so your team sees who’s asking and their billing context.
  • Conversation history persists. Returning to the portal reopens their existing conversation instead of starting a new one.
The toggle requires the helpdesk to be enabled on your account. If the launcher doesn’t appear in the portal, check that first.

Security

  • Sign-in links are single-use and short-lived. Each link expires after 15 minutes or on first use; the client requests a fresh one if needed.
  • TLS-only. All portal traffic over HTTPS.
  • PCI scope is the processor’s. Card data never touches Hiveku servers — it’s tokenized client-side and stored at Stripe/Authorize.Net.
  • Email verification. Sign-in links go to the email on file; clients can’t redirect them.
  • IP and user-agent logging. Each session logs the IP and browser used, viewable in the client’s audit log.
Don’t forward sign-in emails to colleagues — the link is tied to the original recipient. If multiple people need access, add them as additional billing contacts on the client record so each gets their own link.

Portal activity

The Portal activity card under Commerce → Settings → Client portal → Contacts & activity answers “who is actually using this?”: who has access, when each contact last signed in, how many sessions are live right now, and recent portal events. Each list has a View all quick-look popup for the full picture.

Managing client contacts

The people who can sign in to your portal are managed under Commerce → Settings → Client portal → Contacts & activity. The Client contacts card lists everyone with portal access and lets you:
  • Add a contact — Click New contact to create one without leaving portal settings
  • Edit a contact — Fix a name, phone, job title, or email in place
  • Send sign-in links in bulk — Select multiple contacts and send each their own sign-in link in one action
  • Remove a contact — Removing a contact also revokes their portal access
  • Filter and find: The list filters by lifecycle stage (it defaults to customers), a quick-look popup shows a contact’s details in place, and you can jump straight to the contact in CRM
Each contact’s row opens an access panel with per-contact actions: Invite to portal, Send sign-in link, Open as (see below), Grant billing access for a company, and Revoke. Revoking signs the contact out of every active device.
Changing a contact’s email address signs them out of all active portal sessions. Sign-in links prove identity through email, so an email change means the person must sign in again from a link sent to the new address. This is deliberate — it prevents a stale session from surviving an email handoff.

Multiple billing contacts

A client (especially an enterprise client) might need multiple people to access the portal — accounts payable, the project lead, the executive sponsor. Add multiple billing contacts on the company record. Each signs in with their own email and gets their own session, scoped to the same company’s data. The audit log shows which contact viewed which document, useful for tracking who pulled a statement or paid an invoice.

Inviting clients to the portal

A sign-in link gets a client into the portal, but an invite is the better first touch — it’s a welcome email that explains what the portal is before asking them to click anything.
1

Open the contact's access panel

Go to Commerce → Settings → Client portal → Contacts & activity and select the contact.
2

Click Invite to portal

The invite email sends to the contact’s address on file. If you’ve selected a company in the panel, the invite also grants billing access for that company, so one click sets up an enterprise contact completely.
3

Customize the invite copy (optional)

Under the Emails section of portal settings, edit the invite’s subject and body. Leave both blank to use the default copy. Invites can send from Hiveku’s address or from your own verified email domain, so the email looks like it came from you.

Members: clients manage their own team

The Members tab (on by default, under the Members section of Access & permissions) shows clients everyone at their company who can use the portal, with two roles. That is the whole difference: admins can add and remove, nothing else changes. You assign roles from the contact’s access panel in Contacts & activity (a Member/Admin toggle next to each company grant). New members invited by a portal admin sign in the same way as everyone else, with an emailed link; an invitation never signs anyone in by itself. A few guardrails apply automatically: the member cap and email-domain lock from the Advanced section, no invitations to suppressed or removed addresses, and removal cuts access immediately, including any signed-in devices. Admins cannot remove themselves.

Changing a sign-in email

A client’s email address is their portal identity, so changing it requires proving control of both mailboxes. From the Members tab, the client clicks Change email, receives a 6-digit code at their current address, then a second code at the new address. Only after both codes are verified does the email change, and every other signed-in device is signed out. Nobody else can change a member’s email, not even a portal admin or your own team from this flow.

See the portal as your client

“What does my client actually see?” is the most common portal support question. Answer it directly: click Open as on any contact’s access panel to open the portal in a new tab, signed in as that client.
  • It’s exactly their view. Same capabilities, same invoices, same branding — if a tab is hidden for them, it’s hidden for you.
  • It’s read-only. An amber banner across the top reads “Viewing as [client name] — payments and changes are disabled.” Every action that would change anything — paying an invoice, editing a card, accepting an estimate — is blocked while you’re viewing as them.
  • It’s short-lived. The view-as session expires after 60 minutes and doesn’t renew itself. Click Exit in the banner to end it sooner.
Use it to verify branding after a change, walk a client through the portal over the phone while seeing their exact screen, or confirm a permissions toggle did what you expected.

Disabling the portal for a client

If a client requests no portal access (rare, but happens with strict-security industries), you can disable portal links for their account. Invoices then send via PDF attachment only, with manual payment instructions. Toggle in the client’s settings.

Troubleshooting

The portal scopes by client record. Make sure the invoice is sent (not draft) and is associated with the same contact/company as the session. If you sent the invoice to a different contact at the same company, that contact has its own session.
Verification and the SSL certificate normally complete within minutes of adding the DNS records. The Check button on Commerce → Settings → DNS tells you exactly what is wrong (wrong CNAME target, missing record, or a Cloudflare-proxied record). See Use Your Own Domain for Billing for the records and the Cloudflare gotcha.
Check the processor connection (Stripe or Authorize.Net) — if it’s disconnected or has expired credentials, the portal can save the method to Hiveku’s record but the processor won’t store the actual token. Re-authorize the connection in Payments.
There’s no self-serve delete — billing records are retained for accounting reasons. If the relationship is over, mark them inactive in CRM. For GDPR / privacy-law deletion requests, see your account’s privacy settings.
The tab only appears when See their payment history is on under Commerce → Settings → Client portal → Access & permissions. Portal tabs hide themselves when the matching capability is off — check the toggle, then use Open as to confirm the client’s view.
Two switches control it: the helpdesk must be enabled on your account, and Show the live-chat widget must be on in portal settings. If both are on and it still doesn’t appear, use Open as to see the portal as the client — the launcher renders for signed-in portal sessions only.
It should — the export carries the same search and status filter as the list. If the numbers differ, the client likely changed the filter after downloading. Have them re-export with the filter they want; the file always reflects the filters at the moment of export.

What’s next?

Set Up the Client Portal

Branding, custom domain, and security walkthrough.

Invoices

What clients see and pay through the portal.

Payments

Connect Stripe or Authorize.Net to enable portal payments.

Contracts

Documents that show up in the portal’s Documents section.

Payment Pages

Shareable checkout pages for taking a payment without an invoice.

Use Your Own Domain for Billing

Serve the portal and payment pages from billing.youragency.com.