{"id":306303,"date":"2026-08-27T13:53:48","date_gmt":"2026-08-27T13:53:48","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/authlatch\/"},"modified":"2026-08-27T14:04:14","modified_gmt":"2026-08-27T14:04:14","slug":"authlatch","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/authlatch\/","author":23383027,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.2","stable_tag":"1.0.2","tested":"7.1","requires":"6.4","requires_php":"8.0","requires_plugins":null,"header_name":"AuthLatch","header_author":"Rayhan Sardar","header_description":"Passwordless login with magic links, passkeys, single-session control, admin-scoped access links, and built-in SMTP delivery.","assets_banners_color":"d0d2d5","last_updated":"2026-08-27 14:04:14","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/RayhanSysMin\/authlatch","header_author_uri":"https:\/\/github.com\/RayhanSysMin","rating":0,"author_block_rating":0,"active_installs":0,"downloads":52,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.1":{"tag":"1.0.1","author":"madc0de","date":"2026-08-27 13:53:14","revision":3668985},"1.0.2":{"tag":"1.0.2","author":"madc0de","date":"2026-08-27 14:04:14","revision":3669007}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3668985,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3668985,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256},"icon.svg":{"filename":"icon.svg","revision":3668985,"resolution":false,"location":"assets","locale":false}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3668985,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3668985,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.1","1.0.2"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[185112,218738,35316,6696,183349],"plugin_category":[41],"plugin_contributors":[277891],"plugin_business_model":[],"class_list":["post-306303","plugin","type-plugin","status-publish","hentry","plugin_tags-magic-link","plugin_tags-passkey","plugin_tags-passwordless-login","plugin_tags-smtp","plugin_tags-webauthn","plugin_category-communication","plugin_contributors-madc0de","plugin_committers-madc0de"],"banners":{"banner":"https:\/\/ps.w.org\/authlatch\/assets\/banner-772x250.png?rev=3668985","banner_2x":"https:\/\/ps.w.org\/authlatch\/assets\/banner-1544x500.png?rev=3668985","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":"https:\/\/ps.w.org\/authlatch\/assets\/icon.svg?rev=3668985","icon":"https:\/\/ps.w.org\/authlatch\/assets\/icon.svg?rev=3668985","icon_2x":false,"generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>AuthLatch helps site owners replace routine password logins with secure passwordless access.<\/p>\n\n<p>Key features:<\/p>\n\n<ul>\n<li>One-time magic links requested by username or email, with expiry and one-use tokens.<\/li>\n<li>Passkey login using WebAuthn\/FIDO2.<\/li>\n<li>Self-service AuthLatch sidebar page for selected user roles.<\/li>\n<li>Users can add, revoke, and name their own passkeys.<\/li>\n<li>Users can send a magic login link to their own account email.<\/li>\n<li>Per-role passkey access and per-user passkey limits.<\/li>\n<li>Branded responsive login screen with method tabs for magic links, passkeys, and password fallback.<\/li>\n<li>Single active session control.<\/li>\n<li>Admin-generated login links with optional IP binding and auto logout.<\/li>\n<li>Admin-scoped login links that can block selected admin menus for that session.<\/li>\n<li>Built-in SMTP settings for hosts where PHP mail delivery is disabled.<\/li>\n<li>Audit log for important authentication events.<\/li>\n<li>RTL-friendly login UI.<\/li>\n<\/ul>\n\n<p>AuthLatch stores magic-link validators as hashes, verifies passkeys server-side, and uses WordPress capabilities, nonces, sanitization, and escaping throughout the admin interface.<\/p>\n\n<h3>Setup<\/h3>\n\n<h4>Magic links<\/h4>\n\n<ol>\n<li>Enable Magic links in AuthLatch &gt; Settings.<\/li>\n<li>Set the default link expiry.<\/li>\n<li>Configure the email subject and body.<\/li>\n<li>Configure SMTP if the host disables PHP mail.<\/li>\n<li>Users can request a login link from the login page with either username or email.<\/li>\n<li>Enabled self-service roles can also send a login link from AuthLatch in the admin sidebar.<\/li>\n<\/ol>\n\n<h4>Passkeys<\/h4>\n\n<ol>\n<li>Enable Passkeys in AuthLatch &gt; Settings.<\/li>\n<li>Select the roles allowed to use passkeys.<\/li>\n<li>Set the maximum passkeys per user.<\/li>\n<li>Use HTTPS on the live site.<\/li>\n<li>Users with allowed roles can open AuthLatch in the admin sidebar and click Add passkey.<\/li>\n<li>Users can revoke old passkeys from the same page.<\/li>\n<\/ol>\n\n<h4>Self-service sidebar page<\/h4>\n\n<ol>\n<li>Open AuthLatch &gt; Settings.