Skip to content

WordPress JWT Auth

Replaces WordPress logins with single sign-on through an OIDC provider or an identity-aware proxy, configured entirely in wp-config.php.

WordPressActiveMIT
View on GitHub (opens in a new tab)
Platform

WordPress

License
MIT
Status
Active

Passwords are the weakest part of most WordPress sites, and managing accounts site by site doesn't scale. This plugin hands authentication to an identity provider you already trust. Every login goes to the provider, accounts are created on demand, and password login is refused on every path WordPress exposes. There's no admin screen; everything is set with constants in wp-config.php, so it's easy to manage across many sites.

Features

  • OIDC mode. Redirects to your provider with PKCE by default, discovering endpoints from the issuer automatically.

  • Proxy mode. Trusts a signed JWT injected by an upstream proxy such as Cloudflare Zero Trust, checked against the provider's keys and audience.

  • No password logins. Username and password attempts fail everywhere, including XML-RPC, application passwords, and WooCommerce checkout. WP-CLI and cron are exempt.

  • WooCommerce aware. Adds a sign-in button to My Account and Checkout. Exclusive mode removes the password forms and closes the reset, registration, and checkout account flows that would otherwise hand out a session without asking the provider.

  • Email-PIN provider. A companion Cloudflare Worker can act as a multi-tenant OIDC provider that signs people in with a six-digit emailed code or magic link, with single sign-on across your sites.

  • Local development friendly. Native login can stand in on development environments.

Getting started

Download the release zip from GitHub Releases, upload it as a plugin, and add your provider's constants to wp-config.php. The README has checklists for Zitadel and Cloudflare Zero Trust. Requires PHP 8.4 and WordPress 6.4 or later.

Related projects

All open-source projects

Stores and serves the WordPress media library from S3-compatible object storage, with direct browser uploads and document thumbnails.

GPL-3.0-or-laterGitHub

Routes all WordPress email through the Cloudflare Email Sending API and keeps a searchable log of every message, with no settings screen.

Need help with it?

Need this implemented? Our Websites team sets up single sign-on for WordPress and WooCommerce.