[memb_request_magic_link]

Description

This shortcode creates a passwordless login form where users input their email and receive a one-time use login link. It's an alternative to a normal login form that requires a password.

Note: This shortcode WON'T DISPLAY if you are already logged in or logged in as an admin.

Only renders on singular posts/pages (or block editor render requests). The redirect and email defaults can be pre-filled via query string parameters (?redirect_to=...&email=...).

The login link expires. The lifetime is set by the Magic Links time limit setting, and the default is 24 hours. Each link works once; after a successful login the token is spent.

The HTML this shortcode renders comes from a template you can override in your theme. See Shortcode Templates.

Shortcode Examples

[memb_request_magic_link]

With a post-login redirect:

[memb_request_magic_link redirect="/members/welcome/"]

With a custom button and field labels:

[memb_request_magic_link button_text="Send My Link" username_label="Enter your email:"]

Once a valid member enters their email, they receive an email with a one-time use link.

Shortcode Parameters

redirect

URL the user is redirected to after clicking the magic link that is emailed to them. This is useful for sending members to a specific page after logging in. Default: '~' (the value of ?redirect_to= if present, otherwise the current page).

button_text

Text shown on the submit button. Default: Log In.

email

Pre-fills the email address field. Default: the value of ?email= if present, otherwise empty.

username_label

Label text shown before the email field. Default: Email for Access Link:.

username_placeholder

Placeholder text shown inside the empty email field. Default: Send Login Link to Email Address.

Additional Information

Rate limiting

Requests are rate limited to 3 per 5-minute window, counted separately per email address and per IP address. If a visitor goes over the limit, no email is sent and the page reloads with ?magic_link_limited=1, which the form template displays as a "too many requests" message.

What happens after submission

Whether or not the email belongs to a member, the page reloads with ?magic_link_sent=1 and the form template shows a confirmation message. The same response for known and unknown emails prevents anyone from probing your site for valid member addresses.

Customizing the email

The email that goes out uses the magic_link_html and magic_link_text templates, which you can override. See Email Templates.

Other uses

For the full end-to-end recipe (automated first-login links from HighLevel, including the sync field and the welcome automation), see Magic Links.

This shortcode can be used in place of a password reset option since members can request a login link and then sign in and change their password.

You can also opt to use this in place of a normal login form and do away with passwords for your membership site. This type of login is becoming more common.

Finally, when the CRM isn't generating or storing passwords, you won't be able to email new members a password. Instead, you'll need to use this shortcode to allow members to log in for the first time and set a password if you choose to use them.

Shortcode Attributes

Attribute Value
Conditional No
Nestable No
Accepts formatting No

Hooks

The magic link email is customizable with four filters:

  • wpal/torii/email/magic_link/subject filters the subject line, and receives the user ID.
  • wpal/torii/email/magic_link/body_html filters the HTML body, and receives the user ID and token.
  • wpal/torii/email/magic_link/body_text filters the plain text body, and receives the user ID and token.
  • wpal/torii/email/magic_link/body is applied to both bodies last, and receives the user ID and token.