# Simple JWT Login > Simple JWT Login is a free, open-source WordPress plugin that adds JWT authentication to the WordPress REST API. Supports login, register, auto-login, endpoint protection, token refresh, and more. ## blog News and tutorials about Simple-JWT-Login - [Blog](/blog.md): News and tutorials about Simple-JWT-Login ### archive Archive - [Archive](/blog/archive.md): Archive ### authors - [Authors](/blog/authors.md) #### nicumicle - [Nicu Micle](/blog/authors/nicumicle.md) - [Nicu Micle](/blog/authors/nicumicle/authors/2.md) ### cors-setup-apache Step-by-step guide to configuring CORS on an Apache server so your headless frontend can call the WordPress REST API with Simple JWT Login. - [CORS Setup on Apache Server](/blog/cors-setup-apache.md): Step-by-step guide to configuring CORS on an Apache server so your headless frontend can call the WordPress REST API with Simple JWT Login. ### headless-wordpress-jwt-authentication Add production-ready JWT authentication to your headless WordPress setup - from token generation to protected endpoints. - [Headless WordPress: JWT Auth Done Right](/blog/headless-wordpress-jwt-authentication.md): Add production-ready JWT authentication to your headless WordPress setup - from token generation to protected endpoints. ### javascript-sdk-usage-react A real-world walkthrough of using the Simple JWT Login JavaScript SDK inside a React app to authenticate against the WordPress REST API. - [Using the JavaScript SDK in a React App](/blog/javascript-sdk-usage-react.md): A real-world walkthrough of using the Simple JWT Login JavaScript SDK inside a React app to authenticate against the WordPress REST API. ### new-website-design-2026 We've redesigned the Simple JWT Login website with a cleaner UI, built-in search, AI-friendly content, and improved SEO. - [A Faster, Smarter New Website Design](/blog/new-website-design-2026.md): We've redesigned the Simple JWT Login website with a cleaner UI, built-in search, AI-friendly content, and improved SEO. ### page #### 2 News and tutorials about Simple-JWT-Login - [Blog](/blog/page/2.md): News and tutorials about Simple-JWT-Login ### simple-jwt-login-export-import-add-on The Export-Import add-on for Simple JWT Login lets you copy your full configuration - Auth Codes, protection rules, and settings - between WordPress sites. - [Export-Import Add-on Released](/blog/simple-jwt-login-export-import-add-on.md): The Export-Import add-on for Simple JWT Login lets you copy your full configuration - Auth Codes, protection rules, and settings - between WordPress sites. ### simple-jwt-login-js-sdk-0.1.1 The official Simple JWT Login JavaScript SDK is now available, making it easy to authenticate against the WordPress REST API from JS apps. - [Release JavaScript SDK](/blog/simple-jwt-login-js-sdk-0.1.1.md): The official Simple JWT Login JavaScript SDK is now available, making it easy to authenticate against the WordPress REST API from JS apps. ### simple-jwt-login-mailpoet Simple JWT Login's MailPoet add-on lets you embed personalized, one-click magic-link logins directly inside MailPoet newsletter campaigns. - [MailPoet add-on released](/blog/simple-jwt-login-mailpoet.md): Simple JWT Login's MailPoet add-on lets you embed personalized, one-click magic-link logins directly inside MailPoet newsletter campaigns. ### simple-jwt-login-plus-docusaurus Simple JWT Login's documentation and blog have moved to a new Docusaurus-powered site, with better docs and a smoother experience for WordPress developers. - [Welcome to the New Simple JWT Login Site](/blog/simple-jwt-login-plus-docusaurus.md): Simple JWT Login's documentation and blog have moved to a new Docusaurus-powered site, with better docs and a smoother experience for WordPress developers. ### simple-jwt-login-security-hardening A practical checklist for hardening Simple JWT Login in production - algorithm selection, Auth Codes, IP restrictions, and more. - [JWT Security Hardening Guide](/blog/simple-jwt-login-security-hardening.md): A practical checklist for hardening Simple JWT Login in production - algorithm selection, Auth Codes, IP restrictions, and more. ### simple-jwt-login-wp-glob WPGlob featured Simple JWT Login in its roundup of the best WordPress password management and authentication plugins. - [Simple JWT Login in the news](/blog/simple-jwt-login-wp-glob.md): WPGlob featured Simple JWT Login in its roundup of the best WordPress password management and authentication plugins. ### tags - [Tags](/blog/tags.md) #### tags - [2 posts tagged with "Add-on"](/blog/tags/tags/add-on.md): Plugin Addons - [2 posts tagged with "Headless WordPress"](/blog/tags/tags/headless-wordpress.md): Articles about headless WordPress architecture and JWT authentication - [3 posts tagged with "JWT Authentication"](/blog/tags/tags/jwt-authentication.md): Articles about JSON Web Token (JWT) authentication - [4 posts tagged with "News"](/blog/tags/tags/news.md): Plugin news - [2 posts tagged with "Release"](/blog/tags/tags/release.md): Plugin Releases - [3 posts tagged with "Security"](/blog/tags/tags/security.md): WordPress REST API security and authentication best practices - [6 posts tagged with "Tutorial"](/blog/tags/tags/tutorial.md): Tutorials and guides for Simple JWT Login - [2 posts tagged with "WordPress Plugin"](/blog/tags/tags/wordpress-plugin.md): WordPress plugin tips, features, and usage guides - [One post tagged with "WPGraphQL"](/blog/tags/tags/wpgraphql.md): Integrating Simple JWT Login with WPGraphQL ### top-features-simple-jwt-login A deep dive into the five standout features of Simple JWT Login that help you build secure, modern WordPress-powered applications without the boilerplate. - [5 Standout Features of Simple JWT Login](/blog/top-features-simple-jwt-login.md): A deep dive into the five standout features of Simple JWT Login that help you build secure, modern WordPress-powered applications without the boilerplate. ### wpgraphql-jwt-authentication A step-by-step guide to securing your WPGraphQL API with JWT tokens - setup, authenticated queries, mutations, and token handling. - [Authenticate WPGraphQL with JWT Tokens](/blog/wpgraphql-jwt-authentication.md): A step-by-step guide to securing your WPGraphQL API with JWT tokens - setup, authenticated queries, mutations, and token handling. ## releases Blog - [Release Notes](/releases.md): Blog ### archive Archive - [Archive](/releases/archive.md): Archive ### authors - [Authors](/releases/authors.md) #### nicumicle - [Nicu Micle](/releases/authors/nicumicle.md) - [Nicu Micle](/releases/authors/nicumicle/authors/2.md) - [Nicu Micle](/releases/authors/nicumicle/authors/3.md) - [Nicu Micle](/releases/authors/nicumicle/authors/4.md) ### page #### 2 Blog - [Release Notes](/releases/page/2.md): Blog #### 3 Blog - [Release Notes](/releases/page/3.md): Blog #### 4 Blog - [Release Notes](/releases/page/4.md): Blog ### simple-jwt-login-release-3.4.4 Released version 3.4.4 - [New Plugin Release 3.4.4](/releases/simple-jwt-login-release-3.4.4.md): Released version 3.4.4 ### simple-jwt-login-release-3.4.5 Released version 3.4.5 - [New Plugin Release 3.4.5](/releases/simple-jwt-login-release-3.4.5.md): Released version 3.4.5 ### simple-jwt-login-release-3.4.7 Released version 3.4.7 - [New Plugin Release 3.4.7](/releases/simple-jwt-login-release-3.4.7.md): Released version 3.4.7 ### simple-jwt-login-release-3.4.8 Released version 3.4.8 - [New Plugin Release 3.4.8](/releases/simple-jwt-login-release-3.4.8.md): Released version 3.4.8 ### simple-jwt-login-release-3.4.9 Released version 3.4.9 - [New Plugin Release 3.4.9](/releases/simple-jwt-login-release-3.4.9.md): Released version 3.4.9 ### simple-jwt-login-release-3.5.0 Released version 3.5.0 - [New Plugin Release 3.5.0](/releases/simple-jwt-login-release-3.5.0.md): Released version 3.5.0 ### simple-jwt-login-release-3.5.1 Released version 3.5.1 - [New Plugin Release 3.5.1](/releases/simple-jwt-login-release-3.5.1.md): Released version 3.5.1 ### simple-jwt-login-release-3.5.2 Released version 3.5.2 - [New Plugin Release 3.5.2](/releases/simple-jwt-login-release-3.5.2.md): Released version 3.5.2 ### simple-jwt-login-release-3.5.3 Released version 3.5.3 - [New Plugin Release 3.5.3](/releases/simple-jwt-login-release-3.5.3.md): Released version 3.5.3 ### simple-jwt-login-release-3.5.4 Released version 3.5.4 - [New Plugin Release 3.5.4](/releases/simple-jwt-login-release-3.5.4.md): Released version 3.5.4 ### simple-jwt-login-release-3.5.5 Released version 3.5.5 - [New Plugin Release 3.5.5](/releases/simple-jwt-login-release-3.5.5.md): Released version 3.5.5 ### simple-jwt-login-release-3.5.6 Released version 3.5.6 - [New Plugin Release 3.5.6](/releases/simple-jwt-login-release-3.5.6.md): Released version 3.5.6 ### simple-jwt-login-release-3.5.7 Released version 3.5.7 - [New Plugin Release 3.5.7](/releases/simple-jwt-login-release-3.5.7.md): Released version 3.5.7 ### simple-jwt-login-release-3.5.8 Released version 3.5.8 - [New Plugin Release 3.5.8](/releases/simple-jwt-login-release-3.5.8.md): Released