QR code sign-in

Scan a code with a device that is already signed in. Fast on a shared screen — and useless without that second device.

  • Intermediate
  • 4 min read
  • Applies to 2.0

Not available in 2.0

This method cannot be turned on in 2.0. The code is in the Pro plugin — the class, its settings and its endpoints all exist — but the Authentication screen builds no card for it, so there is nothing to select and attrua_pro_active_auth_method never takes the value. Everything below describes how the method behaves, and stays here for the release that exposes it.

Turn it on

User Access → Authentication, select QR code — once the screen offers it. The defaults are a challenge valid for 2 minutes and a page that checks for approval every 3 seconds.

The login page showing a QR challenge.

How a sign-in goes

The login page displays a code. The member scans it with a device where they are already signed in — a phone, usually — and approves the request there. The waiting page notices within a few seconds and opens the session.

Nothing is typed on the machine being signed in to, which is the appeal: on a shared or public screen, no password is exposed to whatever is watching.

What it needs from your members

A second device, already signed in. That is the whole condition, and it is a hard one:

  • A member on a new phone has nothing to scan with
  • A member on one device only cannot use this method at all
  • A first sign-in is impossible — there is no signed-in device yet

As the site's only method, QR code excludes anyone without a second signed-in device. It suits an internal tool where everyone already has a phone signed in; it does not suit a public membership site.

  • You have signed in by scanning, from a second device
  • You have tried with a device that is not signed in, to see what a member in that situation gets
  • Your emergency access link is saved outside the site

Related articles

Something missing or out of date? Tell support.