How to add passwordless member login to WordPress
WordPress does not provide passwordless member login out of the box. You need a custom authentication plugin or a membership add-on that emails a short-lived, single-use login link. For a Paid Memberships Pro site, its Magic Login add-on is the quickest practical route.
- 01Choose the login flow
- 02Understand the manual route
- 03Fix email delivery first
- 04Install the membership add-on
- 05Set the member email
- 06Test the failure cases
What you need
- A WordPress membership or LMS site with registered members
- Administrator access to WordPress
- Reliable transactional email delivery
- A staging site or test member account
Choose the login flow
Decide whether members will enter an email address, a username, or either one. The usual flow is: the member submits their identifier, WordPress sends a time-limited link, and clicking that link creates the normal logged-in session before redirecting the member to their account or course.
Keep ordinary password login available while you introduce passwordless login. It gives members a fallback if they cannot access their email and gives administrators a recovery route.
Understand the manual route
WordPress core provides the standard login page at wp-login.php, but it does not provide a complete passwordless member-login flow. A manual implementation therefore needs a custom plugin, not just a setting or a small theme tweak.
The plugin must create unpredictable, single-use tokens, store them safely, expire them, rate-limit requests, avoid revealing whether an email belongs to an account, authenticate the correct user, enforce your membership rules, and invalidate the token immediately after use. It also needs safe redirects and a dependable email path. Do not build this by placing a reusable user ID or secret in a URL.
This route is reasonable for a developer who needs unusual behaviour or already maintains a custom authentication plugin. For most membership sites, the security and support burden is not worth writing from scratch.
Fix email delivery first
Configure transactional email before turning the feature on for members. Magic-link plugins normally send through WordPress mail functions, so poor hosting mail configuration can leave users waiting for links that never arrive. An SMTP service or a properly configured transactional mail provider is the safer setup.
Send a link to a real test account and check the inbox, spam folder, link destination, expiry message, and redirect. Also check that your caching, security, cookie-consent, and URL-rewriting tools do not alter the login-link request.
Install the membership add-on
For the fast route, install Paid Memberships Pro and its Magic/Passwordless Login add-on. In the WordPress dashboard, open Memberships > Add Ons, find the add-on, install it, and activate it. Paid Memberships Pro must already be active.
The add-on adds an “Email Me a Login Link” option to the WordPress login page and PMPro frontend login forms. A member enters an email address or username, receives a secure link, and is logged in when the link is opened.
Set the member email
On Paid Memberships Pro 3.4 or later, edit the message under Memberships > Settings > Email Templates and select Login Link. Keep the !!login_link!! variable in the email body or the authentication link will not work. You can also include a short warning that the link should not be forwarded.
The add-on uses a single-use link that expires after 15 minutes and limits a member to one request every five minutes. It deliberately shows a generic confirmation message when the submitted address is not linked to an account, which helps prevent account discovery.
Test the failure cases
Test with an active member, an expired member, an unknown email address, an expired link, a link opened twice, repeated requests, and a member who has no access to their inbox. Confirm that restricted pages still check membership after login and that the member lands on the right account or course page.
Do not remove the normal password login until you have tested account recovery and administrator access. If you use two-factor authentication, CAPTCHA, a custom login form, or aggressive security rules, test those integrations separately. The PMPro add-on fires the normal WordPress login action after token authentication, but third-party compatibility still needs checking on your site.
Let Paid Memberships Pro do it
One-time email login links for Paid Memberships Pro members; choose it to remove password resets without adding social login.
Sources
- developer.wordpress.org /advanced-administration/security/logging-in/?utm_source=ope…
- wordpress.org /plugins/magic-login/?utm_source=openai
- paidmembershipspro.com /add-ons/magic-login/?utm_source=openai
Questions
- Does WordPress support passwordless login by itself?
- No. WordPress core provides the normal username-and-password login flow, but not a complete member magic-link system. You need a custom plugin that handles tokens, expiry, email delivery, sessions, rate limits, and membership checks, or an add-on that already implements those parts.
- Can members still use their passwords after passwordless login is added?
- Yes, if you use the Paid Memberships Pro Magic Login add-on. Passwordless login is added as another option on the login form rather than replacing the existing password login, so members can use either method. Keeping the password route also provides a fallback when a member cannot access their email.
- How long should a member login link remain valid?
- Keep the link short-lived and single-use. The Paid Memberships Pro add-on expires links after 15 minutes, deletes the token after successful login, and limits new requests to once every five minutes per user. Those limits reduce the damage from forwarded or intercepted links and help prevent repeated email requests.
- Why are members not receiving passwordless login emails?
- The usual cause is email delivery, not the login form. Check WordPress mail configuration, SMTP or transactional email settings, spam filtering, the sender domain, and whether the member entered the address attached to their account. Send a test message before launch and show a generic confirmation message rather than confirming whether an account exists.
- Is a magic link the same as social login?
- No. A magic link authenticates a member through a time-limited link sent to the email address on their WordPress account. Social login uses an external identity provider such as Google or Facebook. If your goal is to remove password resets without adding social accounts, email magic links are the more direct fit.