Skip to content
مرسال
Log in Try free
Passwordless Login: The Mersal OTP Plugin for WordPress

Forgotten passwords are the biggest cause of lost customers at login. The Mersal OTP plugin removes the problem entirely: the customer enters their number, receives a code on WhatsApp or SMS, and they're in. That's it.

The problem, in numbers

In any online store, the login screen is the biggest drop-off point after the cart itself. The recurring causes: a forgotten password, a recovery email that no longer works, or an account created a year ago under an address the customer can't remember. Each one ends with a closed tab instead of a completed purchase.

Code-based login solves all three at once: there is nothing to remember, nothing to recover, and identity is the phone number the customer is holding.

Why code-based login works better in Arab markets

  • A large share of users live on their phone more than their email, and many hold an address they barely check.
  • There's no password to forget or leak — which measurably cuts support tickets.
  • The number is verified automatically — so your database is clean from day one, and the numbers in your later campaigns are real numbers.
  • WhatsApp is on virtually every customer's phone, so the code arrives in seconds at no SMS cost.

What the plugin does

  • OTP login and registration over WhatsApp, SMS or email.
  • One-tap login and confirmation links — the customer taps instead of typing a code.
  • An international phone field (intl-tel-input) with country selection and auto-formatting, which sharply reduces invalid numbers.
  • WhatsApp message styles: lists or buttons, not just plain text.
  • A phone column on the Users screen inside the WordPress admin.
  • SSO with your Mersal account — one-click setup instead of copying keys.

How it works, step by step

  1. The customer types their number into the international phone field, and the plugin normalises the format automatically (dropping the leading zero, adding the country code).
  2. The plugin calls Mersal, which picks the enabled channel in the order you configured.
  3. The customer receives a 4- or 6-digit code, or a one-tap confirmation link.
  4. On verification: an existing number is logged in, a new one gets an account created immediately with no second registration screen.

That last step is what actually moves the needle: from the customer's side there is no difference between "log in" and "sign up" — one step covers both.

Installation

  1. Download the plugin from its page on mersal.it (the link always serves the latest build).
  2. Upload it from WordPress admin → Plugins → Add New → Upload and activate.
  3. Connect it to your Mersal account via SSO.
  4. Choose which OTP channels are enabled and the gateway for each.
  5. Test it yourself from a private browsing window.

That last step is not optional. Testing while logged in to the same browser shows you different screens than a visitor sees, so use a private window or a second browser.

Settings worth getting right on day one

  • Channel order: WhatsApp first as the cheapest and fastest, then SMS, with email last as a fallback.
  • Code length: 6 digits for stores, 4 is enough for simple sites.
  • Validity window: 5 to 10 minutes. Longer than that widens the window for abuse.
  • Resend limit: put a countdown in front of the "resend" button so you aren't paying for duplicate messages.
  • Where it's active: login, registration and WooCommerce checkout can each be enabled independently.

Customising the message

Keep it to your site name and the code. Something like "Your {site} login code: 481920 — valid for 5 minutes" reads faster than a full paragraph. Avoid any links in the code message other than the one-tap confirmation link, because extra links raise the odds of the message being filtered as spam.

With WooCommerce

On WooCommerce the benefit compounds: the same number the customer logged in with is the number you'll send order and shipping notifications to. Instead of collecting numbers in one place and sending from another, the loop closes by itself.

And because every number was verified by a code, order notifications actually arrive — unlike numbers mistyped into a plain text field.

Common problems and fixes

  • The code never arrives on WhatsApp: confirm the WhatsApp gateway is connected in the Mersal dashboard and the number carries the right country code. Send a test message from Mersal first to establish whether the fault is the gateway or the plugin.
  • The field renders unstyled or misaligned: usually a CSS clash with the theme. Enable the plugin's stylesheet option, or exclude login pages from CSS concatenation in your caching plugin.
  • A correct code is rejected as invalid: this is almost always caching. Exclude wp-login.php, cart and checkout from the page cache.
  • Numbers get rejected: check the allowed countries in the phone field settings — it is sometimes left restricted to a single country.
  • Existing customers with old accounts: keep password login alongside OTP during a transition period and let each customer attach their number on first login.

Automatic updates

The plugin updates itself from our server, so you don't have to manually upload a new build to every site each time. If you maintain many client sites, that removes a recurring maintenance chore.

Security tips

  • Keep code validity short (5–10 minutes).
  • Enable an attempt limit to prevent guessing — five tries, then a cooldown.
  • Keep email as a fallback channel in case WhatsApp isn't available for a given user.
  • Cap how many codes one number or one IP can request per hour, so nobody can drain your balance.
  • Never write the code to a log — not even an error log.

Frequently asked questions

Does it work with any theme? Yes, it uses the standard WordPress screens. Themes that build their own custom login screen may need the shortcode placed manually.

Can login be phone-only, with no email? Yes, email can be made optional in the registration settings.

What does it cost? OTP messages draw on your Mersal balance like any other message, and WhatsApp is clearly cheaper than SMS — one more reason to keep it first in the channel order.

Share this article:
share work chat