Today in this blog we will see How to Create a Login and Signup page in PHP and how to reset the password by login and how to enter the username in the index page without using SESSION.
How to Build a Login and signup System with PHP and MySQL. Here is a quick solution to build a login system with PHP and MySQL. Nowadays almost every website provides registration and login functionality. Thus, it is necessary to add a login system to modern web applications.
In this tutorial, we walk you through the entire process of creating a user registration system. Users can create an account by providing a username, password, Confirm Password. Once the account is created, the user can log in to his/her own account. Once the user login, it will redirect to the dashboard page. In addition, the user can log out from his panel. This complete system we are developing uses PHP and MySQL.
Plus, we’ll show you how to create secure pages that are only accessible by logged-in users. Without login, the user cannot access the page.
How to create login and signup page in PHP, follow it as given below.
Table of Contents
Step 1: Create a New Database
Create a new database named is “myweb“.
Create new Database MySQL Query
Step 2: Create a New Table
In the new database, create a new table named “users”.
Create a new table MySQL Query
CREATE TABLE `users` (
`id` int(11) NOT NULL,
`username` varchar(50) NOT NULL,
`password` varchar(255) NOT NULL,
`created_at` datetime DEFAULT current_timestamp()
Step3: Create a config.php File.
In the config.php file, you add your database name and database credentials. Assuming you are running MySQL Server with default settings (user with no password ‘root’) must be entered.
/* Database credentials. Assuming you are running MySQL
server with default setting (user 'root' with no password) */
define('DB_SERVER', 'localhost');
define('DB_USERNAME', 'root');
define('DB_PASSWORD', '');
define('DB_NAME', 'myweb');
/* Attempt to connect to MySQL database */
$link = mysqli_connect(DB_SERVER, DB_USERNAME, DB_PASSWORD, DB_NAME);
// Check connection
if($link === false){
die("ERROR: Could not connect. " . mysqli_connect_error());
Step4: Session Create for Logged in User
Create a new File named session.php File. Create a new File named session.php File. Include this file index.php and other files.
// Initialize the session
// Check if the user is logged in, if not then redirect him to login page
if(!isset($_SESSION["loggedin"]) || $_SESSION["loggedin"] !== true){
header("location: login.php");
Step5: Create a Signup Form.
Example:- For sign-up, we will create a new file named registration.php.
// Include config file
require_once "config.php";
// Define variables and initialize with empty values
$username = $password = $confirm_password = "";
$username_err = $password_err = $confirm_password_err = "";
// Processing form data when form is submitted
// Validate username
$username_err = "Please enter a username.";
} elseif(!preg_match('/^[a-zA-Z0-9_]+$/', trim($_POST["username"]))){
$username_err = "Username can only contain letters, numbers, and underscores.";
} else{
// Prepare a select statement
$sql = "SELECT id FROM users WHERE username = ?";
if($stmt = mysqli_prepare($link, $sql)){
// Bind variables to the prepared statement as parameters
mysqli_stmt_bind_param($stmt, "s", $param_username);
// Set parameters
$param_username = trim($_POST["username"]);
// Attempt to execute the prepared statement
/* store result */
if(mysqli_stmt_num_rows($stmt) == 1){
$username_err = "This username is already taken.";
} else{
$username = trim($_POST["username"]);
} else{
echo "Oops! Something went wrong. Please try again later.";
// Close statement
// Validate password
$password_err = "Please enter a password.";
} elseif(strlen(trim($_POST["password"])) < 6){
$password_err = "Password must have atleast 6 characters.";
} else{
$password = trim($_POST["password"]);
// Validate confirm password
$confirm_password_err = "Please confirm password.";
} else{
$confirm_password = trim($_POST["confirm_password"]);
if(empty($password_err) && ($password != $confirm_password)){
$confirm_password_err = "Password did not match.";
// Check input errors before inserting in database
if(empty($username_err) && empty($password_err) && empty($confirm_password_err)){
// Prepare an insert statement
$sql = "INSERT INTO users (username, password) VALUES (?, ?)";
if($stmt = mysqli_prepare($link, $sql)){
// Bind variables to the prepared statement as parameters
mysqli_stmt_bind_param($stmt, "ss", $param_username, $param_password);
// Set parameters
$param_username = $username;
$param_password = password_hash($password, PASSWORD_DEFAULT); // Creates a password hash
// Attempt to execute the prepared statement
