Skip to main content

Setup

Setup

Start with one administrator account before enforcing login requirements for a wider team.

  1. Install and activate the Awthy plugin once the WordPress.org package is available.
  2. Open the account-security page.
  3. Test email recovery with a non-critical account and confirm the message arrives.
  4. Enroll TOTP for the primary administrator.
  5. Store recovery material somewhere private and durable.
  6. Test a login challenge in a private browser session.
  7. Only then consider enforcement for administrators or staff.

Recovery before enforcement

Awthy setup is recovery-first. Do not turn on stricter role enforcement until a real recovery path has been proven:

  • Email recovery has delivered to a mailbox the account owner controls.
  • Recovery codes have been generated, saved, and kept outside the WordPress dashboard.
  • The last administrator has a way back in that does not depend on an already-authenticated browser session.
  • Customer-facing WooCommerce flows have been tested before any customer enforcement claim is published.

Availability note

Before the WordPress.org listing is live, public CTAs should route to product-access contact or setup documentation. Do not publish install instructions that imply the listing is already available.