- 01Enter username & password
- 02Open your authenticator
- 03Verify & log in
Start with your usual WordPress login details.
Choose verification methods by role, so the people with the most access have an extra check before entering WordPress.
Available in the current release. Authenticator apps, passkeys and recovery codes were added in 3.0.
Follow a member of your team through a sign-in that requires an authenticator app.
Start with your usual WordPress login details.
People reuse passwords, share them and lose them to phishing. For an account that can publish content or change site settings, checking the password alone leaves too much resting on one secret.
FluentAuth applies verification rules by role. Require an authenticator app or passkey for device verification independent of the mailbox, or use email codes where that policy fits your users.
Protect the roles with the most access while giving each user a supported way to complete verification.
Get FluentAuth →Available in the current release. Authenticator apps, passkeys and recovery codes were added in 3.0.
Follow the setup guide →
An authenticator app generates rotating codes. A passkey uses a registered authenticator. Email verification sends a code to the account’s mailbox.
Administrators are a natural starting point. Editors and other staff may need protection too, depending on what their roles allow. Test any custom checkout or member login alongside the standard WordPress flow.
Both prove access to the same mailbox. A magic link does not trigger another email challenge, but a required device factor still applies. Choose a device method when you need verification independent of email.
Choose a verification policy for your team, enrol a test account and confirm the recovery path before enforcing it.