Passkey login for WordPress

Phishing-resistant sign-in with passkeys (WebAuthn), plus magic-link login and trusted devices, with per-role enforcement and a grace period so rollout never locks a team out.

Passkeys require PHP 8.2 or newer, the one Pro capability above the plugin's 7.0 baseline.

3
passkeys per user by default (cap adjustable or removable)
7 days
default grace period when enforcing passkeys for a role
30 days
default trusted-device duration (max 5 devices)
10 min
magic-link token expiry, rate-limited to 3 requests

What it does

Passkeys replace passwords with cryptographic credentials stored on the user's device and unlocked by the device itself. There is nothing to phish, nothing to reuse and nothing to leak in a database dump.

For users who are not ready for passkeys, magic-link login sends a one-time sign-in link by email, and trusted devices let approved hardware skip the second factor for a period you control.

How it works

The implementation is built on the audited open-source WebAuthn framework. You choose which roles may or must use passkeys; enforcement comes with a seven-day default grace period so nobody is stranded mid-rollout. Registration and login ceremonies default to five-minute windows, and user verification can be required.

Passkey forms integrate with WooCommerce, membership and Easy Digital Downloads login screens, ship as shortcodes for custom pages, and every registration is tracked in a passkey log.

  • WebAuthn passkeys with per-role enforcement and grace period
  • Magic-link login with optional IP verification and CAPTCHA
  • Trusted devices: 30-day default, max 5, new-device notifications
  • WooCommerce, membership and EDD login form integration
  • Shortcodes for custom login and registration pages
  • Passkey activity log with configurable retention

Documentation

Passkeys overview

What passkeys are and how rollout works.

Read the guide →

Passkey settings

Enforcement, caps, timeouts and roles.

Read the guide →

Magic-link login

One-time sign-in links by email.

Read the guide →

Trusted devices

Skip 2FA on hardware you approve.

Read the guide →

Passkey questions

What are the server requirements?

Passkeys need PHP 8.2 or newer (the underlying WebAuthn framework requires it). Everything else in the plugin runs on PHP 7.0.

Can I force administrators to use passkeys?

Yes. Enforcement is per role, with a default seven-day grace period so users can enroll before the requirement bites.

What if a user loses their device?

Users can register more than one passkey (three by default), and administrators manage registered passkeys from the users list and profile screens.

Related features

Free

Two-factor authentication

Email codes and authenticator apps: free.

Learn more →
Pro

SMS 2FA

Text-message codes through your own Twilio account.

Learn more →
Pro

2FA at scale

Roll out and audit second factors across a whole team.

Learn more →

All features →

Secure your site today

Install the free plugin from WordPress.org and set up real protection with the guided setup wizard. Upgrade to Pro whenever you need more.