QR code sign-in
Scan a code with a device that is already signed in. Fast on a shared screen — and useless without that second device.
- Intermediate
- 4 min read
- Applies to 2.0
Not available in 2.0
This method cannot be turned on in 2.0. The code is in the Pro plugin —
the class, its settings and its endpoints all exist — but the Authentication
screen builds no card for it, so there is nothing to select and
attrua_pro_active_auth_method never takes the value. Everything below
describes how the method behaves, and stays here for the release that
exposes it.
Turn it on
User Access → Authentication, select QR code — once the screen offers it. The defaults are a challenge valid for 2 minutes and a page that checks for approval every 3 seconds.

The login page showing a QR challenge.
How a sign-in goes
The login page displays a code. The member scans it with a device where they are already signed in — a phone, usually — and approves the request there. The waiting page notices within a few seconds and opens the session.
Nothing is typed on the machine being signed in to, which is the appeal: on a shared or public screen, no password is exposed to whatever is watching.
What it needs from your members
A second device, already signed in. That is the whole condition, and it is a hard one:
- A member on a new phone has nothing to scan with
- A member on one device only cannot use this method at all
- A first sign-in is impossible — there is no signed-in device yet
As the site's only method, QR code excludes anyone without a second signed-in device. It suits an internal tool where everyone already has a phone signed in; it does not suit a public membership site.
- You have signed in by scanning, from a second device
- You have tried with a device that is not signed in, to see what a member in that situation gets
- Your emergency access link is saved outside the site
Related articles
Something missing or out of date? Tell support.