version 3.5.8 ### simple-jwt-login-release-3.6.0 Released version 3.6.0 - [New Plugin Release 3.6.0](/releases/simple-jwt-login-release-3.6.0.md): Released version 3.6.0 ### simple-jwt-login-release-3.6.1 Released version 3.6.1 - [New Plugin Release 3.6.1](/releases/simple-jwt-login-release-3.6.1.md): Released version 3.6.1 ### simple-jwt-login-release-3.6.2 Released version 3.6.2 - [New Plugin Release 3.6.2](/releases/simple-jwt-login-release-3.6.2.md): Released version 3.6.2 ### simple-jwt-login-release-3.6.3 Released version 3.6.3 - [New Plugin Release 3.6.3](/releases/simple-jwt-login-release-3.6.3.md): Released version 3.6.3 ### simple-jwt-login-release-3.6.4 Released version 3.6.4 - [New Plugin Release 3.6.4](/releases/simple-jwt-login-release-3.6.4.md): Released version 3.6.4 ### simple-jwt-login-release-3.6.5 Released version 3.6.5 - security patch, bug fixes, and WordPress 6.9 compatibility - [New Plugin Release 3.6.5](/releases/simple-jwt-login-release-3.6.5.md): Released version 3.6.5 - security patch, bug fixes, and WordPress 6.9 compatibility ### simple-jwt-login-release-4.0.0 Released version 4.0.0 - major redesign, new features, OAuth expansion, 2FA, API Keys, Audit Logs, Webhooks, and more - [New Plugin Release 4.0.0](/releases/simple-jwt-login-release-4.0.0.md): Released version 4.0.0 - major redesign, new features, OAuth expansion, 2FA, API Keys, Audit Logs, Webhooks, and more ### tags - [Tags](/releases/tags.md) #### breaking-change - [One post tagged with "breaking-change"](/releases/tags/breaking-change.md) #### bugfix - [19 posts tagged with "bugfix"](/releases/tags/bugfix.md) - [19 posts tagged with "bugfix"](/releases/tags/bugfix/page/2.md) - [19 posts tagged with "bugfix"](/releases/tags/bugfix/page/3.md) - [19 posts tagged with "bugfix"](/releases/tags/bugfix/page/4.md) #### feature - [10 posts tagged with "feature"](/releases/tags/feature.md) - [10 posts tagged with "feature"](/releases/tags/feature/page/2.md) #### security - [2 posts tagged with "security"](/releases/tags/security.md) ## search - [Search the documentation](/search.md) ## api ### v3 #### autologin Authenticate and automatically log in a user to WordPress using a valid JSON Web Token (JWT). - [Autologin](/api/v3/autologin.md): Authenticate and automatically log in a user to WordPress using a valid JSON Web Token (JWT). #### change-user-password Change user password - [Change user password](/api/v3/change-user-password.md): Change user password #### delete-user Delete user - [Delete user](/api/v3/delete-user.md): Delete user #### get-jwt Authenticate - [Authenticate](/api/v3/get-jwt.md): Authenticate #### refresh-jwt Refresh expired JWT - [Refresh expired JWT](/api/v3/refresh-jwt.md): Refresh expired JWT #### register-user Register WordPress user - [Register user](/api/v3/register-user.md): Register WordPress user #### revoke-jwt Revoke JWT - [Revoke JWT](/api/v3/revoke-jwt.md): Revoke JWT #### send-reset-password-code Send reset password code - [Send reset password code](/api/v3/send-reset-password-code.md): Send reset password code #### simple-jwt-login This is the Simple-JWT-Login WordPress plugin API Documentation. - [Simple-JWT-Login](/api/v3/simple-jwt-login.md): This is the Simple-JWT-Login WordPress plugin API Documentation. #### validate-jwt Validate JWT - [Validate JWT](/api/v3/validate-jwt.md): Validate JWT ### v4 #### autologin Validates the supplied JWT, resolves the matching WordPress user, and redirects the - [Auto-login user into WordPress](/api/v4/autologin.md): Validates the supplied JWT, resolves the matching WordPress user, and redirects the #### change-user-password Sets a new password for the user. Two authentication modes are supported: - [Change user password](/api/v4/change-user-password.md): Sets a new password for the user. Two authentication modes are supported: #### create-api-key Generates a new API key for the authenticated WordPress user. The full key value - [Create an API key](/api/v4/create-api-key.md): Generates a new API key for the authenticated WordPress user. The full key value #### delete-api-key Permanently removes the API key record from the database. This action is - [Permanently delete an API key](/api/v4/delete-api-key.md): Permanently removes the API key record from the database. This action is #### delete-user Permanently deletes the WordPress user identified by the JWT payload. The JWT is - [Delete a WordPress user](/api/v4/delete-user.md): Permanently deletes the WordPress user identified by the JWT payload. The JWT is #### get-jwt Validates the user's WordPress credentials and returns a signed JWT. An optional - [Authenticate and obtain a JWT](/api/v4/get-jwt.md): Validates the user's WordPress credentials and returns a signed JWT. An optional #### list-api-keys Returns a paginated list of API keys owned by the authenticated WordPress user. - [List API keys](/api/v4/list-api-keys.md): Returns a paginated list of API keys owned by the authenticated WordPress user. #### oauth-token-get Browser-redirect flow: exchanges a provider authorization code for a WordPress - [Exchange OAuth authorization code for a WordPress JWT (GET)](/api/v4/oauth-token-get.md): Browser-redirect flow: exchanges a provider authorization code for a WordPress #### oauth-token-post API flow: exchanges a provider-issued token for a WordPress JWT and returns the - [Exchange OAuth token for a WordPress JWT (POST)](/api/v4/oauth-token-post.md): API flow: exchanges a provider-issued token for a WordPress JWT and returns the #### refresh-jwt Exchanges a valid refresh token for a new JWT (and a new refresh token). The - [Refresh an expired JWT](/api/v4/refresh-jwt.md): Exchanges a valid refresh token for a new JWT (and a new refresh token). The #### register-a-new-word-press-user Creates a new WordPress user account. At minimum, `email` and `password` must be - [Register a new WordPress user](/api/v4/register-a-new-word-press-user.md): Creates a new WordPress user account. At minimum, `email` and `password` must be #### revoke-api-key Soft-deletes (revokes) an API key by recording a `revoked_at` timestamp. The key - [Revoke an API key](/api/v4/revoke-api-key.md): Soft-deletes (revokes) an API key by recording a `revoked_at` timestamp. The key #### revoke-jwt Marks the provided JWT as revoked in the database. Once revoked, the token is - [Revoke a JWT](/api/v4/revoke-jwt.md): Marks the provided JWT as revoked in the database. Once revoked, the token is #### send-reset-password-code Sends a one-time reset code to the user's registered email address. The code must - [Send reset password email](/api/v4/send-reset-password-code.md): Sends a one-time reset code to the user's registered email address. The code must #### simple-jwt-login **Simple-JWT-Login** is a free, open-source WordPress plugin that adds JSON Web Token (JWT) - [Simple-JWT-Login](/api/v4/simple-jwt-login.md): **Simple-JWT-Login** is a free, open-source WordPress plugin that adds JSON Web Token (JWT) #### update-api-key Updates the `name`, `permissions`, and/or `expires_at` of an existing API key. - [Update an API key](/api/v4/update-api-key.md): Updates the `name`, `permissions`, and/or `expires_at` of an existing API key. #### validate-jwt Verifies the JWT signature, checks expiry and revocation status, and returns the - [Validate a JWT and retrieve user details](/api/v4/validate-jwt.md): Verifies the JWT signature, checks expiry and revocation status, and returns the #### validate-jwt-post Identical to `GET /auth/validate` but accepts the JWT in the request body instead of - [Validate a JWT and retrieve user details (POST variant)](/api/v4/validate-jwt-post.md): Identical to `GET /auth/validate` but accepts the JWT in the request body instead of #### verify-two-factor Completes the Two-Factor Authentication challenge issued by `POST /auth`. When - [Verify Two-Factor Authentication code](/api/v4/verify-two-factor.md): Completes the Two-Factor Authentication challenge issued by `POST /auth`. When ## docs Simple JWT Login is a free WordPress plugin that adds JWT authentication to the REST API - login, register, auto-login, and more. - [Introduction](/docs.md): Simple JWT Login is a free WordPress plugin that adds JWT authentication to the REST API - login, register, auto-login, and more. ### 3.0.0 Simple JWT Login is a free WordPress plugin that adds JWT authentication to the REST API - login, register, auto-login, protect endpoints, and more. No coding required. - [Introduction](/docs/3.0.0.md): Simple JWT Login is a free WordPress plugin that adds JWT authentication to the REST API - login, register, auto-login, protect endpoints, and more. No coding required. #### applications - [Exchange id_token with a WordPress JWT](/docs/3.0.0/applications/google/id_token_to_wp_jwt.md): Overview - [OAuth Login](/docs/3.0.0/applications/google/login.md): Enable OAuth on WordPress login - [Exchange OAuth Code with Google ID Token](/docs/3.0.0/applications/google/oauth_code.md): Overview - [Setup](/docs/3.0.0/applications/google/setup.md): Create