<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>authentication on</title><link>https://docs.whmcs.com/9-1/tags/authentication/</link><description>Recent content in authentication on</description><generator>Hugo -- gohugo.io</generator><atom:link href="https://docs.whmcs.com/9-1/tags/authentication/index.xml" rel="self" type="application/rss+xml"/><item><title>Troubleshooting Authentication</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/troubleshooting-authentication/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/troubleshooting-authentication/</guid><description>Lists linked troubleshooting articles grouped by category, including general WHMCS authentication issues, Facebook, Google, and Twitter Sign-In Integration errors, password reset problems, and two-factor authentication issues.</description></item><item><title>Troubleshooting Licensing</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-licensing/troubleshooting-licensing/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-licensing/troubleshooting-licensing/</guid><description>Serves as an index of licensing error troubleshooting articles and points to separate guides for the cPanel Licensing Addon and control panel licensing issues within hosting modules.</description></item><item><title>Two-Factor Authentication</title><link>https://docs.whmcs.com/9-1/system/authentication/two-factor-authentication/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/two-factor-authentication/</guid><description>Compares the three 2FA services (Time-Based Tokens, Duo Security, YubiKey), lists where clients and admins configure 2FA, covers server-clock-mismatch error messages, and links troubleshooting articles for common 2FA issues.</description></item><item><title>Duo® Security</title><link>https://docs.whmcs.com/9-1/system/authentication/duo-security/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/duo-security/</guid><description>Explains retrieving the Duo Client ID, Client Secret, and API hostname from the Duo Security admin portal to configure it at Configuration &amp;gt; System Settings &amp;gt; Two Factor Authentication, the admin email/license-key format Duo uses, and how to reactivate a user&amp;rsquo;s 2FA after a lost device.</description></item><item><title>Reset a User Password</title><link>https://docs.whmcs.com/9-1/clients/client-management-tutorials/reset-a-user-password/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/clients/client-management-tutorials/reset-a-user-password/</guid><description>Explains the self-service password reset flow via Forgotten Password on the login form, the two-hour validity of the confirmation link, and the SQL query against tblusers to force a reset on a self-hosted installation by clearing a user&amp;rsquo;s password and token fields.</description></item><item><title>Set a User Password Manually</title><link>https://docs.whmcs.com/9-1/clients/client-management-tutorials/set-a-user-password-manually/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/clients/client-management-tutorials/set-a-user-password-manually/</guid><description>Gives steps to manually set a user&amp;rsquo;s password from the Users tab of the client profile by selecting Change Password from the Actions column dropdown, entering the new password, and clicking Save.</description></item><item><title>API Credentials</title><link>https://docs.whmcs.com/9-1/system/authentication/api-credentials/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/api-credentials/</guid><description>Details the steps to create, edit, and delete API roles and API credential pairs at Configuration &amp;gt; System Settings &amp;gt; Manage API Credentials, including generating identifier/secret pairs and assigning permission roles to a credential.</description></item><item><title>Single Sign-On</title><link>https://docs.whmcs.com/9-1/system/authentication/single-sign-on/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/single-sign-on/</guid><description>Details the View Products &amp;amp; Services and Perform Single Sign-On permissions required by users, per-server per-admin-role-group access controls configurable under a server&amp;rsquo;s SSO Access Control setting, and the Client Area Quick Shortcuts section for direct control panel authentication.</description></item><item><title>Application Links</title><link>https://docs.whmcs.com/9-1/system/authentication/application-links/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/application-links/</guid><description>Covers activating and configuring Application Links for cPanel, the supported Ordering, Support, and Account links table, the Application Link Activity Log levels (Debug, Information, Notice, Warning), and where users and admins can revoke single sign-on permissions.</description></item><item><title>Sign-In Integrations</title><link>https://docs.whmcs.com/9-1/system/authentication/sign-in-integrations/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/sign-in-integrations/</guid><description>Explains activating a Facebook, Google, or Twitter sign-in provider with API credentials at Configuration &amp;gt; System Settings &amp;gt; Sign-In Integrations, where users manage linked accounts under Profile &amp;gt; Security Settings, and where sign-in errors log in the Activity Log.</description></item><item><title>OpenID Connect</title><link>https://docs.whmcs.com/9-1/system/authentication/openid-connect/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/openid-connect/</guid><description>Covers generating and resetting OAuth Client API Credentials and authorized redirect URIs at Utilities &amp;gt; System &amp;gt; OpenID Connect, and gives the full step-by-step setup to let cPanel &amp;amp; WHM users log in via WHMCS External Authentication, including the Well Known Config URI and SSL requirements.</description></item><item><title>OpenID Connect Development</title><link>https://docs.whmcs.com/9-1/system/authentication/openid-connect-development/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/openid-connect-development/</guid><description>Documents the developer workflow for OpenID Connect authentication against WHMCS: the .htaccess rewrite rule for the discovery document, the client_id/response_type/scope/redirect_uri/state authentication request parameters, exchanging the authorization code for access_token and id_token, and the iss/sub/aud/iat/exp ID token claims.