Title: Keyless Login
Author: susheelhbti
Published: <strong>2026-يىلى 20-ماي</strong>
Last modified: 2026-يىلى 20-ماي

---

قىستۇرما ئىزدە

![](https://s.w.org/plugins/geopattern-icon/keyless-login.svg)

# Keyless Login

 يازغۇچى [susheelhbti](https://profiles.wordpress.org/susheelhbti/)

[چۈشۈر](https://downloads.wordpress.org/plugin/keyless-login.zip)

 * [تەپسىلاتلار](https://ug.wordpress.org/plugins/keyless-login/#description)
 * [باھالاشلار](https://ug.wordpress.org/plugins/keyless-login/#reviews)
 *  [ئورنىتىش](https://ug.wordpress.org/plugins/keyless-login/#installation)
 * [ئىجادىيەت](https://ug.wordpress.org/plugins/keyless-login/#developers)

 [قوللاش](https://wordpress.org/support/plugin/keyless-login/)

## چۈشەندۈرۈش

**Keyless Login** brings modern, phishing-resistant authentication to your WordPress
site.

Log in with your fingerprint, face, or a hardware security key — no password ever
required or transmitted. Implemented entirely in pure PHP using only the built-in`
openssl` extension. No Composer, no vendor folder, no third-party libraries.

#### How It Works

KeylessWP implements the [W3C WebAuthn Level 2](https://www.w3.org/TR/webauthn-2/)
specification from scratch:

 * A custom CBOR decoder parses authenticator data
 * Custom ASN.1/DER builders construct public keys
 * PHP’s built-in `openssl_verify()` verifies ECDSA P-256 (ES256) and RSA-2048 (
   RS256) signatures
 * Credentials are stored in a dedicated database table with sign-count clone detection

#### Supported Authentication Methods

 * 🖐 Fingerprint sensors (Touch ID, Windows Hello)
 * 😊 Face recognition (Face ID, Windows Hello face camera)
 * 🔑 Hardware security keys (YubiKey, Google Titan Key, Feitian)
 * 🔐 Platform passkey managers (iCloud Keychain, Google Password Manager)

#### Features

 * Full FIDO2 / WebAuthn Level 2 implementation — pure PHP
 * ECDSA P-256 (ES256) and RSA-2048 (RS256) signature verification
 * Zero external libraries — only PHP’s built-in `openssl` extension required
 * Passkey registration and management from the user profile page
 * Per-credential device naming, creation date, and last-used tracking
 * Sign-count verification on every authentication (clone detection)
 * Phishing-resistant: credentials are cryptographically bound to your domain
 * Admin settings page with live usage statistics
 * Graceful fallback: the standard password form remains available
 * Translatable — all strings use `__()` with the `keylesswp` text domain

#### Privacy

KeylessWP does not collect, transmit, or share any user data. No external services
are contacted. Biometric data never leaves the user’s device — only a cryptographic
public key is stored on the server.

## ئورنىتىش

 1. Upload the `keylesswp` folder to `/wp-content/plugins/`
 2. Activate the plugin via **Plugins  Installed Plugins**
 3. Go to **Users  Your Profile** and click **Register New Passkey**
 4. Follow your device’s biometric or security-key prompt
 5. Log out and click **Sign in with Passkey** on the login page

#### Requirements

 * PHP 8.0 or higher
 * PHP `openssl` extension (enabled by default on virtually all hosts)
 * HTTPS — required by the WebAuthn browser API
 * WordPress 6.4 or higher

## FAQ

### Does this plugin require any external library or Composer?

No. Everything — CBOR decoding, ASN.1/DER key building, ECDSA and RSA verification—
is implemented in pure PHP using only the `openssl` extension that ships with PHP.

### Does this work without HTTPS?

No. The WebAuthn browser API will refuse to run on non-secure origins. All modern
WordPress hosting provides HTTPS.

