[memb_totp_verify]

Description

The interstitial step of 2FA login. Only renders for logged-out visitors carrying a valid challenge token (?totp_token=) created at login time. The form accepts a 6-digit TOTP code or a recovery code, and displays failed-attempt feedback with remaining attempts (and a locked message once attempts are exhausted).

When no valid token is present, a "please log in" message with login link renders instead, optionally auto-redirecting to the login page after 3 seconds (redirect attribute, on by default).

The HTML this shortcode renders comes from a template you can override in your theme. See Shortcode Templates.

Shortcode Examples

[memb_totp_verify]

Without the auto-redirect, custom login link:

[memb_totp_verify redirect="false" login_text="Return to sign in" login_url="/login/"]

Shortcode Parameters

message

Custom text for the no-token state. Default: '' ("Please log in to continue.").

login_text

Custom login link text. Default: '' ("Click here to log in.").

login_url

Custom login URL. Default: '' (the WordPress login URL).

redirect

'false' disables the 3-second JS redirect to the login page in the no-token state. Default: 'true'.

Shortcode Attributes

Attribute Value
Conditional No
Nestable No
Accepts formatting No

Hooks

wpal/torii/totp/interstitial/before_card, card_header, and after_form (actions) inject custom markup around the verification card.