Features
Everything Support Pin Pro does — grouped by area.
Identity verification
- Client-generated PINs — clients create a unique numeric support PIN from their client area with a single click. No staff involvement required.
- Multi-surface verification — staff verify PINs from three places:
- The dashboard verification widget — ideal for phone calls and live chat, no client context needed.
- The support-ticket modal — a “Verify Support PIN” button in the ticket interface, pre-scoped to the ticket’s linked client.
- The client summary card — the current PIN and status are always visible on the client profile.
- Clear verdicts — every verification returns Valid, Used, Expired, Inactive or Not Found, each with a distinct colour-coded result.
- Replay protection — PINs are marked as Used on explicit admin confirmation (configurable) so a verified PIN can never be accepted again.
- Full ticket workflow — the verify modal is pre-scoped to the ticket’s client, so agents never check the wrong account.
PIN lifecycle management (admin)
- Dashboard — live statistics: total, active and expired PINs, clients with PINs, generated today, verified today, plus a recent-activity feed and quick actions.
- Support Pins page — a searchable DataTable of every PIN across all clients with client, PIN code, live expiry countdown, status, timestamps and actions.
- Clients page — search any client by name, email or ID and manage every PIN that client has ever had.
- Complete action set — per-PIN Generate, Extend (adds the configured hours), Terminate (immediately expires), Mark as Used and Delete — every state change runs inside
Capsule::transaction(). - Client summary card — the native client profile gains a Support PIN panel with the current PIN, status, expiry, verify button and a link into the PIN manager.
- Automatic hygiene — PINs auto-expire after the configured hours; expired PINs older than 24 hours can be removed by the daily cron.
Client area
- Dedicated Support PIN page — the current PIN, expiry time and a live countdown that ticks down to the second.
- Self-service — clients generate and revoke their own PINs through CSRF-protected forms with clear feedback.
- PIN History & Security Log — every PIN ever generated for the account, with who generated it, timestamps, status and verification context.
- Role & permission context card — Primary Owner or Sub-User, with the capabilities available.
- “How verification works” guide — a friendly three-step explainer (Generate → Share → Get verified).
- Sidebar widget — an optional, positionable widget with a live countdown, copy button and show/hide toggle.
- Support menu link — an optional Support PIN entry under the client-area Support menu.
Sub-users & permissions
- Granular permission — account owners grant sub-users access via the WHMCS Users & Permissions interface; a dedicated “Support PIN” permission is registered with WHMCS.
- Shared or individual PINs — each sub-user can have their own PIN or share the account owner’s PIN, depending on configuration.
- Owner notifications — the account owner is emailed whenever a sub-user generates a PIN.
- Clean UX — sub-users without permission see a clear “Support PIN access not enabled” message; full-access accounts are handled correctly.
Security & audit
- Comprehensive activity log — every action with client, user (sub-user name or “Owner”), action, detail, PIN code, status and expiry.
- Human-readable actions — “PIN generated by staff”, “PIN revoked by client”, “PIN removed by cron job”, “PIN verification failed” …
- Failed attempts logged — invalid, expired, used and not-found verification attempts are all recorded.
- Hide PIN mode — optionally masks the PIN in the client area (last two digits only); admins always see the full code.
- Copy to clipboard — a copy button with visual feedback for chat-based verification.
Emails & notifications
- PIN delivery — optionally email the newly generated PIN to the client.
- Owner alerts — optionally email the account owner when a sub-user generates a PIN.
- Email preferences — per-client opt-out toggles on the WHMCS client profile.