How do I let customers log in with an e-mail code?
Customers can log in to the front pages without a password. They enter only their username or e-mail address and receive a one-time code by e-mail. That code is valid for fifteen minutes. This login method applies to the front pages only, not to the admin panel.
Switching the setting on
Go to Configuration > System > Security settings and set Allow login via e-mail code (front pages) to Yes. The setting is off by default. While it is off, nobody sees a login method to choose from.
The customer chooses
With the setting on, the profile on the front pages shows a Login method field with the options Login with password and Login via e-mail code (no password). Switching works both ways:
| From | To | What the customer does |
|---|---|---|
| Password | E-mail code | Enter the current password as confirmation. The password is removed afterwards. |
| E-mail code | Password | Request a code, enter it as confirmation and then choose a new password. |
The code always goes to the e-mail address already on file, never to an address entered at that moment. That way nobody can take over an account by changing the address first.
Converting a customer as an administrator
Open the customer, go to the block of the linked user and choose Change password / method. The same choice is offered there, so you can convert a single customer without them having to do it. There is no button to convert every customer at once; for new customers the import can do it.
Making the e-mail code mandatory
Do you want customers to be unable to go back to a password? First put those customers on the e-mail code, then switch the Allow login via e-mail code setting off again. From that moment on:
- logging in with the e-mail code keeps working;
- the choice disappears from the profile and the customer sees a notice that changing the login method is unavailable;
- customers who still have a password simply keep it.
Switch the setting back on later and everyone can choose again.
Points to watch
- A customer without a valid e-mail address cannot log in: there is no address to send the code to.
- A code is valid for fifteen minutes. If the customer requests a new code within a minute, the same code is sent again.
- The admin panel does not offer this login method. Administrators always keep a password.
- If an unknown username is entered, the same code screen appears and no e-mail is sent. This is deliberate: it prevents anyone from finding out which accounts exist.
Check that the customer has a valid e-mail address before converting them. Without a working address the code never arrives and the customer cannot log in at all.






