WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: wp-rest-api-authentication (Used by 18 domains)

JWT Authentication for WP REST APIs

👤 miniOrange 📦 v4.3.0 🔗 Plugin Homepage

WordPress REST API endpoints are open and unsecured by default which can be used to access your site data. Secure WordPress APIs from unauthorized users with our JWT Authentication for WP REST APIs plugin.

Our plugin offers below authentication methods to Protect WP REST API endpoints:
JWT Authentication
Basic Authentication
API Key Authentication
OAuth 2.0 Authentication
– External Token based Authentication 2.0/OIDC/JWT/Firebase provider’s token authentication methods.

You can authenticate default WordPress endpoints and custom-developed REST endpoints and third-party plugin REST API endpoints like that of Woocommerce, Learndash, Buddypress, Gravity Forms, CoCart, etc.

WP REST API Authentication Methods in our plugin

  • JWT Authentication
    Provides an endpoint where you can pass the user credentials, and it will generate a JWT (JSON Web Token), which you can use to access the WordPress REST APIs accordingly.
    Additionally, to maintain a seamless user experience without frequent logins needed due to token expiry, you can use our Refresh and Revoke token mechanisms feature.
    When the access token expires, instead of forcing the user to log in again, the client can request a new access token using a valid refresh token.
  • API Key Authentication
  • Basic Authentication:
    – 1. Username: Password
    – 2. Client-ID: Client-Secret
  • OAuth 2.0 Authentication
    – 1. Password Grant
    – 2. Client Credentials Grant
  • Third Party Provider Authentication

Following are some of the integrations that are possible with WP REST API Authentication:

  • Learndash API Authentication
  • Custom Built REST API Endpoints Authentication
  • BuddyPress API Authentication
  • WooCommerce API Authentication
  • Gravity Form API Authentication
  • External/Third-party plugin API endpoints integration in WordPress

You can also disable the WP REST APIs with our plugin such that no one can make API calls to your WordPress REST API endpoints.Our plugin also provides Refresh and Revoke Token that can be used to improve the API security.

Benefits of Refresh Token

  • Enhances security by keeping access tokens short-lived.
  • Improves user experience with uninterrupted sessions.
  • Reduces login frequency.

Benefits of Revoke Token

  • Protects against token misuse if a device is lost or compromised.
  • Enables admin-triggered logouts or session control.
  • Useful for complying with stricter session policies.

With this plugin, the user is allowed to access your site’s resources only after successful WP REST API authentication. JWT Authentication for WP REST APIs plugin will make your WordPress endpoints secure from unauthorized access.

Plugin Feature List

FREE PLAN

  • Authenticate only default core WordPress REST API endpoints.
  • Basic Authentication with username and password.
  • JWT Authentication (JSON Web Token Authentication).
  • Enable Selective API protection.
  • Restrict non-logged-in users to access REST API endpoints.
  • Disable WP REST APIs

PREMIUM PLAN

  • Authenticate all REST API endpoints (Default WP, Custom APIs,Third-Party plugins)
  • JWT Token Authentication (JSON Web Token Authentication)
  • Login, Refresh and Revoke token endpoints for token management
  • API Key Authentication
  • Basic Authentication (username/password and email/password)
  • OAuth 2.0 Authentication
  • Universal API key and User-specific API key for authentication
  • Selective API protection.
  • Disable WP REST APIs
  • Time-based token expiry
  • Role-based WP REST API authentication
  • Custom Header support rather than just Authorization to increase security.
  • Create users in WordPress based on third-party provider access tokens (JWT tokens) authentication.

Privacy

This plugin does not store any user data.

