Find your situation in the table, then follow the steps below it. None of these needs FTP access to the plugin files or a support ticket; the wp-config.php and WP-CLI routes need access to your server (file manager, SFTP or SSH).
| Situation | Fastest way back in |
|---|
| You forgot the login address | Search your email for “Your login address”, run wp authlify url get, or add AUTHLIFY_DISABLE_HIDE to wp-config.php. |
| “Too many failed login attempts” | Wait for the time shown, use “Is this your account? Email me an unlock link.”, ask another administrator, or run wp authlify unlock --all. |
| “Access from your network is blocked” | Your address is on the Always block list. Another administrator removes it, or you empty the list with WP-CLI. |
| The CAPTCHA will not let you through | Add AUTHLIFY_DISABLE_CAPTCHA to wp-config.php. |
| You lost your phone and backup codes | Use the recovery email link on the two-factor step, ask another administrator to reset you, run wp authlify reset_2fa, or add AUTHLIFY_DISABLE_2FA to wp-config.php. |
| The new login address shows “page not found” | See The login address shows “page not found”. |
| A Pro country, hours or honeypot rule blocks you | Add AUTHLIFY_PRO_DISABLE_RULES to wp-config.php (Authlify Pro). |
1. You forgot the login address
- Check your email. Every time the address changes, Authlify emails it to the site admin address (Settings → General) and to the person who changed it. The subject is “[Your site name] Your login address”. While you are still logged in somewhere, Authlify → Login URL → If you ever lose the login URL → Email it to me now sends it again.
- WP-CLI. Print the address:
wp authlify url get
If it prints wp-login.php followed by “(custom login URL is off)”, no custom address is set. - wp-config.php. Open wp-config.php in the root of your WordPress installation and add this line above the line that says “That’s all, stop editing!”:
define( 'AUTHLIFY_DISABLE_HIDE', true );
The custom address is switched off at once and /wp-login.php works again. Log in there, check or change the address under Authlify → Login URL, then remove the line.
If wp-config.php contains define( 'AUTHLIFY_SLUG', '…' );, that value is the login address. While AUTHLIFY_SLUG is set, the Login URL field is locked. If both constants are set, AUTHLIFY_DISABLE_HIDE wins.
2. Turn the custom address off from the command line
wp authlify url reset
This switches the custom address off (and cancels any unconfirmed change), so you log in at wp-login.php. It refuses to run while AUTHLIFY_SLUG is defined; remove that line instead. To set a known address directly, without the confirmation step:
wp authlify url set my-private-door
set refuses to run while AUTHLIFY_SLUG or AUTHLIFY_DISABLE_HIDE is defined, and applies the same rules as the Login URL screen (length, characters, reserved words, existing pages).
3. Locked out after wrong passwords
- Wait. The message says how long. The first lockout lasts 15 minutes by default; repeat lockouts last longer.
- Email yourself an unlock link. Click “Is this your account? Email me an unlock link.” under the lockout message and enter your username or email address. The link goes to the account’s own email address, works for 30 minutes, and lets that one account log in from the same device and address; the lockout for everyone else stays. At most 3 requests per hour per account and address (10 per hour per address in total). Nothing is sent when nothing is locked, or when the account does not exist.
- Ask another administrator. They go to Authlify → Security → Brute force → Locked out right now and click Unlock next to your address, or Unlock everyone.
- WP-CLI. List the active lockouts, then unlock one address, a network, or everything:
wp authlify lockouts
wp authlify unlock 203.0.113.7
wp authlify unlock 198.51.100.0/24
wp authlify unlock --all
Unlocking an address also clears its network lockout. --all also lifts paused accounts. With Authlify Pro, wp authlify unlock also lifts honeypot bans.
4. Your address is on the block list
“Access from your network is blocked.” means your address matches Always block. Another administrator can remove it on Authlify → Security → Brute force. With WP-CLI you can empty the list:
wp eval "\Authlify\Settings::update( array( 'ip_denylist' => '' ) );"
5. The CAPTCHA stops you logging in
Add this line to wp-config.php, log in, fix the keys or choose another provider under Authlify → Security → CAPTCHA, then remove the line:
define( 'AUTHLIFY_DISABLE_CAPTCHA', true );
While it is set, every CAPTCHA is off and the CAPTCHA tab says so.
6. You cannot pass the two-factor step
- Recovery email. On the two-factor step, “Can’t use your methods? Email me a recovery link” sends a one-time link to the account’s email address. See Two-factor recovery.
- Another administrator can reset you under Authlify → Two-factor → Reset for a user.
- WP-CLI. Remove a person’s authenticator app, backup codes and passkeys (user ID, login name or email; note the underscore):
wp authlify reset_2fa [email protected]
- wp-config.php. This turns two-factor login off for everyone without deleting anything; Pro two-factor rules and passkey-only roles pause too:
define( 'AUTHLIFY_DISABLE_2FA', true );
7. An Authlify Pro rule blocks you
Country rules, login hours, honeypot bans and the “refuse the new login” session limit are all switched off by:
define( 'AUTHLIFY_PRO_DISABLE_RULES', true );
If agency white-labelling hides Authlify from your own account, define( 'AUTHLIFY_PRO_AGENCY_OFF', true ); lifts every agency restriction.
Remove every emergency line from wp-config.php as soon as you are back in. While it is there, that protection is off for everyone.