Skip to content

Connecting a site

Connecting a site is a one-time pairing between the WordPress agent and your organization. After that, ConstellaWP talks to the agent over HTTPS with HMAC-SHA256 signed requests.

  1. You install and activate the ConstellaWP Agent.
  2. The plugin generates a token (cwa_ + 64 hex characters) and shows it under Settings → ConstellaWP.
  3. In ConstellaWP you submit Site URL + Authorization Token.
  4. ConstellaWP checks that the plugin REST API is up, verifies the token, and posts a site_id back to the agent.
  5. The agent stores the SaaS URL and site_id, marks itself connected, and starts heartbeats.

Older agents (before 1.1.0) used a 32-character hex token without the cwa_ prefix. ConstellaWP still accepts those.

  • Public site URL, name, and optional site icon
  • WordPress version, PHP version, plugin version
  • Capabilities reported by the agent (WP-CLI, shell_exec, disk space, restore support, and similar)
  • Connection status and last heartbeat time

The raw agent token is stored hashed (SHA-256) on the SaaS. It is never shown again after pairing. Storage credentials for backups live on the organization, not on the site.

Use Settings → Authorization Token on the site when:

  • You regenerated the token in WordPress
  • You reinstalled or copied the site to a new server and the token changed
  • Jobs fail with authentication errors (invalid_signature, invalid_token)

Paste the current token from Settings → ConstellaWP and reconnect. Owners and admins can do this; members cannot.

Settings → Revoke disconnects the site from ConstellaWP. Monitoring and jobs stop immediately. The plugin remains in WordPress until you deactivate it. Only owners and admins can revoke; only owners can delete the site record.

Every authenticated call uses:

X-ConstellaWP-Signature: HMAC-SHA256(token, timestamp + nonce + body)
X-ConstellaWP-Timestamp: unix time
X-ConstellaWP-Nonce: 32 hex characters

Timestamps must be within 5 minutes. Nonces are remembered for 10 minutes to block replays. The agent refuses a SaaS URL that is not HTTPS (except in development).

If something goes wrong, continue to Troubleshooting.