Back to Blog
Email Verification Sep 03, 2026

Setting Up OTP Login Authentication for WooCommerce with CEV PRO

Yash Patel

Yash Patel

Administrator

Setting Up OTP Login Authentication for WooCommerce with CEV PRO

Most of your customers reuse passwords. When one of those passwords leaks from another site, the first thing an attacker does is try it on stores that hold saved addresses, order history, and stored payment tokens. Your login page becomes the weak point, and a password alone is no longer proof that the right person is signing in.

It doesn’t have to work that way.

CEV PRO – Customer Email Verification for WooCommerce adds a one-time code (OTP) step to WooCommerce logins. You choose when the code is required: on every sign-in, only when a login looks unfamiliar, or only when a risk score says it’s worth interrupting the customer. The code goes to the email address on the account, so a stolen password on its own gets nobody in.

This guide walks through configuring OTP login authentication in CEV PRO, from the master switch to the challenge policy, the email customer receives, and how to test it.

How to set up OTP login authentication in CEV PRO

1. Install CEV PRO and open the settings
Upload and activate the plugin, then go to WooCommerce → Email Verification → Settings. The settings page is split into sections: Signup Verification, Checkout Verification, General, Login Authentication, Two-Factor Authentication, Spam Protection, and Advanced.

2. Set the OTP length, expiry, and resend limit
Open the General section first. Choose a 4-digit or 6-digit code (6 is harder to guess, 4 is quicker to type on a phone), then set an expiration anywhere from 10 minutes to 72 hours, or leave it to never expire. Set a resend limit of 1 or 3 attempts so nobody can flood a customer’s inbox by hammering the resend button.

3. Turn on Login Authentication
Open the Login Authentication section and enable the master switch. With this on, returning customers can be asked for a one-time code at login. Administrators, editors, and shop managers are never prompted, so your team’s workflow doesn’t change.

4. Decide when to challenge: every login or unrecognized logins only
For the strictest policy, turn on Require OTP on every login. Every customer enters a code every time, regardless of device or location. For a lighter touch, leave that off and use Require OTP verification for unrecognized login, which only sends a code when a sign-in matches one of the conditions below it.

5. Tune the unrecognized login conditions
Three conditions decide what counts as unfamiliar: login from a new device (a browser not seen before), login from a new location (a new IP address), and last login more than 15, 30, or 60 days ago. All three are on by default. If your customers travel a lot or shop from several devices, consider switching off the location rule and keeping the other two.

6. Or let Smart suspicious-login detection decide
Instead of fixed conditions, enable Smart suspicious-login detection. CEV PRO scores each sign-in using new device, new country, a burst of failed password attempts, and long idle periods, and only asks for a code when the score crosses a threshold. Pick a sensitivity: Low challenges only clearly risky sign-ins, Balanced is the recommended middle, and Strict reacts to weaker signals.

7. Customise the login OTP email and popup
Open the Email Customizer and edit the login authentication email subject, heading, and content. You can drop in placeholders such as {login_otp}, {login_device}, {login_browser}, {login_ip}, and {login_time} so the customer sees exactly which sign-in triggered the code. The popup styling (accent colour, border radius, font, overlay opacity) is shared across all CEV PRO verification screens, so the login prompt matches your registration and checkout popups.

8. Test with a customer account
Log in as a real customer role from a private browser window. Staff roles are exempt, so testing with your admin account will show nothing. You should see the popup, receive the email, and get through with the code. Try the resend button and let a code expire to confirm your limits behave the way you expect.

Which login policy fits your store

PolicyBest for
OTP on every loginHigh-value accounts, B2B portals, stores with saved payment methods
Unrecognized login conditionsMost stores, predictable rules you can explain to support
Smart suspicious-login detectionStores with mobile-heavy or travelling customers who hate extra steps
Authenticator app 2FA (separate section)Customers who want to opt in to app-based codes with recovery codes

The last row is worth a note. Two-Factor Authentication lives in its own settings section and uses authenticator apps rather than email codes. It can be scoped by user role, remembers a trusted device for up to 30 days, and is opt-in for the customer. You can run it alongside login OTP, or on its own.

Conclusion

A password alone is a weak lock on an account that holds addresses and order history. CEV PRO puts a one-time code between a leaked password and your customer’s account, and lets you decide how often that code is required so security doesn’t turn into friction. Set the policy once, customise the email, and the login page stops being your store’s soft spot.

🔒 Ready to secure your WooCommerce customer logins?

One-time codes at login, sent only when you decide they’re needed, with no extra step for your staff.

14-Day Money-Back Guarantee. HPOS Compatible. Blocks Checkout Ready. Priority Support.