an application - [Shortcode](/docs/3.0.0/applications/google/shortcode.md): Shortcode Configuration #### auth-codes Auth Codes are an optional security layer that adds a shared secret to your API requests. Think of them as API keys: a caller must include the correct AUTH_CODE value alongside their request, otherwise the plugin rejects it. - [Auth Codes](/docs/3.0.0/auth-codes.md): Auth Codes are an optional security layer that adds a shared secret to your API requests. Think of them as API keys: a caller must include the correct AUTH_CODE value alongside their request, otherwise the plugin rejects it. #### authentication Generate, refresh, validate, and revoke JWT tokens via the WordPress REST API using Simple JWT Login. Supports HS256/384/512 and RS256/384/512 algorithms. - [Authentication](/docs/3.0.0/authentication.md): Generate, refresh, validate, and revoke JWT tokens via the WordPress REST API using Simple JWT Login. Supports HS256/384/512 and RS256/384/512 algorithms. #### autologin Use Simple JWT Login to auto-login WordPress users via a tokenized URL - perfect for magic links, email campaigns, and single sign-on (SSO) flows. - [Autologin](/docs/3.0.0/autologin.md): Use Simple JWT Login to auto-login WordPress users via a tokenized URL - perfect for magic links, email campaigns, and single sign-on (SSO) flows. #### change-password This endpoint completes the password reset flow by applying a new password. The user must supply the reset code they received by email (from the Reset Password step), along with their email address and the desired new password. - [Change password](/docs/3.0.0/change-password.md): This endpoint completes the password reset flow by applying a new password. The user must supply the reset code they received by email (from the Reset Password step), along with their email address and the desired new password. #### cli Manage Simple JWT Login from the command line - generate tokens, validate JWTs, and configure the plugin without touching the WordPress admin UI. - [WP-CLI Add-on](/docs/3.0.0/cli.md): Manage Simple JWT Login from the command line - generate tokens, validate JWTs, and configure the plugin without touching the WordPress admin UI. #### code_examples - [Register a WordPress user with PHP and get the jwt](/docs/3.0.0/code_examples/php/register_and_get_jwt.md): Introduction #### code-examples Welcome to our Code Examples page, dedicated to unraveling the simplicity and power of Simple-JWT-Login. - [Code Examples](/docs/3.0.0/code-examples.md): Welcome to our Code Examples page, dedicated to unraveling the simplicity and power of Simple-JWT-Login. #### configuration Server - [Configuration](/docs/3.0.0/configuration.md): Server #### cors Simple-JWT-Login includes built-in Cross-Origin Resource Sharing (CORS) support, implemented in compliance with the W3C CORS specification. - [CORS](/docs/3.0.0/cors.md): Simple-JWT-Login includes built-in Cross-Origin Resource Sharing (CORS) support, implemented in compliance with the W3C CORS specification. #### delete-user The Delete User endpoint allows you to remove a WordPress user account via a REST API call authenticated with a JWT. This is useful for self-service account deletion flows in mobile apps or headless front-ends. - [Delete WordPress User](/docs/3.0.0/delete-user.md): The Delete User endpoint allows you to remove a WordPress user account via a REST API call authenticated with a JWT. This is useful for self-service account deletion flows in mobile apps or headless front-ends. #### error-codes Every error response from Simple-JWT-Login includes a numeric errorCode field. Use the table below to look up the meaning of a specific code and how to resolve it. - [Error codes](/docs/3.0.0/error-codes.md): Every error response from Simple-JWT-Login includes a numeric errorCode field. Use the table below to look up the meaning of a specific code and how to resolve it. #### export-import The Export-Import add-on lets you copy your Simple-JWT-Login configuration - including Auth Codes, protection rules, and all general settings - from one WordPress site to another in just a few steps. This is especially useful when setting up staging environments, migrating sites, or replicating a configuration across a network of sites. - [Simple-JWT-Login Export-Import Add-on](/docs/3.0.0/export-import.md): The Export-Import add-on lets you copy your Simple-JWT-Login configuration - including Auth Codes, protection rules, and all general settings - from one WordPress site to another in just a few steps. This is especially useful when setting up staging environments, migrating sites, or replicating a configuration across a network of sites. #### hooks Simple JWT Login exposes 16 WordPress action and filter hooks - customize JWT payloads, authentication responses, user registration, redirects, and more without touching plugin code. - [Hooks](/docs/3.0.0/hooks.md): Simple JWT Login exposes 16 WordPress action and filter hooks - customize JWT payloads, authentication responses, user registration, redirects, and more without touching plugin code. #### mailpoet The Simple-JWT-Login MailPoet add-on lets you embed personalized, one-click login links inside your MailPoet email campaigns. When a subscriber clicks the link, they are automatically logged into your WordPress site - no password entry required. - [MailPoet](/docs/3.0.0/mailpoet.md): The Simple-JWT-Login MailPoet add-on lets you embed personalized, one-click login links inside your MailPoet email campaigns. When a subscriber clicks the link, they are automatically logged into your WordPress site - no password entry required. #### protect-endpoints Require a valid JWT for any WordPress REST API route using Simple JWT Login. Lock down sensitive endpoints by HTTP method with exact or prefix matching. - [Protect Endpoints](/docs/3.0.0/protect-endpoints.md): Require a valid JWT for any WordPress REST API route using Simple JWT Login. Lock down sensitive endpoints by HTTP method with exact or prefix matching. #### refresh-token Use this endpoint to exchange an expired (or about-to-expire) JWT for a fresh one, without requiring the user to re-enter their credentials. This is the standard mechanism for keeping long-running sessions alive. - [Refresh token](/docs/3.0.0/refresh-token.md): Use this endpoint to exchange an expired (or about-to-expire) JWT for a fresh one, without requiring the user to re-enter their credentials. This is the standard mechanism for keeping long-running sessions alive. #### register-user Register new WordPress users programmatically via a REST API endpoint using Simple JWT Login. Supports role assignment, auth codes, and IP restrictions. - [Register User](/docs/3.0.0/register-user.md): Register new WordPress users programmatically via a REST API endpoint using Simple JWT Login. Supports role assignment, auth codes, and IP restrictions. #### reset-password This endpoint initiates the password reset flow for an existing WordPress user. Depending on the plugin configuration, it can silently save a reset code to the database, send the standard WordPress reset email, or deliver a fully customized email template. - [Reset password](/docs/3.0.0/reset-password.md): This endpoint initiates the password reset flow for an existing WordPress user. Depending on the plugin configuration, it can silently save a reset code to the database, send the standard WordPress reset email, or deliver a fully customized email template. #### revoke-token Revoking a token immediately invalidates it - any subsequent request using that token will be rejected. Call this endpoint when a user logs out or when you need to terminate a specific session (e.g., after a password change or suspicious activity). - [Revoke token](/docs/3.0.0/revoke-token.md): Revoking a token immediately invalidates it - any subsequent request using that token will be rejected. Call this endpoint when a user logs out or when you need to terminate a specific session (e.g., after a password change or suspicious activity). #### validate-token Use this endpoint to verify whether a JWT is valid. On success, the response includes the corresponding WordPress user's profile, their roles, and the decoded JWT header and payload. - [Validate token](/docs/3.0.0/validate-token.md): Use this endpoint to verify whether a JWT is valid. On success, the response includes the corresponding WordPress user's profile, their roles, and the decoded JWT header and payload. #### wpgraphql Simple-JWT-Login integrates with WPGraphQL to bring JWT authentication to your GraphQL layer. Once configured, any GraphQL query or mutation can require a valid JWT, making it straightforward to build secure, headless WordPress applications. - [WPGraphQL](/docs/3.0.0/wpgraphql.md): Simple-JWT-Login integrates with WPGraphQL to bring JWT authentication to your GraphQL layer. Once configured, any GraphQL query or mutation can require a valid JWT, making it straightforward to build secure, headless WordPress applications. ### api-keys