Skip to content
WordPress.org
  • Showcase
  • Plugins
  • Themes
  • Hosting
  • News
    • Learn WordPress
    • Documentation
    • Education
    • Forums
    • Developers
    • Blocks
    • Patterns
    • Photos
    • Openverse ↗︎
    • WordPress.tv ↗︎
    • About WordPress
    • Make WordPress
    • Events
    • Five for the Future
    • Enterprise
    • Gutenberg ↗︎
    • Job Board ↗︎
  • Swag ↗︎
  • Get WordPress
Get WordPress
WordPress.org

Plugin Directory

ThreeWay Login

  • Submit a plugin
  • My favorites
  • Log in
  • Submit a plugin
  • My favorites
  • Log in

ThreeWay Login

By Planet 9
Download
  • Details
  • Reviews
  • Installation
  • Development
Support

Description

ThreeWay Login replaces the first view of the standard WordPress login screen with three clear choices:

  • Continue with a passkey using Face ID, a fingerprint, or the device screen lock
  • Receive a one-time 6-digit code by email
  • Use the classic WordPress password form

Before a passkey is configured, administrators can choose whether email code login or the classic username-and-password form is shown first. After a passkey is created, the same browser shows passkey login as the primary choice. The passkey preference is stored only in that browser. The classic WordPress login remains available at all times.

Passkeys use the WebAuthn standard and create phishing-resistant credentials tied to the website. Private passkey keys remain in the user’s device or passkey provider. Only the public credential is stored in WordPress.

Email codes expire after 10 minutes, can be used once, and allow no more than five verification attempts. The plugin uses neutral responses and request limits to reduce account discovery and automated abuse.

The plugin does not create accounts. Every login method works only for an existing WordPress user.

Passkey management

Signed-in users can add and remove passkeys from their WordPress profile. Sites with a custom account area can place the [threeway_login_passkeys] shortcode on a protected page.

After each new login, users without a passkey can see the setup invitation once. They can create a passkey, close the invitation for that login, or choose not to see it again. It is not shown when the user already has a passkey or has permanently dismissed the invitation.

Settings

Open Settings → ThreeWay Login to choose the default method for browsers without a passkey and to customize the login email subject, introductory text, accent color, and passkey invitation.

Requirements

Passkeys require HTTPS and a browser with WebAuthn support. Local development on localhost is also supported.

Email codes are sent through the standard WordPress wp_mail() function. Reliable delivery depends on the website’s email configuration. A properly configured transactional email or SMTP service is recommended.

Security

Passkey ceremonies verify the website origin, relying-party identifier, challenge, user presence, and device user verification. Only ES256 P-256 passkeys are requested and accepted.

Email codes are generated with a cryptographically secure random-number generator, stored only as site-specific HMAC digests, expire after 10 minutes, become invalid after use, and are replaced when a new code is requested.

All successful methods establish a normal WordPress session through WordPress core authentication cookies and fire the standard wp_login action.

Privacy

The plugin does not operate an external service and does not add tracking. Email delivery is handled by WordPress and any mail provider already configured by the website owner.

The plugin registers suggested text with the WordPress Privacy Policy Guide.

Screenshots

Log in with a passkey using Face ID, a fingerprint, or the device screen lock.
Log in with a passkey using Face ID, a fingerprint, or the device screen lock.
Request a one-time 6-digit code using the email address of an existing account.
Request a one-time 6-digit code using the email address of an existing account.
Receive the clearly formatted login code by email.
Receive the clearly formatted login code by email.
Enter the time-limited code to complete sign-in.
Enter the time-limited code to complete sign-in.
Add or remove passkeys from the standard WordPress profile screen.
Add or remove passkeys from the standard WordPress profile screen.
Invite signed-in users without a passkey to set one up for faster future access.
Invite signed-in users without a passkey to set one up for faster future access.
Configure the default login method, login email, and passkey invitation under Settings.
Configure the default login method, login email, and passkey invitation under Settings.

Installation

  1. Upload the plugin ZIP through Plugins → Add New Plugin → Upload Plugin.
  2. Activate ThreeWay Login.
  3. Optionally open Settings → ThreeWay Login to customize the login email.
  4. Open the standard WordPress login page to see the new login choices.
  5. Sign in and open your profile to add a passkey.

No configuration is required.

FAQ

Does this disable password login?

