No they don't have to. They can email users a link with an embedded hash that automatically logs them in. These links can expire. This is similar to how an email password reset works.
OKCupid used to use tokens fwiw.
The assumption of course is that they and only they can access the email address specified in their account profile. If that's not the case then this all becomes a bit more problematic.