DomainExposuresHeadersLast Checked
f*a*c*i*e*a*k*t*n*t*o*s.com (WP 6.9.4) C 2026-06-03 03:55:34
s*c*i*r*o*l*.com (WP 5.4.19) ⚠️ F 2026-06-01 06:02:57
d*o*c*e*.cz (WP 5.5.18) ⚠️ F 2026-05-30 22:59:59
s*e*e*-*o*t*o*i*.f*y*h*e*s*a*i*g.com D 2026-05-30 06:55:09
l*c*k*a*e*.com (WP 5.4.19) ⚠️ F 2026-05-28 18:19:07
b*o*.b*b*l*n*t*r*n.com (WP 5.3.1) ⚠️ F 2026-05-27 03:06:17
p*t*n*x*.com (WP 5.5.3) ⚠️ F 2026-05-27 00:14:45
a*c*e*-*a*k*n.com (WP 6.9.4) F 2026-05-25 00:01:21
p*s*m*n*t*r.com (WP 6.9.4) C 2026-05-24 04:17:48
w*c*m*u*.org (WP 6.7.2) F 2026-05-23 11:43:33
f*r*m.m*n*o*a*g*.com (WP 6.0.11) ⚠️ D 2026-05-14 20:04:37
f*q.m*n*o*a*g*.com (WP 6.0.11) 💀 ⚠️ D 2026-05-14 20:04:37
h*n*s*o*.c*.th (WP 6.9.4) F 2026-05-14 03:28:59
t*a*e*e*i*i*d.com (WP 4.9.5) ⚠️ F 2026-05-12 20:19:30
n*t*r*l*s*s*e*s*o*-*i*d.com (WP 5.7.15) ⚠️ F 2026-05-12 17:42:16
p*u*i*s.m*n*o*a*g*.com (WP 6.0.11) ⚠️ D 2026-05-11 22:33:25
t*n*n*.com (WP 6.9.4) F 2026-05-11 18:46:53
m*i*r*o*g*a*h*n.com (WP 4.9.29) ⚠️ F 2026-05-04 10:35:13

Top 50 Plugins

Plugin Count
elementor 1,853,982
contact-form-7 1,824,242
elementor-pro 1,079,666
woocommerce 837,953
revslider 634,084
jetpack 476,287
js_composer 444,260
wp-rocket 344,896
essential-addons-for-elementor-lite 304,971
gravityforms 297,593
complianz-gdpr 266,410
cookie-law-info 239,557
instagram-feed 234,194
google-site-kit 228,065
sitepress-multilingual-cms 227,639
google-analytics-for-wordpress 219,146
header-footer-elementor 215,701
elementskit-lite 215,335
bluehost-wordpress-plugin 192,135
gutenberg 165,644
gutenberg-core 164,038
cookie-notice 158,158
litespeed-cache 138,389
the-events-calendar 136,486
wpforms-lite 132,399
gtranslate 131,741
astra-sites 121,813
popup-maker 119,220
woocommerce-payments 115,110
tablepress 114,259
coblocks 102,359
honeypot 100,795
astra-addon 97,721
duracelltomi-google-tag-manager 96,519
wp-smushit 96,107
all-in-one-seo-pack 95,647
LayerSlider 94,031
bb-plugin 92,475
megamenu 89,546
premium-addons-for-elementor 89,292
akismet 87,733
mailchimp-for-wp 85,899
cleantalk-spam-protect 85,524
woocommerce-gateway-stripe 85,097
ml-slider 83,778
borlabs-cookie 82,727
fusion-builder 81,876
wp-pagenavi 81,757
ewww-image-optimizer 81,191
smart-slider-3 80,072

Top 50 Themes

Theme Count
hello-elementor 634,290
Divi 524,258
astra 434,451
flatsome 144,160
Avada 127,673
generatepress 127,171
pub 112,934
twentytwentyfour 86,024
oceanwp 85,856
kadence 81,310
enfold 73,951
sydney 68,854
salient 68,356
twentyseventeen 57,976
h4 57,965
bb-theme 56,264
betheme 53,476
cocoon-master 52,585
blocksy 52,542
dt-the7 47,464
twentytwentyfive 45,506
neve 40,672
Avada-Child-Theme 38,593
woodmart 34,194
gox 34,143
bridge 33,672
twentytwentyone 32,976
lightning 32,206
twentytwenty 30,922
swell 28,990
Impreza 27,393
bricks 26,782
voxel 26,186
twentytwentythree 24,606
Newspaper 24,441
sinatra 23,657
kubio 21,805
twentytwentytwo 20,334
uncode 19,696
epik-redesign 19,283
twentysixteen 18,921
storefront 18,389
pro 18,135
Total 15,131
extendable 14,931
yith-wonder 14,124
hello-theme-child-master 13,776
yootheme 13,391
themify-ultra 13,380
hestia 13,293