Two-step login

Email first, password on the next step. A familiar shape borrowed from the big providers — and it changes nothing about security.

  • Beginner
  • 3 min read
  • Applies to 2.0

Turn it on

User Access → Authentication, select Two-step login, and save. There is nothing else to configure.

The login form at its first step, asking only for an email address.

How a sign-in goes

The form asks for an email address on its own. Once entered, the address is checked and the password field appears — with the member's avatar, so they can see whose account they are signing in to.

The shape is the one Google and Microsoft made familiar, which is most of the reason to choose it.

What it does not change

The authentication itself is WordPress's. Splitting the form in two does not add a factor, does not slow an attacker down, and does not protect a weak password. It is an interface choice.

Two-step login is not two-factor authentication. If your goal is a second layer rather than a second screen, choose Password with two-factor.

There is one side effect worth knowing: the first step tells the visitor whether an address has an account here. That is inherent to the shape — the big providers have the same property — but it is a fact about your site to weigh before enabling it.

Related articles

Something missing or out of date? Tell support.