Rapls Passkey Pro (EN)

Rapls Passkey Pro (EN)
🔐 Passwordless login for WordPress

Stop typing passwords.
Sign in to WordPress with a passkey.

Sign in with Touch ID, Windows Hello, Face ID, or a security key. A passkey (WebAuthn / FIDO2) is phishing-resistant, and the server only ever stores a public key. Activate it, register one passkey, and you’re done — your passwords keep working alongside it.

  • Set up in under a minute
  • Passwords keep working
  • Plays nice with 2FA plugins
  • WP-CLI ready
The Passkey section of the profile screen, listing a registered passkey and the Register a passkey button.

Setup takes under a minute — add a passkey from your profile, then sign in with one touch next time.

passwordless

Same login. No password, no code to type.

Password + 2FA
recall, type, wait for a code
Passkey
one touch
1

One touch with your fingerprint, face, or PIN. Nothing to type — no password, no one-time code.

why passkeys

Why passkeys are safe

A passkey’s strength is the mechanism itself — not inflated numbers, but properties that public-key cryptography gives you for free.

Shared secrets

0

Only a public key is stored on the server

public-key

Sign-in

1 touch

Touch ID, Windows Hello, Face ID

passwordless

Factor covered

2FA

One passkey satisfies the second factor

integrates

Passwords

kept

Never disabled — they still work

optional

Passkeys use WebAuthn / FIDO2 public-key cryptography. The private half of the key pair generated at registration stays on your device; only the public key is sent to the server. Authentication is bound to each site’s origin, so it simply doesn’t succeed on a look-alike site (phishing resistance). Which factor is covered, and whether passwords coexist, depends on your plugins and settings.

how it works

Why it’s secure

A password is a remembered secret you send in full every time — so it gets stolen, reused, and skimmed on look-alike sites. A passkey sends no secret at all; it returns only a signature, on the spot.

Password login

Sends the secret every time

  1. Remember and type your password
  2. Reuse and leaks stay a risk
  3. Type a one-time code as well
  4. Codes can be skimmed by relay phishing
Passkey login

Returns a signature, not a secret

  1. The browser asks for your passkey
  2. Verify with Touch ID, Windows Hello, or Face ID
  3. The device signs a challenge bound to the site’s origin
  4. Signed in — there is no secret to steal

features

This much, from the free plugin alone

The core of going passwordless is all in Free. Feel the “no more typing passwords” moment before you spend anything.

Passwordless sign-in

Phishing-resistant login via WebAuthn / FIDO2. There is no secret to remember, and it never succeeds on a look-alike site.

Same device and cross-device

Same-device passkeys with Touch ID / Windows Hello / Face ID, plus the browser’s own cross-device flow — scan with your phone.

Passwords keep working

Existing password login is never disabled. Nothing is taken away — passkeys are added on top.

Shortcodes & blocks

[rapls_passkey_login] / [rapls_passkey_register] and matching Gutenberg blocks (login button, passkey management), with redirect and label options.

Manage your passkeys

Rename, suspend, and resume individual passkeys. Admins get a searchable site-wide list under Users → Passkeys.

Coexists with security plugins & hardening

Works alongside SiteGuard, CloudSecure WP Security, Wordfence (Login Security), and Two-Factor. Their image CAPTCHA still applies, and a passkey satisfies the Wordfence / Two-Factor second factor. Plus reCAPTCHA v3 on the password form, a login rate limit, a first-run setup check, WP-CLI, an audit log, and an emergency break-glass. Free sends nothing externally.

secure by design

Security, from every angle

A passkey’s strength comes from three properties working together.

WebAuthn

Phishing-resistant

Authentication is bound to the site’s origin. On a convincing look-alike the signature won’t verify, so a lured user still can’t be skimmed.

FIDO2

No shared secrets

The server stores only a public key. Even if it leaks, there is simply no secret an attacker could use to impersonate you.

2FA

Doubles as a second factor

It integrates with Wordfence Login Security and Two-Factor, so one passkey satisfies the site’s two-factor requirement.

get started

Passwordless in three steps

1

Install

Install Rapls Passkey from WordPress.org and activate it.

2

Register a passkey

On your profile page, add a passkey using Touch ID, Windows Hello, or Face ID.

