A complete passwordless authentication addon for WHMCS that lets your clients log in to the client area with a single click — no password required. Magic Login Link sends a secure, time-sensitive login link straight to the client's email address; opening it signs the user in through WHMCS' native Single Sign-On engine.
The module eliminates login friction while keeping accounts thoroughly protected. Every token is single-use, expires automatically, is bound to the requester's IP address and browser fingerprint, and is protected by a built-in rate limiting engine (per-IP and per-email throttling with a configurable decay window). Clients can request a magic link themselves from the login page, and administrators can generate or send one directly from the Client Summary page or the Client Users table.
The addon ships with a full analytics Dashboard (token metrics, login trends, security events and system health), a dedicated Activity Logs screen with a filterable, server-side audit trail of every event, two ready-made email templates (Magic Link Request and Magic Link Security Alert) that install into WHMCS' email template editor with registered merge fields, and a single Configuration page for expiry, throttling, fingerprint binding, security alerts and automatic log pruning — everything governed by modern, secure, CSRF-protected admin screens.
v2.5 adds full observability and tighter admin control on top of the existing passwordless login engine:
hsc_magiclink_activity_logs) recording every event with a severity level (success / info / warning / danger), the acting user or admin, IP address and browser/device. Events include token requests, admin sends, every email send (and failure), login successes and failures, IP / browser mismatches, rate-limit hits, manual invalidations and record deletions.email_sent / email_failed.PruneActivityLogsDays), in addition to old tokens (PruneLogsDays).0 = never expires).CreateSsoToken API and redirects to a configurable destination (default /clientarea.php).EmailPreLog hook stops the magic-link email (which contains the login URL) from being stored in WHMCS' email logs.{$login_link}, {$login_url}, {$expire_time} (request) and {$login_ip}, {$login_time}, {$user_agent} (security alert).Be the first to review Magic Login Link For WHMCS.
Start the discussion about Magic Login Link For WHMCS.
CreateSsoToken).WHMCS_ROOT/modules/addons/MagicLink/templates_c/ (compiled Smarty templates, created automatically at runtime).Module Activity Logs & observability
hsc_magiclink_activity_logs table recording every event: token_requested, token_sent_admin, email_sent, email_failed, login_success, login_failed, token_invalidated, tokens_invalidated, token_deleted, rate_limit_exceeded, user_agent_mismatch, ip_mismatch.email_sent / email_failed in the Activity Logs.token_deleted entry to the Activity Logs. The Browser & Device column was removed from the audit table.PruneActivityLogsDays, default 60 days).