ThreeWay Login

ThreeWay Login

Details
View on WordPress

ThreeWay Login replaces the first view of the standard WordPress login screen with three clear choices:

  • Continue with a passkey using Face ID, a fingerprint, or the device screen lock
  • Receive a one-time 6-digit code by email
  • Use the classic WordPress password form

Before a passkey is configured, administrators can choose whether email code login or the classic username-and-password form is shown first. After a passkey is created, the same browser shows passkey login as the primary choice. The passkey preference is stored only in that browser. The classic WordPress login remains available at all times.

Passkeys use the WebAuthn standard and create phishing-resistant credentials tied to the website. Private passkey keys remain in the user’s device or passkey provider. Only the public credential is stored in WordPress.

Email codes expire after 10 minutes, can be used once, and allow no more than five verification attempts. The plugin uses neutral responses and request limits to reduce account discovery and automated abuse.

The plugin does not create accounts. Every login method works only for an existing WordPress user.

Passkey management

Signed-in users can add and remove passkeys from their WordPress profile. Sites with a custom account area can place the [threeway_login_passkeys] shortcode on a protected page.

After each new login, users without a passkey can see the setup invitation once. They can create a passkey, close the invitation for that login, or choose not to see it again. It is not shown when the user already has a passkey or has permanently dismissed the invitation.

Settings

Open Settings ThreeWay Login to choose the default method for browsers without a passkey and to customize the login email subject, introductory text, accent color, and passkey invitation.

Requirements

Passkeys require HTTPS and a browser with WebAuthn support. Local development on localhost is also supported.

Email codes are sent through the standard WordPress wp_mail() function. Reliable delivery depends on the website’s email configuration. A properly configured transactional email or SMTP service is recommended.

Security

Passkey ceremonies verify the website origin, relying-party identifier, challenge, user presence, and device user verification. Only ES256 P-256 passkeys are requested and accepted.

Email codes are generated with a cryptographically secure random-number generator, stored only as site-specific HMAC digests, expire after 10 minutes, become invalid after use, and are replaced when a new code is requested.

All successful methods establish a normal WordPress session through WordPress core authentication cookies and fire the standard wp_login action.

Privacy

The plugin does not operate an external service and does not add tracking. Email delivery is handled by WordPress and any mail provider already configured by the website owner.

The plugin registers suggested text with the WordPress Privacy Policy Guide.

Details

Plugin code:
threeway-login
Plugin version:
1.0.4
Author:
Outdated:
No
WP version:
6.4 or higher
PHP version:
7.4 or higher
Test up to WP version:
7.1.3
Total installations:
0
Last updated:
2026-10-09
Rating:
Times rated:
0
authentication
email-login
login
passkeys
passwordless