Built by the company that had to trust it first

TrustedLogin came out of GravityKit’s own support team, and GravityKit still runs its support through it every day.

Origin, specific and honest

Zack Katz founded GravityKit, a WordPress plugin business now in its second decade, built on GravityView and its add-ons. Running support for GravityView, the recurring bottleneck wasn’t the bugs; it was getting access to look at them. Every ticket that needed a site login added a round of email, a wait, and often a password left sitting in the thread afterward. TrustedLogin started as the fix for that, inside GravityKit, before it was a product anyone else could buy.

Why that matters to you

GravityKit is a profitable, decade-old WordPress business, not a startup spending a raise to find a market. It runs its own support team through TrustedLogin today: the same grant flow, the same dashboard, the same expiry rules you’d get. Whenever a GravityKit customer asks, that’s what the same flow gets them: someone inside the site within minutes, fixing instead of describing, with a record that they were there. If TrustedLogin broke in a way that mattered, GravityKit’s own support team would feel it before any customer does.

The TrustedLogin dashboard for a new team: usage cards for logins and sites accessed against the plan's monthly caps, a Recent Logins panel with a View all activity link, and a three-step Connect your first site guide covering API credentials, installing the Connector plugin, and granting access.

Small team, on purpose

TrustedLogin is run by a small team. That’s not an apology. It means fewer people who could mishandle a customer’s access request, a shorter chain between a bug report and a fix, and nobody routing your support data through a department that’s never touched the product. What it means concretely: the structural safety below is a claim you can verify yourself, not one you have to take on trust.

The structural safety

Three things hold regardless of team size, and regardless of whether TrustedLogin as a company is still around in five years:

The SDK is open source: read exactly what runs on your customer’s site at github.com/trustedlogin/client. The Connector is GPL-licensed and its full source ships through WordPress.org.

The Connector has been live on WordPress.org since September 2024: a public listing, public reviews, public version history, not a private build only we can see.

Every grant is a real WordPress account the customer’s own site created. The customer, or their host, can revoke it directly in wp-admin, with or without TrustedLogin’s service being reachable.