Security (PRO)
Limit How Many Times a Magic Link Can Be Used
A Magic Link is single use by default, which is the right behaviour for a login emailed to one person. When you need a link that works a set number of times, Magic Link gives you two controls: the free Token Validity setting fixes a site-wide usage count for every link, and Magic Link PRO adds a per-link Usage Limit you set when you create a link, including unlimited use for a kiosk or shared device.
Set a site-wide usage count (Free)
Token Validity decides how many times each Magic Link can be redeemed across your whole site. It ships set to 1, so the first person to open a link is logged in and the link is spent.
- Go to
Magic Link → Settings → General. - Find Token Validity.
- Enter the number of times a link may be used.
- Save the settings.
This value applies to every link the plugin issues, so raise it only if you want all of your Magic Links to work more than once.
Set a limit on a single link (PRO)
PRO feature
Per-link Usage Limit is available in Magic Link PRO. In the free version, usage is governed only by the site-wide Token Validity setting above.
When you need one link to behave differently from the rest, set its Usage Limit at the moment you create it:
- Go to
Magic Link → Magic Links. - Open the Create Magic Link form and choose the user.
- Set the token lifespan as usual.
- In Usage Limit, enter how many times this link may be used. Enter
0for a link that never runs out. - Generate the link.
The Usage Limit field only appears when Magic Link PRO is active.
What the numbers mean
| Value | Behaviour |
|---|---|
1 |
Single use. The link is spent the first time it is opened. This is the default. |
3 |
Works three times, then stops. |
0 |
Unlimited. Works until the link expires. |
A link is marked as used only once its allowance is gone. A link with a limit of 3 that has been opened twice still shows as active, because it still works.
When a multi-use link helps
Not every link is sent to a single person. A per-link limit lets you cover these cases without generating and tracking several links:
- Shared access for a small group. Give three reviewers one link and set the limit to
3. - A link that survives an email client. Some corporate mail systems and security scanners open links before the recipient does. A limit of
2leaves a working link for the real person even if something touched it first. - A standing link for a kiosk or shared device. Set
0and the same link keeps working until it expires.
Expiry still applies
The usage limit and the expiry time are separate, and whichever runs out first wins. A link with a limit of 0 and a lifespan of 15 minutes still stops working after 15 minutes. For a link that lasts, give it both a high limit and a long lifespan. See Set Magic Link expiry.
Use unlimited links carefully
A link set to 0 is a working key to that account for as long as it is valid, and anyone who has the URL can use it as many times as they like. Before you create one:
- Keep the lifespan short. An unlimited link that expires in an hour is a very different risk from one that lasts a month.
- Avoid sending unlimited links by email — email is forwarded, archived, and scanned.
- Use them for low-privilege accounts, not administrators.
- Revoke the link as soon as the job is done rather than waiting for it to expire. See Manage Magic Links.
Conclusion
Use the free Token Validity setting to change the usage count for every Magic Link, or Magic Link PRO's per-link Usage Limit when one link needs to behave differently. Pair a usage limit with a short lifespan to keep multi-use links safe, and revoke them once the work is done. Next, learn how to create a Magic Link for a user.
FAQs
Is a Magic Link single use by default?
Yes. The free Token Validity setting at Magic Link → Settings → General ships set to 1, so every link is spent the first time it is opened. Raise Token Validity to allow all links to be reused, or use the PRO per-link Usage Limit to change the count for one link at a time.
How do I make a Magic Link work more than once?
For all links, set Token Validity to a higher number under Magic Link → Settings → General. For a single link, use Magic Link PRO: open the Create Magic Link form at Magic Link → Magic Links and set Usage Limit to the number of allowed uses.
Can a Magic Link be used an unlimited number of times?
Yes, with Magic Link PRO. Set the link's Usage Limit to 0 when you create it and it works until it expires. Treat unlimited links as a working key to the account: keep the lifespan short, avoid emailing them, and revoke them once you are done.
Is per-link Usage Limit free or PRO?
The site-wide Token Validity count is free. Setting a Usage Limit on an individual link when you create it requires Magic Link PRO. Without PRO, the Usage Limit field does not appear and every link follows the Token Validity value.
Does the usage limit override the expiry time?
No. The usage limit and the expiry time work independently, and whichever runs out first wins. A link with unlimited uses still stops working once its lifespan ends, and a link with uses remaining still stops working once it expires.