Magic Login Linkfor WHMCS · Documentation
v2.5.0

Admin Usage Guide

The top menu (Dashboard, Activity Logs, Email Template links, Configuration) switches between the admin screens. The current page stays highlighted.


1. Dashboard

The landing page gives you an overview of the whole module:

  • Metric cards — total / active / used / expired / invalidated / failed tokens, successful logins with a month-over-month trend, security events and throttled/blocked attempts.
  • Audit table — every magic-link token with client links, IP lookup links, status badges, request / used-expired timestamps and Invalidate / Delete action buttons (AJAX with confirmation, no page reload).
  • Top users — the users with the most successful magic-link logins.
  • Recent activity — the latest entries from the Activity Logs.
  • System health — activity-log table presence and record count, plus the configured token / activity pruning retention.

2. Activity Logs

A complete audit trail of everything the module does:

  • Metric cards — total events, failed / security warnings (danger + warning), admin actions and user actions.
  • Server-side DataTable — searchable across description, IP, actor, IDs and event type; filterable by Severity (success / info / warning / danger) and Event Type.
  • Per-row Delete — removes a single log record via AJAX (with confirmation) and writes a token_deleted entry to the Activity Logs.
  • Old records are pruned automatically by the daily cron job after PruneActivityLogsDays days.

See the event types reference for the full list of what is recorded and at which severity.

3. Email Templates

The menu’s Email Template dropdown opens the two WHMCS email templates used by the module for direct editing:

  • Magic Link Request — sent when a magic link is generated. Merge fields: {$login_link} (clickable link), {$login_url} (plain URL), {$expire_time} (expiry in hours).
  • Magic Link Security Alert — sent after a successful magic-link login. Merge fields: {$user_email}, {$login_time}, {$login_ip}, {$user_agent}.
Never logged — the Magic Link Request email is not written to WHMCS’ email activity log (the EmailPreLog hook suppresses it), because it contains the live login URL. The send itself is recorded in the module’s Activity Logs instead.

4. Sending links as an admin

  • Client Summary page — the Send Magic Link action link (in the Action Links section next to “Login as Owner”) immediately generates a fresh token, invalidates the user’s previous active tokens and emails the link. A growl notice confirms the result without a page reload.
  • Client Users page — the Send Magic Link entry in each user-row dropdown targets a specific account user rather than the client.

Both actions are logged as token_sent_admin and email_sent in the Activity Logs, and in WHMCS’ own activity log.