Authentication Settings
Configure Masteriyo login and sign-up security: email verification, QR code login, and a limit on concurrent login sessions per user.
The Authentication tab groups the settings that control how users sign in and how their login is secured. Each section below corresponds to a sub-tab within Masteriyo > Settings > Authentication.
Email Verification
- Enable Email Verification — Default: On. When enabled, users must verify their email address before they get full access to your site.
QR Login
- Enable QR Login — Default: Off. Lets users log in via a QR code or login link generated from their account profile.
- Attention Message — A text field shown alongside the QR login. Default: "Attention: Possession of the QR code or login link grants login access to anyone."
Limit Login Session
- Maximum Active Sessions — Default: 0 (unlimited). Caps the number of concurrent device logins allowed per user. Set a positive number to limit how many devices can stay signed in at once.
reCAPTCHA
This sub-tab appears only when the free Google reCAPTCHA add-on is activated under Masteriyo > Addons. It lets you protect your login and registration forms from bots and spam.
For setup and configuration details, see the Google reCAPTCHA add-on documentation.
Two-Factor Authentication Pro
Adds a one-time password (OTP) step on top of the normal login. Available with Masteriyo Pro.
- Enable Two Factor Authentication — Turns the OTP challenge on or off.
- Location — Where the second factor is enforced: Masteriyo & WP Login, Masteriyo login only, or WP login only.
- OTP Length — Number of digits in the one-time code. Default: 6.
- OTP Expiration Interval — How long a code stays valid, in seconds. Default: 1800 (30 minutes); minimum 120.
- OTP Resend Interval — Minimum wait before a user can request a new code. Entered in seconds (minimum 60). Default: 120 seconds (2 minutes).
- OTP Resend Max Attempts — Maximum number of times a user can request a new code. Default: 10 (min 1, max 100).
For full setup instructions, see the Two-Factor Authentication documentation. Two-Factor Authentication is built into Masteriyo Pro — it moved from an add-on into core in v3.1.0, so no add-on activation is needed.
Social Login Pro
Lets users sign in with their existing social accounts. This sub-tab appears when the Social Login add-on is active.
- Google — Toggle Google Login and enter the Client ID and Secret Key (a read-only Redirect Url is provided to paste into your Google credentials).
- Facebook — Toggle Facebook Login and enter the App ID and App Secret (a read-only Redirect Url is provided to paste into your Facebook app).
For full setup instructions, see the Social Login add-on documentation.
Was this article helpful to you?
Give us Rating
Last edited on July 22, 2026.
Edit this page