Product
Solutions
Compare
Resources
Get early access Talk to us
One-click login

Open any site's WordPress admin in one click

Sign into any website you manage from the dashboard, as yourself, with exactly the role you were given. Nobody on your team ever holds a password for a client site, and when somebody leaves, one action ends their access everywhere at once.

On every plan. No add-on pricing.

Updated

app.wpcentrify.com/websites
Your websites34 connected
Passwords held
0
none required
Signed in now
3
across 3 sites
Locked down
12
admin login off
Team members
6
own role each
NRnorthridge-dental.comAdministrator on this site
AdminLogin
Take me toDashboardPluginsThemesUsersWooCommerce orders
HVharvest-collective.storeEditor on this site
EditorLogin
BFbramble-fields.orgEditor on this site
EditorLogin
MPmeridian-partners.comAuthor on this site
AuthorLogin
LWlakeside-wellness.coEditor on this site
EditorLogin

What is one-click WordPress login?

One-click WordPress login signs you into a site's wp-admin from a management dashboard without typing a password, using a sign-in link that works once and expires within a minute instead of a shared login. It removes the password spreadsheet, and with it the accounts left behind on client sites when people move on.

WPCentrify gives each person on your team their own one-click login to every WordPress site they are allowed into. They arrive as themselves, at the role you set for them on that site, and removing a person from your workspace ends their sessions on every site at once. Once nobody needs the password form, lockdown can switch off the normal WordPress login for administrators.

WPCentrify one-click login at a glance

  • No shared passwords: everyone signs in as themselves.
  • Sign-in links work once, expire within a minute and never appear in the address bar.
  • A role you set per person per site, applied again at every sign-in.
  • Remove someone once and their sessions end on every site.
  • Optional lockdown refuses the WordPress login form, XML-RPC and application passwords for administrators.
  • The site's own administrator can switch it off from inside WordPress at any time.
The problem

Twelve sites, twelve passwords, one contractor

Every agency has done this. Somebody new needs into twelve client sites, so twelve WordPress administrator accounts get created and twelve passwords get emailed. Three months later that person has moved on and nobody is certain which sites still let them in.

The other common shortcut is worse: one shared account on every site, so the site's own history records the same name for five different people and none of it means anything when a client asks who changed the theme.

One-click login takes the password out of the picture entirely. Access is something you grant in the dashboard and take back in the dashboard.

Access is one part of a wider routine, which our guide to managing WordPress clients from onboarding to offboarding sets out step by step.

What this replaces

  • Hunting through a password manager fifteen times a day
  • One administrator account per person per site, multiplying fast
  • Accounts left behind on client sites after a project ends
  • A shared login that makes five people look like one in the site's history
  • No record of who was in which site, or when
What you can do

Access you grant, and take back, from one place

Sign in as yourself, in one click

Press Login next to any website and you are in wp-admin in a new tab, as your own account. No password prompt, no shared login, nothing to remember about which site uses which email address.

Land exactly where you were going

Choose the screen before you click: the dashboard, Plugins, Themes, Users, Updates, WooCommerce orders or any admin page you name. Your choice is remembered for next time.

Everyone is themselves on the site

The first time somebody signs into a site, an account is made for them there, in their own name and marked as managed by WPCentrify. The site's own history shows who did what, because it really was them. Accounts that already exist on those sites, including the ones left behind by people who have gone, are handled through bulk WordPress user management.

You set the role, per person, per site

Editor on the twelve sites a contractor works on and nothing at all on the other twenty-eight. Or Administrator on one and Author everywhere else. Or every site, including the ones you connect next year. What that person can do inside the dashboard itself is a separate setting, covered by the roles you give them inside WPCentrify. Not sure which WordPress role fits? See WordPress user roles explained. Every session is also written to an audit log you can export.

The cap holds on every sign-in

The role you allowed is applied each time somebody arrives, so lowering it today is what they get tomorrow. Nobody quietly becomes an administrator between one visit and the next.

Remove someone once, gone everywhere

Take a person out of the workspace and every session they hold on every site ends within a minute, their accounts are switched off, and there is nothing to tidy up site by site. Reducing a single grant does the same, immediately.

See who is signed in right now

A live list of every open session across the portfolio, who it belongs to and which site it is on, with a Sign out button on each one.

Works when the login page is hidden

Signing in does not use the WordPress login page, so it keeps working on sites where a security plugin has moved it, rate-limited it or shut it off completely.

Your client stays in charge

The site's own administrator can switch one-click login off, or lockdown off, from inside WordPress at any time. It takes effect immediately and you are told. None of this can be forced on a client.

