Support Pin Profor WHMCS · Documentation
v2.0.0

Features

Everything Support Pin Pro does — grouped by area.


Identity verification

  • Client-generated PINs — clients create a unique numeric support PIN from their client area with a single click. No staff involvement required.
  • Multi-surface verification — staff verify PINs from three places:
    • The dashboard verification widget — ideal for phone calls and live chat, no client context needed.
    • The support-ticket modal — a “Verify Support PIN” button in the ticket interface, pre-scoped to the ticket’s linked client.
    • The client summary card — the current PIN and status are always visible on the client profile.
  • Clear verdicts — every verification returns Valid, Used, Expired, Inactive or Not Found, each with a distinct colour-coded result.
  • Replay protection — PINs are marked as Used on explicit admin confirmation (configurable) so a verified PIN can never be accepted again.
  • Full ticket workflow — the verify modal is pre-scoped to the ticket’s client, so agents never check the wrong account.

PIN lifecycle management (admin)

  • Dashboard — live statistics: total, active and expired PINs, clients with PINs, generated today, verified today, plus a recent-activity feed and quick actions.
  • Support Pins page — a searchable DataTable of every PIN across all clients with client, PIN code, live expiry countdown, status, timestamps and actions.
  • Clients page — search any client by name, email or ID and manage every PIN that client has ever had.
  • Complete action set — per-PIN Generate, Extend (adds the configured hours), Terminate (immediately expires), Mark as Used and Delete — every state change runs inside Capsule::transaction().
  • Client summary card — the native client profile gains a Support PIN panel with the current PIN, status, expiry, verify button and a link into the PIN manager.
  • Automatic hygiene — PINs auto-expire after the configured hours; expired PINs older than 24 hours can be removed by the daily cron.

Client area

  • Dedicated Support PIN page — the current PIN, expiry time and a live countdown that ticks down to the second.
  • Self-service — clients generate and revoke their own PINs through CSRF-protected forms with clear feedback.
  • PIN History & Security Log — every PIN ever generated for the account, with who generated it, timestamps, status and verification context.
  • Role & permission context card — Primary Owner or Sub-User, with the capabilities available.
  • “How verification works” guide — a friendly three-step explainer (Generate → Share → Get verified).
  • Sidebar widget — an optional, positionable widget with a live countdown, copy button and show/hide toggle.
  • Support menu link — an optional Support PIN entry under the client-area Support menu.

Sub-users & permissions

  • Granular permission — account owners grant sub-users access via the WHMCS Users & Permissions interface; a dedicated “Support PIN” permission is registered with WHMCS.
  • Shared or individual PINs — each sub-user can have their own PIN or share the account owner’s PIN, depending on configuration.
  • Owner notifications — the account owner is emailed whenever a sub-user generates a PIN.
  • Clean UX — sub-users without permission see a clear “Support PIN access not enabled” message; full-access accounts are handled correctly.

Security & audit

  • Comprehensive activity log — every action with client, user (sub-user name or “Owner”), action, detail, PIN code, status and expiry.
  • Human-readable actions — “PIN generated by staff”, “PIN revoked by client”, “PIN removed by cron job”, “PIN verification failed” …
  • Failed attempts logged — invalid, expired, used and not-found verification attempts are all recorded.
  • Hide PIN mode — optionally masks the PIN in the client area (last two digits only); admins always see the full code.
  • Copy to clipboard — a copy button with visual feedback for chat-based verification.

Emails & notifications

  • PIN delivery — optionally email the newly generated PIN to the client.
  • Owner alerts — optionally email the account owner when a sub-user generates a PIN.
  • Email preferences — per-client opt-out toggles on the WHMCS client profile.