Configuration
All module-wide settings live on the module’s own Configuration page and are stored in the hsc_magiclinkconfig table.
Login & tokens
| Setting | Description |
Link Expires (hours)
LinkExpires | How long a magic link stays valid. Default 24. Set 0 for links that never expire. |
Login Limit Threshold
LoginLimitThreshold | Maximum consecutive logins allowed on a single token before it is rejected. Default 5. |
Fallback Redirect URL
FallbackRedirectUrl | Where the user lands after a successful login. Default /clientarea.php. |
Security
| Setting | Description |
Strict IP Matching
StrictIPMatching | Require the login to come from the same IP address that requested the link. |
Bind User Agent
BindUserAgent | Require the login to use the same browser/device (SHA-256 fingerprint) that requested the link. |
Enable Rate Limiting
EnableRateLimiting | Toggle the request throttling engine. |
Max Login Requests
MaxLoginRequests | Requests allowed per decay window, enforced per IP and per email address. Default 3. |
Rate Limit Decay (minutes)
RateLimitDecayMinutes | Sliding window used by the throttle counters. Default 15. |
Verified Client Only
VerifiedClient | When WHMCS email verification is enabled, only users with a verified email address can request a magic link. |
Email alerts
| Setting | Description |
Login Security Alert
EnableLoginSecurityAlert | Send the Magic Link Security Alert email after each successful magic-link login. |
Enable Security Alerts
EnableSecurityAlerts | Master switch for dispatching login alert emails. |
Appearance & housekeeping
| Setting | Description |
Custom Login Button
Button | Your own HTML for the login-page button. Leave empty to use the built-in button. |
Prune Tokens (days)
PruneLogsDays | Delete finished tokens older than this many days via the daily cron. Default 30. |
Prune Audit Logs (days)
PruneActivityLogsDays | Delete old activity log rows older than this many days via the daily cron. Default 60. |
Addon module setting — the only setting stored in WHMCS’ native addon-modules storage (tbladdonmodules) is Delete Module Database, used on deactivation to optionally drop all module tables and remove the Magic Link Request email template.