Stop typing passwords.
Sign in to WordPress with a passkey.
Sign in with Touch ID, Windows Hello, Face ID, or a security key. A passkey (WebAuthn / FIDO2) is phishing-resistant, and the server only ever stores a public key. Activate it, register one passkey, and you’re done — your passwords keep working alongside it.
- Set up in under a minute
- Passwords keep working
- Plays nice with 2FA plugins
- WP-CLI ready

Setup takes under a minute — add a passkey from your profile, then sign in with one touch next time.
passwordless
Same login. No password, no code to type.
One touch with your fingerprint, face, or PIN. Nothing to type — no password, no one-time code.
why passkeys
Why passkeys are safe
A passkey’s strength is the mechanism itself — not inflated numbers, but properties that public-key cryptography gives you for free.
Shared secrets
0
Only a public key is stored on the server
public-keySign-in
1 touch
Touch ID, Windows Hello, Face ID
passwordlessFactor covered
2FA
One passkey satisfies the second factor
integratesPasswords
kept
Never disabled — they still work
optionalPasskeys use WebAuthn / FIDO2 public-key cryptography. The private half of the key pair generated at registration stays on your device; only the public key is sent to the server. Authentication is bound to each site’s origin, so it simply doesn’t succeed on a look-alike site (phishing resistance). Which factor is covered, and whether passwords coexist, depends on your plugins and settings.
how it works
Why it’s secure
A password is a remembered secret you send in full every time — so it gets stolen, reused, and skimmed on look-alike sites. A passkey sends no secret at all; it returns only a signature, on the spot.
Sends the secret every time
- Remember and type your password
- Reuse and leaks stay a risk
- Type a one-time code as well
- Codes can be skimmed by relay phishing
Returns a signature, not a secret
- The browser asks for your passkey
- Verify with Touch ID, Windows Hello, or Face ID
- The device signs a challenge bound to the site’s origin
- Signed in — there is no secret to steal
features
This much, from the free plugin alone
The core of going passwordless is all in Free. Feel the “no more typing passwords” moment before you spend anything.
Passwordless sign-in
Phishing-resistant login via WebAuthn / FIDO2. There is no secret to remember, and it never succeeds on a look-alike site.
Same device and cross-device
Same-device passkeys with Touch ID / Windows Hello / Face ID, plus the browser’s own cross-device flow — scan with your phone.
Passwords keep working
Existing password login is never disabled. Nothing is taken away — passkeys are added on top.
Shortcodes & blocks
[rapls_passkey_login] / [rapls_passkey_register] and matching Gutenberg blocks (login button, passkey management), with redirect and label options.
Manage your passkeys
Rename, suspend, and resume individual passkeys. Admins get a searchable site-wide list under Users → Passkeys.
Coexists with security plugins & hardening
Works alongside SiteGuard, CloudSecure WP Security, Wordfence (Login Security), and Two-Factor. Their image CAPTCHA still applies, and a passkey satisfies the Wordfence / Two-Factor second factor. Plus reCAPTCHA v3 on the password form, a login rate limit, a first-run setup check, WP-CLI, an audit log, and an emergency break-glass. Free sends nothing externally.
secure by design
Security, from every angle
A passkey’s strength comes from three properties working together.
Phishing-resistant
Authentication is bound to the site’s origin. On a convincing look-alike the signature won’t verify, so a lured user still can’t be skimmed.
No shared secrets
The server stores only a public key. Even if it leaks, there is simply no secret an attacker could use to impersonate you.
Doubles as a second factor
It integrates with Wordfence Login Security and Two-Factor, so one passkey satisfies the site’s two-factor requirement.
get started
Passwordless in three steps
Install
Install Rapls Passkey from WordPress.org and activate it.
Register a passkey
On your profile page, add a passkey using Touch ID, Windows Hello, or Face ID.
Sign in with a touch
From then on, sign in with your passkey. Your password still works too.
free vs pro
Free and Pro
Go passwordless with Free; roll it out across your organization with Pro. Pro includes every Free feature.
| Feature | Free | Pro |
|---|---|---|
| Passwordless sign-in (WebAuthn / FIDO2) | ✓ | ✓ |
| Same-device & cross-device passkeys (native browser flow) | ✓ | ✓ |
| Passwords keep working alongside | ✓ | ✓ |
| Shortcodes & Gutenberg blocks | ✓ | ✓ |
| Rename / suspend / resume passkeys | ✓ | ✓ |
| Site-wide passkey list (admin, searchable) | ✓ | ✓ |
| 2FA plugin integration, reCAPTCHA v3, login rate limit | ✓ | ✓ |
| WP-CLI, audit log, Site Health, break-glass | ✓ | ✓ |
| Cross-device QR login (with 4-digit code) | — | ✓ |
| Role-based passkey enforcement (grace period) | — | ✓ |
| Single-use recovery codes, email magic-link login | — | ✓ |
| Passwordless sign-up, adaptive step-up | — | ✓ |
| Authenticator policy (MDS / AAGUID), webhooks, adoption reports | — | ✓ |
| Multisite network policy, settings export / import | — | ✓ |
pricing
Pricing
Every core passwordless feature is in the free version. Pro is a one-time purchase with a year of updates.
Free
Start free, go passwordless
$0
Free forever
- Passwordless sign-in (WebAuthn / FIDO2)
- Same-device & cross-device passkeys, passwords coexist
- Shortcodes & blocks, passkey management & list
- 2FA integration, reCAPTCHA v3, WP-CLI, audit log
Pro Add-on
1-site license
$39
$19
One-time purchase · 1 year of updates · excl. tax
Launch price — through Dec 31, 2026
- Everything in Free, plus:
- Cross-device QR login, role-based enforcement
- Recovery codes, email magic-link, passwordless sign-up
- Adaptive step-up, authenticator policy, webhooks
- Adoption reports, multisite, settings import/export
🛡 14-day money-back guarantee — full refund, no questions asked
Pro Add-on
5-site license
$79
$39
One-time purchase · 1 year of updates · excl. tax
Launch price — through Dec 31, 2026
- Everything in the 1-site license
- Use on up to 5 sites
- Built for agencies and freelancers
🛡 14-day money-back guarantee — full refund, no questions asked
Includes 1 year of updates and email support. Payments are processed securely by Stripe.
* Launch price, available through December 31, 2026. From January 1, 2027 the regular price applies: $39 (1 site) / $79 (5 sites).
* Prices in USD, excl. tax, one-time purchase. Renewal after the first year is optional — the plugin keeps working either way.
* 14-day money-back guarantee: full refund within 14 days of purchase, no questions asked (Refund Policy).
faq
Frequently asked questions
Can I use the free version on its own?
Will passwords stop working?
Which devices and browsers work?
Does it work with my 2FA plugin?
What if I lose my device and get locked out?
Is Pro a subscription? Can I get a refund?
What are the requirements?
Go passwordless, starting today.
The free version is all you need to begin. Install it and register one passkey.

