Stop leaving logins in a shared vault

The Connector plugin gives your agency scoped, time-boxed access to client sites, logged per login, without a password that outlives the project.

The TrustedLogin Sites screen listing every customer WordPress site that has granted the team access, with columns for Site, Connected, Expires, Access Key, Last login and Status, and a Log in button on each row.

The moment this is for

A client relationship ends, or a contractor rolls off the account, and somewhere there’s still a shared 1Password entry with that client’s admin password in it, unrotated, because rotating it means touching a live site nobody wants to touch. Every client you’ve ever had adds one more entry to a vault that’s become a liability with a search bar.

What changes with the Connector

Install the Connector plugin on your own agency site once. Each client site that’s granted you access shows up there, with the duration and role your team was given, not a standing password you have to remember to revoke. When the engagement ends, there’s no vault entry to clean up; access already expired, or you revoke it in one click.

The TrustedLogin Connector's setup screen in WordPress admin, headed Create your first team, with fields for Account ID, Public Key and Private Key, a picker for which roles provide support, and a Help Desk selector.

Compared to a password vault

A vault like 1Password is real infrastructure for a real problem: role-based sharing, breach monitoring, credentials that live outside WordPress entirely. It doesn’t solve this one. The password it shares is still a standing WordPress password, and revoking it means rotating it on the live site, not toggling something off in the vault.

TrustedLogin doesn’t share a password in the first place, so there’s nothing standing to leave behind when the engagement ends.

A single site's record in TrustedLogin, showing the site domain, its expiry time, a Log in to site button, a Revoke access button, and an Access Info panel listing the access key, secret ID, who connected it, when it was created and when it expires.

The fleet view

Every client site that’s granted your agency access shows up in one dashboard: what role you have, when it expires, who on your team used it and when. Whenever a client asks for a hand, someone on your team can be inside that specific site within minutes, working the actual problem instead of scheduling a call about it. That’s the audit trail a client can ask for after the fact, and the one you’d want if you ever had to prove nobody on your team was in a site they shouldn’t have been.

Getting client sites set up

Client sites need the piece that lets them grant you access in the first place, installed on the client’s site, not yours. If a client already runs a plugin built on the TrustedLogin SDK, they can likely grant you access through it directly. If not, talk to us about the setup that fits an agency without a product of its own.

One-time secrets

When a credential has to travel — an API key, a hosting login, a database password — it travels through a one-time link that TrustedLogin itself can’t open, not through the ticket. The link is created and stored on your own WordPress site, set to disappear the moment it’s read or at an expiry you choose up to 30 days, and it leaves a record of who opened it and when.

Who this is for

For agencies and maintenance shops with a fleet of client sites they don’t host, and two or more people who log into those sites every week.

If you hold the admin passwords for three sites you built yourself, a vault is doing the job. This starts paying once the fleet outgrows the person tracking it.