This Summer season, boost your WHMCS with premium modules and save 15% off.
Use promo code: SUMMER2026
Auto Client Area Login For WHMCS
Auto Client Area Login turns any WHMCS client email into a one-click, passwordless login by dropping a secure, time-limited auto-login link — a WHMCS single sign-on (SSO) magic link — straight into the template. One merge field — {$sso_url} — works out what the email is actually about and takes the client directly to that invoice, service, domain, support ticket or quote, signed in, with no password prompt in the way. It falls back to the client area dashboard when the email isn't about anything specific. Every magic link is a random token with no derivable link to the client or record, expires on a schedule you control, can be made single-use, and is checked for ownership both when issued and again when clicked — so an auto-login link can never end up opening someone else's invoice. Every issued link is logged, searchable, and revocable, and specific clients or whole client groups can be excluded from the passwordless login feature entirely.
Admin Area Features
-
Settings tab: Link Expiry Hours (the lifetime of a new auto-login link, stored per link at the moment it's issued — so changing this never affects links already emailed), a Single-Use Links toggle (off by default, since clients often reopen the same email more than once), and a Log Retention period controlling how long expired SSO links are kept before the daily cron removes them.
-
Where Auto-Login Applies: an on/off switch for each single sign-on destination — Invoices, Services, Domains, Support Tickets, Quotes and Client Area Home — so passwordless login can be allowed for invoices but switched off for support tickets, for example. Turning a destination off stops new magic links being issued for it; links already sent keep working until they expire.
-
Email Template Variables reference, listed directly on the Settings tab, documenting every variable and exactly what it opens.
-
Links tab: every issued magic link, newest first, showing when it was issued, its source (the email template, or "By admin" for a hand-generated link), the client, how many times it's been opened and when it was last visited, its expiry, and its current status (Active, Used, Expired or Revoked). Includes a full per-link access log (date, IP address, user agent and outcome — including failed attempts against unknown tokens), a one-click Revoke action that kills a link immediately while keeping its history, and a Clear All action. Link tokens themselves are never displayed anywhere in the admin area, since a token is a live SSO credential until it expires.
-
Generate Link: create a working passwordless login link by hand for any client and destination (Invoice, Service, Domain, Quote or Client Area Home), with its own expiry and single-use setting — useful when a client says they can't get in and needs a one-click login link immediately. Support tickets can't be generated this way, since a ticket URL needs a code WHMCS only supplies at send time.
-
Access Restrictions tab: exclude individual clients (by ID, with their name and email shown) or entire client groups from receiving one-click login links. An excluded client keeps the ordinary WHMCS password sign-in flow — the exclusion also disables SSO links already sent to them, not just new ones. Orphaned exclusion entries (a client ID that no longer resolves, because the account was deleted) are surfaced so the list can be tidied.
-
Info tab: module name, installed version, license key, licensed domain, next due date, live WHMCS version, PHP version and ionCube Loader version.
-
Licensing: license key entry with automatic daily re-validation, an instant re-check after saving configuration, and a manual sync control.
- Administrator access is restricted through the standard WHMCS Addon Modules access control (admin role groups).
-
Automatic module updates through the WHMCS daily cron, ionCube-aware, logged to the Activity Log.
- Optional Refresh Database setting to remove the module's tables on deactivation (default: off, so issued links and settings survive a deactivate/reactivate).
Client Area Features
- The client area has no page of its own — a valid single sign-on link signs the client straight in, passwordless, and redirects them to the invoice, service, domain, ticket, or quote the email named, or to the client area home page.
- When a magic link can't be used (expired, already used, revoked, or unrecognised), the client is sent to the ordinary login page with a clear, plain-language notice — rendered using the active theme's own alert styling, so it matches Six, Twenty-One, Lagom (including dark mode) or any custom template automatically, without the module shipping its own client-area stylesheet.
Configurable Options
-
License Key and Refresh Database (module Configure Options, System Settings → Addon Modules).
-
Link Expiry Hours — how long a new auto-login link stays usable after the email is sent.
-
Single-use links — global default for one-time passwordless login; can be overridden per link when generating one by hand.
-
Log Retention (days) — how long expired SSO links are kept before nightly cleanup.
-
Per-destination toggles for Invoices, Services, Domains, Support Tickets, Quotes and Client Area Home — controlling exactly where magic links are allowed.
-
Excluded Clients and Excluded Client Groups — maintained on the Access Restrictions tab, for opting specific accounts out of passwordless login entirely.
What the Module Works With
Email templates
- Any client-facing WHMCS email template. The module checks each template's
type and never issues an auto-login link for an admin-facing template, since those still carry the client's ID and a link in one would sign in whoever opened it as that client.
- A magic link is only ever created for a template whose subject or body actually contains one of the module's SSO variables — nothing is minted for templates that would never display it.
Merge field variables
-
{$sso_url} — the recommended single sign-on variable; auto-detects the most specific destination the email offers
-
{$sso_clientarea_url} — always the client area home page
-
{$sso_invoice_url}, {$sso_service_url}, {$sso_domain_url}, {$sso_ticket_url}, {$sso_quote_url} — explicit per-destination one-click login variables, populated only when the email is actually about that record
-
{$csso_url} — legacy alias of {$sso_url}, kept working for templates edited under the module's previous name, Auto Invoice Login
WHMCS integration points
- WHMCS's own
CreateSsoToken API for the passwordless sign-in itself
- The invoice, service, domain and ticket URLs WHMCS already generates for its own emails, used as the destination source wherever WHMCS supplies one (a support ticket's URL, in particular, carries a per-ticket code that only WHMCS can produce)
- Client groups (
tblclientgroups), for the group-level auto-login exclusion list
- The WHMCS daily cron, for pruning long-expired link records and for module auto-update
Why Choose WHMPRESS
WHMPress modules are built around the failure cases, not just the happy path. Auto Client Area Login only issues a client area auto-login link when an email template actually contains one of its variables, so a busy install doesn't quietly accumulate thousands of unused SSO credentials. Every link's destination is re-verified against the client's current records at the moment it's clicked, not just when it was sent. And when a magic link can't be used, the client sees a plain, theme-native explanation on the ordinary login page — no broken interstitial, no unstyled error screen. Every WHMPress module ships with setup documentation and direct support from the developers who built it.
General Compatibility
-
WHMCS Versions: Fully compatible with versions 9.0.3 to 8.7
-
PHP Versions: Supports PHP 8.4, 8.3, 8.2, and 8.1
-
Themes Supported: Works with WHMCS themes such as Six, Twenty-One, and Lagom WHMCS Client Theme
-
System Requirement: Requires ionCube Loader v13 or later
Take your User Experience to the next level with this must-have tool for WHMCS!
Module Price
Monthly Price: 5$.
Annually Price: 29$.
One-Time Price: 49$.
OPEN-SOURCE VERSION: $199 One-time Price.
Alex Brow @alex8730
Handy module that saves clients from the hassle of remembering passwords. Auto-login links work perfectly, expiration times are customizable, and redirects are smooth. Login logs give us full visibility, and automatic cleanup keeps things tidy. . Great little tool.
Plame Nick @plame1451
Secure password less login links for clients. Saves support time and works perfectly
Ferdi @ferdi8564
I have started using the module, and it has proven to be extremely beneficial for the clients. I am very happy with its performance and the value it brings.