Support Pin Profor WHMCS · Documentation
v2.0.0

How It Works

The lifecycle of a support PIN — from generation to cleanup, with every step audited.


The lifecycle of a support PIN

  1. Generate — A client (or sub-user) opens the Support PIN page and clicks Generate New PIN. The module creates a unique numeric code, stamps it with the current time, applies the configured expiry window (if enabled) and sets its status to active. If multiple active PINs are not allowed, any existing active PIN for that account is automatically expired inside a database transaction first.
  2. Share — The client reads the PIN to the support agent over the phone or in live chat. With copy-to-clipboard enabled, they can send it instantly in a chat window.
  3. Verify — The agent enters the code in the dashboard widget, the ticket modal or the client summary card. The module looks the PIN up, checks its status and expiry, and returns a clear verdict:
    • Valid — the PIN is active and within its expiry window.
    • Used — the PIN was already consumed and cannot be reused.
    • Expired — the PIN passed its expiry time.
    • Inactive — the PIN exists but is not currently active.
    • Not Found — no PIN matches the entered code.
  4. Mark as Used — After the conversation, the agent (or the configured workflow) marks the PIN as Used. This permanently prevents the code from being accepted again, closing the verification loop.
  5. Expire & cleanup — PINs that reach their expiry timestamp are automatically flagged as expired by the daily cron. If enabled, expired PINs older than 24 hours are removed from the database entirely to keep the tables lean.

Status flow

                    +---------+        generate       +---------+
                    |         |  ------------------>  |  active |
                    |  (new)  |                        +---------+
                    +---------+                              |
                                                             | expires_at reached
                                                             v
                    +---------+        terminate       +---------+
                    | expired |  <--------------------- |  used   |
                    +---------+                          +---------+
                        ^                                   ^
                        |  auto-expire (cron)               | mark-as-used (admin)
                        |                                   |
              +---------+----------+                +----------------+
              |  all active PINs   |                |  verified PIN  |
              +--------------------+                +----------------+

Every transition is recorded in the Activity Log so you always know who did what, to which PIN, and when.

Where verification happens

  • Dashboard widget — type any code and check it instantly, with no client context needed. Perfect for inbound phone calls.
  • Support-ticket modal — the Verify Support PIN button is pre-scoped to the ticket’s linked client, so the check always runs against the right account.
  • Client summary card — the current PIN and status sit right on the client’s profile for quick reference during a review.
Failed attempts count — invalid, expired, used and not-found verification attempts are written to the audit trail too, giving your security review a complete picture.