Connecting a site
Connecting a site is a one-time pairing between the WordPress agent and your organization. After that, ConstellaWP talks to the agent over HTTPS with HMAC-SHA256 signed requests.
Pairing flow
Section titled “Pairing flow”- You install and activate the ConstellaWP Agent.
- The plugin generates a token (
cwa_+ 64 hex characters) and shows it under Settings → ConstellaWP. - In ConstellaWP you submit Site URL + Authorization Token.
- ConstellaWP checks that the plugin REST API is up, verifies the token, and posts a
site_idback to the agent. - The agent stores the SaaS URL and
site_id, marks itself connected, and starts heartbeats.
Older agents (before 1.1.0) used a 32-character hex token without the cwa_ prefix. ConstellaWP still accepts those.
What ConstellaWP stores
Section titled “What ConstellaWP stores”- Public site URL, name, and optional site icon
- WordPress version, PHP version, plugin version
- Capabilities reported by the agent (WP-CLI,
shell_exec, disk space, restore support, and similar) - Connection status and last heartbeat time
The raw agent token is stored hashed (SHA-256) on the SaaS. It is never shown again after pairing. Storage credentials for backups live on the organization, not on the site.
Reconnect
Section titled “Reconnect”Use Settings → Authorization Token on the site when:
- You regenerated the token in WordPress
- You reinstalled or copied the site to a new server and the token changed
- Jobs fail with authentication errors (
invalid_signature,invalid_token)
Paste the current token from Settings → ConstellaWP and reconnect. Owners and admins can do this; members cannot.
Revoke
Section titled “Revoke”Settings → Revoke disconnects the site from ConstellaWP. Monitoring and jobs stop immediately. The plugin remains in WordPress until you deactivate it. Only owners and admins can revoke; only owners can delete the site record.
HTTPS and signatures
Section titled “HTTPS and signatures”Every authenticated call uses:
X-ConstellaWP-Signature: HMAC-SHA256(token, timestamp + nonce + body)X-ConstellaWP-Timestamp: unix timeX-ConstellaWP-Nonce: 32 hex charactersTimestamps must be within 5 minutes. Nonces are remembered for 10 minutes to block replays. The agent refuses a SaaS URL that is not HTTPS (except in development).
If something goes wrong, continue to Troubleshooting.