Licence and account

Storing your provider key with us

Optional. Paste your API key once, encrypted, and let every site collect it.

What this is for

Normally you paste your Claude, DeepL or OpenAI key into each site. That is fine for one site and tedious for twenty, and worse when the key changes and twenty sites need editing.

So your account has a store. Put the key there once, and any site on any of your licences can collect it with a button in the plugin. It is off unless you use it, and nothing else in WPGlotty depends on it.

How it is kept

The key is strongly encrypted before it is stored.

It is tied to your account, so a stored key cannot be moved to somebody else’s. And it is never shown again to anybody, us included: there is no screen, no export and no support procedure that reveals one. Your page shows the provider, the last four characters and the date.

Two things are needed, not one

This is the part worth understanding. A licence key sits in wp_options on every site you run, in every backup of those sites, and in every staging copy somebody made and forgot. If it alone could collect your provider key, your Anthropic account would be exactly as safe as your least-maintained WordPress install.

So collecting takes the licence key and a code. You open a window on your account page and it shows you a code; you type that into the plugin. The code is good for fifteen minutes, and one of them sets up as many sites as you can get through in that time.

A key found in an old backup collects nothing, because the code was never in the backup. Five wrong guesses and the window shuts itself.

Checking a key works

Beside each stored key there is a Test. It asks the provider whether it recognises the key and reports what came back: recognised, refused, or the provider being unreachable, which is a verdict on them rather than on the key.

It translates nothing, so it costs nothing and you can press it as often as you like. A key that is refused usually means half of it was copied, or it was revoked at the provider.

You see everything that happens

Every collection is listed on your account with the site, the address it came from and the time, and e-mailed to you. So is every refusal, which is the more interesting one: something trying a licence key without the code is exactly what you would want to hear about.

Delete a key and it is gone from our side at once. Sites that already collected it keep their copy, which the plugin also stores encrypted, keyed off that site’s own WordPress salts. Change the key at your provider if you want those copies to stop working too.

If you would rather not

Then do not, and nothing changes. Paste the key into each site as before. We never see it, it goes from your server to your provider, and that remains true for as long as you leave this store empty.

One thing to know if you do use it: a site that has collected holds every key you stored, not only the one it translates with. That is worth a thought before putting the store to work on a site you do not control.