Choosing your sign-in method
Three ways to sign in, and only one is active at a time — plus two add-ons that sit alongside whichever you pick.
- Beginner
- 6 min read
- Applies to 2.0
Pick one
User Access → Authentication lists the ways your members can sign in. Select one and save.

The Authentication tab with the three methods, one selected.
| Method | What the visitor does |
|---|---|
| Password | The usual: username or email, and a password |
| Two-step login | Email first, password on the next step |
| Magic link | Receives a one-time link by email, no password |
Password is the default, and the one a site runs on until you change it.
One at a time — this is the important part
This is not a set of checkboxes. The site has one sign-in method, and choosing a new one replaces the previous one for every user.
Switch to magic link and passwords stop being asked for — a member who cannot reach their inbox cannot get in at all. There is no "password or magic link, whichever they prefer".
Get your emergency access link before you change method, and keep it somewhere outside the site. It is the one URL that reaches the classic WordPress form whatever the active method is — and the moment you need it is the moment you cannot sign in to find it.
The two add-ons
Two things on the same screen are not methods, and do not replace anything. They sit alongside whichever method is active, each in its own section below the picker:
- Password with two-factor — after the password, a code by email or from an authenticator app. See Password with two-factor.
- Social login — provider buttons on the form. Password sign-in and a Google button can coexist. See Social login.
Two further methods exist in the Pro code — authenticator app on its own and QR code — but 2.0 ships no control for them: the Authentication screen does not offer them, so they cannot be turned on. Their articles are marked accordingly.
Before you switch
- Your emergency access link is saved outside the site
- Email delivery is tested, if the method you chose sends anything
- You have signed in with the new method in a private window, as a non-administrator
- Your members know it is coming — a changed sign-in screen with no warning reads as a broken site
Next steps
Something missing or out of date? Tell support.