Create long-lived API keys in Simple JWT Login to authenticate REST API requests without a JWT - scoped permissions, expiry dates. - [API Keys](/docs/api-keys.md): Create long-lived API keys in Simple JWT Login to authenticate REST API requests without a JWT - scoped permissions, expiry dates. ### applications #### google - [Exchange id_token with a WordPress JWT](/docs/applications/google/id_token_to_wp_jwt.md): Exchange a Google id_token for a WordPress JWT, completing Google Sign-In authentication with Simple JWT Login. - [OAuth Login](/docs/applications/google/login.md): Enable a "Continue with Google" button on the WordPress login and register screens with Simple JWT Login. - [Exchange OAuth Code with Google ID Token](/docs/applications/google/oauth_code.md): Exchange a Google OAuth authorization code for an access_token or id_token using Simple JWT Login. - [Setup](/docs/applications/google/setup.md): Create a Google Developer Console project and obtain OAuth credentials for Google Sign-In with Simple JWT Login. - [Shortcode](/docs/applications/google/shortcode.md): Configure the "Continue with Google" button shortcode options for Simple JWT Login's Google OAuth integration. ### audit-logs Record and review authentication events in Simple JWT Login - logins, registrations, password resets, OAuth, 2FA, API key usage, and settings changes. - [Audit Logs](/docs/audit-logs.md): Record and review authentication events in Simple JWT Login - logins, registrations, password resets, OAuth, 2FA, API key usage, and settings changes. ### auth-codes Add a shared-secret layer to Simple JWT Login endpoints. Auth Codes protect login, register, delete, and password-reset routes. - [Auth Codes](/docs/auth-codes.md): Add a shared-secret layer to Simple JWT Login endpoints. Auth Codes protect login, register, delete, and password-reset routes. ### authentication Generate, refresh, validate, and revoke JWT tokens via the WordPress REST API using Simple JWT Login. Supports HS256/384/512 and RS256/384/512 algorithms. - [Authentication](/docs/authentication.md): Generate, refresh, validate, and revoke JWT tokens via the WordPress REST API using Simple JWT Login. Supports HS256/384/512 and RS256/384/512 algorithms. ### autologin Use Simple JWT Login to auto-login WordPress users via a tokenized URL - perfect for magic links, email campaigns, and single sign-on (SSO) flows. - [Autologin](/docs/autologin.md): Use Simple JWT Login to auto-login WordPress users via a tokenized URL - perfect for magic links, email campaigns, and single sign-on (SSO) flows. ### cli Manage Simple JWT Login from the command line - generate tokens, validate JWTs, and configure the plugin without touching the WordPress admin UI. - [WP-CLI Add-on](/docs/cli.md): Manage Simple JWT Login from the command line - generate tokens, validate JWTs, and configure the plugin without touching the WordPress admin UI. ### code-examples PHP and JavaScript code examples for Simple JWT Login - register users, get a JWT, and call the WordPress REST API from a headless app. - [Code Examples](/docs/code-examples.md): PHP and JavaScript code examples for Simple JWT Login - register users, get a JWT, and call the WordPress REST API from a headless app. #### register-and-get-jwt Complete PHP example - register a WordPress user, obtain a JWT with Simple JWT Login, and create a post via the REST API. - [Register a User in PHP and Get a JWT](/docs/code-examples/register-and-get-jwt.md): Complete PHP example - register a WordPress user, obtain a JWT with Simple JWT Login, and create a post via the REST API. #### todo-app Build a JWT-authenticated todo app in vanilla JavaScript, storing each todo as a private WordPress post via the REST API. - [Todo App with Vanilla JS](/docs/code-examples/todo-app.md): Build a JWT-authenticated todo app in vanilla JavaScript, storing each todo as a private WordPress post via the REST API. #### woocommerce-headless-store A complete browser example that manages WooCommerce products, cart, and checkout using only a JWT - no consumer key/secret and no nonce. - [Headless WooCommerce with Vanilla JS](/docs/code-examples/woocommerce-headless-store.md): A complete browser example that manages WooCommerce products, cart, and checkout using only a JWT - no consumer key/secret and no nonce. ### configuration Full guide to Simple JWT Login General settings - route namespace, JWT algorithms, verification rules, input sources, middleware, and security options. - [Configuration](/docs/configuration.md): Full guide to Simple JWT Login General settings - route namespace, JWT algorithms, verification rules, input sources, middleware, and security options. ### cors Configure CORS headers for Simple JWT Login REST endpoints - control allowed origins, methods, and headers for browser clients. - [CORS](/docs/cors.md): Configure CORS headers for Simple JWT Login REST endpoints - control allowed origins, methods, and headers for browser clients. ### dashboard Overview of Simple JWT Login plugin status - see at a glance which routes, security features, integrations, and monitoring options are active. - [Dashboard](/docs/dashboard.md): Overview of Simple JWT Login plugin status - see at a glance which routes, security features, integrations, and monitoring options are active. ### delete-user Delete WordPress user accounts via a JWT-authenticated REST API call. Useful for self-service account deletion in mobile apps and headless front-ends. - [Delete User](/docs/delete-user.md): Delete WordPress user accounts via a JWT-authenticated REST API call. Useful for self-service account deletion in mobile apps and headless front-ends. ### error-codes Full reference of Simple JWT Login error codes - what each numeric errorCode means and how to resolve it. - [Error codes](/docs/error-codes.md): Full reference of Simple JWT Login error codes - what each numeric errorCode means and how to resolve it. ### export-import Copy your Simple JWT Login configuration - Auth Codes, protection rules, and settings - between WordPress sites with the Export-Import add-on. - [Simple-JWT-Login Export-Import Add-on](/docs/export-import.md): Copy your Simple JWT Login configuration - Auth Codes, protection rules, and settings - between WordPress sites with the Export-Import add-on. ### hooks Simple JWT Login exposes 16 WordPress action and filter hooks to customize JWT payloads, auth responses, registration, redirects, and more. - [Hooks](/docs/hooks.md): Simple JWT Login exposes 16 WordPress action and filter hooks to customize JWT payloads, auth responses, registration, redirects, and more. ### integrations #### oauth Connect Simple JWT Login with Google, Auth0, Facebook, and GitHub OAuth 2.0 - let users sign in with existing accounts and get a WordPress JWT. - [OAuth](/docs/integrations/oauth.md): Connect Simple JWT Login with Google, Auth0, Facebook, and GitHub OAuth 2.0 - let users sign in with existing accounts and get a WordPress JWT. - [Exchange OAuth Code for Auth0 Tokens](/docs/integrations/oauth/auth0/exchange-code.md): Exchange the Auth0 authorization code for Auth0 tokens using Simple JWT Login. - [Exchange access_token for WordPress JWT](/docs/integrations/oauth/auth0/exchange-token.md): Exchange an Auth0 access_token for a WordPress JWT using Simple JWT Login. - [Setup](/docs/integrations/oauth/auth0/setup.md): Configure Auth0 OAuth credentials in Simple JWT Login to enable Auth0 sign-in for your WordPress site. - [Exchange OAuth Code for Facebook Tokens](/docs/integrations/oauth/facebook/exchange-code.md): Exchange the Facebook authorization code for Facebook tokens using Simple JWT Login. - [Exchange access_token for WordPress JWT](/docs/integrations/oauth/facebook/exchange-token.md): Exchange a Facebook access_token for a WordPress JWT using Simple JWT Login. - [Setup](/docs/integrations/oauth/facebook/setup.md): Configure Facebook OAuth credentials in Simple JWT Login to enable Facebook sign-in for your WordPress site. - [Exchange OAuth Code for GitHub Tokens](/docs/integrations/oauth/github/exchange-code.md): Exchange the GitHub authorization code for GitHub tokens using Simple JWT Login. - [Exchange access_token for WordPress JWT](/docs/integrations/oauth/github/exchange-token.md): Exchange a GitHub access_token for a WordPress JWT using Simple JWT Login. - [Setup](/docs/integrations/oauth/github/setup.md): Configure GitHub OAuth credentials in Simple JWT Login to enable GitHub sign-in for your WordPress site. - [Exchange OAuth Code for id_token](/docs/integrations/oauth/google/exchange-code.md): Exchange the Google OAuth authorization code for a Google id_token using Simple JWT Login. - [Exchange id_token for WordPress JWT](/docs/integrations/oauth/google/exchange-token.md): Exchange a Google id_token for a WordPress JWT using Simple JWT Login. - [Setup](/docs/integrations/oauth/google/setup.md): Configure Google OAuth credentials in Simple JWT Login to enable Google sign-in for your WordPress site. - [Shortcode](/docs/integrations/oauth/google/shortcode.md): Use