Support PIN For WHMCS
| Line 59: | Line 59: | ||
{| | {| | ||
|style="padding: 0px 0px 0px 45px;"|✔ Set PIN Expiration Time, In Hours | |style="padding: 0px 0px 0px 45px;"|✔ Set PIN Expiration Time, In Hours | ||
| − | |||
| − | |||
| − | |||
| − | |||
|} | |} | ||
| Line 70: | Line 66: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 0px 45px;"|✔ Expire A PIN Automatically | + | |style="padding: 0px 0px 0px 45px;"|✔ Expire A PIN Automatically After A Configurable Number Of Uses (0 = Unlimited) |
|} | |} | ||
| Line 90: | Line 86: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 0px 30px | + | |style="padding: 0px 0px 0px 30px;"|✔ Enable Or Disable The Generate PIN Button |
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 0px 30px;"|✔ One-Time PIN Reveal With A Copy-To-Clipboard Button | + | |style="padding: 0px 0px 0px 30px;"|✔ One-Time PIN Reveal With A Copy-To-Clipboard Button, And A Live Countdown To Expiry In The Client Area Sidebar |
|} | |} | ||
| Line 147: | Line 127: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 20px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_1.png | + | |style="padding: 0px 0px 20px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_1.png</div> |
|} | |} | ||
| Line 155: | Line 135: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 20px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_2.png | + | |style="padding: 0px 0px 20px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_2.png</div> |
|} | |} | ||
| Line 164: | Line 144: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_3.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_3.png</div> |
|} | |} | ||
| Line 177: | Line 157: | ||
|style="padding: 10px 0px 15px 15px;"|The dashboard gives an at-a-glance read on PIN volume through four counters: | |style="padding: 10px 0px 15px 15px;"|The dashboard gives an at-a-glance read on PIN volume through four counters: | ||
| − | *'''Active''' - PINs currently valid and not yet used. | + | *'''Active''' - PINs currently valid and not yet used up. |
| − | *'''Used''' - PINs that have | + | *'''Used''' - PINs that have reached their configured verification limit. |
*'''Expired''' - PINs past their expiration time. | *'''Expired''' - PINs past their expiration time. | ||
| Line 188: | Line 168: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_4.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_4.png</div> |
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 15px 15px;"|Below the counters sits a standalone '' 'Verify Support PIN' '' field. Enter a PIN a client has given you and press '' 'Verify PIN' '' to confirm it | + | |style="padding: 0px 0px 15px 15px;"|Below the counters sits a standalone '' 'Verify Support PIN' '' field. Enter a PIN a client has given you and press '' 'Verify PIN' '' to confirm it - this does not consume the PIN's use count, it only reports a match or no-match. |
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_5.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_5.png</div> |
|} | |} | ||
| Line 218: | Line 198: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_6.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_6.png</div> |
|} | |} | ||
| Line 225: | Line 205: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_7.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_7.png</div> |
|} | |} | ||
| Line 240: | Line 220: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_8.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_8.png</div> |
|} | |} | ||
===PIN Lifecycle=== | ===PIN Lifecycle=== | ||
{| | {| | ||
| − | |style="padding: 10px 0px 15px 15px;"|*''' | + | |style="padding: 10px 0px 15px 15px;"|*'''Allow Multiple Active PINs''' - off by default, which makes a PIN single-use: generating a new one deactivates any previous active PIN. Turned on, a PIN can be verified more than once and several can be active for a client at the same time. |
| − | *''' | + | *'''Expire PIN After X Uses''' - marks a PIN used/expired after this many successful verifications. The default, '''1''', makes every PIN single-use regardless of the toggle above; '''0''' removes the cap entirely. This setting and "Allow Multiple Active PINs" are independent - the toggle controls whether a new PIN revokes an older one, this field controls how many times any one PIN can be verified before it's spent. |
| − | + | ||
| − | + | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_9.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_9.png</div> |
|} | |} | ||
| Line 264: | Line 242: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_10.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_10.png</div> |
|} | |} | ||
===Client Area=== | ===Client Area=== | ||
{| | {| | ||
| − | |style="padding: 10px 0px 15px 15px;"|*'''Enable Generate PIN Button''' - shows or hides the '' 'Generate Support PIN' '' button in the client area. | + | |style="padding: 10px 0px 15px 15px;"|*'''Enable Generate PIN Button''' - shows or hides the '' 'Generate Support PIN' '' button in the client area. When disabled, clients cannot generate new PINs themselves. |
