Provisioning New Members
A new member just paid you. Between their payment and their first login sit four moving parts: the account has to exist, they need a way in, the way in has to reach them, and it all has to happen without anyone on your side touching anything. This guide wires those parts together so the whole trip is automatic.
The shape of the finished flow:
- Your CRM fires a webhook that creates the WordPress account.
- Torii generates a magic link and writes it back to the contact's record in your CRM.
- Your welcome email merges that link into a button.
- The member clicks, lands in the member area, done. No password was created, stored, or emailed at any point.
Each step below maps to one of those parts.
1. Create the member with a webhook
The account creation is a single webhook call from your CRM automation:
https://YOURSITE.com/?operation=create_member&membauth=YOUR_AUTH_KEY
Replace YOURSITE with your domain and YOUR_AUTH_KEY with a webhook secret key from your Torii settings. The full walkthrough, including how the operation is authenticated and where the URL is displayed ready-made, is in Webhooks.
When the webhook arrives, Torii creates the WordPress user from the contact data: email as the login, first and last name, any tags the payload carries applied immediately, and the contact linked to the user for every sync that follows. The password is a random 24-character string nobody ever sees, including you. That's deliberate: passwords don't travel through your CRM, can't leak from it, and can't be emailed in plaintext by an automation you forgot about.
2. Turn on magic links
Under Membership Settings → Magic Links:
- Enable Auto-Generate for New Users. From now on, member creation also generates that member's first login link.
- Set Default Redirect. The default
~sends the member to the dashboard configured for their membership level, which is usually what you want. A specific URL works too. - Decide between single-use links and a time window. The defaults, single use with a one-day limit, are right for a welcome email. If several settings are missing from the screen, scroll down and turn on Advanced Mode.
The generated link doesn't just sit in WordPress. Every CRM connector Torii ships (HighLevel, Keap, ActiveCampaign, HubSpot, Zoho, Ontraport, FluentCRM) writes it into a contact field in your CRM, so the link is sitting in the contact's record waiting for your email to merge it. You choose the field on the connector's settings screen; for HighLevel it's called the Magic Link Sync Field, and you create the field itself in your CRM as a single-line contact field. The HighLevel-specific version of this whole recipe, with screenshots, lives in Magic Links.
3. Build the welcome automation
In your CRM, the automation that runs after purchase does four things, in this order:
- Fire the Create Member webhook (the URL from step 1).
- Wait at least one minute.
- Send the welcome email, merging the magic link contact field into a prominent button.
- Optionally, apply a tag that marks the member as welcomed, for your own reporting.
Write the email like it matters, because it's the first thing your member sees from the inside of your product. One button, one sentence about where it goes. "Your access is ready, click to sign in" outperforms three paragraphs of onboarding every time it's tested.
4. Know about the re-send: fresh links on demand
Members lose emails. Links expire. The get_magiclink operation handles both: it generates a brand-new link for an existing member and writes it to the same CRM contact field, ready for the next email.
https://YOURSITE.com/?operation=get_magiclink&membauth=YOUR_AUTH_KEY
Wire it into any "resend my access" or re-engagement automation, wait a minute, send the email. Because the link regenerates each time, an old link that leaked somewhere stops working as soon as a fresh one is issued.
5. Cover the members who type instead of click
The automated path handles the first login. For everyone else, there's a form. Put [memb_request_magic_link] on your login page (and your post-purchase thank-you page) and members can enter their email, receive a link, and sign in without a password ever existing. It doubles as the password reset: no password to reset, just request a link.
Details and parameters are on the [memb_request_magic_link] page.
6. Test the whole road
Don't wait for a paying customer to find the gaps.
- Create a test contact in your CRM with an inbox you can open.
- Add the contact to the purchase automation manually.
- Confirm the contact record shows the magic link in the sync field after a minute.
- Confirm the WordPress user exists and carries the membership's tags.
- Click the email's button in a private browser window.
You should land on the membership dashboard, signed in, first click. If that worked, every piece did its job: webhook received, account created, link generated and synced, email delivered, access enforced.
Where to go next
The first click currently lands on the member dashboard. If you want it to land somewhere more deliberate, a setup page where the member picks a password and finds their bearings, continue to Setting Up the Onboarding Funnel. The two flows connect: the funnel notices members created by webhook and routes them through setup on that first click.