the Simple JWT Login shortcode to render a "Continue with Google" button anywhere on your WordPress site. #### third-party Connect Simple JWT Login with WPGraphQL, Two-Factor auth, Force Login, and WooCommerce - enabling GraphQL auth, 2FA, and headless WooCommerce. - [Third Party](/docs/integrations/third-party.md): Connect Simple JWT Login with WPGraphQL, Two-Factor auth, Force Login, and WooCommerce - enabling GraphQL auth, 2FA, and headless WooCommerce. - [Force Login](/docs/integrations/third-party/force-login.md): Exempt Simple JWT Login endpoints from Force Login plugin restrictions so unauthenticated clients can still reach the authentication API. - [Two-Factor](/docs/integrations/third-party/two-factor.md): Require two-factor authentication before issuing a WordPress JWT using Simple JWT Login and the Two Factor plugin. - [WooCommerce](/docs/integrations/third-party/woocommerce.md): Use a JWT to authenticate the WooCommerce REST and Store API - manage products and run a headless cart & checkout, no consumer key/secret. - [WPGraphQL](/docs/integrations/third-party/wpgraphql.md): Enable JWT authentication for WPGraphQL queries and mutations in WordPress using Simple JWT Login. ### mailpoet Embed personalized, one-click magic-link logins in MailPoet email campaigns with the Simple JWT Login MailPoet add-on. - [MailPoet](/docs/mailpoet.md): Embed personalized, one-click magic-link logins in MailPoet email campaigns with the Simple JWT Login MailPoet add-on. ### oauth Authenticate WordPress users via third-party OAuth (Google, Auth0) - exchange an authorization code or ID token for a signed WordPress JWT. - [OAuth](/docs/oauth.md): Authenticate WordPress users via third-party OAuth (Google, Auth0) - exchange an authorization code or ID token for a signed WordPress JWT. ### protect-endpoints Require a valid JWT for any WordPress REST API route using Simple JWT Login. Lock down sensitive endpoints by HTTP method with exact or prefix matching. - [Protect Endpoints](/docs/protect-endpoints.md): Require a valid JWT for any WordPress REST API route using Simple JWT Login. Lock down sensitive endpoints by HTTP method with exact or prefix matching. ### refresh-token Exchange a refresh token for a new JWT without requiring user credentials again. Enables long-running sessions in headless WordPress applications. - [Refresh token](/docs/refresh-token.md): Exchange a refresh token for a new JWT without requiring user credentials again. Enables long-running sessions in headless WordPress applications. ### register-user Register new WordPress users programmatically via a REST API endpoint using Simple JWT Login. Supports role assignment, auth codes, and IP restrictions. - [Register User](/docs/register-user.md): Register new WordPress users programmatically via a REST API endpoint using Simple JWT Login. Supports role assignment, auth codes, and IP restrictions. ### reset-password Implement a full password reset flow via the WordPress REST API - request a reset code by email, then apply the new password. - [Reset password](/docs/reset-password.md): Implement a full password reset flow via the WordPress REST API - request a reset code by email, then apply the new password. ### revoke-token Immediately invalidate a JWT so it's rejected by future requests - use on logout or when responding to suspicious activity. - [Revoke token](/docs/revoke-token.md): Immediately invalidate a JWT so it's rejected by future requests - use on logout or when responding to suspicious activity. ### validate-token Verify a JWT and retrieve the associated WordPress user profile, roles, and decoded token claims via the REST API using Simple JWT Login. - [Validate token](/docs/validate-token.md): Verify a JWT and retrieve the associated WordPress user profile, roles, and decoded token claims via the REST API using Simple JWT Login. ### webhooks Fire HTTP notifications to external endpoints on login, register, and other Simple JWT Login events with a custom JSON payload. - [Webhooks](/docs/webhooks.md): Fire HTTP notifications to external endpoints on login, register, and other Simple JWT Login events with a custom JSON payload. --- # Full Documentation Content [News](/blog/tags/tags/news.md)[WordPress Plugin](/blog/tags/tags/wordpress-plugin.md) ## [A Faster, Smarter New Website Design](/blog/new-website-design-2026.md)  ·  2 min read We've redesigned the Simple JWT Login website with a cleaner UI, built-in search, AI-friendly content, and improved SEO. ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/blog/new-website-design-2026.md) --- ### 2026[​](#2026 "Direct link to 2026") * [March 10](/blog/wpgraphql-jwt-authentication.md) [ - ](/blog/wpgraphql-jwt-authentication.md) [Authenticate WPGraphQL with JWT Tokens](/blog/wpgraphql-jwt-authentication.md) * [March 10](/blog/top-features-simple-jwt-login.md) [ - ](/blog/top-features-simple-jwt-login.md) [5 Standout Features of Simple JWT Login](/blog/top-features-simple-jwt-login.md) * [March 10](/blog/simple-jwt-login-security-hardening.md) [ - ](/blog/simple-jwt-login-security-hardening.md) [JWT Security Hardening Guide](/blog/simple-jwt-login-security-hardening.md) * [March 10](/blog/headless-wordpress-jwt-authentication.md) [ - ](/blog/headless-wordpress-jwt-authentication.md) [Headless WordPress: JWT Auth Done Right](/blog/headless-wordpress-jwt-authentication.md) * [March 11](/blog/new-website-design-2026.md) [ - ](/blog/new-website-design-2026.md) [A Faster, Smarter New Website Design](/blog/new-website-design-2026.md) --- # Authors * [![Nicu Micle](https://github.com/nicumicle.png)](/blog/authors/nicumicle.md) ## [Nicu Micle](/blog/authors/nicumicle.md) 12 Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") --- [News](/blog/tags/tags/news.md)[WordPress Plugin](/blog/tags/tags/wordpress-plugin.md) ## [A Faster, Smarter New Website Design](/blog/new-website-design-2026.md)  ·  2 min read We've redesigned the Simple JWT Login website with a cleaner UI, built-in search, AI-friendly content, and improved SEO. ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/blog/new-website-design-2026.md) --- [Release](/blog/tags/tags/release.md) ## [Release JavaScript SDK](/blog/simple-jwt-login-js-sdk-0.1.1.md)  ·  1 min read The official Simple JWT Login JavaScript SDK is now available, making it easy to authenticate against the WordPress REST API from JS apps. ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/blog/simple-jwt-login-js-sdk-0.1.1.md) --- # CORS Setup on Apache Server October 26, 2022 · 2 min read [![Nicu Micle](https://github.com/nicumicle.png)](/blog/authors/nicumicle.md) [Nicu Micle](/blog/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") All the time I have issues setting up [CORS](https://en.wikipedia.org/wiki/Cross-origin_resource_sharing) on my server. I was always struggling with this, and this time I was thinking maybe it is a good time to create a blog article about this. So, In this tutorial, we are going to set up CORS on an apache server. ## How to know that there is a CORS issue?[​](#how-to-know-that-there-is-a-cors-issue "Direct link to How to know that there is a CORS issue?") First, try to call your endpoint from the browser using Javascript. If you see in your console something like: ``` Access to ... at 'http://....' from origin 'http://..' has been blocked by CORS policy: Response to preflight request doesn't pass access control check: No 'Access-Control-Allow-Origin' header is present in the requested resource. ``` So, if you see something related to 'CORS' in the console, that means that you have some CORS issues on your server. ## How to fix this?[​](#how-to-fix-this "Direct link to How to fix this?") The first step that you need to do, is to connect to your server via SSH. On your server, you have to make sure that the headers mod is enabled. ``` sudo a2enmod headers ``` After this, you will see something like this: ``` Enabling module headers. To activate the new configuration, you need to run: service apache2 restart ``` If the headers have been enabled before, you will get a message like this: ``` Module headers already enabled ``` The next step is to edit the apache2 conf file. ``` vi /etc/apache2/apache2.conf ``` If your website is running from `/var/www/html`, in this file, search for: ``` ``` If you can not find that, just add it at the end of the file: ``` AllowOverride None Require all granted Header set Access-Control-Allow-Origin "*" Header set Access-Control-Allow-Methods "GET, POST, PUT, PATCH, DELETE, OPTIONS" Header set Access-Control-Allow-Headers "x-requested-with, Content-Type, origin, authorization, accept, client-security-token" Header set Access-Control-Expose-Headers "Content-Security-Policy, Location" Header set Access-Control-Max-Age "600" RewriteEngine On RewriteCond %{REQUEST_METHOD} OPTIONS RewriteRule ^(.