| − | + | ||
| − | + | ||
| − | + | ||
| − | + | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_11.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_11.png</div> |
|} | |} | ||
==Home Widget== | ==Home Widget== | ||
{| | {| | ||
| − | |style="padding: 10px 0px 15px 15px;"|A compact '' 'Verify Support PIN' '' panel is added to the standard WHMCS admin home dashboard, next to the built-in widgets staff already check every day | + | |style="padding: 10px 0px 15px 15px;"|A compact '' 'Verify Support PIN' '' panel is added to the standard WHMCS admin home dashboard, next to the built-in widgets staff already check every day. Entering a matching PIN here redirects straight to that client's profile - unlike the Client Summary verify field, this path does not consume the PIN's use count. |
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_12.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_12.png</div> |
|} | |} | ||
==Client Summary Integration== | ==Client Summary Integration== | ||
{| | {| | ||
| − | |style="padding: 10px 0px 15px 15px;"|On a client's own '' 'Summary' '' tab, a '' 'Support PIN' '' panel shows that client's current PIN status, when it was created, | + | |style="padding: 10px 0px 15px 15px;"|On a client's own '' 'Summary' '' tab, a '' 'Support PIN' '' panel shows that client's current PIN status, when it was created, when it expires, and when (if ever) it was used. |
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_13.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_13.png</div> |
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 15px 15px;"| | + | |style="padding: 0px 0px 15px 15px;"|While a PIN is Active, the same panel also shows a '' 'Verify PIN' '' field, so the code the client just gave can be checked right there, without leaving the client's profile. Unlike the Home Widget verify field, a successful verification here does count against the PIN's use limit. |
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_14.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_14.png</div> |
|} | |} | ||
| Line 307: | Line 281: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_15.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_15.png</div> |
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 15px 15px;"|Generating a PIN replaces any PIN already in use, so the client is asked to confirm first | + | |style="padding: 0px 0px 15px 15px;"|Generating a PIN replaces any PIN already in use, so the client is asked to confirm first. |
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_16.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_16.png</div> |
|} | |} | ||
| Line 321: | Line 295: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_17.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_17.png</div> |
|} | |} | ||
| Line 328: | Line 302: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 30px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_18.png | + | |style="padding: 0px 0px 30px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_18.png</div> |
|} | |} | ||
| Line 337: | Line 311: | ||
|} | |} | ||
{| | {| | ||
| − | |style="padding: 0px 0px 20px 25px;"|https://docs.modulesgarden.com/images/modules/supportpin/SP_19.png | + | |style="padding: 0px 0px 20px 25px;"|<div class="image">https://docs.modulesgarden.com/images/modules/supportpin/SP_19.png</div> |
|} | |} | ||
=Tips= | =Tips= | ||
{| | {| | ||
| − | |style="padding: 10px 0px 15px 15px;"|1. '''Keep "Hide Full PIN" enabled in production.''' Staff only ever need to verify a PIN a client reads aloud, not to read it back themselves. | + | |style="padding: 10px 0px 15px 15px;"|1. '''Keep "Hide Full PIN" enabled in production.''' Staff only ever need to verify a PIN a client reads aloud, not to read it back themselves - the value is a one-way hash regardless and can never actually be redisplayed. |
|} | |} | ||
{| | {| | ||
| − | |style="padding: 10px 0px | + | |style="padding: 10px 0px 15px 15px;"|2. '''Turn on "Require PIN Verification For Client Access" for the strictest workflow.''' Combined with "Deny Admin Access After PIN Expiration", staff will need to re-verify the client for every new support interaction. |
| + | |} | ||
| + | {| | ||
| + | |style="padding: 10px 0px 30px 15px;"|3. '''Leave "Expire PIN After X Uses" at its default of 1''' unless you have a specific reason for letting a PIN be checked more than once - it's what makes each PIN effectively single-use out of the box. | ||
|} | |} | ||
| Line 357: | Line 334: | ||
{| | {| | ||
|style="padding: 10px 0px 15px 15px;"|'''1. A client cannot see the "Generate Support PIN" button in the client area.'''<br/> | |style="padding: 10px 0px 15px 15px;"|'''1. A client cannot see the "Generate Support PIN" button in the client area.'''<br/> | ||
| − | Check '' 'Settings' '' → '' 'Client Area' '' → '' 'Enable Generate PIN Button' '' is turned on | + | Check '' 'Settings' '' → '' 'Client Area' '' → '' 'Enable Generate PIN Button' '' is turned on. |
