Magic Login Linkfor WHMCS · Documentation
v2.5.0

Magic Login Link for WHMCS

A complete passwordless authentication addon for WHMCS — clients log in with a single click from a secure, time-sensitive email link. No password, no friction, fully protected.


Magic Login Link removes the biggest friction point in the client area: the password form. A client requests a magic link from the login page, receives it by email, clicks it — and is signed in through WHMCS’ native Single Sign-On engine. Administrators can also generate or send magic links directly from the admin area.

Passwordless Login

Single-use, expiring magic links delivered by email and signed in via WHMCS’ native CreateSsoToken SSO engine.

Security Engine

Strict IP matching, SHA-256 browser fingerprint binding, consecutive-login limits and per-IP / per-email rate limiting.

Admin Tools

Send or generate magic links from the Client Summary page and the client users table, with CSRF-protected AJAX actions.

Audit & Analytics

An analytics Dashboard plus a dedicated Activity Logs screen recording every event with severity, actor and filters.

The module ships with two ready-made email templates (Magic Link Request and Magic Link Security Alert) installed into WHMCS’ email template editor with registered merge fields, and a single Configuration page for expiry, throttling, alerts and automatic log pruning — everything governed by modern, secure, CSRF-protected admin screens.

Sensitive by design — magic-link emails are never written to WHMCS’ email activity log (they contain the live login URL), and every other behaviour is recorded in the module’s own audit trail instead.

What’s new in v2.5

v2.5 adds full observability and tighter admin control on top of the existing passwordless login engine:

  • Module Activity Logs — a dedicated audit screen recording every event with severity (success / info / warning / danger), acting user or admin, IP address and event-type filters.
  • Analytics Dashboard — token metrics, login trends, security events, top users, recent activity and system health.
  • Email send logging — every dispatched email (client request, admin send and security alerts) is recorded as email_sent / email_failed.
  • Audit table management — per-row Invalidate and Delete actions with AJAX, SweetAlert confirmation and no page reload.
  • Automatic pruning — the daily cron now prunes old activity log rows in addition to old tokens.
  • Granular admin configuration — strict IP matching, login limits, alerts, redirect URL and retention all configurable in-module.

Requirements

  • WHMCS 8.x or 9.x.
  • WHMCS’ native Single Sign-On feature available (the login uses the CreateSsoToken API).
  • Write access to modules/addons/MagicLink/templates_c/ (compiled Smarty templates).
  • The standard WHMCS daily cron job configured, for automatic token and activity-log pruning.
  • PHP and MySQL/MariaDB (the database used by WHMCS).