<\/li>\n<li>Select roles under Self-Service Page &gt; Sidebar access roles.<\/li>\n<li>Only selected roles will see the AuthLatch sidebar page.<\/li>\n<li>The self-service page lets users manage their own passkeys and send a magic link to their own email.<\/li>\n<\/ol>\n\n<h4>Password fallback<\/h4>\n\n<ol>\n<li>Keep Username\/password login enabled if normal WordPress login should remain available.<\/li>\n<li>Keep admin password fallback enabled if administrators should still be able to log in with a password when password login is otherwise disabled.<\/li>\n<\/ol>\n\n<h4>SMTP<\/h4>\n\n<ol>\n<li>Enable Use SMTP for WordPress emails.<\/li>\n<li>Enter host, port, encryption, username, password, from email, and from name.<\/li>\n<li>Save settings.<\/li>\n<li>Send a test email from AuthLatch &gt; Settings.<\/li>\n<\/ol>\n\n<h3>Privacy<\/h3>\n\n<p>AuthLatch stores authentication-related records in the WordPress database, including hashed magic-link tokens, passkey public-key data, hashed IP values for audit and optional IP binding, and configuration settings. AuthLatch does not store plaintext magic-link validators. SMTP passwords are encrypted with WordPress salts before storage.<\/p>\n\n<h3>Third-Party Libraries<\/h3>\n\n<p>AuthLatch includes the MIT-licensed lbuchs\/WebAuthn library for WebAuthn\/FIDO2 server-side verification.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Upload the plugin ZIP through Plugins &gt; Add New &gt; Upload Plugin.<\/li>\n<li>Activate AuthLatch.<\/li>\n<li>Open AuthLatch &gt; Settings from the WordPress admin sidebar.<\/li>\n<li>Configure magic links, passkeys, self-service roles, branding, and SMTP if needed.<\/li>\n<li>Save settings.<\/li>\n<li>Send a test SMTP email before relying on email-only login.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20authlatch%20require%20a%20separate%20smtp%20plugin%3F\"><h3>Does AuthLatch require a separate SMTP plugin?<\/h3><\/dt>\n<dd><p>No. AuthLatch includes SMTP settings and uses WordPress PHPMailer.<\/p><\/dd>\n<dt id=\"does%20passkey%20login%20require%20https%3F\"><h3>Does passkey login require HTTPS?<\/h3><\/dt>\n<dd><p>Yes. WebAuthn passkeys require a secure browser context, usually HTTPS. Localhost is generally allowed for development.<\/p><\/dd>\n<dt id=\"where%20does%20a%20user%20add%20a%20passkey%3F\"><h3>Where does a user add a passkey?<\/h3><\/dt>\n<dd><p>Allowed users can open AuthLatch from the WordPress admin sidebar and use Add passkey. Passkeys can also be managed from the WordPress profile page.<\/p><\/dd>\n<dt id=\"can%20administrators%20keep%20password%20login%20as%20a%20fallback%3F\"><h3>Can administrators keep password login as a fallback?<\/h3><\/dt>\n<dd><p>Yes. The settings include an administrator password fallback option.<\/p><\/dd>\n<dt id=\"can%20users%20request%20magic%20links%20for%20their%20own%20account%3F\"><h3>Can users request magic links for their own account?<\/h3><\/dt>\n<dd><p>Yes. If their role is selected in Self-Service Page settings, users can open AuthLatch in the sidebar and send a login link to their account email.<\/p><\/dd>\n<dt id=\"does%20authlatch%20send%20data%20to%20an%20external%20service%3F\"><h3>Does AuthLatch send data to an external service?<\/h3><\/dt>\n<dd><p>AuthLatch does not send authentication data to an AuthLatch service. If SMTP is enabled, email is sent through the SMTP server configured by the site administrator.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.2<\/h4>\n\n<ul>\n<li>Updated compatibility metadata for WordPress 7.1.<\/li>\n<\/ul>\n\n<h4>1.0.1<\/h4>\n\n<ul>\n<li>Updated compatibility metadata for WordPress 7.0.<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial WordPress submission release.<\/li>\n<li>Added role-gated self-service AuthLatch sidebar page.<\/li>\n<li>Added user-managed passkey registration and revocation from the sidebar.<\/li>\n<li>Added user self-service magic-link email action.<\/li>\n<li>Added plugin action link for settings.<\/li>\n<\/ul>","raw_excerpt":"Passwordless login for WordPress with magic links, passkeys, self-service account security, and built-in SMTP settings.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/306303","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=306303"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/madc0de"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=306303"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=306303"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=306303"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=306303"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=306303"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=306303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}