Tutorials

How to see what a member sees in XenForo, without their password

A member reports a problem you can't reproduce. How to see their exact view, from permission checks to a logged, time-limited way to impersonate a user in XenForo.

D.C Style · 7 min read
Share on X
On this page

A member says a button is missing or a forum looks empty, and your staff account sees everything just fine. The fastest fix is to see the forum through their eyes. This guide starts with XenForo's own checks, then shows a XenForo impersonate user tool that is logged and time-limited, so you never need to ask for a password.

Never ask a member for their password, even to help them. They may use it elsewhere, and a support chat is no place for it. Everything below works without it.

Why a staff account can't see the problem

Your staff account is rarely a fair test. Staff are usually in extra user groups, such as Moderating or Administrative, on top of Registered. A member gets the combined permissions of all their groups. So a forum or button that is hidden from members often shows for staff.

Other things belong to the member alone:

  • Permissions set on their own account, or on one forum.
  • The style and language they picked.
  • Their unread threads, alerts and conversations.
  • Their account state, such as awaiting email confirmation or banned.
  • Error messages that only their account triggers.

Any of these can explain "it doesn't work for me". Your job is to find which one.

Check their permissions first

Most "I can't see it" reports come down to permissions. XenForo has a tool for exactly this. Open Groups & permissions > Analyze permissions in the Admin CP, enter the member's username and click Analyze. You can pick a forum to see the result there too.

For every permission, it shows the final value and how each of the member's groups added to it. A Never from a forgotten secondary group stands out straight away. So does a forum set to No for their group.

If you are new to Yes, No and Never, read XenForo permissions explained. It covers how groups combine, and why Never is rarely what you want.

Analyzing permissions has limits, though. It tells you what the member may do. It can't show you how a page looks for them, a style they picked, or an error only their account hits.

Use a test account in the same groups

The next step many admins take is a test account. Create a member, put it in the same primary and secondary groups, and browse as that account in a private window. It is free and safe, and it catches most group problems.

A test account is still not the member, though. It lacks their own permissions, their content, their unread state and their style choice. If the problem lives on their account, the test account looks fine and you are back where you started.

Tip:

Keep one test member for this job, with no staff groups. Reset its groups each time to match the member you are helping.

A XenForo impersonate user tool with an audit trail

XenForo doesn't include a way to browse as another member. Our free Login As User add-on adds one, built for accountability rather than convenience alone. Staff with permission switch into a member's account, see what they see, and switch back.

Where staff start a switch

There are six ways in, all behind one permission, Log in as another member:

  • The staff bar, with member search and your recent targets.
  • The moderator tools menu on a member's profile.
  • "Log in as author" in the menu of any post.
  • An icon on each row of the Admin CP user list.
  • The actions menu when editing a user in the Admin CP.
  • A direct link, for anything that should go straight to the confirmation screen.

What keeps it safe

Before the switch, a confirmation screen shows the member's avatar, name and email, so there is no doubt whose account this is. Staff can add a reason, and they re-enter their own password. Each switch needs its own confirmation, so a stolen staff session is not enough on its own.

  • Administrators can never be logged in as. That is built in, not a permission someone could grant.
  • Other groups, such as moderators or VIPs, can be protected with Cannot be logged in as.
  • Sessions end on their own after 30 minutes by default.
  • Staff can't switch into a second member without returning first.
  • Each staff member has one session at a time across the whole board.

While inside an account, the staff bar is tinted and says whose account is in use. A return button sits on every page. Logging out returns staff to their own account instead of signing them out.

Restricted accounts are flagged, not blocked. Banned, disabled and unconfirmed accounts can still be entered, and that is often the point. You see exactly what that member sees.

The audit log and live sessions

A XenForo impersonate user tool is only as good as its record. Login As User writes one log row per session. It holds the staff member, the member, the reason, the IP address, the start time, the duration and how the session ended.

  • Logs > Users > Login as user log lists every session, with filters by staff member, member and date.
  • Users > Active login-as sessions shows who is browsing as whom right now.
  • Administrators with the Login as user: end active sessions permission can end any live session at once.

Usernames are stored on each row. So the log still makes sense after an account is deleted. Finished sessions are kept for 365 days by default, and you can change that.

Leave no trace on the member's account

A support visit shouldn't change the member's forum. By default, Login As User hides six things from the account you visit:

  • The currently online list.
  • The last activity time.
  • Threads and forums being marked as read.
  • Alerts being marked as read.
  • Direct messages being marked as read.
  • Your IP address in their IP history.

Each one can be switched off in the options if you prefer normal behavior. Your IP address is still recorded on the log row, where it belongs.

Note:

If your forum uses Cloudflare or a DigitalPoint add-on, run Login As User 1.1.0 Patch Level 3 or newer. It came out on 25 September 2026. Earlier versions could still show the member as online on those setups, and could move their last activity time.

Patch Level 3 also includes an earlier fix for stale session cookies. Those could end an impersonation after moving to another page.

Good habits for staff

Staff who log in as a member can read their private conversations and settings. Treat the permission like a key to every house on the street.

  1. Give Log in as another member to as few people as you can.
  2. Ask staff to fill in the reason every time.
  3. Return to your own account as soon as you have seen what you need.
  4. Look through the log now and then, just as you would the moderator log.

What to do next

Next time a member reports something you can't reproduce, start with Analyze permissions. If that doesn't explain it, switch into their account and look. Login As User is free and needs XenForo 2.3 and PHP 8.0 or newer. The Login As User setup guide covers the permission, the options and the log in a few minutes.