Opens in a new tab
Turquoise abstract wavy W logo on a black background
Turquoise abstract wavy W logo on a black background
White WP PowerSuite logo on a black background
White WP PowerSuite logo on a black background
[wpps_ai_summarize]
On This Page
Last updated: 14/09/2026

Magic Login

Passwordless login with magic links on wp-login, a shortcode builder, QR codes and one-time codes, optional registration, and email placeholders.

Overview

Let users sign in to WordPress from their email without entering their account password. Magic Login sends a short-lived, one-time access link and can include a QR code or numeric login code, giving users several ways to complete the same passwordless sign-in.

Offer the option on the WordPress login screen, enable it for supported WooCommerce login forms, or place it in your own layout with a shortcode. Role controls, optional registration, request limits, CAPTCHA choices, and PowerSuite 2FA integration let you shape the workflow around your site. Magic Login is a Pro module and requires an active WP PowerSuite license.

Solid black square
Solid black square
Who is this for?
  • Membership and account sites offering email-based passwordless sign-in
  • WooCommerce stores that want an optional alternative to password entry
  • Agencies building branded login pages with shortcode placement
  • Teams that want short-lived email access without issuing permanent support links

Features

One-Click Email Login
Send eligible users a one-time sign-in URL associated with their WordPress account instead of asking them to enter the account password.
QR Code & Numeric Code Options
Include a QR code in the email or let users enter a one-time numeric code, with a configurable length from 6 to 10 digits.
Short-Lived Access
Set link validity from 5 to 60 minutes. Requesting a new link invalidates the user's previous unused link.
Flexible Form Placement
Use the WordPress login option, a full Magic Login screen, supported WooCommerce placement, or the dedicated shortcode.
Optional Registration
Allow unknown email addresses to receive a complete-registration link when registration is deliberately enabled.
Role-Based Availability
Limit which roles may use Magic Login, or leave the list empty to make it available without a role restriction.
Built-In Request Protection
Apply IP and email request limits, code-guess limits, and a honeypot, with optional Google reCAPTCHA or Cloudflare Turnstile verification.
2FA & Redirect Integration
Keep applicable PowerSuite 2FA verification and use supported Redirect After Login rules to determine the destination after authentication.
Email Placeholders & Activity Visibility
Optionally insert access links into eligible WordPress emails and review Magic Login activity and user-level statistics from the administration interface.

Offer WordPress Passwordless Login Without Replacing Accounts

For a user who visits occasionally, entering an account password can be the point where an otherwise simple task stops. Magic Login offers another route: enter the account email address, receive a short-lived sign-in message, and complete access through the link or enabled code option. The user still signs into a WordPress account with its existing permissions. The module changes how that authentication begins rather than creating an anonymous session or granting a new role simply because someone requests an email.
This is a different workflow from administrator-issued support access. Temporary Login is for an administrator creating and controlling an invitation, whereas Magic Login is a self-service email sign-in option for eligible users. That distinction helps avoid using a reusable support invitation as a general customer login method. Magic Login's request response also avoids confirming whether an email belongs to an account, so the public form does not deliberately reveal account existence through its success message.

Use a Link, QR Code or One-Time Login Code

Keep Links Short-Lived and Request Volumes Controlled

A login link should have a clear lifetime rather than sitting in an inbox as permanent access. Magic Login defaults to a 15-minute expiry, with configurable values from 5 to 60 minutes. A new request invalidates the previous unused link for that user, so there is only one live unused link at a time. This keeps the request history from becoming a collection of simultaneously valid credentials and explains why an older email may stop working after another one is requested.
The module also limits requests by both IP address and email address. Default request limits are five per IP over five minutes and three per email over two minutes, with separate controls for repeated code guesses. A honeypot is enabled by default as another check on the request form. These measures govern the Magic Login workflow itself; they are not a claim that the entire website is protected from automated traffic or that live login emails no longer need careful handling.

Place Passwordless Sign-In Where Your Users Need It

Magic Login can appear as an additional option on wp-login.php, on its dedicated full-screen route, or inside your own content using [wp_powersuite_magic_login]. The shortcode provides a way to place the email request form in a branded page rather than forcing every visitor through the default WordPress screen. Its presentation has a starting card and button style, with optional custom CSS for projects that need a closer visual match to an existing layout.
WooCommerce login placement is optional and starts disabled, while the standard WordPress login option starts enabled. These separate choices allow you to introduce passwordless access where it is useful without automatically adding it to every account surface. For the destination after success, Redirect After Login can supply the configured policy. When that module has no applicable rules, Magic Login uses its own fallback behavior, including WooCommerce My Account when WooCommerce is active. Placement and post-login navigation therefore remain separate, deliberate parts of the experience.

