Authentication Settings

Configure Masteriyo login and sign-up security: email verification, QR code login, and a limit on concurrent login sessions per user.

Location: Masteriyo > Settings > Authentication

The Authentication tab groups the settings that control how users sign in and how their login is secured. Each section below corresponds to a sub-tab within Masteriyo > Settings > Authentication.

Email Verification

  • Enable Email Verification — Default: On. When enabled, users must verify their email address before they get full access to your site.

QR Login

  • Enable QR Login — Default: Off. Lets users log in via a QR code or login link generated from their account profile.
  • Attention Message — A text field shown alongside the QR login. Default: "Attention: Possession of the QR code or login link grants login access to anyone."
Because anyone holding the QR code or login link can sign in, keep the attention message in place so users understand the risk of sharing it.

Limit Login Session

  • Maximum Active Sessions — Default: 0 (unlimited). Caps the number of concurrent device logins allowed per user. Set a positive number to limit how many devices can stay signed in at once.

reCAPTCHA

This sub-tab appears only when the free Google reCAPTCHA add-on is activated under Masteriyo > Addons. It lets you protect your login and registration forms from bots and spam.

For setup and configuration details, see the Google reCAPTCHA add-on documentation.

Two-Factor Authentication
Pro

Adds a one-time password (OTP) step on top of the normal login. Available with Masteriyo Pro.

  • Enable Two Factor Authentication — Turns the OTP challenge on or off.
  • Location — Where the second factor is enforced: Masteriyo & WP Login, Masteriyo login only, or WP login only.
  • OTP Length — Number of digits in the one-time code. Default: 6.
  • OTP Expiration Interval — How long a code stays valid, in seconds. Default: 1800 (30 minutes); minimum 120.
  • OTP Resend Interval — Minimum wait before a user can request a new code. Entered in seconds (minimum 60). Default: 120 seconds (2 minutes).
  • OTP Resend Max Attempts — Maximum number of times a user can request a new code. Default: 10 (min 1, max 100).

For full setup instructions, see the Two-Factor Authentication documentation. Two-Factor Authentication is built into Masteriyo Pro — it moved from an add-on into core in v3.1.0, so no add-on activation is needed.

Social Login
Pro

Lets users sign in with their existing social accounts. This sub-tab appears when the Social Login add-on is active.

  • Google — Toggle Google Login and enter the Client ID and Secret Key (a read-only Redirect Url is provided to paste into your Google credentials).
  • Facebook — Toggle Facebook Login and enter the App ID and App Secret (a read-only Redirect Url is provided to paste into your Facebook app).

For full setup instructions, see the Social Login add-on documentation.


Was this article helpful to you?
Give us Rating

Last edited on July 22, 2026.
Edit this page