Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: OpenID Connect / OAuth client 3.0.0-alpha9 New alpha version released for module openid_connect (3.0.0-alpha9). Release: Opensolr Search 4.5.0 Minor update available for module opensolr_search (4.5.0). Release: Timelinr 1.0.1 Minor update available for module timelinr (1.0.1). Usage Milestone: Simplify Module simplify crossed 10,000 active installs. Usage Milestone: Views Reference Filter Module entityreference_filter crossed 10,000 active installs. Usage Milestone: Dropdown Language Module dropdown_language crossed 10,000 active installs. Usage Milestone: Paragraphs Browser Module paragraphs_browser crossed 10,000 active installs. Usage Milestone: OpenAPI Module openapi crossed 10,000 active installs. Usage Milestone: Decoupled Router Module decoupled_router crossed 10,000 active installs. Module Revived: Entityqueue Buttons 1.1.2 Module entityqueue_buttons updated after 8 months of inactivity (1.1.2).

One Time Login Link

48 sites Security covered Drupal 9–11
View on drupal.org

The One-Time Login Link module generates secure, single-use login URLs for Drupal users through its user interface, a REST API, or Drush commands. It allows for configurable expiration and can be used to revoke links, track usage, and is protected by rate limiting.

The One-Time Login Link module provides secure, single-use login URLs for Drupal users. It now includes a full REST API, OpenAPI/Swagger documentation, Drush commands, usage statistics, and link revocation, making it suitable for both UI and programmatic workflows.

Key Features

  • Generate secure one-time login links via UI, REST API, or Drush.
  • Configurable expiration and single-use enforcement.
  • Short URL hashes with cryptographic randomness.
  • Rate limiting per user/IP to prevent abuse.
  • Manual revocation (UI, API, Drush) with audit trail.
  • Usage statistics dashboard and API endpoint.
  • Optional email delivery of generated links.
  • OpenAPI/Swagger UI for interactive API exploration.

REST API & Documentation

  • Interactive API Docs: /api/docs/onetimelogin
  • OpenAPI Spec: /api/v1/onetimelogin/openapi.json
  • Endpoints: generate, check, revoke, list, statistics

Drush Commands

drush otl:generate <uid>
drush otl:check <hash>
drush otl:revoke <hash>
drush otl:statistics

Post-Installation

  1. Enable the module and grant permissions.
  2. Use the contextual link on user profiles to generate URLs.
  3. Optionally configure rate limits, expiration, and email notifications.

Additional Requirements

No external dependencies. Compatible with Drupal 10 and 11.

Recommended Modules/Libraries

  • Admin Toolbar – Better administrative UX.
  • REST UI – Easier REST permission setup.

Similar Projects

  • Password Reset Link – Similar concept with extra steps.
  • Login As User – Direct admin impersonation without one-time links.

This module focuses on secure, single-use links with full API support and auditing.

Supporting this Module

Contributions are welcome via issues, patches, and documentation improvements on Drupal.org.

Community Documentation

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
8
Tracked since
Mar 2025
Latest release
6 months ago
Releases (12 mo)
4
Maintenance
Slowing

Release Timeline

Releases

Version Type Core Release date
1.0.6 Stable 9–11 Feb 10, 2026
1.0.5 Stable 9–11 Jan 28, 2026
1.0.4 Stable 9–11 Jan 28, 2026
1.0.3 Stable 9–11 Oct 21, 2025
1.0.2 Stable 9–11 Aug 18, 2025
1.0.1 Stable 9–11 Aug 5, 2025
1.0.0 Stable 10–11 Apr 8, 2025
1.0.x-dev Dev 9–11 Mar 5, 2025