// Redirect to login page
header("location: login.php");
} else{
echo "Oops! Something went wrong. Please try again later.";
// Close statement
// Close connection
<!DOCTYPE html>
<html lang="en">
<meta charset="UTF-8">
<title>Sign Up</title>
<link rel="stylesheet" href="">
<link rel="stylesheet" type="text/css" href="style.css">
body{ font: 14px sans-serif; }
.wrapper{ width: 360px; padding: 20px; }
<div class="wrapper">
<h2>Sign Up</h2>
<p>Please fill this form to create an account.</p>
<form action="<?php echo htmlspecialchars($_SERVER["PHP_SELF"]); ?>" method="post">
<div class="form-group">
<input type="text" name="username" class="form-control <?php echo (!empty($username_err)) ? 'is-invalid' : ''; ?>" value="<?php echo $username; ?>">
<span class="invalid-feedback"><?php echo $username_err; ?></span>
<div class="form-group">
<input type="password" name="password" class="form-control <?php echo (!empty($password_err)) ? 'is-invalid' : ''; ?>" value="<?php echo $password; ?>">
<span class="invalid-feedback"><?php echo $password_err; ?></span>
<div class="form-group">
<label>Confirm Password</label>
<input type="password" name="confirm_password" class="form-control <?php echo (!empty($confirm_password_err)) ? 'is-invalid' : ''; ?>" value="<?php echo $confirm_password; ?>">
<span class="invalid-feedback"><?php echo $confirm_password_err; ?></span>
<div class="form-group">
<input type="submit" class="btn btn-primary" value="Submit">
<input type="reset" class="btn btn-secondary ml-2" value="Reset">
<p>Already have an account? <a href="login.php">Login here</a>.</p>
The output of the above code will look like this.
Step6: Create a Login Form.
Example:- For Login, we will create a new file named Login.php.
// Initialize the session
// Check if the user is already logged in, if yes then redirect him to welcome page
if(isset($_SESSION["loggedin"]) && $_SESSION["loggedin"] === true){
header("location: index.php");
// Include config file
require_once "config.php";
// Define variables and initialize with empty values
$username = $password = "";
$username_err = $password_err = $login_err = "";
// Processing form data when form is submitted
// Check if username is empty
$username_err = "Please enter username.";
} else{
$username = trim($_POST["username"]);
// Check if password is empty
$password_err = "Please enter your password.";
} else{
$password = trim($_POST["password"]);
// Validate credentials
if(empty($username_err) && empty($password_err)){
// Prepare a select statement
$sql = "SELECT id, username, password FROM users WHERE username = ?";
if($stmt = mysqli_prepare($link, $sql)){
// Bind variables to the prepared statement as parameters
mysqli_stmt_bind_param($stmt, "s", $param_username);
// Set parameters
$param_username = $username;
// Attempt to execute the prepared statement
// Store result
// Check if username exists, if yes then verify password
if(mysqli_stmt_num_rows($stmt) == 1){
// Bind result variables
mysqli_stmt_bind_result($stmt, $id, $username, $hashed_password);
if(password_verify($password, $hashed_password)){
// Password is correct, so start a new session
// Store data in session variables
$_SESSION["loggedin"] = true;
$_SESSION["id"] = $id;
$_SESSION["username"] = $username;
// Redirect user to welcome page
header("location: index.php");
} else{
// Password is not valid, display a generic error message
$login_err = "Invalid username or password.";
} else{
// Username doesn't exist, display a generic error message
$login_err = "Invalid username or password.";
} else{
echo "Oops! Something went wrong. Please try again later.";
// Close statement
// Close connection
<!DOCTYPE html>
<html lang="en">
<meta charset="UTF-8">
<link rel="stylesheet" href="">
<link rel="stylesheet" type="text/css" href="style.css">
body{ font: 14px sans-serif; }
.wrapper{ width: 360px; padding: 20px; }
<div class="wrapper">
<p>Please fill in your credentials to login.</p>
echo '<div class="alert alert-danger">' . $login_err . '</div>';
<form action="<?php echo htmlspecialchars($_SERVER["PHP_SELF"]); ?>" method="post">
<div class="form-group">
<input type="text" name="username" class="form-control <?php echo (!empty($username_err)) ? 'is-invalid' : ''; ?>" value="<?php echo $username; ?>">
<span class="invalid-feedback"><?php echo $username_err; ?></span>
<div class="form-group">
<input type="password" name="password" class="form-control <?php echo (!empty($password_err)) ? 'is-invalid' : ''; ?>">
<span class="invalid-feedback"><?php echo $password_err; ?></span>
<div class="form-group">
<input type="submit" class="btn btn-primary" value="Login">
<p>Don't have an account? <a href="register.php">Sign up now</a>.</p>
The output of the above code will look like this.