No. The classic WordPress password form remains available as one of the login choices.

Can every registered user use a passkey?

Yes. A signed-in user can add a passkey from the WordPress profile screen or from a protected page containing the [threeway_login_passkeys] shortcode.

Can a user log in with a passkey before creating one?

No. A user first signs in with an existing method and creates a passkey. Future logins can then use that passkey.

Does an email code register a new user?

No. Codes are sent only to email addresses already attached to a WordPress account. The response does not reveal whether an account exists.

Why does an unknown email address still show the code screen?

This is intentional. Showing a different response would allow attackers to discover which email addresses have accounts. No email is sent and no login can succeed when the address is unknown.

Why did the email not arrive?

The plugin uses the website’s normal WordPress email system. Check spam filtering and configure a reliable transactional email or SMTP service if normal WordPress emails are not delivered reliably.

Does this work with custom login forms or WooCommerce?

This initial release changes the standard WordPress login screen. The created WordPress session works normally throughout the website, but direct integration into custom login forms is not included yet.

What data is stored?

For passkeys, WordPress stores the public credential, a signature counter, creation date, and last-used date. Private keys never reach WordPress. Email login temporarily stores a hashed code, user reference, expiration time, and attempt counter. Temporary code data expires automatically.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“ThreeWay Login” is open source software. The following people have contributed to this plugin.

Contributors
  • Planet 9

Translate “ThreeWay Login” into your language.

Interested in development?

Browse the code, check out the SVN repository, or subscribe to the development log by RSS.

Changelog

1.0.4

  • Renamed the plugin to ThreeWay Login with the distinctive threeway-login slug.
  • Removed bundled translation files in favor of translate.wordpress.org.
  • Removed inline login CSS and retained the standard WordPress form when JavaScript is unavailable.

1.0.3

  • Added a setting to choose email code or username and password as the default when no passkey is configured.
  • Show the passkey setup invitation only once after each new login, with separate options to postpone or permanently dismiss it.
  • Aligned the plugin folder, main file, REST namespace, and text domain with the WordPress.org slug.
  • Completed uninstall cleanup and reduced temporary database writes for rejected code requests.

1.0.2

  • Added consistent spacing above and below explanatory text on the login screens.

1.0.1

  • Fixed the external “Use another login method” switch.
  • Removed the redundant Back link from the email form.
  • Fixed hidden controls and the misplaced “or” separator.
  • Added spacing below explanatory text.

1.0.0

  • Renamed the plugin during initial development.
  • Added a settings page under Settings.
  • Added a clean HTML email with a prominent login code.
  • Added customizable email subject, introduction, and accent color.
  • Clarified the email-code flow while retaining account-enumeration protection.
  • Fixed the link back from classic password login.

0.2.0

  • Show email code login by default until a passkey has been configured.
  • Show passkey login as the primary choice after successful setup in that browser.
  • Added a one-time, dismissible passkey setup prompt after login.
  • Hide the passkey option when it is unsupported or not yet configured.
  • Keep password login available as a backup.

0.1.0

  • Initial testing release.
  • Added passkey login and passkey management.
  • Added 6-digit one-time email codes.
  • Kept the classic WordPress password login available.
  • Added browser-local memory of the last selected login method.

Meta

  • Version 1.0.4
  • Last updated 12 hours ago
  • Active installations Fewer than 10
  • WordPress version 6.4 or higher
  • Tested up to 7.1.3
  • PHP version 7.4 or higher
  • Tags
    authenticationemail loginloginpasskeyspasswordless
  • Advanced View

Ratings

No reviews have been submitted yet.

Your review

See all reviews

Contributors

  • Planet 9

Support

Got something to say? Need help?

View support forum

  • About
  • News
  • Hosting
  • Privacy
  • Showcase
  • Themes
  • Plugins
  • Patterns
  • Learn
  • Documentation
  • Developers
  • WordPress.tv ↗
  • Get Involved
  • Events
  • Donate ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org

The WordPress® trademark is the intellectual property of the WordPress Foundation.

  • Visit our X (formerly Twitter) account
  • Visit our Bluesky account
  • Visit our Mastodon account
  • Visit our Threads account
  • Visit our Facebook page
  • Visit our Instagram account
  • Visit our LinkedIn account
  • Visit our TikTok account
  • Visit our YouTube channel
  • Visit our Tumblr account
Code is Poetry