← All features
Two-factor authentication

A password is only the first step.

Choose verification methods by role, so the people with the most access have an extra check before entering WordPress.

Available in the current release. Authenticator apps, passkeys and recovery codes were added in 3.0.

Why it matters

A password can be correct and still be in the wrong hands.

People reuse passwords, share them and lose them to phishing. For an account that can publish content or change site settings, checking the password alone leaves too much resting on one secret.

How it helps your site

Add another check before access.

FluentAuth applies verification rules by role. Require an authenticator app or passkey for device verification independent of the mailbox, or use email codes where that policy fits your users.

What you gain

Protect the roles with the most access while giving each user a supported way to complete verification.

Get FluentAuth →
Inside FluentAuth

See the controls behind the experience.

Available in the current release. Authenticator apps, passkeys and recovery codes were added in 3.0.

Follow the setup guide →
FluentAuth settings showing passkey, authenticator app and email verification options.
FluentAuth settings showing passkey, authenticator app and email verification options. Select the image to view it full size.

How the policy works

  1. Choose the roles that need verification and the methods they can use.
  2. Have users enrol their device method and save recovery codes where applicable.
  3. Test sign-in and recovery before requiring the policy across the team.

An authenticator app generates rotating codes. A passkey uses a registered authenticator. Email verification sends a code to the account’s mailbox.

Start with the roles that can change the site

Administrators are a natural starting point. Editors and other staff may need protection too, depending on what their roles allow. Test any custom checkout or member login alongside the standard WordPress flow.

Both prove access to the same mailbox. A magic link does not trigger another email challenge, but a required device factor still applies. Choose a device method when you need verification independent of email.

Make account protection part of every workday.

Choose a verification policy for your team, enrol a test account and confirm the recovery path before enforcing it.