Step7: Making a Dashboard Page.
Create an index.php page that will open by the login.
<?php // Initialize the session
// Check if the user is already logged in, if yes then redirect him to welcome page
include 'session.php'; ?>
<!DOCTYPE html>
<html lang="en">
<meta charset="UTF-8">
<link rel="stylesheet" href="">
<link rel="stylesheet" type="text/css" href="style.css">
body{ font: 14px sans-serif; text-align: center; }
<h1 class="mt-5"><a href="" target="blanck" >Wel Come HOME</a></h1>
<h1 class="my-5">Hi, <b><?php echo htmlspecialchars($_SESSION["username"]); ?></b>. Welcome to our site.</h1>
<a href="reset-password.php" class="btn btn-warning">Reset Your Password</a>
<a href="logout.php" class="btn btn-danger ml-3">Sign Out of Your Account</a>
The output of the above code will look like this.
Step8: Create a Logout (Destroy session) Page.
To create the logout page, create a new file named logout.php.
// Initialize the session
// Unset all of the session variables
$_SESSION = array();
// Destroy the session.
// Redirect to login page
header("location: login.php");
Step9: Create a New reset-password.php File.
To reset the password, create a new file named reset-password.php.
// Initialize the session
// Check if the user is logged in, otherwise redirect to login page
include 'session.php';
// Include config file
require_once "config.php";
// Define variables and initialize with empty values
$new_password = $confirm_password = "";
$new_password_err = $confirm_password_err = "";
// Processing form data when form is submitted
// Validate new password
$new_password_err = "Please enter the new password.";
} elseif(strlen(trim($_POST["new_password"])) < 6){
$new_password_err = "Password must have atleast 6 characters.";
} else{
$new_password = trim($_POST["new_password"]);
// Validate confirm password
$confirm_password_err = "Please confirm the password.";
} else{
$confirm_password = trim($_POST["confirm_password"]);
if(empty($new_password_err) && ($new_password != $confirm_password)){
$confirm_password_err = "Password did not match.";
// Check input errors before updating the database
if(empty($new_password_err) && empty($confirm_password_err)){
// Prepare an update statement
$sql = "UPDATE users SET password = ? WHERE id = ?";
if($stmt = mysqli_prepare($link, $sql)){
// Bind variables to the prepared statement as parameters
mysqli_stmt_bind_param($stmt, "si", $param_password, $param_id);
// Set parameters
$param_password = password_hash($new_password, PASSWORD_DEFAULT);
$param_id = $_SESSION["id"];
// Attempt to execute the prepared statement
// Password updated successfully. Destroy the session, and redirect to login page
header("location: login.php");
} else{
echo "Oops! Something went wrong. Please try again later.";
// Close statement
// Close connection
<!DOCTYPE html>
<html lang="en">
<meta charset="UTF-8">
<title>Reset Password</title>
<link rel="stylesheet" href="">
<link rel="stylesheet" type="text/css" href="style.css">
body{ font: 14px sans-serif; }
.wrapper{ width: 360px; padding: 20px; }
<div class="wrapper">
<h2>Reset Password</h2>
<p>Please fill out this form to reset your password.</p>
<form action="<?php echo htmlspecialchars($_SERVER["PHP_SELF"]); ?>" method="post">
<div class="form-group">
<label>New Password</label>
<input type="password" name="new_password" class="form-control <?php echo (!empty($new_password_err)) ? 'is-invalid' : ''; ?>" value="<?php echo $new_password; ?>">
<span class="invalid-feedback"><?php echo $new_password_err; ?></span>
<div class="form-group">
<label>Confirm Password</label>
<input type="password" name="confirm_password" class="form-control <?php echo (!empty($confirm_password_err)) ? 'is-invalid' : ''; ?>">
<span class="invalid-feedback"><?php echo $confirm_password_err; ?></span>
<div class="form-group">
<input type="submit" class="btn btn-primary" value="Submit">
<a class="btn btn-link ml-2" href="index.php">Cancel</a>
The output of the above code will look like this.
Step10: Create a New style.css File.
All forms have to be styled for more attractive, for that we have to create a new file named style.css
margin: 0;
padding: 0;
box-sizing: border-box;
background: #f5f5f5;
.wrapper {
background: #9cb7d5;
margin: auto;
margin-top: 5%;
border-radius: 8px;
box-shadow: -2px 5px 22px 3px rgb(0 0 0 / 50%);
Here your Login and Signup page in PHP is ready.