Click WP Admin on any site in Console and you are signed in to that site’s WordPress admin, with no password. This article covers how to choose which WordPress user you land as, and the small plugin you will see on your site that makes the button work.
This feature was previously called single sign-on (SSO) in Console and in older versions of this article. Same button, clearer name: it is a one-click login.
Choosing who you sign in as
The WP Admin button shows who you will be signed in as. The first time you click it on a site, Console asks which WordPress user to use (Open WP Admin as):
You can pick any WordPress user, not just administrators. Choose an Editor or Author to work with fewer permissions, or your own account so changes are attributed to you.
Tick Remember my choice to make that user your default for the site.
If the site has only one administrator, the picker is skipped and you land as that user.
Changing the default later
The WP Admin button is a split button: it shows who you will sign in as, and its Change user option lets you pick someone else.
You can also set it from the users list:
Open the site in Console and choose Users under WordPress.
Edit the user you want and tick Use for one-click login.
The current default shows a Login User badge in the users table. One thing worth knowing: the sign-in action next to each user on that list logs you in as that user once, without changing your remembered default.
The plugin you will see on your site
Under Plugins → Must-Use in your WordPress admin there is a plugin named Hosting Tools One-Click Login (older versions were named Hosting Tools SSO). It is installed and maintained by Wordify on every site we host, and it is what makes the WP Admin button work. You did not add it, and nothing is wrong.
What it does: when you click WP Admin, Console creates a single-use login token for the user you chose. The plugin on your site checks that token and signs you in. That is the whole job.
It only acts when a login link is used. On ordinary page loads it does nothing beyond a quick early check.
It does not collect data or send anything from your site.
Tokens are single use and short-lived. A used or expired link lands on the normal WordPress login screen.
It cannot be deactivated from wp-admin. WordPress treats every must-use plugin that way, and here it is deliberate: it keeps one-click login working reliably on every site we host.
Which user should you choose?
Pick the account that matches how you want to work:
Administrator: full control of the site, for managing settings, plugins, and content.
A lower role such as Editor or Subscriber: open the site with limited permissions when you only need a restricted view.
Your own personal login: sign in as yourself so your activity is attributed to your account.
If you have questions about any of this, our support team is available 24/7 with a one-hour response time. Reach out from your dashboard.