Everyday Use
Control How Long Login Links Stay Active
Need login links to expire quickly for security, or last longer so users have time to open them? Magic Link controls this with two free settings under Magic Link → Settings → General: Token Lifespan sets how long a link stays valid, and Token Validity sets how many times it can be used. Once the lifespan ends or the link hits its usage limit, it stops working and the user requests a new one.
By default a Magic Link lasts 5 minutes and works once (single-use). You can raise or lower both values to match the balance of convenience and security your site needs.
What Each Setting Does
- Token Lifespan — how long a link stays valid, entered as a number plus a unit (Minutes, Hours, or Days). The default is 5 minutes, and the lifespan can range from 1 to 1440 minutes (up to 24 hours) when measured in minutes.
- Token Validity — how many times a single link can be used before it stops working. The default is 1, meaning each link is single-use.
Why Expiry Matters
Expiry settings let you balance convenience against security:
- Shorter lifespans tighten control over access and reduce the window in which a leaked link could be used.
- Longer lifespans give users extra time to find the email and finish logging in.
- Single-use validity (the default) ensures each link works exactly once, so a forwarded or intercepted link cannot be reused.
How to Configure Expiry
- Go to Magic Link → Settings → General in the WordPress admin.
- Set Token Lifespan — enter a number, then choose Minutes, Hours, or Days.
- Set Token Validity — enter how many times a link may be used (default: 1).
- Click Save Changes.

Expiry Settings Reference
| Setting | What it controls | Default | Options |
|---|---|---|---|
| Token Lifespan | How long a link stays valid | 5 minutes | Number + unit (Minutes / Hours / Days); 1–1440 minutes |
| Token Validity | How many times a link can be used | 1 | Any whole number of uses |
Conclusion
Token Lifespan and Token Validity give you free, precise control over how long Magic Links last and how many times they work, letting you tune the trade-off between user convenience and account security. Next, decide where users land after signing in with redirect after Magic Link login, or make passwordless the default with Force Magic Link Login.
FAQs
How long does a Magic Link last by default?
By default a Magic Link lasts 5 minutes and can be used once. You can change the duration with Token Lifespan under Magic Link → Settings → General, entering a number and choosing Minutes, Hours, or Days. When the lifespan runs out, the link stops working and the user must request a new one.
Can a Magic Link be used more than once?
Yes, if you raise Token Validity above its default of 1. Token Validity sets how many times a single link can be used before it stops working. Leaving it at 1 keeps links single-use, which is the most secure option because a forwarded or intercepted link cannot be reused.
What is the maximum Magic Link expiry time?
When set in minutes, Token Lifespan accepts a value from 1 to 1440 minutes, which is up to 24 hours. You can also express longer durations by choosing the Hours or Days unit. Shorter lifespans are more secure; longer ones give users more time to open the email.
Are expiry settings available in the free version?
Yes. Both Token Lifespan and Token Validity are free and live under Magic Link → Settings → General. You do not need Magic Link PRO to control how long links stay valid or how many times they can be used.
What happens when a Magic Link expires?
Once a link passes its Token Lifespan or reaches its Token Validity usage limit, it no longer logs anyone in. The user simply requests a new link from the login form or is issued a fresh one, and the expired link becomes inactive.