Control Who Can Request Access and Whether Registration Is Open

The allowed-roles setting can restrict Magic Login to the account groups that should use email-based sign-in. Leaving that list empty means no role filter, rather than disabling the feature. This is useful when a website wants passwordless access for selected members or customers but intends other accounts to follow a different authentication policy. Requests still pass through the module's email checks, request limits, and any configured CAPTCHA protection before the corresponding access workflow proceeds.
Registration is a separate option and is off by default. When enabled, an email address that does not belong to an existing account can receive a complete-registration link, with Subscriber as the default new-user role. The shortcode's automatic mode can distinguish an existing-user login from the permitted registration invitation. Enabling Magic Login alone should therefore not be described as opening public account creation: the registration setting and selected role remain intentional administrative decisions within the passwordless workflow.

Retain 2FA and Add CAPTCHA Through Magic Login's Own Controls

A passwordless first step does not have to remove a site's additional verification requirement. Magic Login can hand applicable accounts to Two-Factor Authentication before access is completed. Its 2FA-bypass option is off by default, so bypassing that challenge is a separate setting rather than an automatic consequence of using an emailed link. This matters on sites that want convenient primary authentication while retaining the second-step policy already assigned to selected roles.
Magic Login also has its own CAPTCHA selection: none, Google reCAPTCHA, or Cloudflare Turnstile. Those integrations use the shared PowerSuite verifiers for the Magic Login action. They should be configured through this workflow rather than assuming an ordinary login-page CAPTCHA toggle automatically protects the magic-link request form. Together with the honeypot and request limits, the options let you decide how much verification the request stage needs without confusing CAPTCHA with account authentication or 2FA.

Add Login Access to Eligible Emails and Review Activity

Some websites already send account-related emails and may prefer to include a sign-in action in that communication. The optional auto-login placeholder feature replaces {{MAGIC_LINK}}, {{MAGIC_LINK_BUTTON}}, or {{MAGIC_LOGIN_QR}} inside an eligible WordPress email body for its recipient. It starts disabled and still respects the recipient's eligibility and request limits. This is not permission to insert live credentials into every outgoing message; enable it for a deliberate email workflow and treat the resulting access link as sensitive account information.
The dedicated Magic Login page includes an activity list, and an optional Users-table statistics column provides another place to review usage. Successful authentication also exposes an event that Admin Login Alerts can use for qualifying administrator notifications when configured. These tools provide operational visibility, but successful email sending should not be confused with guaranteed inbox delivery or a completed login. Test the actual email and verification flow so the sign-in option works for the people who are expected to rely on it.

Use Cases

  • Returning Member Access
    Offer existing eligible members a short-lived email sign-in option when they do not want to enter their WordPress account password.
  • Optional WooCommerce Passwordless Login
    Add Magic Login to the supported WooCommerce login form and connect the successful sign-in to the store's intended account destination.
  • Branded Frontend Login Pages
    Place the shortcode inside a designed page so visitors can request a link without being limited to the standard WordPress login layout.
  • Controlled Registration by Email
    Enable registration deliberately when new visitors should receive a complete-registration link, using the selected default role for their new account.
  • Account Emails With a Sign-In Action
    Use eligible email placeholders to include one-time access in a planned communication workflow while retaining the module's role and request-limit checks.

Frequently Asked Questions

Related Modules

Let members update their login name from their profile when life changes—fix a typo, drop an old email-style handle, or match a...
Disabled
Pick where users land after login—global default, optional per-role URLs on supported plans, and WooCommerce-friendly behavior.
Disabled
Notifies you by email when an administrator logs in—useful for spotting unfamiliar access.
Disabled
GitHub login for your site—great for technical audiences, with optional new-user signup.
Disabled
Letter-based profile images with customizable colors—great when you want a polished look without relying on Gravatar.
Disabled
Sign in with Google—simple for visitors, optional auto-registration for new users.
Disabled
View active WordPress login sessions, force logout users, and limit concurrent sessions by role.
Disabled
Brand the login page with colors, background, and layout options.
Disabled
Control whether logins use username, email, or both—cleaner experience and fewer hints to guessers.
Disabled
Add “Continue with Facebook” on your login page so visitors can use their Meta account instead of another password. Works with the...
Disabled