Skip to content

WP Admin login and custom login addresses

How Log in to WP Admin and Visit WP login work, and how Avaloi follows a login page that a security plugin moved to a secret address.

Your site's Info tab has two ways into WordPress admin:

  • Log in to WP Admin signs you in without a password. The link works once and expires after 60 seconds.
  • Visit WP login opens the WordPress login form, where you sign in with your WordPress username and password.

The Domains tab has the same Visit WP login link under the primary domain.

On a WordPress Multisite network, the WordPress network card on Info has Log in to Network Admin. It makes the same single-use link and lands a super administrator in the Network Admin. Anyone else who uses it lands on the dashboard of the main site. Send network: true to POST /v1/environments/{id}/wp-admin-login for the same thing.

Turn one click login off

Each environment has a One click WordPress login card in Tools. Choose Disable to turn Log in to WP Admin off for that environment, and Enable to turn it back on. It works the same on live, staging, and multidevs, because it changes no code.

While it is off:

  • Avaloi makes no login links. The Log in to WP Admin button leaves the Info tab, Log in as leaves the WordPress users list, and the button on User management is disabled with a note that says why.
  • Links made just before you turned it off stop working. The node deletes every login ticket the site still holds.
  • The site answers its one click login address, /.well-known/avaloi-login, with a plain "not found" page, so the address does not reveal itself.
  • Visit WP login still opens the WordPress login page. Everyone signs in there with their WordPress username and password.

Why turn it off. One click login lets anyone with access to your Avaloi company, or an API key with the sites:write scope, open WordPress admin without a WordPress password. Turn it off when your security policy asks that every WordPress sign-in goes through the WordPress login form, for example so a security plugin's two-factor check or login log covers every sign-in, or when people manage the site in Avaloi who should not be WordPress administrators.

The switch runs as a job and is recorded in User activity. Through the API, send PUT /v1/environments/{id}/tools/auto-login with {"enabled": false} or {"enabled": true}. While it is off, POST /v1/environments/{id}/wp-admin-login answers 409 with the code auto_login_disabled and makes no job and no link. The MCP tool set_auto_login_enabled does the same as the switch.

Sites with a custom login address

Security plugins such as Solid Security, WPS Hide Login, Patchstack, and All-In-One Security can move the login page from /wp-login.php to a secret address, for example /my-secret-login/. Visitors who try /wp-login.php or /wp-admin then get an error page.

Avaloi follows the change:

  • The Avaloi MU plugin asks WordPress where its login page is, the same way WordPress builds the address for a visitor who is signed out.
  • Visit WP login opens that address, so the link keeps working after a plugin moves the login page.
  • Avaloi checks the address again when it is more than an hour old, and after a plugin is activated, deactivated, installed, updated, or deleted through Avaloi.
  • Until the site has reported its address, the link opens /wp-login.php.

The link always uses your primary domain, or the temporary domain when the site has no primary domain yet. Only the path comes from the site.

Log in to WP Admin keeps working with these plugins. It signs you in before they check the request, then opens the admin address WordPress reports.

Who can see the address

A custom login address is a secret that keeps bots away from your login form. Avaloi shows it only to people who can see the site in the dashboard, and to API keys with the sites:read scope. It is never part of the public health check.

The API route is GET /v1/environments/{id}/wp-login-url.

Quick answers

Visit WP login opens a page that does not exist. The address may have changed in the last hour outside Avaloi, for example from the plugin's settings in WP Admin. Wait a moment and reload the dashboard, or use Log in to WP Admin, which does not need the login page.

The label says a plugin on this site changed the address, with no name. Code that Avaloi does not recognize, such as a theme or a custom plugin, changed the address. The link still opens the right page.

Can I turn the custom address off? Yes, in the settings of the plugin that set it. Avaloi picks up the change within the hour.

For WordPress users and one-click login as another user, see WordPress users and one-click login.

Still stuck?

Email [email protected] with your site name and what you tried, or send us a message.