</description></item><item><title>Cloudflare Proxy Check Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/cloudflare-proxy-check-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/cloudflare-proxy-check-errors/</guid><description>Covers the System Health CloudFlare Proxy Check warning about missing trusted proxy settings that can end login sessions prematurely, and gives the one-click fix: click the reconfigure link to add Cloudflare&amp;rsquo;s IP addresses to the Trusted Proxies list in General Settings&amp;rsquo; Security tab.</description></item><item><title>Frequent Logouts</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/frequent-logouts/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/frequent-logouts/</guid><description>Diagnoses frequent logouts by cause: PHP session misconfiguration (checked via System Health), proxy/CDN misconfiguration breaking IP detection, insufficient disk space, changing visitor IPs, or VPN use, with workarounds like disabling Session IP Check or using database session storage.</description></item><item><title>Invalid License API Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-licensing/invalid-license-api-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-licensing/invalid-license-api-errors/</guid><description>Explains that the Your license key is invalid API error occurs when a license check runs from a non-web context like a CLI script or cron with a mismatched outbound IP, with steps to confirm the context, calling method, and IP mismatch, and recommending remote HTTP requests to api.php instead of the localAPI helper.</description></item><item><title>Invalid License Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-licensing/invalid-license-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-licensing/invalid-license-errors/</guid><description>Covers the License Invalid error at Admin Area login caused by an incorrect license key in configuration.php or an unreissued license after moving the installation, with steps to verify the $license value against the issued key and reissue it via Services &amp;gt; My Licenses or through the hosting provider.</description></item><item><title>Login Details Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/login-details-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/login-details-errors/</guid><description>Covers the Client Area error &amp;ldquo;Login Details Incorrect. Please try again,&amp;rdquo; typically caused by the login URL not matching the WHMCS System URL setting, often after adding SSL or moving the installation, and the fix: align the URL with the System URL setting in General Settings.</description></item><item><title>Login Redirect Loops</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/login-redirect-loops/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/login-redirect-loops/</guid><description>Covers login redirect loops and Invalid csrf protection token errors caused by PHP session problems, with diagnostics via System Health and the test_sessions.php file, plus fixes: correct the session tmp path&amp;rsquo;s permissions/space, or disable Session IP Check or use database session storage.</description></item><item><title>Login Session Length</title><link>https://docs.whmcs.com/9-1/system/php/login-session-length/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/php/login-session-length/</guid><description>Explains that the session.gc_maxlifetime PHP setting (default 1440 seconds) controls login timeout, how to increase it via php.ini or a custom php.ini file in the WHMCS directory, and how conflicting session.save_path values from other PHP scripts on the same account can shorten it unexpectedly.</description></item><item><title>No Connection Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-licensing/no-connection-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-licensing/no-connection-errors/</guid><description>Covers the No Connection admin login error caused by cURL or DNS problems, with steps to test connectivity via login.php?conntest=1 against a.licensing.whmcs.com, verify DNS for whmcs.com, and a PHP 7 workaround for restrictive shared or reseller hosting.</description></item><item><title>Oops! Access Denied Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/oops-access-denied-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/oops-access-denied-errors/</guid><description>Covers the &amp;ldquo;Oops! Access Denied - Forbidden&amp;rdquo; error, caused by missing administrator role permissions, a missing account owner password blocking Login as Owner, or restricted WHMCS Cloud features, and fixes: assign permissions in Administrator Roles or reset the owner&amp;rsquo;s password via email, SQL, or manual reset.</description></item><item><title>Oops! Too Many Requests Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/oops-too-many-requests-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/oops-too-many-requests-errors/</guid><description>Covers the Client Area error &amp;ldquo;Oops! You have sent too many requests,&amp;rdquo; triggered by 10 failed login attempts within 10 minutes, and gives the fix: verify login credentials and retry after the temporary block clears, checking the Activity Log for the source IP.</description></item><item><title>PHP Session Storage Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/php-session-storage-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/php-session-storage-errors/</guid><description>Covers the login-blocking error &amp;ldquo;PHP session storage is not writeable,&amp;rdquo; caused by mismatched session.save_path values across PHP configuration files or a non-writable storage location, and the fix: align session.save_path across configs and grant write permissions to the storage location.</description></item><item><title>Remember Me Session Ended</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/remember-me-session-ended/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/remember-me-session-ended/</guid><description>Diagnoses an ended admin Remember Me session by cause: 30-day expiry, exceeding the 5-device Remember Me cap, logout or signing in without Remember Me, a password change, an IP address or browser change, an admin being disabled, or an encryption hash rotation, with steps to check the Activity Log and Admin Log for unrecognized sessions.</description></item><item><title>Sessions Are Not Removed</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/sessions-are-not-removed/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/sessions-are-not-removed/</guid><description>Attributes persistent sessions to non-standard PHP session.gc_probability and session.gc_divisor values, often 0, which disable garbage collection, and directs self-hosted users to restore the defaults or WHMCS Cloud users to contact Technical Support.