Skip to content

Connect a site

A connected site is a live WordPress site you host, paired to your workspace through the ReDock Connect plugin. There are two ways in and they end in the same place. Pair one site by hand and you paste a key the site printed. Onboard a list and ReDock Web makes a short code per site, which somebody types into the plugin on each one.

Either way the site keeps its own key, and it is the site that hands the key over.

  1. In ReDock Web, open Pair a site. The card at the top of the page has the plugin on it: press Download ReDock Connect and you get the zip.

    The top of the Pair a site page. A card headed Don’t have the plugin yet? lists three steps, upload it under Plugins then Add New then Upload Plugin, activate it, open Settings then ReDock Connect, and carries a Download ReDock Connect button next to the file name redock-connect-1.12.0.zip.

  2. On the WordPress site, go to Plugins → Add New → Upload Plugin, upload that zip, and activate it.

  3. In the same site’s wp-admin, open Settings → ReDock Connect. This page is the whole switch: every way into the site is a key listed on it, and revoking one stops that client working straight away.

    The ReDock Connect settings page inside wp-admin, headed ReDock Connect, explaining that the plugin pairs the site with ReDock, that every request must be signed with a connect key, that wp-config.php never leaves the site, and that revoking a key stops that client immediately.

  4. Under Add a client key, give the key a name you will recognise later, choose what it is used by, and press Add a client key. The key starts rdk1_ and is shown once. Copy it before you leave that screen.

  5. Back in ReDock Web on Pair a site, type the site address, paste the key, and press Pair site. ReDock Web asks the site to prove the key with a signed request before it saves anything.

    The Pair a site form: a Site address field showing the placeholder your-site.com, a Connect key field showing rdk1_, and a green Pair site button, with a note saying pairing also installs ReDock Blocks on the site through the same signed channel.

  6. The site appears on All sites a moment later, with its state, its ReDock Connect version, when it last answered, and its client group.

    The All sites list showing twelve sites sorted so the ones in trouble come first, each row carrying a state pill, the ReDock Connect version, when the site last answered, and the client group it is filed under.

Pairing also installs ReDock Blocks on the site, through the same signed channel, so the design tools work there without anybody uploading anything by hand. If that part fails the site is still paired, and its row offers the fix.

Taking on a client usually means a dozen sites at once, so Onboard a list is built for a paste rather than a form.

  1. Open Onboard a list and paste the addresses, one site per line. Up to a hundred from one paste. An address with https:// or just the domain, either works. Nothing is contacted yet.

  2. Pick the client group the batch should join, or type a new one. Every site in the batch is filed under it as it lands, so the filing happens once rather than site by site afterwards.

    The Onboard a list page: a large box holding three site addresses one per line, a Client group picker, a field for a new group, and a green Make the codes button.

  3. Press Make the codes. Each site gets a code of eight characters, from an alphabet with nothing in it that can be misread. The codes are shown once and cannot be looked up again, so print the list or copy it somewhere safe before you leave the page. A lost code is replaced with New code, not recovered.

    The Codes page. A warning strip says these codes are shown once and cannot be shown again. Under it, each site has a large monospace code such as 6GGRVXA9 and a line saying to enter it on that site under Settings, ReDock Connect.

  4. On each site, an administrator opens Settings → ReDock Connect, types that site’s code and presses Connect. The site then sends its own key straight to ReDock Web over its own connection. Nothing is pasted, and the key never touches a clipboard or a browser address bar.

  5. Watch the batch. Rows turn green as the sites answer. A code lasts 24 hours, works once, and dies on the fifth wrong try, so a row that has been tried four times says so.

    A batch on the Onboard a list page: five sites with their states, two Connected in green, two Waiting with an expiry time, and one marked Needs attention after four wrong tries, each waiting row offering New code.

The site keeps the key. Every request between the site and ReDock Web is signed with it, and a request that is not signed correctly is refused. What ReDock Web stores is a working key derived from the one the site holds, wrapped under a secret only ReDock Web has. The key you pasted is discarded the moment it has been checked.

The key reaches inside the folders a site is edited in. It cannot touch wp-config.php or the site root.

One site can be paired with more than one client, each with its own key: your desktop app, your workspace, a colleague’s. The plugin’s settings page in wp-admin lists them all with a Revoke next to each, and Revoke all ends every one of them at once. Deactivating the plugin ends every connection too.

Revoking on the site is the end of it. There is no cookie session and no second door.


No account yet? Create one at app.redock.xyz, then come back to step 1. Already signed in? Open ReDock Web.