|} | |} | ||
{| | {| | ||
| − | |style="padding: 10px 0px | + | |style="padding: 10px 0px 15px 15px;"|'''2. Staff are locked out of a client's data unexpectedly.'''<br/> |
This happens when '' 'Require PIN Verification For Client Access' '' is enabled and the previously verified PIN has expired. Ask the client to read out their current PIN again, or generate a new one, and verify it from the Client Summary panel or the module's Dashboard. | This happens when '' 'Require PIN Verification For Client Access' '' is enabled and the previously verified PIN has expired. Ask the client to read out their current PIN again, or generate a new one, and verify it from the Client Summary panel or the module's Dashboard. | ||
| + | |} | ||
| + | {| | ||
| + | |style="padding: 10px 0px 30px 15px;"|'''3. A PIN stops working after being checked once, even though it hasn't expired.'''<br/> | ||
| + | This is expected with the default policy: '' 'Expire PIN After X Uses' '' is '''1''' out of the box, so a PIN is spent after its first successful verification. Raise that value (or set it to '''0''' for no limit) in '' 'Settings' '' → '' 'PIN Lifecycle' '' if clients need to be verified more than once per PIN. | ||
|} | |} | ||
Revision as of 13:32, 22 July 2026
Contents |
About Support PIN For WHMCS
| Support PIN For WHMCS closes a simple but common support gap: confirming that a client contacting support is really the account owner. The module gives every client a short, one-time-visible PIN they can read aloud, and gives staff a matching set of tools to check it, or to identify a client from the PIN alone, without ever seeing the PIN in reverse. PINs are stored as a one-way digest and are never recoverable, even from the database. |
- Addon Module Features:
| ✔ Generate A Short-Lived Support PIN From The Client Area |
| ✔ Verify A Support PIN To Identify The Calling Client: |
| ✔ From The Module's Own Dashboard |
| ✔ From A Widget On The WHMCS Admin Home Dashboard |
| ✔ From A Panel Embedded Directly On The Client Summary Page |
| ✔ View Dashboard With PIN Status Counters: |
| ✔ Active / Used / Expired / Revoked, Each Filterable With One Click |
| ✔ Manage All Issued PINs In A Single Table: |
| ✔ Revoke A Single PIN |
| ✔ Revoke Multiple PINs With A Mass Action |
| ✔ Configure PIN Policy: |
| ✔ Set PIN Length |
| ✔ Set PIN Expiration Time, In Hours |
| ✔ Allow Or Block Multiple Active PINs Per Client |
| ✔ Expire A PIN Automatically After A Configurable Number Of Uses (0 = Unlimited) |
| ✔ Control Staff Access: |
| ✔ Require PIN Verification Before Staff Can Open Client Data |
| ✔ Deny Admin Access Again Once The Verified PIN Expires |
| ✔ Hide The Full PIN Value In The Admin UI |
| ✔ Enable Or Disable The Generate PIN Button |
| ✔ One-Time PIN Reveal With A Copy-To-Clipboard Button, And A Live Countdown To Expiry In The Client Area Sidebar |
| ✔ Confirmation Step Before Generating A New PIN |
| ✔ View And Manage Module Logs |
- General Info:
| ✔ PINs Are Stored As A One-Way Digest And Are Never Recoverable, Even From The Database |
| ✔ Multi-Language Support With Custom Translations Tool |
| ✔ Requires PHP 8.1 Or Later |
Installation
| This tutorial will show you how to successfully install and configure Support PIN For WHMCS. We will guide you step by step through the whole installation and configuration process. |
| 1. Extract the package and upload its content into the main WHMCS directory, then log in to your WHMCS admin area. Go to 'System Settings' → 'Addon Modules'. Find 'Support PIN' in the list and press the 'Activate' button. |
![]() |
| 2. In the next step, you need to permit access to this module. To do so, click on the 'Configure' button, tick 'Full Administrator' and press 'Save Changes'. |
![]() |
| 3. You have just successfully installed Support PIN! You can access your module under 'Addons' → 'Support PIN'. |
![]() |
Management
| Support PIN For WHMCS lets clients generate a short-lived verification PIN, and gives your staff several places to check it against a client's claim. In this guide, we will walk you through every section and option of the module in detail. |
Dashboard
The dashboard gives an at-a-glance read on PIN volume through four counters:
Each counter has its own 'Show' button, which filters the table below to just that status. |
![]() |
| Below the counters sits a standalone 'Verify Support PIN' field. Enter a PIN a client has given you and press 'Verify PIN' to confirm it - this does not consume the PIN's use count, it only reports a match or no-match. |
![]() |
Underneath, the full table of issued PINs lists, per PIN:
Use the trash icon on a row to 'Revoke PIN' on that single entry. |
![]() |
| To revoke several PINs at once, tick the checkboxes of the rows you want to remove, open the mass action menu above the table, and choose 'Revoke PIN'. |
![]() |
Settings
| The 'Settings' tab groups every PIN policy option into four panels. |
PIN Settings
*PIN Length - the number of digits generated for each new PIN.
