WordPress OSINT, maintenance or security needs? Reach out!
TLDWP

Plugin: wp-rest-api-authentication (Used by 15 domains)

JWT Authentication for WP REST APIs

πŸ‘€ miniOrange πŸ“¦ v4.3.0 πŸ”— Plugin Homepage

WordPress REST API endpoints are open and unsecured by default which can be used to access your site data. Secure WordPress APIs from unauthorized users with our JWT Authentication for WP REST APIs plugin.

Our plugin offers below authentication methods to Protect WP REST API endpoints:
– JWT Authentication
– Basic Authentication
– API Key Authentication
– OAuth 2.0 Authentication
– External Token based Authentication 2.0/OIDC/JWT/Firebase provider’s token authentication methods.

You can authenticate default WordPress endpoints and custom-developed REST endpoints and third-party plugin REST API endpoints like that of Woocommerce, Learndash, Buddypress, Gravity Forms, CoCart, etc.

WP REST API Authentication Methods in our plugin

  • JWT Authentication
    Provides an endpoint where you can pass the user credentials, and it will generate a JWT (JSON Web Token), which you can use to access the WordPress REST APIs accordingly.
    Additionally, to maintain a seamless user experience without frequent logins needed due to token expiry, you can use our Refresh and Revoke token mechanisms feature.
    When the access token expires, instead of forcing the user to log in again, the client can request a new access token using a valid refresh token.
  • API Key Authentication
  • Basic Authentication:
    – 1. Username: Password
    – 2. Client-ID: Client-Secret
  • OAuth 2.0 Authentication
    – 1. Password Grant
    – 2. Client Credentials Grant
  • Third Party Provider Authentication

Following are some of the integrations that are possible with WP REST API Authentication:

  • Learndash API Authentication
  • Custom Built REST API Endpoints Authentication
  • BuddyPress API Authentication
  • WooCommerce API Authentication
  • Gravity Form API Authentication
  • External/Third-party plugin API endpoints integration in WordPress

You can also disable the WP REST APIs with our plugin such that no one can make API calls to your WordPress REST API endpoints.Our plugin also provides Refresh and Revoke Token that can be used to improve the API security.

Benefits of Refresh Token

  • Enhances security by keeping access tokens short-lived.
  • Improves user experience with uninterrupted sessions.
  • Reduces login frequency.

Benefits of Revoke Token

  • Protects against token misuse if a device is lost or compromised.
  • Enables admin-triggered logouts or session control.
  • Useful for complying with stricter session policies.

With this plugin, the user is allowed to access your site’s resources only after successful WP REST API authentication. JWT Authentication for WP REST APIs plugin will make your WordPress endpoints secure from unauthorized access.

Plugin Feature List

FREE PLAN

  • Authenticate only default core WordPress REST API endpoints.
  • Basic Authentication with username and password.
  • JWT Authentication (JSON Web Token Authentication).
  • Enable Selective API protection.
  • Restrict non-logged-in users to access REST API endpoints.
  • Disable WP REST APIs

PREMIUM PLAN

  • Authenticate all REST API endpoints (Default WP, Custom APIs,Third-Party plugins)
  • JWT Token Authentication (JSON Web Token Authentication)
  • Login, Refresh and Revoke token endpoints for token management
  • API Key Authentication
  • Basic Authentication (username/password and email/password)
  • OAuth 2.0 Authentication
  • Universal API key and User-specific API key for authentication
  • Selective API protection.
  • Disable WP REST APIs
  • Time-based token expiry
  • Role-based WP REST API authentication
  • Custom Header support rather than just Authorization to increase security.
  • Create users in WordPress based on third-party provider access tokens (JWT tokens) authentication.

Privacy

This plugin does not store any user data.

