MultiCmsManager

One-click login

One-click admin login to client sites, without shared passwords

Spreadsheets of client passwords are a risk no agency should take. One click takes you into the admin, and there’s a record of who did it.

The problem

Shared passwords, forgotten accounts.

Every site has its own admin, its own password and often an “agency” account shared by the whole team. When someone leaves, nobody really changes the passwords.

And a password reused across dozens of sites is an invitation to whoever finds it.

How it works

A link that works exactly once.

  1. 1

    Signed request

    The platform asks the site for a login link with a signed request.

  2. 2

    Single-use link

    The site creates a random token valid for 60 seconds, stores only its hash and returns the link.

  3. 3

    Logged access

    The login uses the CMS’s own flow and is recorded both on the platform and in the site’s log.

In detail

Secure by design.

  • Random 32-byte token, valid for 60 seconds, usable once
  • Link accepted only if it points to the site’s own domain
  • Only for active administrators, checked again at login
  • Security plugins and CMS logs record it like a normal login
  • The site owner can turn it off in the plugin settings
  • Two-factor authentication mandatory on the platform

FAQ

Frequently asked questions

Does one-click login bypass the site’s 2FA?

Yes, because security lives in the platform account, where two-factor authentication is mandatory. The site owner can still turn the feature off.

Does it work with Joomla?

Yes, it uses the same flow as Joomla’s own passwordless login, so user plugins and action logs work as usual.

Try it on your clients’ sites.

During the beta we welcome agencies in small groups and set up the first sites together.