WordPress maintenance or security needs? Reach out!
TLDWP

Plugin: miniorange-oauth-20-server (Used by 10 domains)

WP OAuth Server ( Login with WordPress )

WP OAuth Server plugin turns your WordPress site into an OAuth Server, enabling Login with WordPress. It allows you to login into Rocket Chat, Invision Community, WordPress, Odoo, EasyGenerator, Salesforce, Zapier, Moodle WordPress SSO, ServiceNow, Edunext, Wickr, Freshdesk, FreshWorks, ServiceNow, ShinyProxy, Knack database, Circle.so, Tribe.so, Tribe, Mobilize, Nextcloud SSO, Church Online, iSpring LMS, Academy of Mine, BoardEffect, TalentLMS, Laravel, PowerSchool, PowerSchool, Joomla, HubSpot SSO, shopify sso integration, MeritHub, Bookstack, Pimcore, 360 Learning, EventMobi, Synology, Drupal, Piano Analytics, Zerotier, and any other OAuth 2.0 compliant applications using WordPress SSO credentials.

| WordPress OAuth Server Setup Guides | API Documentation | Demo / Trial |

You can checkout the below video tutorial to know how to setup SSO with your OAuth/OpenID Compliant Applications.

Basically, the OAuth Server plugin allows users to login into applications that are OAuth 2.0 compliant, facilitating oauth server SSO using their WordPress login credentials. As it’s name suggests, it follows the OAuth 2.0 protocol. Along with that, it also supports OpenID Connect (OIDC), and JWT protocols.

The primary goal of the OAuth Server plugin is to provide Single Sign-On Login with WordPress, so users do not need to remember a username and password for each application.
Using WordPress as OAuth Server, once Single Sign On is enabled, users do not need to store sensitive information to login into different applications.

Discovery URL
The discovery url / well-known endpoint can be used to get metadata about your Identity Server, essential for setting up oauth server SSO. It will return information about the OAuth/OpenID endpoints, issuer URL, supported grant types, supported scopes, key material along with claims in the JSON format. These details can be used by the clients to create an OpenID server request, enhancing the WordPress SSO experience. The well known configuration URL is accessible via /.well-known/openid-configuration, in relation to the issuer URL.

JWT Token Verification
JWT signing, which ensures the integrity of the tokens used during the WordPress SSO process, supports both symmetric and asymmetric algorithms provided by the OAuth Server. The plugin’s free version supports HS256, while the premium version supports RS256, enhancing security especially in scenarios involving HubSpot SSO and Nextcloud SSO.

HS256, a symmetric signature algorithm, indicates that the signature is generated and verified using the same secret key. It is supported in the free version of the OAuth Server plugin, which is useful for basic OAuth Server SSO configurations.

RS256, an asymmetric signature algorithm is different from a symmetric algorithm in that a pair of private and public keys is used to sign and validate the data respectively instead of a single secret key in an oauth server SSO setup.

Why RSA algorithm should be used?
The use of a public and private key pair makes RS256 more secure in comparison to HS256 where the public key is shared and might be compromised whereas in RS256, even if you do not have the control over your client, your data remains secure as it is signed using a private key. The premium version of the OAuth Server plugin supports the RS256 algorithm.

Postman collection
Postman collection JSON is a file that can be used for testing the configuration of OAuth 2.0 flow in the WP OAuth Server plugin without configuring an external OAuth Client by generating the access token and the API call to the resource endpoint subsequently.

LIST OF POPULAR OAUTH CLIENTS SUPPORTED

WORDPRESS OAUTH / OPENID CONNECT SERVER USE CASES

  • If you want to use your WordPress site as an Identity Server / OAuth Server / OAuth Provider and utilize Login with WordPress to access your client site/application with WordPress user’s login credentials, then you can use this plugin. You can also decide what kind of user data/attributes you want to send while Single Sign-On into your client site/application, including Moodle WordPress SSO and Nextcloud SSO functionalities.
  • If you want to login to your Mobile app / Single Page web app (SPA) using your WordPress credentials, then you can use the Authorization code with PKCE flow grant type to achieve your use case.
  • Single set of credentials will be used to login to multiple WordPress websites.
  • You can access the NGINX resources using NGINX Authentication. Once you login into your client application using WP OAuth Server credentials, you will get JWT. Your client application can further use it for NGINX Authentication.
  • Membership sync or role mapping is used to sync the memberships or roles assigned to your users from OAuth Server to OAuth/OpenID Client.
  • Custom Attribute Mapping is helpful if you want to send additional attributes (beyond the default ones) from your WordPress usermeta table to your OAuth/OpenID client using Login with WordPress.

WORDPRESS OAUTH / OPENID CONNECT SERVER FREE VERSION FEATURES

  • Supports Login with WordPress for Single Client application
  • Protocol Support: OAuth 2.0, OpenID Connect (OIDC)
  • Discovery document / well-known endpoint for automatic configuration
  • JWT signing using HS256 or RS256 algorithm (Note: In RS256 algorithm, the keys will be common for all the free version installations)
  • Postman collection for testing OAuth 2.0 flow without actually configuring the client application
  • Server Response: Sends User ID, username, email, first name, last name, display name in the response
  • Grant types Supported: Authorization Code grant
  • Multi-Site Support: Implement the WordPress as OAuth Server within a WordPress Multisite network environment to Login with WordPress users into configured applications.
  • Master Switch: Block / unblock OAuth API calls between OAuth Clients and OAuth Server
  • Token Length: Change the access token length
  • OAuth API Documentation
  • Setup guides to configure the plugin with various OAuth Clients (more coming soon)

