# Connect a site to BetterShield Hub

Connect a WordPress site to BetterShield Hub: choose read-only or read-and-fix, approve it on the site’s own consent page, and disconnect at any time.

BetterShield Hub is a free, optional dashboard for people who look after several sites. You connect each site from its own **BetterShield › Hub** screen (listed as **BetterShield Hub** under Agents in the plugin's sidebar). The same card is on **Settings › General** under **What leaves this site**, and at the end of Quick Setup as **Connect to BetterShield Hub**.

## Before you start

- The site runs BetterShield 1.1.0 or newer.
- You are signed in as an administrator who can manage BetterShield. The same account starts the connection and approves it.
- Everything in BetterShield works without the hub. Nothing on the site waits on it.

## Connect a site

1. Go to **BetterShield › Hub**.
2. Under **What the hub may do**, choose **Read this site and apply fixes that can be undone** (the default) or **Read this site only**.
3. Press **Connect to BetterShield Hub**.
4. Your browser opens BetterShield Hub, which brings you back to this site's own consent page. Finish within 15 minutes, or start again from step 1.
5. Check the consent page and press **Connect**. **Not now** cancels.

Before your browser leaves, BetterShield turns on what the connection needs under **Agents › Connect**, if it is off: **Let an assistant connect to this site** and **Let my agent read security information**, plus **Let agents act: changes that can be undone right away, anything heavier once you agree** for read-and-fix. It never turns any of them off.

## The consent page

The page is titled **Connect an assistant** and lists the **Site**, who you are **Signed in as**, and where it **Sends you back to**, which should be the hub's address.

- **Allow it to change this site** appears when you chose read-and-fix, and is ticked by default. Untick it to connect read-only.
- If **Ask for my password before an action that removes a protection** is on under **Settings › General**, the page asks for your password to allow changes. Unticking the box connects for reading without it.
- The page refuses a hub connection that was not started from this site's dashboard by the account approving it.

## What the hub can see and do

- **Read this site only**: the hub sees the score, findings and a few security views, such as administrators by display name and role. It changes nothing.
- **Read this site and apply fixes that can be undone**: the hub can also apply and undo fixes, and only ones that can be undone.

Either way:

- The score, findings and fixes are still worked out on the site. The hub shows what the site reports.
- The connection runs as the account that approved it, and every change the hub makes is recorded in the site's activity log.
- Changes to how people sign in, and taking a protection off, wait for a person to agree each time.
- The site never contacts the hub. The hub contacts the site, and checks every few minutes that its front page answers.

If you later turn off **Let agents act: changes that can be undone right away, anything heavier once you agree** under **Agents › Connect**, the hub can still read but changes nothing. See [BetterShield Hub](/bettershield-hub/) for what the hub does with this across your sites.

## Hub address

The card shows **Hub address**, `https://hub.bettershield.ai` by default.

| Option | What it does | Default |
|---|---|---|
| **Change** | Opens the **Hub address** field. Enter an https address with no query, fragment or user name, then press **Save address**. Leave it empty for the default. | Not shown while connected ("disconnect to change it") |
| `BETTERSHIELD_HUB_URL` in wp-config.php | Pins the address, for hosts that manage many sites. The card then shows "(set in wp-config.php)" and the address cannot be changed on screen. | Not set |

To move a connected site to another hub address, disconnect, change the address, then connect again.

## If the card says the hub is refused

A connected site can still refuse the hub, and the card names why:

- The site is marked as a staging copy. Undo that answer on the **Overview**.
- **Let an assistant connect to this site** is off under **Agents › Connect**.
- **Let my agent read security information** is off under **Agents › Connect**.

The connection is kept, and the hub is let in again once every reason is undone.

## Disconnect

1. Go to **BetterShield › Hub**.
2. Press **Disconnect**. Every hub connection on this site ends at once.

The connection is also listed under **Agents › Connect** in **Connected apps**, where **Revoke** ends it too.

> **Note:** Removing a site inside the hub does not end the connection. Only Disconnect (or Revoke) on the site does.

Disconnecting leaves the **Agents › Connect** switches as they are. Turn them off there if no other assistant uses them.

## Related

- [BetterShield Hub](/bettershield-hub/)
- [Connect an AI assistant](/docs/connect-an-ai-assistant/)
- [Hardening](/docs/hardening/)
- [Install and set up](/docs/install-and-set-up/)
