A complete passwordless authentication addon for WHMCS that lets your clients log in to the client area with a single click — no password required. Magic Login Link sends a secure, time-sensitive login link straight to the client's email address; opening it signs the user in through WHMCS' native Single Sign-On engine.
The module eliminates login friction while keeping accounts thoroughly protected. Every token is single-use, expires automatically, is bound to the requester's IP address and browser fingerprint, and is protected by a built-in rate limiting engine (per-IP and per-email throttling with a configurable decay window). Clients can request a magic link themselves from the login page, and administrators can generate or send one directly from the Client Summary page or the Client Users table.
The addon ships with a full analytics Dashboard (token metrics, login trends, security events and system health), a dedicated Activity Logs screen with a filterable, server-side audit trail of every event, two ready-made email templates (Magic Link Request and Magic Link Security Alert) that install into WHMCS' email template editor with registered merge fields, and a single Configuration page for expiry, throttling, fingerprint binding, security alerts and automatic log pruning — everything governed by modern, secure, CSRF-protected admin screens.
v2.5 adds full observability and tighter admin control on top of the existing passwordless login engine:
hsc_magiclink_activity_logs) recording every event with a severity level (success / info / warning / danger), the acting user or admin, IP address and browser/device. Events include token requests, admin sends, every email send (and failure), login successes and failures, IP / browser mismatches, rate-limit hits, manual invalidations and record deletions.email_sent / email_failed.PruneActivityLogsDays), in addition to old tokens (PruneLogsDays).0 = never expires).CreateSsoToken API and redirects to a configurable destination (default /clientarea.php).EmailPreLog hook stops the magic-link email (which contains the login URL) from being stored in WHMCS' email logs.{$login_link}, {$login_url}, {$expire_time} (request) and {$login_ip}, {$login_time}, {$user_agent} (security alert).We also offer full source code licenses for all of our products. Source code access for Magic Login Link is available for $280 USD. Please contact our support team for further details or to request a purchase.
The best place to start if you need help with a specific product is to contact the developer. All WHMCS Marketplace developers have both a website and support URL listed.
Module Activity Logs & observability
hsc_magiclink_activity_logs table recording every event: token_requested, token_sent_admin, email_sent, email_failed, login_success, login_failed, token_invalidated, tokens_invalidated, token_deleted, rate_limit_exceeded, user_agent_mismatch, ip_mismatch.email_sent / email_failed in the Activity Logs.token_deleted entry to the Activity Logs. The Browser & Device column was removed from the audit table.PruneActivityLogsDays, default 60 days).PruneLogsDays, default 30 days).EnableLoginSecurityAlert).{$user_email}, {$login_time}, {$login_ip}, {$user_agent} merge fields.user_agent column) and validated at login (BindUserAgent).0/1) to string states — active, used, expired — enabling proper single-use/expiry lifecycle management.
This module allow you to add a page for your terms of use and you can add description and keyword
Social Login is a free WHMCS plugin that allows your visitors to comment, login and register with 40+ social networks like for example Twitter, Facebook, LinkedIn, Instagram, Google and Yahoo.
This module allow you to add a page for your privacy policy and you can add description and keywords
Generates dated XML sitemap including Products and Knowledgebase with cron and management options.
Arjen Kocken @arjen4010
I did not try this module at the moment, I'm thinking about it. But first I want to say something about this conversation, we use some modules from Hard Soft Code, and they are all working as expected and are available in the client area. So I can't find me in his reaction.
A question about the product, it's looking like a solution for people that can't remember password or still writing it on paper, they also write it down when you told them 1000x to don't do that. But ok, I think more people can agree this problem.
About the security of this, is it possible to disable this option by default and give the client the possibility to turn it on from the client area? I can think that some clients will be happy with this solution, but I think some other customers see it as a security issue. The best will be if they can set a permission per contact, let's say the one that pays invoices "yes", the developer "no".
Another idea will be if it's working in combination with the Authy module: https://marketplace.whmcs.com/product/846-authy-security-module
And for me the idea of 24 hours is way to long, also 1 hour feels for me like a issue. Any idea to also add options like 5, 15, 30 min? If there is a solution for both, I will really think about using it.
Chris . @chris8303
Total con stay away from these guys. Purchased and didn't work, also invalidated the licence a day later and deleted my account. Stay well away!
HardSoftCode Teams @HardSoftCode
Be aware of this buyer. After buying from us and download the module he go and open a paypal claim and says that he did not received the module and we have close his account
Owner@HardSoftCode