Title: ThreeWay Login
Author: Planet 9
Published: <strong>October 9, 2026</strong>
Last modified: October 9, 2026

---

Search plugins

![](https://ps.w.org/threeway-login/assets/banner-772x250.png?rev=3736905)

![](https://ps.w.org/threeway-login/assets/icon-256x256.png?rev=3736905)

# ThreeWay Login

 By [Planet 9](https://profiles.wordpress.org/planet9/)

[Download](https://downloads.wordpress.org/plugin/threeway-login.1.0.4.zip)

 * [Details](https://wordpress.org/plugins/threeway-login/#description)
 * [Reviews](https://wordpress.org/plugins/threeway-login/#reviews)
 *  [Installation](https://wordpress.org/plugins/threeway-login/#installation)
 * [Development](https://wordpress.org/plugins/threeway-login/#developers)

 [Support](https://wordpress.org/support/plugin/threeway-login/)

## Description

ThreeWay Login replaces the first view of the standard WordPress login screen with
three clear choices:

 * Continue with a passkey using Face ID, a fingerprint, or the device screen lock
 * Receive a one-time 6-digit code by email
 * Use the classic WordPress password form

Before a passkey is configured, administrators can choose whether email code login
or the classic username-and-password form is shown first. After a passkey is created,
the same browser shows passkey login as the primary choice. The passkey preference
is stored only in that browser. The classic WordPress login remains available at
all times.

Passkeys use the WebAuthn standard and create phishing-resistant credentials tied
to the website. Private passkey keys remain in the user’s device or passkey provider.
Only the public credential is stored in WordPress.

Email codes expire after 10 minutes, can be used once, and allow no more than five
verification attempts. The plugin uses neutral responses and request limits to reduce
account discovery and automated abuse.

The plugin does not create accounts. Every login method works only for an existing
WordPress user.

#### Passkey management

Signed-in users can add and remove passkeys from their WordPress profile. Sites 
with a custom account area can place the `[threeway_login_passkeys]` shortcode on
a protected page.

After each new login, users without a passkey can see the setup invitation once.
They can create a passkey, close the invitation for that login, or choose not to
see it again. It is not shown when the user already has a passkey or has permanently
dismissed the invitation.

#### Settings

Open **Settings  ThreeWay Login** to choose the default method for browsers without
a passkey and to customize the login email subject, introductory text, accent color,
and passkey invitation.

#### Requirements

Passkeys require HTTPS and a browser with WebAuthn support. Local development on
localhost is also supported.

Email codes are sent through the standard WordPress `wp_mail()` function. Reliable
delivery depends on the website’s email configuration. A properly configured transactional
email or SMTP service is recommended.

### Security

Passkey ceremonies verify the website origin, relying-party identifier, challenge,
user presence, and device user verification. Only ES256 P-256 passkeys are requested
and accepted.

Email codes are generated with a cryptographically secure random-number generator,
stored only as site-specific HMAC digests, expire after 10 minutes, become invalid
after use, and are replaced when a new code is requested.

All successful methods establish a normal WordPress session through WordPress core
authentication cookies and fire the standard `wp_login` action.

### Privacy

The plugin does not operate an external service and does not add tracking. Email
delivery is handled by WordPress and any mail provider already configured by the
website owner.

The plugin registers suggested text with the WordPress Privacy Policy Guide.

## Screenshots

[⌊Log in with a passkey using Face ID, a fingerprint, or the device screen lock.⌉⌊
Log in with a passkey using Face ID, a fingerprint, or the device screen lock.⌉[

Log in with a passkey using Face ID, a fingerprint, or the device screen lock.

[⌊Request a one-time 6-digit code using the email address of an existing account.⌉⌊
Request a one-time 6-digit code using the email address of an existing account.⌉[

Request a one-time 6-digit code using the email address of an existing account.

[⌊Receive the clearly formatted login code by email.⌉⌊Receive the clearly formatted
login code by email.⌉[

Receive the clearly formatted login code by email.

[⌊Enter the time-limited code to complete sign-in.⌉⌊Enter the time-limited code 
to complete sign-in.⌉[

Enter the time-limited code to complete sign-in.

[⌊Add or remove passkeys from the standard WordPress profile screen.⌉⌊Add or remove
passkeys from the standard WordPress profile screen.⌉[

Add or remove passkeys from the standard WordPress profile screen.

[⌊Invite signed-in users without a passkey to set one up for faster future access.⌉⌊
Invite signed-in users without a passkey to set one up for faster future access.⌉[

Invite signed-in users without a passkey to set one up for faster future access.

[⌊Configure the default login method, login email, and passkey invitation under 
Settings.⌉⌊Configure the default login method, login email, and passkey invitation
under Settings.⌉[

Configure the default login method, login email, and passkey invitation under Settings.

