Auto Client Area Login

Auto Client Area Login

Developed By WHMPress

Compatible with WHMCS v9.0
This Summer season, boost your WHMCS with premium modules and save 15% off.
Use promo code: SUMMER2026

Auto Client Area Login For WHMCS

Auto Client Area Login turns any WHMCS client email into a one-click, passwordless login by dropping a secure, time-limited auto-login link — a WHMCS single sign-on (SSO) magic link — straight into the template. One merge field — {$sso_url} — works out what the email is actually about and takes the client directly to that invoice, service, domain, support ticket or quote, signed in, with no password prompt in the way. It falls back to the client area dashboard when the email isn't about anything specific. Every magic link is a random token with no derivable link to the client or record, expires on a schedule you control, can be made single-use, and is checked for ownership both when issued and again when clicked — so an auto-login link can never end up opening someone else's invoice. Every issued link is logged, searchable, and revocable, and specific clients or whole client groups can be excluded from the passwordless login feature entirely.

Admin Area Features

  • Settings tab: Link Expiry Hours (the lifetime of a new auto-login link, stored per link at the moment it's issued — so changing this never affects links already emailed), a Single-Use Links toggle (off by default, since clients often reopen the same email more than once), and a Log Retention period controlling how long expired SSO links are kept before the daily cron removes them.
  • Where Auto-Login Applies: an on/off switch for each single sign-on destination — Invoices, Services, Domains, Support Tickets, Quotes and Client Area Home — so passwordless login can be allowed for invoices but switched off for support tickets, for example. Turning a destination off stops new magic links being issued for it; links already sent keep working until they expire.
  • Email Template Variables reference, listed directly on the Settings tab, documenting every variable and exactly what it opens.
  • Links tab: every issued magic link, newest first, showing when it was issued, its source (the email template, or "By admin" for a hand-generated link), the client, how many times it's been opened and when it was last visited, its expiry, and its current status (Active, Used, Expired or Revoked). Includes a full per-link access log (date, IP address, user agent and outcome — including failed attempts against unknown tokens), a one-click Revoke action that kills a link immediately while keeping its history, and a Clear All action. Link tokens themselves are never displayed anywhere in the admin area, since a token is a live SSO credential until it expires.
  • Generate Link: create a working passwordless login link by hand for any client and destination (Invoice, Service, Domain, Quote or Client Area Home), with its own expiry and single-use setting — useful when a client says they can't get in and needs a one-click login link immediately. Support tickets can't be generated this way, since a ticket URL needs a code WHMCS only supplies at send time.
  • Access Restrictions tab: exclude individual clients (by ID, with their name and email shown) or entire client groups from receiving one-click login links. An excluded client keeps the ordinary WHMCS password sign-in flow — the exclusion also disables SSO links already sent to them, not just new ones. Orphaned exclusion entries (a client ID that no longer resolves, because the account was deleted) are surfaced so the list can be tidied.
  • Info tab: module name, installed version, license key, licensed domain, next due date, live WHMCS version, PHP version and ionCube Loader version.
  • Licensing: license key entry with automatic daily re-validation, an instant re-check after saving configuration, and a manual sync control.
  • Administrator access is restricted through the standard WHMCS Addon Modules access control (admin role groups).
  • Automatic module updates through the WHMCS daily cron, ionCube-aware, logged to the Activity Log.
  • Optional Refresh Database setting to remove the module's tables on deactivation (default: off, so issued links and settings survive a deactivate/reactivate).

Client Area Features

  • The client area has no page of its own — a valid single sign-on link signs the client straight in, passwordless, and redirects them to the invoice, service, domain, ticket, or quote the email named, or to the client area home page.
  • When a magic link can't be used (expired, already used, revoked, or unrecognised), the client is sent to the ordinary login page with a clear, plain-language notice — rendered using the active theme's own alert styling, so it matches Six, Twenty-One, Lagom (including dark mode) or any custom template automatically, without the module shipping its own client-area stylesheet.

Configurable Options

  • License Key and Refresh Database (module Configure Options, System Settings → Addon Modules).
  • Link Expiry Hours — how long a new auto-login link stays usable after the email is sent.
  • Single-use links — global default for one-time passwordless login; can be overridden per link when generating one by hand.
  • Log Retention (days) — how long expired SSO links are kept before nightly cleanup.
  • Per-destination toggles for Invoices, Services, Domains, Support Tickets, Quotes and Client Area Home — controlling exactly where magic links are allowed.
  • Excluded Clients and Excluded Client Groups — maintained on the Access Restrictions tab, for opting specific accounts out of passwordless login entirely.

What the Module Works With

Email templates

  • Any client-facing WHMCS email template. The module checks each template's type and never issues an auto-login link for an admin-facing template, since those still carry the client's ID and a link in one would sign in whoever opened it as that client.
  • A magic link is only ever created for a template whose subject or body actually contains one of the module's SSO variables — nothing is minted for templates that would never display it.

