Magic Login Linkfor WHMCS · Documentation
v2.5.0

Features

Everything the module does — grouped by area. Every item below is recorded in the module’s Activity Logs audit trail.


Passwordless login

  • Login page button — a “Magic Login Link” button is injected automatically into the client-area login page (or supply your own custom button HTML). Clicking it opens a modal where the visitor enters their email address.
  • Single-use, expiring tokens — every magic link works exactly once and expires after the configured number of hours (default 24; 0 = never expires).
  • Native SSO sign-in — clicking the link logs the user in through WHMCS’ CreateSsoToken API and redirects to a configurable destination (default /clientarea.php).
  • Account-enumeration safe — the request form always shows the same generic success response whether or not the email exists.

Security engine

  • Strict IP matching — require the login to come from the same IP address that requested the link.
  • Browser/device fingerprint binding — the requester’s User-Agent is stored as a SHA-256 hash and must match at login.
  • Consecutive login limit — cap how many times a single token can be used in sequence; the counter resets when the user logs in with their normal password.
  • Rate limiting & cooldown — per-IP and per-email request throttling with a configurable decay window.
  • Automatic token invalidation — all active tokens are expired when the client or user changes their password.
  • Login security alert email — after every magic-link login the user receives a notification with the account, date & time, IP address and browser/device used (toggleable).
  • Sensitive email suppression — the EmailPreLog hook stops the magic-link email (which contains the login URL) from being stored in WHMCS’ email logs.

Admin tools

  • Send / generate from the admin area — a Send Magic Link action link on the Client Summary page and in the Users & Permissions dropdown of the client users table: send the email instantly or generate a copy-paste URL.
  • Analytics Dashboard — token counts by status, lifetime logins with month-over-month trend, security event counts, throttled attempts, top users, recent activity feed and a system health panel.
  • Audit table actions — invalidate an active token or permanently delete an audit record straight from the Dashboard, with SweetAlert confirmation and AJAX table reload.
  • Activity Logs screen — server-side DataTable with global search, severity and event-type filters, severity badges, actor labels (User / Admin / System) and a per-row AJAX delete.

Email integration

  • Two ready-made email templates created on activation: Magic Link Request and Magic Link Security Alert.
  • Custom merge fields registered in WHMCS’ email template editor: {$login_link}, {$login_url}, {$expire_time} (request) and {$login_ip}, {$login_time}, {$user_agent} (security alert).

Housekeeping

  • Daily cron pruning — old used/expired/invalidated/failed tokens and old activity log rows are removed automatically after the configured retention days.
  • Clean deactivation — tables and data are only removed when the Delete Module Database option is enabled.

Every event is audited

Each of the following event types appears in the Activity Logs with a severity level, the acting user or admin, IP address and description:

Event typeSeverityWhen it fires
token_requestedinfoA client requested a magic link from the login modal.
token_sent_admininfoAn admin generated a magic link for a client user.
email_sentsuccess / infoAny magic-link or security-alert email dispatched successfully.
email_faileddangerAn email dispatch failed or threw an exception.
login_successsuccessA user signed in via a magic link.
login_faileddangerLogin rejected (used/expired token, or login limit exceeded).
ip_mismatchdangerLogin came from a different IP than the request.
user_agent_mismatchdangerLogin came from a different browser/device fingerprint.
rate_limit_exceededwarningA link request was throttled by IP or email rate limiting.
token_invalidatedwarningAn admin manually invalidated an active token.
tokens_invalidatedwarningAll active tokens expired (e.g. after a password change).
token_deletedwarningAn admin permanently deleted an audit record.