🔐 Mandatory WordPress Support Flow: Secure Token-Based Access

Camilo Aponte

Camilo Aponte

Last updated on Sep 30, 2026

To improve security, accountability, and compliance, Search Atlas no longer supports accessing customer WordPress environments via shared usernames or passwords.

All WordPress support access must be granted via temporary Support Access Tokens, generated directly by the customer inside their WordPress admin.

This flow is mandatory and replaces all previous credential-sharing practices.

✅ What’s Changing (High Level)

  1. No more WordPress usernames or passwords shared, stored, or requested
  2. Temporary, revocable access via secure token links
  3. Admin-only access, controlled by the customer
  4. Time-limited access with automatic expiration
  5. Full visibility and accountability of who accessed what, and when

🧩 Prerequisites (Required)

Before support access can be granted, all of the following must be true:

  1. Plugin version must be 2.5.16 or higher. Any version below 2.5.16 is not supported and cannot use token-based access.
  2. The customer must be logged in as a WordPress ADMIN. Only Admin users can generate support tokens.

🛠️ The Mandatory Support Flow (Step by Step)

1. Customer updates to the latest plugin version. Minimum supported version: v2.5.16. Without this version, support access cannot be granted.

2. Customer generates a Support Access Token. Path inside WordPress: WordPress Admin → Settings → Support Access. From here, the customer can choose an expiration time (for example, 4 hours), add a short description (bug, issue, investigation context), and generate a secure, temporary access link.

3. Customer shares the secure link. The generated link is shared with Customer Support, Product Specialists, and the WordPress Team if needed. No usernames or passwords should ever be sent.

4. Search Atlas team accesses WordPress via the link. Using the link, team members are automatically logged in as ADMIN, and access uses the same User ID that generated the token. Full admin-level debugging and investigation is allowed.

5. Access is revoked after work is completed. Once the issue is fixed, tested, or fully investigated, the Search Atlas team must revoke the support token and inform the customer that access has been terminated. This is a required step, not optional.

6. If the token expires before work is finished. Tokens may expire based on the timeframe chosen by the customer. If this happens, politely request a new Support Access Link, clearly explain why additional access is needed, and never attempt to reuse or bypass expired tokens.

🚫 Critical Rules (Non-Negotiable)

Do not ask for, store, or accept WordPress usernames or passwords.

👑 Admin Role Required

Only WordPress Admins can generate tokens and grant support access.

📁 Exception: FTP Access

This flow applies only to WordPress admin access. If FTP access is required, the existing FTP request process remains unchanged, coordinate via CS/PS as usual.

🧠 Why This Matters

This flow protects customer security, reduces liability, improves trust, and creates a clear, auditable support process. Following this process is mandatory for all WP-related support cases.

📌 Summary

  1. Token-based access is now the only approved method
  2. Credentials are no longer allowed
  3. Access is temporary, revocable, and customer-controlled
  4. Expired access means requesting a new token
  5. Security first, always

This WordPress Support Access flow marks a fundamental shift in how we provide secure, reliable, and compliant support to our customers. By fully eliminating credential sharing and moving to a controlled, token-based access model, we protect both our customers’ environments and our own teams while maintaining the level of support quality they expect from Search Atlas.

If you need further assistance, open the chat widget in the bottom-right corner of the platform and type human teammate to be connected with a member of our team.