Magic Login Link for WHMCS
A complete passwordless authentication addon for WHMCS — clients log in with a single click from a secure, time-sensitive email link. No password, no friction, fully protected.
Magic Login Link removes the biggest friction point in the client area: the password form. A client requests a magic link from the login page, receives it by email, clicks it — and is signed in through WHMCS’ native Single Sign-On engine. Administrators can also generate or send magic links directly from the admin area.
Passwordless Login
Single-use, expiring magic links delivered by email and signed in via WHMCS’ native CreateSsoToken SSO engine.
Security Engine
Strict IP matching, SHA-256 browser fingerprint binding, consecutive-login limits and per-IP / per-email rate limiting.
Admin Tools
Send or generate magic links from the Client Summary page and the client users table, with CSRF-protected AJAX actions.
Audit & Analytics
An analytics Dashboard plus a dedicated Activity Logs screen recording every event with severity, actor and filters.
The module ships with two ready-made email templates (Magic Link Request and Magic Link Security Alert) installed into WHMCS’ email template editor with registered merge fields, and a single Configuration page for expiry, throttling, alerts and automatic log pruning — everything governed by modern, secure, CSRF-protected admin screens.
What’s new in v2.5
v2.5 adds full observability and tighter admin control on top of the existing passwordless login engine:
- Module Activity Logs — a dedicated audit screen recording every event with severity (success / info / warning / danger), acting user or admin, IP address and event-type filters.
- Analytics Dashboard — token metrics, login trends, security events, top users, recent activity and system health.
- Email send logging — every dispatched email (client request, admin send and security alerts) is recorded as
email_sent/email_failed. - Audit table management — per-row Invalidate and Delete actions with AJAX, SweetAlert confirmation and no page reload.
- Automatic pruning — the daily cron now prunes old activity log rows in addition to old tokens.
- Granular admin configuration — strict IP matching, login limits, alerts, redirect URL and retention all configurable in-module.
Requirements
- WHMCS 8.x or 9.x.
- WHMCS’ native Single Sign-On feature available (the login uses the
CreateSsoTokenAPI). - Write access to
modules/addons/MagicLink/templates_c/(compiled Smarty templates). - The standard WHMCS daily cron job configured, for automatic token and activity-log pruning.
- PHP and MySQL/MariaDB (the database used by WHMCS).