## Installation

 1. Upload the plugin ZIP through **Plugins  Add New Plugin  Upload Plugin**.
 2. Activate **ThreeWay Login**.
 3. Optionally open **Settings  ThreeWay Login** to customize the login email.
 4. Open the standard WordPress login page to see the new login choices.
 5. Sign in and open your profile to add a passkey.

No configuration is required.

## FAQ

### Does this disable password login?

No. The classic WordPress password form remains available as one of the login choices.

### Can every registered user use a passkey?

Yes. A signed-in user can add a passkey from the WordPress profile screen or from
a protected page containing the `[threeway_login_passkeys]` shortcode.

### Can a user log in with a passkey before creating one?

No. A user first signs in with an existing method and creates a passkey. Future 
logins can then use that passkey.

### Does an email code register a new user?

No. Codes are sent only to email addresses already attached to a WordPress account.
The response does not reveal whether an account exists.

### Why does an unknown email address still show the code screen?

This is intentional. Showing a different response would allow attackers to discover
which email addresses have accounts. No email is sent and no login can succeed when
the address is unknown.

### Why did the email not arrive?

The plugin uses the website’s normal WordPress email system. Check spam filtering
and configure a reliable transactional email or SMTP service if normal WordPress
emails are not delivered reliably.

### Does this work with custom login forms or WooCommerce?

This initial release changes the standard WordPress login screen. The created WordPress
session works normally throughout the website, but direct integration into custom
login forms is not included yet.

### What data is stored?

For passkeys, WordPress stores the public credential, a signature counter, creation
date, and last-used date. Private keys never reach WordPress. Email login temporarily
stores a hashed code, user reference, expiration time, and attempt counter. Temporary
code data expires automatically.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“ThreeWay Login” is open source software. The following people have contributed 
to this plugin.

Contributors

 *   [ Planet 9 ](https://profiles.wordpress.org/planet9/)

[Translate “ThreeWay Login” into your language.](https://translate.wordpress.org/projects/wp-plugins/threeway-login)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/threeway-login/), check
out the [SVN repository](https://plugins.svn.wordpress.org/threeway-login/), or 
subscribe to the [development log](https://plugins.trac.wordpress.org/log/threeway-login/)
by [RSS](https://plugins.trac.wordpress.org/log/threeway-login/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.4

 * Renamed the plugin to ThreeWay Login with the distinctive `threeway-login` slug.
 * Removed bundled translation files in favor of translate.wordpress.org.
 * Removed inline login CSS and retained the standard WordPress form when JavaScript
   is unavailable.

#### 1.0.3

 * Added a setting to choose email code or username and password as the default 
   when no passkey is configured.
 * Show the passkey setup invitation only once after each new login, with separate
   options to postpone or permanently dismiss it.
 * Aligned the plugin folder, main file, REST namespace, and text domain with the
   WordPress.org slug.
 * Completed uninstall cleanup and reduced temporary database writes for rejected
   code requests.

#### 1.0.2

 * Added consistent spacing above and below explanatory text on the login screens.

#### 1.0.1

 * Fixed the external “Use another login method” switch.
 * Removed the redundant Back link from the email form.
 * Fixed hidden controls and the misplaced “or” separator.
 * Added spacing below explanatory text.

#### 1.0.0

 * Renamed the plugin during initial development.
 * Added a settings page under Settings.
 * Added a clean HTML email with a prominent login code.
 * Added customizable email subject, introduction, and accent color.
 * Clarified the email-code flow while retaining account-enumeration protection.
 * Fixed the link back from classic password login.

#### 0.2.0

 * Show email code login by default until a passkey has been configured.
 * Show passkey login as the primary choice after successful setup in that browser.
 * Added a one-time, dismissible passkey setup prompt after login.
 * Hide the passkey option when it is unsupported or not yet configured.
 * Keep password login available as a backup.

#### 0.1.0

 * Initial testing release.
 * Added passkey login and passkey management.
 * Added 6-digit one-time email codes.
 * Kept the classic WordPress password login available.
 * Added browser-local memory of the last selected login method.

## Meta

 *  Version **1.0.4**
 *  Last updated **11 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.4 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [authentication](https://wordpress.org/plugins/tags/authentication/)[email login](https://wordpress.org/plugins/tags/email-login/)
   [login](https://wordpress.org/plugins/tags/login/)[passkeys](https://wordpress.org/plugins/tags/passkeys/)
   [passwordless](https://wordpress.org/plugins/tags/passwordless/)
 *  [Advanced View](https://wordpress.org/plugins/threeway-login/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/threeway-login/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/threeway-login/reviews/)

## Contributors

 *   [ Planet 9 ](https://profiles.wordpress.org/planet9/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/threeway-login/)