BetterShield

Let trusted browsers skip the code screen

3 min read

With BetterShield Ultra, people can trust a browser for up to 90 days so it skips the two-factor code screen. Set the window and forget devices.

With trusted devices on, the two-factor code screen offers a checkbox. A browser someone trusts skips the code screen on later sign-ins until its time is up. Set it on BetterShield › Ultra › Trusted devices, part of BetterShield Ultra. It is off until you choose a number of days.

Turn it on

OptionWhat it doesWhy it mattersDefault
Days a device stays trusted1 to 90 days. 0 turns trusted devices off, and the checkbox disappears from the code screen. Press Save.People who sign in daily on their own laptop are not asked for a code every time.0 (off)

Once it is on, the code screen shows a checkbox such as Trust this device for 30 days: no code asked here until then. Ticking it and entering a valid code remembers that browser on this site.

What trusting a device does not do

It is a skip, never a way in.

  • The password, or a passkey, is still needed every time.
  • Every browser an account trusts is forgotten when its password changes, whichever way it changes: a reset, the profile screen, an administrator or WP-CLI. The same happens when two-factor on the account is set up again or turned off.
  • Shortening the window shortens the trust already given. Setting it to 0 stops every trusted browser skipping the code.
  • An account keeps up to ten trusted browsers on a site. Trusting another drops the oldest.
  • On multisite, a browser trusted on one site skips the code on that site only.

Devices you trust

This card lists the browsers your own account trusts on this site. Each is named by its browser and system, such as Chrome on Mac, with when it was trusted and until when.

  • Forget removes one. That browser is asked for the code at its next sign-in.
  • With none, the card says the choice is offered on the code screen when trusted devices are on.

Devices other accounts trust

For people who manage BetterShield. It lists each account holding a trusted device on this site, and how many. The devices themselves are not shown.

  1. Press Forget this account’s devices beside the account.
  2. Read what will happen, then confirm. The account is asked for a code on its next sign-in, on every browser it trusted. Nothing else about the account changes, and they can trust a browser again.

On a site with many accounts, the card reads them in batches. Check more accounts reads the next one, and the card says how many accounts it has checked so far.

When to use it

Trusted devices suit sites where people sign in often from their own computers. On shared or public computers, people should leave the box unticked. If a laptop is lost, forget that account’s devices here, or have the person change their password, which forgets them all.

What is kept, and what is recorded

For each trusted browser, the site keeps a hash of the token the browser holds (never the token itself), the browser and system it was recognized as, which site trusted it, when, and when the trust runs out. A request under Tools › Erase Personal Data removes them. See Privacy and personal data.

Saving is recorded like a change to the Sign-in policies: lengthening the window appears in the activity log as Two-factor requirement changed, rated high. With Ask for my password before an action that removes a protection on (Settings › General), saving or forgetting another account’s devices asks for your password.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield