Magic Login Linkfor WHMCS · Documentation
v2.5.0

Configuration

All module-wide settings live on the module’s own Configuration page and are stored in the hsc_magiclinkconfig table.


Login & tokens

SettingDescription
Link Expires (hours)
LinkExpires
How long a magic link stays valid. Default 24. Set 0 for links that never expire.
Login Limit Threshold
LoginLimitThreshold
Maximum consecutive logins allowed on a single token before it is rejected. Default 5.
Fallback Redirect URL
FallbackRedirectUrl
Where the user lands after a successful login. Default /clientarea.php.

Security

SettingDescription
Strict IP Matching
StrictIPMatching
Require the login to come from the same IP address that requested the link.
Bind User Agent
BindUserAgent
Require the login to use the same browser/device (SHA-256 fingerprint) that requested the link.
Enable Rate Limiting
EnableRateLimiting
Toggle the request throttling engine.
Max Login Requests
MaxLoginRequests
Requests allowed per decay window, enforced per IP and per email address. Default 3.
Rate Limit Decay (minutes)
RateLimitDecayMinutes
Sliding window used by the throttle counters. Default 15.
Verified Client Only
VerifiedClient
When WHMCS email verification is enabled, only users with a verified email address can request a magic link.

Email alerts

SettingDescription
Login Security Alert
EnableLoginSecurityAlert
Send the Magic Link Security Alert email after each successful magic-link login.
Enable Security Alerts
EnableSecurityAlerts
Master switch for dispatching login alert emails.

Appearance & housekeeping

SettingDescription
Custom Login Button
Button
Your own HTML for the login-page button. Leave empty to use the built-in button.
Prune Tokens (days)
PruneLogsDays
Delete finished tokens older than this many days via the daily cron. Default 30.
Prune Audit Logs (days)
PruneActivityLogsDays
Delete old activity log rows older than this many days via the daily cron. Default 60.
Addon module setting — the only setting stored in WHMCS’ native addon-modules storage (tbladdonmodules) is Delete Module Database, used on deactivation to optionally drop all module tables and remove the Magic Link Request email template.