Skip to content

Add your first site

Pairing proves you control the WordPress admin. The plugin generates an authorization token; you paste the site URL and token into ConstellaWP. The SaaS then calls the agent over HTTPS, verifies the token, and registers the site.

  • Administrator access on the WordPress site
  • WordPress 6.0 or higher, PHP 8.1 or higher
  • A ConstellaWP account with permission to add sites (owner or admin)
  1. Get the plugin package (zip from ConstellaWP, or the constellawp-agent repository).
  2. In WordPress, go to Plugins → Add New → Upload Plugin and upload the zip, or copy the constellawp-agent folder into wp-content/plugins/.
  3. Activate ConstellaWP Agent.

On activation the plugin creates a token: cwa_ followed by 64 hexadecimal characters. It is stored encrypted in the WordPress database (AES-256-GCM using WordPress salts).

  1. In wp-admin, open Settings → ConstellaWP.
  2. Copy the Site URL (the public URL of the site).
  3. Copy the Authorization Token.

Keep the token private. Anyone with it can authorize ConstellaWP to talk to the agent.

  1. Sign in at app.constellawp.com.
  2. Open Sites and choose Add New Site.
  3. Paste the Site URL and Authorization Token.
  4. Submit. ConstellaWP verifies the plugin (GET /wp-json/constellawp-agent/v1/status), then authenticates (POST .../verify) and registers a site_id on the agent (POST .../register).

When that succeeds, the site appears as active. Heartbeats start, and an inventory job can run.

  • Open the site dashboard to see WordPress version, PHP, pending updates, and recent events.
  • Add a storage destination before you can run backups.
  • Optionally link a hosting account from the site’s Settings or the organization Hosting page.

If you regenerate the token in Settings → ConstellaWP, or reinstall the plugin, the old token stops working. In ConstellaWP, open the site Settings, paste the new token under Authorization Token, and reconnect.

Revoking the site from ConstellaWP stops monitoring immediately. The plugin stays installed until you deactivate it in WordPress.

If pairing fails, see Connection troubleshooting.