Merge field variables

  • {$sso_url} — the recommended single sign-on variable; auto-detects the most specific destination the email offers
  • {$sso_clientarea_url} — always the client area home page
  • {$sso_invoice_url}, {$sso_service_url}, {$sso_domain_url}, {$sso_ticket_url}, {$sso_quote_url} — explicit per-destination one-click login variables, populated only when the email is actually about that record
  • {$csso_url} — legacy alias of {$sso_url}, kept working for templates edited under the module's previous name, Auto Invoice Login

WHMCS integration points

  • WHMCS's own CreateSsoToken API for the passwordless sign-in itself
  • The invoice, service, domain and ticket URLs WHMCS already generates for its own emails, used as the destination source wherever WHMCS supplies one (a support ticket's URL, in particular, carries a per-ticket code that only WHMCS can produce)
  • Client groups (tblclientgroups), for the group-level auto-login exclusion list
  • The WHMCS daily cron, for pruning long-expired link records and for module auto-update

Why Choose WHMPRESS

WHMPress modules are built around the failure cases, not just the happy path. Auto Client Area Login only issues a client area auto-login link when an email template actually contains one of its variables, so a busy install doesn't quietly accumulate thousands of unused SSO credentials. Every link's destination is re-verified against the client's current records at the moment it's clicked, not just when it was sent. And when a magic link can't be used, the client sees a plain, theme-native explanation on the ordinary login page — no broken interstitial, no unstyled error screen. Every WHMPress module ships with setup documentation and direct support from the developers who built it.

General Compatibility

  • WHMCS Compatibility: Supports WHMCS Versions 8.7 to 9.X

  • PHP Versions: Supports PHP 8.4, 8.3, 8.2, and 8.1

  • Themes Supported: Works with WHMCS themes such as Six, Twenty-One, and Lagom WHMCS Client Theme

  • System Requirement: Requires ionCube Loader v13 or later

Take your User Experience to the next level with this must-have tool for WHMCS!

Available billing cycles

Monthly.

Annually.

One-Time.

OPEN-SOURCE.

 

Reviews

5 stars
3
3
4 stars
0
0
3 stars
0
0
2 stars
0
0
1 star
0
0
Alex Brow avatar

Alex Brow @alex8730

July 2, 2026 at 12:21:06 PM

Handy module that saves clients from the hassle of remembering passwords. Auto-login links work perfectly, expiration times are customizable, and redirects are smooth. Login logs give us full visibility, and automatic cleanup keeps things tidy. . Great little tool.

  • 2 months ago
  • Version Number 1.1.0
Plame Nick avatar

Plame Nick @plame1451

May 11, 2026 at 12:43:15 PM

Secure password less login links for clients. Saves support time and works perfectly

  • 4 months ago
  • Version Number 1.1.0
Ferdi  avatar

Ferdi @ferdi8564

February 6, 2025 at 07:04:32 AM

I have started using the module, and it has proven to be extremely beneficial for the clients. I am very happy with its performance and the value it brings.

  • 1 year ago
  • Version Number 1.0

Version Compatibility


Compatible with WHMCS v9.0

Full Version Compatibility


  • Selected versions of WHMCS v9.0
        9.0.0 - 9.0.6
  • Selected versions of WHMCS v8.13
        8.13.0 - 8.13.5
  • All versions of WHMCS v8.12
  • All versions of WHMCS v8.11
  • Selected versions of WHMCS v8.10
        8.10.0
  • Selected versions of WHMCS v8.9
        8.9.0
  • Selected versions of WHMCS v8.8
        8.8.0
  • All versions of WHMCS v8.7
  • All versions of WHMCS v8.6
  • All versions of WHMCS v8.5
  • All versions of WHMCS v8.4
  • All versions of WHMCS v8.3
  • All versions of WHMCS v8.2
  • All versions of WHMCS v8.1
  • All versions of WHMCS v8.0

Support for this product

The best place to start if you need help with a specific product is to contact the developer. All WHMCS Marketplace developers have both a website and support URL listed.

Developed By WHMPress

Changelog

v1.3.0 Released August 24th, 2026

Latest Version


  • Activating or deactivating the module returned a blank page instead of the WHMCS confirmation screen. promotion_banner.php carried a UTF-8 byte order mark, which PHP sends to the browser before any code runs; with output already started WHMCS could no longer issue its post-activation redirect. The BOM and the stray trailing bytes have been removed.
  • Table rows in the Links and Access Restrictions tabs rendered with a broken bottom border in the Actions column. The action cell was styled display: flex, which stops a <td> behaving as a table cell, so its border no longer aligned with the rest of the row. The icons are now laid out by an inline-flex wrapper inside the cell, in both the server-rendered markup and the rows added over AJAX.

