Beryl Admin Gate connects a site to the Beryl Studio WP Admin Gate service. The service supplies user authorization, an authenticated proxy, short-lived signed access assertions and known-vulnerability matching. It is a substantive external service, not a license-validation server.
An account and the companion Chrome extension are required for proxy access. The service is currently available as a free beta; future paid subscriptions require separate agreement. Current availability and pricing: https://auth.beryl-studio.jp/. The plugin contains no subscription checkout, time-limited local functionality, remote PHP/JavaScript loader or private signing key. Local configuration checks and optional XML-RPC authentication control work without a service account.
Activation starts in connection-check mode (access restrictions OFF). Registration alone does not enable restrictions. After confirming a connection through the Chrome extension, an administrator can explicitly enable protection. WordPress’s own login is still required. Normal updates preserve the selected protection state; explicit reactivation/reinstallation resets restrictions to OFF while retaining pairing information.
This plugin limits access to administrative routes, including authenticated AJAX and REST requests. Public pages and unauthenticated AJAX remain available. Compatibility with membership plugins, front-end logged-in functionality, external editors, backup tools and other authentication plugins must be tested before enabling protection. It does not guarantee prevention of intrusion, scan all files, patch vulnerabilities or back up the site.
The service provider is Beryl Studio. Service: https://auth.beryl-studio.jp/
Terms: https://auth.beryl-studio.jp/terms/
Privacy policy: https://auth.beryl-studio.jp/privacy-policy/
Setup: https://auth.beryl-studio.jp/gate-setup/
Support: https://beryl-susukino.jp/design/
No WP Admin Gate service request is made merely by activating the plugin. An administrator starts pairing with a registration code and explicitly confirms the external-service disclosure in Settings > WP Admin Gate.
The plugin records login success/failure (submitted username and time) and update events locally, retaining the latest 100 events. These are visible to administrators in the security report and are not included in the service inventory. Stored pairing, settings and reports remain when the plugin is deactivated. Removing the plugin through WordPress deletes its options and temporary challenges from that installation. Deletion does not cancel a service contract or remove the service-side site record; manage those separately in the service account.
PHP 8.1 or later with OpenSSL and mbstring; HTTPS and working WordPress REST API for pairing. A single WordPress installation/site is supported; multisite network activation is not supported in this release. Test Cloudflare/WAF rules, custom login URLs and other security plugins before enabling access restrictions.