3

Sign in with a touch

From then on, sign in with your passkey. Your password still works too.

free vs pro

Free and Pro

Go passwordless with Free; roll it out across your organization with Pro. Pro includes every Free feature.

FeatureFreePro
Passwordless sign-in (WebAuthn / FIDO2)
Same-device & cross-device passkeys (native browser flow)
Passwords keep working alongside
Shortcodes & Gutenberg blocks
Rename / suspend / resume passkeys
Site-wide passkey list (admin, searchable)
2FA plugin integration, reCAPTCHA v3, login rate limit
WP-CLI, audit log, Site Health, break-glass
Cross-device QR login (with 4-digit code)
Role-based passkey enforcement (grace period)
Single-use recovery codes, email magic-link login
Passwordless sign-up, adaptive step-up
Authenticator policy (MDS / AAGUID), webhooks, adoption reports
Multisite network policy, settings export / import

pricing

Pricing

Every core passwordless feature is in the free version. Pro is a one-time purchase with a year of updates.

Free

Start free, go passwordless

 

$0

Free forever

 

  • Passwordless sign-in (WebAuthn / FIDO2)
  • Same-device & cross-device passkeys, passwords coexist
  • Shortcodes & blocks, passkey management & list
  • 2FA integration, reCAPTCHA v3, WP-CLI, audit log
Get it on WordPress.org

Pro Add-on

5-site license

$79

$39

One-time purchase · 1 year of updates · excl. tax

Launch price — through Dec 31, 2026

  • Everything in the 1-site license
  • Use on up to 5 sites
  • Built for agencies and freelancers
See Pro details

🛡 14-day money-back guarantee — full refund, no questions asked

Includes 1 year of updates and email support. Payments are processed securely by Stripe.
* Launch price, available through December 31, 2026. From January 1, 2027 the regular price applies: $39 (1 site) / $79 (5 sites).
* Prices in USD, excl. tax, one-time purchase. Renewal after the first year is optional — the plugin keeps working either way.
* 14-day money-back guarantee: full refund within 14 days of purchase, no questions asked (Refund Policy).

faq

Frequently asked questions

Can I use the free version on its own?
Yes. Passwordless sign-in (WebAuthn / FIDO2), same-device and cross-device passkeys, coexistence with passwords, shortcodes and Gutenberg blocks, renaming / suspending / resuming passkeys, the site-wide passkey list, 2FA plugin integration, reCAPTCHA v3 and a login rate limit, WP-CLI, an audit log, Site Health checks, and the emergency break-glass are all in Free. The Pro add-on layers on cross-device QR login, role-based enforcement, recovery codes, email magic-link login, passwordless sign-up, authenticator policy, and more.
Will passwords stop working?
No. In Free, password login is never disabled — it coexists with passkeys. Nothing is taken away; passkeys are simply added. If you want specific users to be fully passwordless, Pro lets you migrate them in phases.
Which devices and browsers work?
Any modern browser that supports built-in authenticators (Touch ID, Windows Hello, Face ID) or FIDO2 security keys. If the device in front of you has no passkey, you can still sign in with the browser’s built-in cross-device flow by scanning with your phone.
Does it work with my 2FA plugin?
Yes. It integrates with Wordfence Login Security and Two-Factor, and a passkey is treated as the site’s second factor. When a weaker alternative login (such as a password) is used, the site’s two-factor requirement still applies.
What if I lose my device and get locked out?
In Free, password login coexists, which prevents lockout. In an emergency you can also temporarily disable passkey prompts with define(‘RAPLS_PASSKEY_BYPASS’, true);. Pro adds single-use recovery codes and email magic-link login so you can recover safely even in a fully passwordless setup.
Is Pro a subscription? Can I get a refund?
No — it is a one-time purchase. It includes one year of updates and email support, and the plugin keeps working afterward (renewal is optional). Within 14 days of purchase we refund in full, for any reason — one email to info@raplsworks.com is all it takes. See the Refund Policy for details.
What are the requirements?
WordPress 6.0 or later (latest recommended) and PHP 8.2 or later. Passkeys require HTTPS (except on localhost) — browsers refuse WebAuthn without it. Using Pro requires the free Rapls Passkey plugin (0.12.0 or later) installed and active.

Go passwordless, starting today.

The free version is all you need to begin. Install it and register one passkey.

タイトルとURLをコピーしました