WORDPRESS OAUTH / OPENID CONNECT SERVER PREMIUM VERSION FEATURES

  • All FREE version features
  • Supports Login with WordPress for Multiple Client applications
  • Server Response: Sends all the profile attributes along with roles, allows to send custom attributes from usermeta table and also customize the attribute names that need to be sent in server response
  • Grant Types Supported: Authorization Code Grant, Implicit Grant, Password Grant, Client Credentials Grant, Refresh Token Grant, Authorization Code grant with PKCE flow
  • Token Lifetime: Configure the access token and refresh token expiry time
  • Enforce State Parameter: Based on client configuration, you can enable or disable state parameter
  • Authorize / Consent prompt: Enable / disable the consent screen
  • Redirect / Callback URI Validation: Enable / disable this feature, based on dynamic redirect to a different pages for certain conditions
  • JWT Signing Algorithm: Supports signing algorithms HSA and RSA (with dynamic keys for each client setup)
  • Additional endpoints: Provides Introspection endpoint, OpenID Connect Single logout endpoint, Revoke endpoint

A grant is a method of acquiring an access token. Deciding which grants to implement depends on the type of client the end user will be using, and the experience you want for your users.

WE SUPPORT FOLLOWING GRANTS:

  • Authorization code grant : This code grant is used when there is a need to access the protected resources on behalf of the user on another third party application.
  • Implicit grant : This grant relies on resource owner and registration of redirect uri. In authorization code grant users need to ask for authorization and access token each time, but here access token is granted for a particular redirect uri provided by a client using a particular browser.
  • Client credential grant : This grant type heads towards specific clients, where access token is obtained by client by only providing client credentials. This grant type is quite confidential.
  • Resource owner password credentials grant : This type of grant is used where the resource owner has a trust relationship with the client. Just by using username and password, provided by resource owner authorization and authentication can be achieved.
  • Refresh token grant : Access tokens obtained in OAuth flow eventually expire. In this grant type client can refresh his or her access token.
  • Authorization code grant with PKCE flow : This grant type is used for public clients like mobile and native apps, Single Page web apps, where there is a risk of client secret being compromised.

REST API AUTHENTICATION

Rest API is very much open to interact. Creating posts, getting information of users and much more is readily available.
It secures unauthorized access to your WordPress sites/pages using our WordPress REST API Authentication plugin .

DomainExposuresHeadersLast Checked
p*c*o*o*h.com (WP 6.2.2) F Jul 25, 2026
t*e*h*n*a*a*e*y.org (WP 6.2) F Jul 25, 2026
s*r*n*-*a*.com F Jul 20, 2026
r*y*l*c*u*.com F Jul 19, 2026
j*m*s*a*t*n*i*h*.co F Jul 18, 2026
v*s*i*v*d*o*.ru (WP 5.9.13) F Jul 18, 2026
a*d*j*m*s*n.com (WP 6.9.4) F Jul 16, 2026
l*a*n*i*h*i*i.org A Jul 4, 2026
e*t*r.black (WP 7.0) F Jul 3, 2026
l*a*n*i*h*i*i.com A Jul 3, 2026

Top 50 Plugins

Plugin Count
elementor 1,770,800
contact-form-7 1,751,038
elementor-pro 1,053,194
woocommerce 817,228
revslider 608,137
jetpack 454,023
js_composer 419,131
wp-rocket 341,762
essential-addons-for-elementor-lite 264,545
gravityforms 256,827
complianz-gdpr 256,512
google-site-kit 233,580
cookie-law-info 228,020
instagram-feed 224,275
sitepress-multilingual-cms 210,518
header-footer-elementor 206,421
google-analytics-for-wordpress 204,873
bluehost-wordpress-plugin 192,441
elementskit-lite 179,964
gutenberg 167,613
cookie-notice 148,298
litespeed-cache 145,730
gtranslate 124,547
wpforms-lite 123,413
the-events-calendar 122,062
astra-sites 112,933
popup-maker 109,462
woocommerce-payments 109,078
gutenberg-core 103,757
tablepress 102,441
honeypot 97,761
astra-addon 93,695
wp-smushit 90,678
duracelltomi-google-tag-manager 90,484
layerslider 88,961
all-in-one-seo-pack 88,878
coblocks 86,972
bb-plugin 86,693
akismet 84,765
premium-addons-for-elementor 84,160
ml-slider 82,467
cleantalk-spam-protect 82,317
mailchimp-for-wp 81,478
megamenu 80,189
woocommerce-gateway-stripe 79,257
jet-engine 78,153
ewww-image-optimizer 76,933
fusion-builder 76,862
wp-pagenavi 76,554
smart-slider-3 76,050

Top 50 Themes

Theme Count
hello-elementor 621,086
Divi 494,757
astra 413,584
flatsome 141,244
Avada 120,740
generatepress 114,796
oceanwp 80,246
kadence 78,437
pub 72,694
enfold 68,508
salient 64,908
twentyseventeen 54,272
bb-theme 53,314
twentytwentyfour 52,540
betheme 52,499
blocksy 50,868
cocoon-master 49,294
dt-the7 45,385
twentytwentyfive 45,240
woodmart 44,090
neve 38,013
Avada-Child-Theme 36,885
gox 36,389
h4 36,284
bridge 31,203
twentytwentyone 30,240
lightning 30,078
twentytwenty 28,719
swell 28,176
bricks 26,581
Impreza 26,030
Newspaper 24,226
twentytwentythree 22,092
epik-redesign 19,107
twentytwentytwo 18,778
uncode 18,436
pro 17,620
twentysixteen 17,578
storefront 16,303
sydney 16,207
Total 14,335
hello-theme-child-master 14,054
factory-templates-4 13,740
themify-ultra 12,961
extendable 12,656
hestia 12,552
yootheme 12,457
yith-wonder 12,069
porto 11,968
twentyfifteen 11,880