Lockdown

Once nobody needs the login page, you can close it

This is the part that only becomes possible once passwords are out of the picture. For any site, or all of them, you can switch off the normal WordPress login for administrators. The login form, XML-RPC and application passwords are refused, and the site answers as though there were nothing there to find.

Go one step further and turn away any administrator session reaching wp-admin that did not come through WPCentrify. Customers, subscribers, front-end logins, WooCommerce checkout and everything else on the site carry on exactly as before. The people locked out are the ones guessing at your client's administrator password. Anything that still arrives is flagged by sign-in monitoring.

It is enforced on the site itself, on every request, rather than only inside our dashboard. A tool that hides the button but leaves the door open has not locked anything.

And if it goes wrong

  • The way in is tested end to end first, and the site is not locked if that test fails
  • You are given a single-use recovery link at the moment you switch it on
  • There is an emergency switch in wp-config.php that always works
  • A site that cannot reach WPCentrify for a day relaxes on its own, and tells you
  • The site owner can turn it off from inside WordPress, immediately
On the record

Every login, and everything done after it

A session is not just a line saying somebody arrived. You get who signed in, to which site, as which account, from where, to which screen and for how long, and then what they actually did while they were there: plugins activated or removed, themes changed, users added, settings edited.

It is all in your activity log, filterable and exportable. When a client asks who was in their site on Tuesday and what changed, the answer is a document rather than a recollection.

That record is also what makes access worth granting. Handing somebody the keys is a much easier decision when everything done with them is written down.

Settings the owner controls

  • On or off, per workspace and per website
  • How long a sign-in link lives, and how long a session lasts
  • Require two-factor on the WPCentrify account before this can be used
  • Allow or refuse parallel sessions, and tie links to the requesting address
  • An allowlist of addresses or countries
  • Which identity a person lands as, and the role cap per person per site
Security

Nothing worth stealing is left lying around

A sign-in link lives for under a minute, works exactly once, belongs to the person and the computer that asked for it, and never appears in the address bar, browser history or the site's own logs. Nothing about your team is kept on a client site beyond an account with a role and a password nobody knows. Sessions end on their own after a length you set, with no remember me, and each site keeps checking that a session is still allowed and ends it the moment the answer is no. You can cut off every open session on a site at any time, from the dashboard.

Answers

Questions about one-click login

It creates an account for a person the first time they sign into that site, named after them, at the role you allowed and no higher, with no password anybody knows or could use. Remove the person and the account is switched off. You can also have it deleted outright and its content handed to another user.

Their own WordPress administrator switches it off from inside WordPress. It stops immediately and you are told. Nothing about this can be forced on a client, which is the correct arrangement and worth saying to a nervous one.

There is no reusable password to steal, lose or leave behind. Access is capped at a role you chose, every session is on the record, and taking it away is one action rather than a job on every site. It is a smaller surface than a spreadsheet of admin logins, not a bigger one.

Nobody can sign in through WPCentrify until it is back, and sessions already open end within five minutes. That is deliberate rather than a limitation: access that survives us losing contact is access nobody can withdraw. A locked-down site relaxes its lockdown on its own after a day, and the recovery link and the switch in wp-config always work.

Yes. Signing in does not use the WordPress login page at all, so moving, rate-limiting or hiding that page makes no difference, and lockdown is applied before those plugins run.

Yes, per site or across all of them. The login form, XML-RPC and application passwords are refused for administrators, and you can go further and turn away any administrator reaching wp-admin that did not come through WPCentrify. Customers, subscribers, front-end logins and WooCommerce checkout are untouched.

It tests the way in from end to end before the strictest mode is applied and refuses to lock the site if that test does not pass. You also get a single-use recovery link, there is an emergency switch in wp-config.php, and a site that cannot reach WPCentrify for a day relaxes on its own and tells you.

Every plan. It is part of the platform rather than an add-on, and workspace owners switch it on themselves.

WordPress itself asks for a username and password, so passwordless sign-in comes from a plugin or a management platform. With WPCentrify you press Login next to a site in the dashboard, and a single-use sign-in link opens that site's wp-admin as you, at the role you were given, without a password.

Avoid creating a shared administrator account. In WPCentrify, add the person to your workspace and allow them on the sites they need at the role they need. They sign in with one click, and when the work is done, removing them ends their access on every site at once.

Remove them from your WPCentrify workspace. Every session they hold on every site ends within a minute, the accounts made for them are switched off, and there is nothing to tidy up site by site.

Available now

Stop emailing passwords for client sites

One click in, the right role, the whole session on the record, and one click to take it all back when somebody moves on.

Free during early access. No credit card required.