</description></item><item><title>Single Sign-On Active Session Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/sso-active-session-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/sso-active-session-errors/</guid><description>Covers the OAuth authorization request denied due to unexpected active login session for Closed User ID error, and lists steps to terminate the session in the Admin Log, change the client Profile Status to Active or Inactive, and retry with a new token.</description></item><item><title>Single Sign-On Closed User Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/sso-closed-user-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/sso-closed-user-errors/</guid><description>Covers the Single Sign-On authentication denied for Closed User ID error, caused by attempting single sign-on for a client whose account status is Closed, and gives the fix of updating the client&amp;rsquo;s Profile Status field to Active or Inactive and saving the change.</description></item><item><title>Single Sign-On Configuration Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/sso-configuration-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/sso-configuration-errors/</guid><description>Covers the Single Sign-On authentication denied per configuration for User ID error, caused by the client disabling single sign-on in their Client Area security settings, and gives the fix of the client re-enabling single sign-on under Account &amp;gt; Security Settings and saving the change.</description></item><item><title>Single Sign-On Token Errors</title><link>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/sso-token-errors/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/troubleshooting/troubleshoot-authentication/sso-token-errors/</guid><description>Covers the Unable to authenticate with Single Sign-On token for User ID error, lists checks for CreateSsoToken API success, OAuth token validity, token expiry, user ID, and client status, and gives the fix of generating and redirecting with a new single-use token.</description></item><item><title>Enable 2FA Globally</title><link>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/enable-2fa-globally/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/enable-2fa-globally/</guid><description>Lists the steps to activate a 2FA service at Configuration &amp;gt; System Settings &amp;gt; Two Factor Authentication, including the Enable for use by Clients and Enable for use by Administrative Users checkboxes and saving the configuration.</description></item><item><title>Enable 2FA for Admins</title><link>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/enable-2fa-for-admins/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/enable-2fa-for-admins/</guid><description>Provides the six-step process for an admin to enable Time-Based Token 2FA from My Account, including scanning the QR code, entering the authenticator app code, and recording the backup code.</description></item><item><title>Enable 2FA for Clients</title><link>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/enable-2fa-for-clients/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/enable-2fa-for-clients/</guid><description>Walks through enabling Time-Based Token 2FA from Security Settings in the Client Area, including scanning the QR code and recording the backup code, and notes that admins can disable but not enable 2FA for users at Clients &amp;gt; Manage Users.</description></item><item><title>Log In Without a Backup Code</title><link>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/log-in-without-a-backup-code/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/log-in-without-a-backup-code/</guid><description>Gives the SQL command to clear the authmodule and authdata fields in the tbladmins database table for a self-hosted installation, letting a locked-out admin log in without 2FA and reconfigure it on a new device.</description></item><item><title>Log In Without a Token</title><link>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/log-in-without-a-token/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/log-in-without-a-token/</guid><description>Explains the 16-character backup code format, then gives separate step-by-step logins using the Login using Backup Code link for the Admin Area and Client Area, plus how an admin disables 2FA afterward via My Account.</description></item><item><title>Require 2FA</title><link>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/require-2fa/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/require-2fa/</guid><description>Details the Global Two-Factor Authentication Settings checkboxes at Configuration &amp;gt; System Settings &amp;gt; Two Factor Authentication that force users and admins to set up 2FA on their next login.</description></item><item><title>Sign In Using Facebook</title><link>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/sign-in-using-facebook/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/sign-in-using-facebook/</guid><description>Steps through creating a Facebook developer app, requesting public_profile permission, retrieving the App ID and Secret, and entering those credentials under Configuration &amp;gt; System Settings &amp;gt; Sign-In Integrations to activate Facebook login.</description></item><item><title>Sign In Using Google</title><link>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/sign-in-using-google/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/sign-in-using-google/</guid><description>Steps through creating a Google Developer Project, configuring the OAuth consent screen and authorized domains, generating the Client ID and Client Secret, and entering those credentials under Configuration &amp;gt; System Settings &amp;gt; Sign-In Integrations to activate Google login.</description></item><item><title>Sign In Using Twitter</title><link>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/sign-in-using-twitter/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.whmcs.com/9-1/system/authentication/authentication-tutorials/sign-in-using-twitter/</guid><description>Covers creating a Twitter developer app, saving the API key and secret, configuring OAuth 2.0 callback URLs, and entering the ConsumerKey and ConsumerSecret under Configuration &amp;gt; System Settings &amp;gt; Sign-In Integrations to activate Twitter login.</description></item></channel></rss>