DomainExposuresHeadersLast Checked
s*c*i*r*o*l*.com (WP 5.4.19) ⚠️ F 2026-05-01 10:28:59
f*a*c*i*e*a*k*t*n*t*o*s.com (WP 5.6.17) ⚠️ C 2026-04-29 22:52:36
s*e*e*-*o*t*o*i*.f*y*h*e*s*a*i*g.com βœ… D 2026-04-29 14:10:03
l*c*k*a*e*.com (WP 5.4.19) ⚠️ F 2026-04-28 03:02:40
b*o*.b*b*l*n*t*r*n.com (WP 5.3.1) ⚠️ F 2026-04-27 02:53:56
p*t*n*x*.com (WP 5.5.3) ⚠️ F 2026-04-26 23:31:54
p*s*m*n*t*r.com (WP 5.6.17) ⚠️ C 2026-04-23 21:51:51
m*f*n*s*c*n*t*u*t*o*.com (WP 6.6.1) βœ… F 2026-04-23 18:14:48
w*c*m*u*.org (WP 6.7.2) βœ… F 2026-04-22 14:30:59
a*r*v*u.com βœ… F 2026-04-22 03:41:27
a*c*e*-*a*k*n.com (WP 6.9.4) βœ… F 2026-04-20 11:36:20
p*u*i*s.m*n*o*a*g*.com (WP 6.0.11) ⚠️ D 2026-04-11 17:09:57
t*n*n*.com (WP 6.9.4) βœ… F 2026-04-11 08:45:21
n*t*r*l*s*s*e*s*o*-*i*d.com βœ… β€” 2025-11-09 10:10:10
g*t*o*t*.com βœ… β€” 2025-11-07 21:00:41

Top 50 Plugins

Plugin Count
elementor 2,296,020
contact-form-7 2,112,077
elementor-pro 1,301,171
woocommerce 1,070,876
revslider 781,706
js_composer 518,037
jetpack 482,316
wp-rocket 381,369
essential-addons-for-elementor-lite 349,387
header-footer-elementor 291,450
gravityforms 284,103
gutenberg-core 272,914
elementskit-lite 271,276
instagram-feed 268,809
complianz-gdpr 265,852
google-analytics-for-wordpress 265,230
google-site-kit 259,072
cookie-law-info 257,387
sitepress-multilingual-cms 233,298
bluehost-wordpress-plugin 218,977
wpforms-lite 199,893
astra-sites 192,059
litespeed-cache 176,653
gutenberg 160,754
gtranslate 155,830
cookie-notice 151,715
coblocks 146,372
the-events-calendar 136,756
popup-maker 128,842
astra-addon 114,404
bb-plugin 113,855
premium-addons-for-elementor 111,878
LayerSlider 111,644
tablepress 110,511
wp-smushit 110,210
mailchimp-for-wp 109,003
duracelltomi-google-tag-manager 101,084
cleantalk-spam-protect 97,693
creame-whatsapp-me 97,207
woocommerce-gateway-stripe 97,148
akismet 96,811
honeypot 96,681
woocommerce-payments 95,836
megamenu 93,649
pro-elements 92,375
smart-slider-3 92,146
fusion-builder 91,637
custom-fonts 91,230
click-to-chat-for-whatsapp 90,345
pixelyoursite 89,088

Top 50 Themes

Theme Count
hello-elementor 749,021
Divi 619,957
astra 591,577
pub 183,940
generatepress 141,028
Avada 140,230
flatsome 140,135
h4 106,308
oceanwp 102,921
kadence 92,273
enfold 80,783
salient 77,863
bb-theme 71,767
twentytwentyfour 69,986
blocksy 66,299
cocoon-master 65,434
twentytwentyfive 63,491
twentyseventeen 63,269
betheme 62,812
dt-the7 52,398
woodmart 48,531
neve 45,836
twentytwentyone 39,697
bridge 38,979
Avada-Child-Theme 38,038
gox 35,732
swell 34,805
twentytwenty 34,767
lightning 34,356
twentytwentythree 32,116
bricks 28,436
Impreza 28,338
Newspaper 25,729
twentytwentytwo 25,275
epik-redesign 22,537
pro 21,126
storefront 21,025
extendable 20,913
uncode 20,832
twentysixteen 20,585
sydney 19,106
yith-wonder 18,999
themify-ultra 17,749
Total 17,025
twentyfifteen 15,697
porto 15,268
hestia 15,066
yootheme 14,187
twentynineteen 14,182
thrive-theme 14,115