|
![]() |
PIN Lifecycle
*Allow Multiple Active PINs - off by default, which makes a PIN single-use: generating a new one deactivates any previous active PIN. Turned on, a PIN can be verified more than once and several can be active for a client at the same time.
|
![]() |
Staff Access
*Require PIN Verification For Client Access - if enabled, staff must verify a client's Support PIN before that client's data can be opened at all.
|
![]() |
Client Area
| *Enable Generate PIN Button - shows or hides the 'Generate Support PIN' button in the client area. When disabled, clients cannot generate new PINs themselves. |
![]() |
Home Widget
| A compact 'Verify Support PIN' panel is added to the standard WHMCS admin home dashboard, next to the built-in widgets staff already check every day. Entering a matching PIN here redirects straight to that client's profile - unlike the Client Summary verify field, this path does not consume the PIN's use count. |
![]() |
Client Summary Integration
| On a client's own 'Summary' tab, a 'Support PIN' panel shows that client's current PIN status, when it was created, when it expires, and when (if ever) it was used. |
![]() |
| While a PIN is Active, the same panel also shows a 'Verify PIN' field, so the code the client just gave can be checked right there, without leaving the client's profile. Unlike the Home Widget verify field, a successful verification here does count against the PIN's use limit. |
![]() |
Client Area
| A 'Support PIN' panel is added to the client area sidebar on every page. With no PIN active, it shows a single 'Generate Support PIN' button. |
![]() |
| Generating a PIN replaces any PIN already in use, so the client is asked to confirm first. |
![]() |
| Once confirmed, the client sees the new PIN, its expiry timestamp, and a copy-to-clipboard button, with a reminder to copy it now while it's readable. |
![]() |
| Back in the sidebar, the panel now shows the PIN itself with a live countdown to expiry, a 'Hide pin' toggle for privacy on a shared screen, and the option to generate a fresh one at any time. |
![]() |
Logs
| The "Logs" tool makes monitoring and managing module activity records simple and efficient. It provides options to categorize, filter, and view detailed entries, giving you control over the logs. For detailed guidance on using this tool, check its dedicated article, which is available here. |
![]() |
Tips
| 1. Keep "Hide Full PIN" enabled in production. Staff only ever need to verify a PIN a client reads aloud, not to read it back themselves - the value is a one-way hash regardless and can never actually be redisplayed. |
| 2. Turn on "Require PIN Verification For Client Access" for the strictest workflow. Combined with "Deny Admin Access After PIN Expiration", staff will need to re-verify the client for every new support interaction. |
| 3. Leave "Expire PIN After X Uses" at its default of 1 unless you have a specific reason for letting a PIN be checked more than once - it's what makes each PIN effectively single-use out of the box. |
Update Instructions
| An essential guidance through the process of updating the module is offered here. Ensure successful completion of the module update by carefully following each step, thereby preventing data loss or any unforeseen issues. |
Common Problems
| 1. A client cannot see the "Generate Support PIN" button in the client area. Check 'Settings' → 'Client Area' → 'Enable Generate PIN Button' is turned on. |
| 2. Staff are locked out of a client's data unexpectedly. This happens when 'Require PIN Verification For Client Access' is enabled and the previously verified PIN has expired. Ask the client to read out their current PIN again, or generate a new one, and verify it from the Client Summary panel or the module's Dashboard. |
| 3. A PIN stops working after being checked once, even though it hasn't expired. This is expected with the default policy: 'Expire PIN After X Uses' is 1 out of the box, so a PIN is spent after its first successful verification. Raise that value (or set it to 0 for no limit) in 'Settings' → 'PIN Lifecycle' if clients need to be verified more than once per PIN. |


















