Client Area & Sub-Users
What your clients see — the Support PIN page, sub-user permissions and the sidebar widget.
The Support PIN page
Clients access the page via Support → Support PIN (or a link configured by the admin).
- Generate a PIN — click Generate New PIN. A new active PIN is created instantly and displayed prominently in the configured colour and font size, with a live expiry countdown ticking underneath.
- Copy the PIN — if Copy to Clipboard is enabled, a copy button sits beside the PIN. Clicking it copies the code and shows a “Copied!” confirmation — handy for pasting into live chat.
- Revoke a PIN — a client can invalidate a PIN early (e.g. it was shared by mistake). A confirmation prompt prevents accidental revokes.
- Status & expiry — the page always shows whether the current PIN is Active, Used or Expired, along with the exact expiry time and, when enabled, the live countdown.
- PIN History & Security Log — a DataTable of every PIN generated for the account, showing the PIN code, who generated it (with a Sub-User badge where relevant), the generated-at and expires-at timestamps, the status and the verification context.
- Role & permissions card — clients see whether they are the Primary Owner or a Sub-User, and which capabilities they have (generate, view the timer, manage settings and so on).
- How verification works — a short three-step guide (Generate → Share → Get verified) that explains the flow in plain language.
Sub-user behaviour
- Owner — full access. The owner generates the account PIN and can manage account-wide settings.
- Sub-user with permission — can view and generate PINs according to the module configuration, provided the owner has enabled the “Support PIN” permission under Client Area → Users & Permissions.
- Shared PIN mode (default) — sub-users operate on the account owner’s PIN stream. When a sub-user generates a PIN, the shared PIN is refreshed for everyone, and the page notes “This PIN is shared with the account owner.”
- Separate PIN mode — when Sub-Users Generate Their Own PIN is enabled, each sub-user generates and holds their own independent PIN.
- No permission — a sub-user without the Support PIN permission sees a clear “Support PIN access not enabled” message explaining that the primary account owner must enable it.
- Owner notification — when a sub-user generates a PIN and the option is enabled, the account owner receives an email alert.
Sidebar widget
If enabled, a “Support PIN” widget appears in the client-area sidebar (primary or secondary, at a configurable position) showing:
- The current PIN, masked to the last two digits if the Hide PIN setting is on.
- A live expiry countdown, or a “Valid for X hours” summary when the countdown is disabled.
- Quick Generate New Pin Code and View Page links.
- Copy and Show / Hide toggle buttons for convenience.
Email preferences — per-client opt-out toggles for the PIN email and the owner notification are added to the WHMCS client profile, persisted via the
ClientEdit hook.