 

Previous Versions


v1.2.0 Released August 6th, 2026

View/hide detailed changelog

  • Auto-login links now work from ANY client email template, not just invoice emails. A link opens the page the email is actually about: the invoice, the service, the domain, the support ticket or the quote.
  • New {$sso_url} variable, which detects what the email is about and opens the matching page, falling back to the client area home page.
  • Explicit variables for choosing the destination yourself: {$sso_invoice_url}, {$sso_service_url}, {$sso_domain_url}, {$sso_ticket_url}, {$sso_quote_url} and {$sso_clientarea_url}.
  • Per-destination on/off switches, so auto-login can be allowed for invoices but not for support tickets, and so on.
  • Optional single-use links, which stop working after the first successful sign-in (off by default).
  • Links tab listing every issued link with its source, destination, client, visit count, last visit, expiry and status - for diagnosing a link a client says did not work.
  • Generate a link by hand for any client and destination, with its own expiry and single-use setting. Useful when a client cannot get in and needs a working link immediately.
  • Revoke an individual link, which stops it working at once while keeping its record and access history.
  • Access log per link: every visit is recorded with its date, IP address, user agent and outcome, including failed attempts against unknown links.
  • Access Restrictions: exclude individual clients or whole client groups from auto-login links. Excluded accounts keep the ordinary WHMCS sign-in flow, and the exclusion is applied to links already sent as well as new ones.
  • Automatic cleanup of long-expired links through the daily cron, with a configurable retention period.
  • Lagom template support for the notice shown when a link cannot be used, including Lagom's dark mode.
  • Module auto-update support through a daily cron check.
  • Promotion banner support on the module dashboard.
  • "Refresh Database" setting, which drops the module's own tables on deactivation when enabled.
  • Info tab now also reports WHMCS version, PHP version and ionCube Loader version.

Changed

  • Module renamed from "Auto Invoice Login" to "Auto Client Area Login", which reflects that links now reach any client area page rather than only invoices. The module folder is now auto_clientarea_login.
  • Restructured to the WHMPress addon starter template layout, with all helpers, licensing and table setup in functions.php under the whmp_acl_ prefix.
  • Admin area rebuilt with the standard header and tab shell, and the active tab is kept in the URL.
  • Licensing now caches license details locally and re-validates on a daily schedule instead of on every page load, with a manual refresh control.
  • Settings are saved over AJAX with inline feedback instead of a full page reload.
  • Destinations are taken from the URL WHMCS itself provides for invoices and tickets, rather than being constructed. A ticket URL carries a per-ticket parameter that cannot be reproduced, so this is the only correct source.

Fixed

  • Links are no longer created for email templates that do not actually contain one of the module's variables. Previously every outgoing client email created two or three link records regardless, so an install sending a thousand invoices accumulated thousands of records that no email would ever display - each one a live sign-in credential sitting unused in the database.
  • SECURITY: auto-login links were previously derived from the invoice id and the client's email address, which made them predictable - anyone knowing both could produce a working link. Links are now random tokens with no derivable relationship to the client or the record.
  • SECURITY: links are no longer issued for admin-facing email templates. Those emails carry the client's id, so a link in one would have signed whoever opened it in as that client.
  • Ownership is now verified both when a link is issued and again when it is clicked, so a link cannot reach a record the client does not own.
  • The cached local license key was being written and read under an unrelated module's name, so the license was re-validated remotely on every request.
  • An invalid or suspended license was being reported as active in one code path.
  • The link expiry no longer breaks when no expiry period has been configured; it falls back to 24 hours.

Removed

  • The old whmp_auto_invoice_login and whmp_ail_link_expiry_hours tables, replaced by whmp_acl_links and whmp_acl_settings.

Upgrade note

  • The {$csso_url} variable from earlier versions still works and behaves exactly like {$sso_url}, so email templates already edited for Auto Invoice Login keep working without changes.

 

v1.1.0 Released July 10th, 2025

View/hide detailed changelog

Sidebar auto-collapses when the module is accessed from the WHMCS admin area.

 

v1.0 Released January 3rd, 2025

View/hide detailed changelog

Version 1.0.0 - Initial Release (3-01-2025)

  • When an invoice email is sent to a client, it includes a URL containing hashed information.
  • Clicking the URL logs the client in automatically, bypassing the need for manual login.
  • Admin can define an expiration period for the auto-login link form module dashboard.
  • After the set time, the link becomes invalid, preventing unauthorized access.
  • URL hashing ensures data integrity and protects against tampering.
  • Expired links return a customizable error or redirect to the login page.
  • Seamlessly integrates with WHMCS's existing email templates.

 

See also

Discord Notifications

A simplistic, free & open source hook allowing instant Discord notifications when an action is triggered.

Free
Netgsm SMS

Netgsm Sms addon provides you sending customized bulk sms and creating sms templates.

Free
MSG91 SMS/OTP Plugin

MSG91 WHMCS SMS plugin gives you the power and flexibility to stay connected with your customers by sending them an SMS and OTP's for 2FA at the crucial steps that matters the most.

Free
SMS Manager

More Advanced SMS System

Commercial
SMSQ Notify

Send SMS Notification From WHMCS by SMSQ Notify

Free