### Can users still log in with their password?

Yes. By default, the standard password form remains visible alongside the passkey
button. You can change this under **Settings  Keyless Login**.

### What data is stored on the server?

Only the credential ID, public key (PEM format), sign count, device name, and timestamps.
Biometric data is processed entirely on the user’s device and never transmitted.

### Is this compatible with multisite?

Single-site support is the focus of v1.0. Multisite compatibility is planned for
v1.1.

### Privacy Policy

This plugin does not send any data to external servers. No tracking, no analytics,
no third-party services are used. On uninstall, all plugin data is deleted from 
the database.

## باھالاشلار

بۇ قىستۇرمىغا تېخى باھا يېزىلمىدى.

## تۆھپىكار ۋە ئىجادكار

«Keyless Login» كودى ئوچۇق يۇمشاق دېتال. تۆۋەندىكى كىشىلەر بۇ قىستۇرمىغا تۆھپە قوشقان.

تۆھپىكار

 *   [ susheelhbti ](https://profiles.wordpress.org/susheelhbti/)

[«Keyless Login» نى تىلىڭىزغا تەرجىمە قىلىڭ](https://translate.wordpress.org/projects/wp-plugins/keyless-login)

### ئىجادىيەتكە قىزىقامسىز؟

[كودقا كۆز يۈگۈرتۈپ](https://plugins.trac.wordpress.org/browser/keyless-login/)،
[SVN خەزىنە](https://plugins.svn.wordpress.org/keyless-login/) تەكشۈرۈپ ياكى [RSS](https://plugins.trac.wordpress.org/log/keyless-login/?limit=100&mode=stop_on_copy&format=rss)
ئارقىلىق [ئىجادىيەت خاتىرىسى](https://plugins.trac.wordpress.org/log/keyless-login/)
گە مۇشتەرى بولغىلى بولىدۇ.

## ئۆزگىرىش خاتىرىسى

#### 1.0.0

 * Initial release
 * Pure PHP CBOR decoder (RFC 7049)
 * Pure PHP WebAuthn attestation and assertion verifier
 * ES256 (ECDSA P-256) and RS256 (RSA-2048) support
 * Custom DB table with sign-count clone detection
 * Complete registration and authentication flows
 * Admin settings page with usage statistics
 * Full i18n support with `keylesswp` text domain

## Meta

 *  Version **1.0.0**
 *  ئاخىرقى يېڭىلانغان ۋاقىت **2 ئاي بۇرۇن**
 *  ئاكتىپ ئورنىتىش سانى **10 دىن ئاز**
 *  WordPress نەشرى ** 6.4 ياكى يۇقىرى **
 *  **6.9.5** دا سىنالغان
 *  PHP نەشرى ** 8.0 ياكى يۇقىرى **
 *  تىل
 * [English (US)](https://wordpress.org/plugins/keyless-login/)
 * بەلگە
 * [fido2](https://ug.wordpress.org/plugins/tags/fido2/)[passkey](https://ug.wordpress.org/plugins/tags/passkey/)
   [passwordless](https://ug.wordpress.org/plugins/tags/passwordless/)[security](https://ug.wordpress.org/plugins/tags/security/)
   [webauthn](https://ug.wordpress.org/plugins/tags/webauthn/)
 *  [ئالىي كۆرۈنۈش](https://ug.wordpress.org/plugins/keyless-login/advanced/)

## دەرىجە

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/keyless-login/reviews/#new-post)

[بارلىق ئىنكاسنى كۆرسەت](https://wordpress.org/support/plugin/keyless-login/reviews/)

## تۆھپىكار

 *   [ susheelhbti ](https://profiles.wordpress.org/susheelhbti/)

## قوللاش

چۈشەندۈرۈشىڭىز بارمۇ؟ ياردەم لازىممۇ؟

 [قوللاش مۇنبىرىنى كۆرسەت](https://wordpress.org/support/plugin/keyless-login/)