*)$ $1 [R=200,L] ``` Now, you just need to restart the apache: ``` sudo service apache2 restart ``` After this, you will be able to make HTTP calls to your server from the browser. Enjoy. **Tags:** * [Tutorial](/blog/tags/tags/tutorial.md "Tutorials and guides for Simple JWT Login") [Edit this page](https://github.com/simple-jwt-login/website/tree/main/blog/2022-10-26-CORS-setup.md) --- # Headless WordPress: JWT Auth Done Right March 10, 2026 · 8 min read [![Nicu Micle](https://github.com/nicumicle.png)](/blog/authors/nicumicle.md) [Nicu Micle](/blog/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") Headless WordPress has gone mainstream. Teams reach for it when they want WordPress's content management experience paired with a modern front-end - React, Next.js, Vue, or a mobile app. The REST API makes that possible, but it leaves one critical piece unresolved: **authentication**. WordPress's built-in auth is cookie-based and browser-centric. It doesn't translate cleanly to API-first architectures. That's the gap Simple JWT Login fills, and in this article I'll walk through a complete, realistic setup. ## What We're Building[​](#what-were-building "Direct link to What We're Building") A headless WordPress backend with: * JWT-based login (email + password → token) * Token refresh before expiry * Protected REST endpoints that require a valid JWT * User registration via API * Password reset flow * Auto-login links for email campaigns All of this is handled by [Simple JWT Login](https://wordpress.org/plugins/simple-jwt-login/) with zero custom PHP beyond optional hooks. *** ## Installation and Initial Configuration[​](#installation-and-initial-configuration "Direct link to Installation and Initial Configuration") Install Simple JWT Login from the WordPress plugin repository, then navigate to **Simple JWT Login** in your WordPress admin sidebar. The first setting to configure is the **JWT Decryption Key** - this is the secret used to sign and verify tokens. Treat it like a database password: long, random, and stored in a secrets manager rather than hardcoded. ``` Settings > Simple JWT Login > General > JWT Decryption Key ``` Next, select your **algorithm**. For most setups `HS256` (HMAC SHA-256) is the right default. If you need asymmetric signing - for example, to let a third-party service verify tokens without knowing the secret - switch to `RS256` and configure your public/private key pair. Set a reasonable **JWT expiration time**. Sixty minutes is a sensible starting point for most web apps; mobile apps often use longer windows paired with token refresh. *** ## Generating a Token[​](#generating-a-token "Direct link to Generating a Token") Once the plugin is active, your WordPress site immediately has an authentication endpoint: ``` curl -X POST "https://example.com/wp-json/simple-jwt-login/v1/auth" \ -H "Content-Type: application/json" \ -d '{ "email": "user@example.com", "password": "their_password" }' ``` A successful response looks like this: ``` { "success": true, "data": { "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...", "user": { "ID": 42, "user_email": "user@example.com", "display_name": "Jane Doe" } } } ``` Store this token client-side (memory or an `HttpOnly` cookie - avoid `localStorage` for sensitive apps) and attach it to subsequent requests. The plugin also supports **username** and a combined **login field** (email or username) for the initial auth call, configurable under `General > Login by`. *** ## Making Authenticated Requests[​](#making-authenticated-requests "Direct link to Making Authenticated Requests") Once you have a token, include it in the `Authorization` header on every protected request: ``` curl "https://example.com/wp-json/wp/v2/users/me" \ -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." ``` The plugin also accepts the token as a query parameter (`?JWT=`) or in the request body (`{"JWT": ""}`), which is handy for scenarios where setting custom headers is awkward - like certain webhook consumers. *** ## Refreshing Tokens[​](#refreshing-tokens "Direct link to Refreshing Tokens") Short-lived tokens are more secure, but they require your client to handle expiry gracefully. Simple JWT Login provides a dedicated refresh endpoint: ``` curl -X POST "https://example.com/wp-json/simple-jwt-login/v1/auth/refresh" \ -H "Content-Type: application/json" \ -d '{"JWT": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."}' ``` The response is a new token with a fresh expiry. A typical front-end pattern: check the token's `exp` claim before each request, and if it's within a few minutes of expiry, refresh proactively rather than reacting to a 401. *** ## Protecting Your REST Endpoints[​](#protecting-your-rest-endpoints "Direct link to Protecting Your REST Endpoints") A headless WordPress site often exposes more REST routes than intended. Simple JWT Login's **Endpoint Protection** feature lets you require a valid JWT for any route. The most secure posture for a private API: enable **"Protect all endpoints"** and then whitelist only the routes that must be public. ``` Settings > Simple JWT Login > Protect Endpoints Mode: Protect all WordPress Endpoints ``` For a typical blog-style API you might whitelist: * `GET /wp-json/wp/v2/posts` - public post listing * `GET /wp-json/wp/v2/categories` - taxonomy data * `POST /wp-json/simple-jwt-login/v1/auth` - login itself Every other route - user data, media uploads, post creation - requires a valid JWT. You can also protect routes **by HTTP method**. If your front-end needs `GET` on posts to be public but `POST` (creating posts) to be authenticated, that's a single checkbox per method. No custom middleware needed. *** ## User Registration via API[​](#user-registration-via-api "Direct link to User Registration via API") If your application handles its own onboarding flow, you can create WordPress users directly through the API. First, enable registration under: ``` Settings > Simple JWT Login > Register User ``` For security, always pair registration with an **Auth Code** - an API key that must accompany registration requests. This prevents anyone with your API URL from creating arbitrary accounts. ``` curl -X POST "https://example.com/wp-json/simple-jwt-login/v1/users" \ -H "Content-Type: application/json" \ -d '{ "email": "newuser@example.com", "password": "initial_password", "first_name": "Jane", "last_name": "Doe", "auth_code": "YOUR_REGISTRATION_AUTH_CODE" }' ``` You can also configure the plugin to **generate a random password** and return it in the response - useful if you want to issue a temporary password and immediately prompt the user to change it. IP address restrictions and email domain allowlists add further layers of control over who can register. *** ## Password Reset Flow[​](#password-reset-flow "Direct link to Password Reset Flow") The plugin ships a full password reset flow accessible via API, which is often missing from DIY JWT implementations. **Step 1 - Request a reset code:** ``` curl -X POST "https://example.com/wp-json/simple-jwt-login/v1/users/reset_password" \ -H "Content-Type: application/json" \ -d '{"email": "user@example.com"}' ``` **Step 2 - Submit the new password with the code:** ``` curl -X PUT "https://example.com/wp-json/simple-jwt-login/v1/users/reset_password" \ -H "Content-Type: application/json" \ -d '{ "email": "user@example.com", "code": "RESET_CODE_FROM_EMAIL", "new_password": "new_secure_password" }' ``` Three reset modes are available: * **Silent**: The reset code is returned directly in the API response (for custom email delivery). * **Default WordPress email**: Uses WordPress's built-in email template. * **Custom email template**: You define the subject and body using variables like `{{CODE}}`, `{{NAME}}`, and `{{EMAIL}}`. The custom template mode is ideal for headless apps that have their own transactional email design system and don't want WordPress's default styling. *** ## Auto-Login Links for Email Campaigns[​](#auto-login-links-for-email-campaigns "Direct link to Auto-Login Links for Email Campaigns") One of the most underrated features: generate a URL that logs a user in automatically when clicked. Enable auto-login under: ``` Settings > Simple JWT Login > Auto Login ``` Then generate a JWT for the target user and construct the URL: ``` https://example.com/?JWT=&redirectUrl={{site_url}}/account/dashboard ``` When the user clicks that link, Simple JWT Login authenticates them silently and redirects them to their dashboard - already logged in. The `redirectUrl` parameter supports dynamic variables (`{{user_id}}`, `{{user_email}}`, `{{user_first_name}}`, and more), so each link can route the user to a personalized destination. Pair this with the **MailPoet add-on** and you have one-click autologin directly inside email campaigns without a single line of custom code. *** ## Enriching the JWT with Custom Data[​](#enriching-the-jwt-with-custom-data "Direct link to Enriching the JWT with Custom Data") Out of the box, the JWT payload contains standard claims (`sub`, `iat`, `exp`). For most front-ends you'll want to include additional user data to avoid extra API calls after login. Use the `simple_jwt_login_jwt_payload` filter: ``` add_filter('simple_jwt_login_jwt_payload', function($payload, $user) { $payload['display_name'] = $user->display_name; $payload['roles'] = $user->roles; $payload['avatar'] = get_avatar_url($user->ID); return $payload; }, 10, 2); ``` Your front-end can now decode the JWT and immediately render the user's name and avatar without an additional `/users/me` request. *** ## Revoking Tokens[​](#revoking-tokens "Direct link to Revoking Tokens") When a user logs out or changes their password, you'll want to invalidate their existing tokens. Simple JWT Login provides a revoke endpoint: ``` curl -X DELETE "https://example.com/wp-json/simple-jwt-login/v1/auth/revoke" \ -H "Authorization: Bearer " ``` Revoked tokens are blacklisted server-side and will be rejected on subsequent requests, even if they haven't technically expired yet. *** ## A Note on CORS[​](#a-note-on-cors "Direct link to A Note on CORS") If your front-end is served from a different domain than WordPress - which is almost always the case in headless setups - you'll need CORS headers. Simple JWT Login can add `Access-Control-Allow-Origin: *` automatically: ``` Settings > Simple JWT Login > General > Allow CORS ``` For production, you'll typically want to restrict this to your front-end domain via your web server config (Apache or Nginx), using the plugin's CORS setting as a development convenience only. *** ## Conclusion[​](#conclusion "Direct link to Conclusion") Simple JWT Login takes what would otherwise be hundreds of lines of custom authentication code and turns it into a configuration exercise. Token generation, refresh, revocation, endpoint protection, user registration, password resets, and auto-login are all covered out of the box. For teams building headless WordPress - whether the front-end is React, Next.js, Vue, or a native mobile app - it's one of the highest-leverage plugins available. The [documentation](/docs.md) is thorough, the plugin is actively maintained, and the hooks system means you're never painted into a corner when requirements get complex. Install it, spend an hour on the settings, and your WordPress REST API will have authentication that actually fits modern development patterns. **Tags:** * [Tutorial](/blog/tags/tags/tutorial.md "Tutorials and guides for Simple JWT Login") * [Headless WordPress](/blog/tags/tags/headless-wordpress.md "Articles about headless WordPress architecture and JWT authentication") * [JWT Authentication](/blog/tags/tags/jwt-authentication.md "Articles about JSON Web Token (JWT) authentication") * [Security](/blog/tags/tags/security.md "WordPress REST API security and authentication best practices") [Edit this page](https://github.com/simple-jwt-login/website/tree/main/blog/2026-03-10-headless-wordpress-jwt-authentication.md) --- # Using the JavaScript SDK in a React App October 27, 2022 · 5 min read [![Nicu Micle](https://github.com/nicumicle.png)](/blog/authors/nicumicle.md) [Nicu Micle](/blog/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") We just released the first version for the JavaScript SDK. This can be installed in your projects either with `npm`, either with `yarn`. In order to add the Simple-JWT-Login SDK to your project, just type: ``` npm install "simple-jwt-login" ``` or ``` yarn add "simple-jwt-login" ``` ## Set up the environment[​](#set-up-the-environment "Direct link to Set up the environment") Now, let's start a new React project, and include the `simple-jwt-login` sdk. In order to create a new React project in the folder `my-app`, in your console write the following: ``` npx create-react-app my-app ``` You will see a loader, and some files that are being extracted to the folder. Also, when this process finishes, you will see some instructions on how to proceed. Now, we will switch in the console to our new project, and start the React app. ``` cd my-app ``` and then ``` npm start ``` Once the React starts, a new tab will be opened in your Browser: ![React App](/assets/images/react-homescreen-aa5af80b5e768d26622467710e754588.png "React Home-screen") ## Install the Simple-JWT-Login SDK[​](#install-the-simple-jwt-login-sdk "Direct link to Install the Simple-JWT-Login SDK") In your terminal go the folder where you have installed the React App and type: ``` npm install "simple-jwt-login" ``` After this, open a code editor, and in your `package.json` you will see `"simple-jwt-login":"^0.1.4"` ``` "dependencies": { "@testing-library/jest-dom": "^5.16.5", "@testing-library/react": "^13.4.0", "@testing-library/user-event": "^13.5.0", "react": "^18.2.0", "react-dom": "^18.2.0", "react-scripts": "5.0.1", "simple-jwt-login": "^0.1.4", "web-vitals": "^2.1.4" }, ``` At this moment, your React App, can use the simple-jwt-login SDK. ## Create a Register form[​](#create-a-register-form "Direct link to Create a Register form") Now, let's create a form, that will allow us in the future to register users in our WordPress website. For this tutorial, we will create the form in the `src/App.js` file. This file looks like this: ``` import logo from './logo.svg'; import './App.css'; function App() { return (
logo

Edit src/App.js and save to reload.

Learn React
); } export default App; ``` Now, we will remove everything that is inside the `
` tag. ``` // import logo from './logo.svg'; import './App.css'; function App() { return (
); } export default App; ``` Now, let's add 2 inputs and one button that will allow us to specify the email and the password for our users and a function `handleClick` that will handle the click event from the button. ``` // import logo from './logo.svg'; import './App.css'; import {useRef} from 'react'; function App() { const emailRef = useRef(null); const passwordRef = useRef(null); function handleClick() { //TODO: here we will call Simple-JWT-Login } return (
Email: Password:
); } export default App; ``` At this moment, we have a register form: ![React register form](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAA14AAARGCAMAAAAfJJG4AAADAFBMVEUpLDTHyMrf3+BOUFcAAAD8/f1AQ0r////v7+92dnZzdXr+/v7DxMYqLTV2eH22t7r8/PyOj5SsrbDp6epdX2X4+Pk9QEdVV10AAAjNztB6e4ClpqqHiI0wMjr29vbv7+gsLja+v8GDhYqdnqKhoqaRk5ZwcndYWmEyNT02OUEPAADy8vI/QUgtMDhDRkyKi5BLTVTd3d+EhYN9f4RHSlGin6Lz8/Q6PETR0tMABBOAgofl5ueZm56xsrVqbHJlaG01Nz9hY2mur7IABC7o7++pq651dnyusLNtbnTv7+BSVVrJysy7vL/s7O3vp1VaXGIIAQAuBgDU1daWmJuztbi/wMNNDQAIOIJXWmBfYWfW19jCw8Xvxnzj4+QQX6sZBgCSSAhnaW98xu/P7+8ACDVBEABjZGW5ubzv5Jzh4eMmccGDze90dHJkZmyQkZVQUlkmBQCiVgibUAjZ7e9FR04PRI4+idDv0Y1UVlLY2dra29xBREu+vb05CgBzLQMABCPvu2zg7+87PkaoqawHGSwJUJwhEgfv7s17OQsiaraUlZnv6sEBDCDf5u9zwe8AHmKyaCSw1e7u7u/v5t+v5+8AGk/v7tnO6e8EK2/B6e9tXEbJ4e80c7gcOFwAD0I1gMZnsuuusrvu27vI0+Lr3c06WIF+tt8yFgWhzOrowoi66u+Qze6uXxWgiGNrIwCHPAnRkk1BkNvv6K7AxtK6sK6yucjfzb5pTS9CJAzv3LBHbpjv25hQmN7Mhz6O1+8ACj5bHABZp+vnnlDPxL6crcLLrppSaHdBWmimvtnZsYNvf4cvSVcPI0Dit3MsSWhbSjUmU36+cy7v6rrvwnN/pM2dVh+0pKJzvejv6+hdOByBeFqg4OXJfTIjWp1KeKfmy5jLoXPewq2ynIh+VC6NYjtsQRzmrF8rZZDZuaa6t7Hv0aJ8fpJdo9Vri64tLiLo0aoTLVA+MBuqXx+qwuBzZlSbeoOShXwuOHNsfpLg1cminIOqdUVFiaLIxsZAaI6urK6KvqSPAAAACXBIWXMAAAsTAAALEwEAmpwYAAAZY0lEQVR42u3deWBcd2Hg8ZE9sqRItmVLjq3LHh12LMvWgY1vy1aIZcdH7fgAO8G4piSutzaGxtmsS4DGSUNIQzeblCRAExoI5xKahkA5SmE5SktLoQW6LD2B0m53t+fexx/75r253sxopCRSLCufzx+QeW9Gz87MN++93/vNUyIBAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCc9J9a0O7fAky+DRvX19TUNPgXAZNhbv+lgkdzamrkBZNkxZaamhv3yAsm3/HqdE59c+TFjLVjwZj2TO2WO8Ocag7Lixkr+lCX1TW1Wx6KtnJEXshr0rVEW2mTF/KadO3RVprlhbwmXepIsI3qBUYOmel51VeVMTzV275moGud617M+Lyqp82fRF7IS14gL5CXvHiJ55W6evaBke3bm9etKVzaMbt5+/E9vWO95sLIitbNa0ePr5YX8iofyeBod8OJ6uyI/aK9mzOFHeu+sTFadmLnseJXbWjdNZR7Tc2WtnVF63cuDByukNfVAzu7j3uLmNl59awvuSa2ZXew3+o6E1t2tGgPtbPoNY3XxvdxYXqzxs6ruS+9YKf3iBmdV1WZa871A6e2FC/bfz72soGSFw31P4e8VjZFL2r1JvFSy6uspqsLX7a79AknVk48rxWZ17R4k3hJ5FVdu+VMbX28mOqmM/sbsw+uLXzZYPo0bajh9K6FnRezT1g48bwWZJv1JjHz82o/sDqVfrRjdCjX1sWB2ellqeb5mdYGC17WsW/t4NzsZtqiQY76/gnn1ZrZxiFvEjM/r/yBX8fR6IN/pmBWYle0qGfMH7K7Mf7tyXHz2rA0+pELvElc4XldVaJ37LwSvU2lH/wj4aKfG3tLW6P93cRHDkfDJ1St8SYx476QMrtCXonlpZeAZ0cvuzTmllYuCkfnOyacV+LYwr1Hu9TFSy2vdeGSB2M/6efi345MjHFzjdkTzwteknkl9oeLNhQuWhgumjf2pg6HTzguL+RVOa+94aLB0qvIFQYiNodPGJYXvq3cXzGvaCDjmsJF88JFW8feVPSEq+SFgflExbx6wkXbCxdtLzcyv+Z4112dew+13NTW1bxZXshrInltLUolMFJTMgO3+XTpZGB5Ia9x8rqvdBzjQPGsp3Vl5yrKC3mNk9fy0ryuKcprpK9GXshrSvIaXJr/8krf/r5GeSGvycorlZkk/2DPyKVU+vGcU53yQl6TktdoVNf8XgPzyGuy84p2VZ2phLyQ12Tn1VQ6rUNeyGtS8kqFD/oS8kJek57Xmuh+UvJCXlNwcBhe9Fqaeg55rXbjGuQ1sbxmhY8OPIe8VpbcuGZDV8/ha7xFyKs4r13ho6rUxPNKhN9mrlmce3ystvLdO+AKyWtxWS8gr+HMnXv7J57XxuhuHdlXdGRuIzrqTWIG/vLX3D7t+eS1JnO3tsaGBcPNi481n7tqoGqcvLZm7mDfOXDebUSRV6U5h831Nc9tSm/iTbl5icsTbiOKvCrNmG+tfo55Zb7lEthdeBvRG71JyKs4r0Tp73gYJ6+5PZnnhL+q6FI01FHzem8S8irJK/gNRRuLjhCbqtoGx84r+I7Y0fTCRalo9xe+uKXDmwRlrT61oG3b6fkL27YOzBsZnEApvSPtW7M3ym4+srFqQF0AAAAAAAAAAAAAXGZ1TC0fMXEhMKYgrxqmlrzUhb6Ql7yQF/JCXvJCXvJCXsgLeckLeckLeSEv5CUv5CUv5IW8kJe8kJe8kBfyQl7yQl7yQl7IC3nJC3nJC3khL+QlL+QlL+SFvJCXvJCXvJAX8kJe8kJeyEteyAt5yQt5IS/kJS/kJS/khbyQl7yQl7zQF+qifF5MOR8zgSEuAAAAAAAAAADgpWPlsdaeOf41wOR7/Yn6YO77bP8iYPLND79aIi+QF8gLIql1KwZ6TldtHDqxpWnLmY1H29qbV8oLJsOlpaVfcm/c275BXvCCzSl/G4lFd82RF0xNXjU16zfLC6Yor5qahSl5wQvPq77t8IKB9q6B5d37Llbn+5IXvPC8qguW9O6uyvbVKi+Y1LwCzU1RXg/ukBdMcl6JS2eivtrlBZOdV+L8onD5IXnBpOeVOBIt780vSV0YWdG6ee3o8dVj/ayrR1asXbvi3LrUc1z3fKzb3rq5dfu6Cs9I9Z+/5ty5Y3Pmlpmocm7FipHzHfLiMuU1Eh0dNkePNrTuGsqPKG5pK/OxXryzKTfrY2hb66Vx1y1fmLY9/lN60svWxBYNh8/bXbjo+K79mR+3/9rmMn+pjublnUON2SvkN8ae0zF6dH1mxd4Fq0vy6mhtaxtN+VwwpXllrofNix7tLJ42dW1v/OlvOlr0jPnjrmsrfl6gP1y2OLbsdLisIK8DG2M/beM1RX/01s5FRRssuEI+uiX299i2N57X1UPhj+z1wWAq80pFO6uu6NFAyTXnof7CZx9YX7x+YNx1u6M9YWyro4UbzWiKH6WmuquLflz11vjeprrkD3ssu2rlvvJX0HN5dUaPd/lgMJV5rakv/O/+7tJP5ImCefV7SucFN4+7rjfKIDa3MdpLbivdoW3M/bk6y9TRuaZiXo0dmTW9N9ZUzutS9oBypU8GU5jXm2IHh4Ppj9xQw+ldCzsvls7pSB2KltRv3LX1vu6FG4OgqleOvy5ac1XhVmeV7tHmhYu2JmIjfYG+i1UX+7IPjpTLq77p4qGhLcGji9k/S0v2+fUPXhyqrS/N61h2wTqfDKYwr+2xnVDHvrWD2RG4OW3R57c+d3gY7dvqey5kP8bHuhsmsG5ruOquMhMgCw88F4ZLjmcebc6evh1PHxCmjmdrW1ucV1/7NVHFa85vzh5sLsg8uaV1R7irar2pviiv/uzxppMvpjKvbVEWZb/3tTsalDuciA3iLyj78yusa45O4kr2VLl9Zii8wL0+c/Q3GA1a9OXHG09FZ3ZLB4vymlW6vcyLF23OD9XPbig698qMmtzkg8EU5pX5KN5Y/kXRfid7zJUIR9sWdZR9aoV1qejYbnVx07GRhWh/si92aLj0QGGkS4tHIMfKK/rp1cOxhTfF85pdm37Y1O+DwdTlteNi8fhfzMpFsRGDMJMT5Z9aad2+4l1V9upYU37R2sIRlgvVxePsgfbob3BhvLw2RP/FuC9RcdbGnO6qqq2XfC6YurwWZ6Yc9o11CtIZ+1CGCS1dM3ZeY6xbWzROODs31JA/1DtdeDIWXSo7lIrvBKPhwLbx8oouLjStNCmKy5jXjuHcGf+YX1g+HBtvmFVywpQoGgssv251fXxXFe6HlsamEqdqCw5D5+4v+zWZ1mj+xtxx8qqKnzDKixctrxVpo2vbu+ffWF1u5kWRaABvOHZS03dNuWdWWpcZmh8sPA+qD8vtTMRGyjPD8nuiM6/ia1Iro7OvPZXzSq2PP0teXNabAexbM+ar5sUuWWUG8Ru3ljmWrLQucV/sWy9r0pkcWheOFGaP/5YXzrqIot5b8mP2xud6lM8rOvJcn5AX0yCvRctTRfM4jnfd1bn3UMtNbV3Nm+NXhBuyl3p7Bks2UGldtDs6miiYRbw1GonPTvpoKTzui069ukt+TE/85Kt8Xivisz/kxeXLq/FI0byF5tMlUwfzeV19Jj/Bdm3RsVuldYkthcP2PVFXbQUNbQhT2RkbUNk8xqFqZ+W81pZO75AXlyGvRS0DRd/pWldVrsH8fKY5LfmlS4u+rlJpXU/hOdyZaIxxuOBiczRqsT12EDha8neIJgK3VM5rQckcEXnxIuW1JW3WoZaGbfeNLi65CDzSV1M5r0Sq/cGCKey7YvN0K6xrLpi9OJjZBUUX1dblr4z1rYlNqRgu+TsMx79ZXT6vreWPLOXFZZgUVWgwP+m9vm9/X2OZvILx/PZZ+Yj6Yt9+HHtdKhxq35/KXZdqzZ6theMdHUtjF8ai3eCKxDinVZXyapMX0yuvVGYKx4M9I5fSIaTmnOoszSu4LLX9aG5Qv37exNbdFS45kD30q76UPUuqSuSGHYfjoyStY1yerprIwaFzL6ZZXqOZq2C9Yw3M513oye7oGmdPaF1z7pCttzE76H4p3ceiHYnM17/6csequ8Inv75kq8vjsz/K59Uab1BeTI+8ol1VZyoxfl7BWF9b45iTzsusS4XTDM9kf2R7/iAw+OFzw5XXFmV0OlF+7uJ9lfOKQl6fkhfTKq+mommAFfMKLmZFd7Oo3jChdT3Zu2t05ucWtmcqioo4l3vuqTK3D0hkh/drTlXOa2V0cHpeXkynvFLRgERionkl1i0dYwii3LrFmaPDcLzwxoIvoQRzn9ry4x6h3mjnVzzB6kB0xNk7zpzDaAZWj7yYTnmtKbPPqJhX5o4Z7RNbF34hbEtqtPBbl+EI/IpoWLGnZFZu8W+WuLborGqMvKJDy74d8mI6HRxG3ylJTTyvrrJz08dYF43ojYRfa7xQOHW+81TJHNzd5UZN9lQXXQ4bI6+rF5WLU15c3rxm5QfPJ5bXQIW9V8m6OWENDY2FF4ZXh2OHDbGvRKfNHYouIBde914ZHfQNzR3328p3lfu1L8V5rRnt6d6d8rngxcorGg+vSo2ZV9GncW7h5d9K6xIFX8ePR1dVZlkiN7pe05Dvq6Oq5PYcY+XVH+2+6hdUyOtS+N3Mlh0+GLxIeUVzjmqO9o+VV3fV2oJrYit3Fg41VFpXdA/F6tXFGQW7sA3lLhLUzBrJPB7JTBjelxg/r9xtpjYen1v0bejZ8TH+3CRimOq81gxlrgY3LBhuXnys+dxVA1WxvII9UuPe7tbtBxYfONW1qy/2ga+0rvDSV/yS745F5W5gGNiQffKZnq7Rrp7sbPwtvRPJK3ernJr92w53bW5f3nbTlqLbiGa+pz3GfXlg8uccNtfXVJrSm1pa7jef94+7LhGbDRg/KTpSfLPfrMXlZhfX7klMKK+OfePcpddtRHnR80q0VlfK63yZVUvPjb8u90doLP2Sf+ZLzhdL/yznT5Tej3t2YmJ5JeYerpzXhey0SLcR5UXLK3FqS4W81pauOZTdnVRaV3T+s63MEePaMn+W3oXxnWn9wqIWKuQV7IlbKv4Kh8wtuxt8MHjx8kp0dG0sOkJsqmrLzJNaM7yrNvZN54YVuaGDSusS8WkXx0uPGGvLnwKdP5L/DUOLtpVcs6qYV7BjvKkx9hfZf3R5cyr3o8Njz/2ODXmRrT61oG3b6fkL27YOzBsZjH/wU3vWdm/rbKi6af7O9nNFO5NK656vHcPd+1oOtezrHt7xPF7du335wqNVDZ3zFx5uHSn6XvaFtpaW7tXebQAAAAAAAAAAAAAmQx1Ty0dMXAiMKcirhqklL3WhL+QlL+SFvJCXvJCXvJAX8kJe8kJe8kJeyAt5yQt5yQt5IS/kJS/kJS/khbyQl7yQl7yQF/JCXvJCXvJCXsgLeckLeckLeSEv5CUv5CUv5IW8kJe8kBfykhfyQl7yQl7IC3nJC3nJC3khL+QlL+QlL/SFuiifF1POx0xgiIvpr/+Ws1dqCWdv6ff+MZ3tubL3NXu8g0zjfVdd3R1NtVeopjvq6uy/mL5uqbuj9gp2R90t3kOmrbN1TVdyXk11Z72HTOOByNormpE+5CUv5CUvkJe8kJe8kNcL8h/v+q/yggnl9b6XZz3x/ol8vq//yeRrnm+YL//Kddl/fviPX/5v5MVMz+snViWzlvzjd64bP6/v3vP2koVPfvLW8ctY9rPJV/1U9sFPv3LJv5QXMz+vTb/3r0L/tCq56VfufF77pY+97mfkBWXyesVrM//4Dz9OvvVXn89n/m33ygsq51X7uVdmz6uWfeqP2woO+D717CffU1v70Kx31Gb/N/j/L1/7xCfCg8kTf3Hz6z6YWfrksy9/4j3Ri74360ztsh/c9Z7KeS371LPXfiK3pcLtpjf05LOfvFNezIi8Hv615G3pz/ayv/x0+lzs/s9GaXzkPxxMJjd99pGfTb49N7Txvr+6J/2Uu//8kdpffEt45nZb0MFHfhw8M7npD8JRi59/wzv/5LsH8zupcnk9/NSH0q/d9IHwFbHtBht67zc+lPzXvywvZkReb/u1MJJlnz+55LGvv+zdb0i+6l3B0ttfmbz7t1/2Gye/dW/yX2Tz+sV7k3d/bV7db5xM/tmtDz/1zeD87cDfXVf7jTcnf//rA9//dPKd/zZ43bdvePz7q+5O/WaFvJY9cHDTH8yre/eHko/+cvF2l70x+Tdv2ZT4nx+VFzMir9tvTu+fal/95miI4yM3L3lv8DH/5+Tj6Vq+8aGD+bz++uQX0stqv3FD+tU//4bw3OuZjydveyT4/8+8JfkLwU7w1Te89e/fe2fFc6/PvXJTWN9nvrjk14u3W/vG5N2Pfdi5FzMkr8/cm3zda9O7lOSj7woX/GHy0Y/WPvPFdFWBPy3I6/MHo6cs++oTj+Ty+tKqqLkgvvTjV9+QvO2nKg9tfPuGzCt+8JX3F283yKvMQIu8uMIG5r92S+ibJ5Ob0udDf/TxTE9RNsFOKPqU3/7mfF5fWvXW/5L/GVFeyz6WzemZaGd0Q/p/K+Z1+5uX5C8FFG03yKvovEteXMGXlTc99sHwk3/zkr/pDudxPHXDpn8XPOELP1Pw8Y/y+qO3JJc89r9+57rCHIIzt0ej1/2fL6YPMnNdjp3X9f98MPn7v/2VaNCxaLtBXrfdKi+u8Lze+tnlgaeC867rsnup/ESO36z90sHHfytzdSufV+1nfpTO8u4P/E4+r8wIYuQ1YV6/NN51r7f933vCocbv3Fmy3SCvX7hOXsyMc6+nV+UOApd862UZXR8eI69gaP6pbwZphIMRubwey77uZd9J5/WKeF5vLMjrczdnjhyf/GEwbphcctu7ircrL2ZQXulju49mdiy/HntCZkrGMx+P5ZW+NPXVHx9MN5k7OIz1UJxX7ccKTqa+HR7/Zfzgr04GY4VF25UXM2nk8NXBOEP68xzshd4eq2TTr2bWF+eVfW5m5PBjyVc9Uimvpw/mjxb/9OAXfqtgx/ZAsGMr2q68mEl5LfvDg6/49+l/eCC7l/lP/zkYvHjmi9GnPkggl9fDP9z94ez5VD6vL52MXl/7tv/+lVvL5BXMubrtkdwVtvS4xVe//8Ho8ecPBseN8e3Kixl13Ss4+gsPD2+/ecmfpTN4373pBoLx9seDCJY9fc89+bx+Mnnbu6JM0teFM0d6we7n0fTkpocfOPjOPymTV+3nVy35VjrL6//y5uTjrw33Ye8MMw0mgbzmuqLtyouZNWvjr09Gh4dPnwyGy8+++55oclMwKSr4zso/bfp/BUMbH7k5mBS1+2xwqSw9f+mng2lTgx/4aHrp/V87+98+nQwvipXm9fADq5JL7u79+2BI5PFwtxXM77j/94bPBoMb4Zbi25UXMyqv67+bjA7vfjc9iTd5fzTRtvYvgqmFSx77TjB0kT/3Si8Lp/SGs36ffkMyPLD7hx+dDMfZP1j23Cv9gzMv+2zmq8qZmcHZLcW2Ky9m6r02nrzjiU+8I/foe0PvSB/7hVMBsx768t/ue3/28/9QVeYfH/rytqPvqPSDH/rys/sK7zrwvU/97ZFP3DnGdn3fi5l+K5tl//v9mUtVBWPpbmUDk5DXsszlqmBgMT1gIS+YxL1XcL3rH/9u1w9/tGrTe6+TF0zufQ5/N/wOcfL+P7+1Vl4wybcRvf6r/6Pu693vcZdecBNskJe8SPjtlLV+OyUk/G5luJz66+ruuGL3X0131NX1ew+ZvvbUXdH2eAeZ1vuvW85eqW2dvcW+CwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgCvQ/wfQEbWxXALdMgAAAABJRU5ErkJggg== "React Register Form") ## Add the Simple-JWT-Login SDK library[​](#add-the-simple-jwt-login-sdk-library "Direct link to Add the Simple-JWT-Login SDK library") On this step, we need to add the simpl-jwt-login SDK in the code. First, we need to import it. Add this line at the top of your file: ``` import {SimpleJwtLogin} from 'simple-jwt-login' ``` The code should look like this: ``` // import logo from './logo.svg'; import './App.css'; import {useRef} from 'react'; import {SimpleJwtLogin} from 'simple-jwt-login' function App() { const emailRef = useRef(null); const passwordRef = useRef(null); function handleClick() { //TODO: here we will call Simple-JWT-Login } return (
Email: Password:
); } export default App; ``` The next step, is to initialize SimpleJWTLogin. For this example, we have a WordPress instance at `http://localhost:88` with the Simple-JWT-Login plugin installed. The plugin has the default namespace, `simple-jwt-login/v1/`. ``` const simpleJwtLogin = new SimpleJwtLogin("http://localhost:88","/simple-jwt-login/v1"); ``` Next step, would be to get the values from the inputs, and call Simple-JWT-Login when the button "Register User" is clicked. In order to do this, we need to add some code in `handleClick` method: ``` function handleClick() { //init SimpleJWTLogin const simpleJwtLogin = new SimpleJwtLogin("http://localhost:88","/simple-jwt-login/v1"); //Prepare the Request Body with the values from the input const data = {email: emailRef.current.value, password:passwordRef.current.value, nickname:"tests"} //Call WordPress and create User let result = simpleJwtLogin.registerUser(data); //Display the result in the console console.log(result); } ``` ## Wrapping up[​](#wrapping-up "Direct link to Wrapping up") This is how our full code will look like: ``` // import logo from './logo.svg'; import './App.css'; import {useRef} from 'react'; import {SimpleJwtLogin} from 'simple-jwt-login' function App() { const emailRef = useRef(null); const passwordRef = useRef(null); function handleClick() { //init SimpleJWTLogin const simpleJwtLogin = new SimpleJwtLogin("http://localhost:88","/simple-jwt-login/v1"); //Prepare the Request Body with the values from the input const data = {email: emailRef.current.value, password:passwordRef.current.value, nickname:"tests"} //Call WordPress and create User let result = simpleJwtLogin.registerUser(data); //Display the result in the console console.log(result); } return (
Email: Password:
); } export default App; ``` After filling the form and click on "Register User" you will get something similar in your console: ![Register user result](/assets/images/react_register_user_console-1950e85d1d81dc9390aae1fbc3f9f246.png "The final result") ## Conclusion[​](#conclusion "Direct link to Conclusion") Using the simple-jwt-login SDK allows you to connect to WordPress with only a couple of lines of code. You don't need to worry about the endpoints or the request methods. You just need to make sure that you send all the required parameters. **Tags:** * [Tutorial](/blog/tags/tags/tutorial.md "Tutorials and guides for Simple JWT Login") [Edit this page](https://github.com/simple-jwt-login/website/tree/main/blog/2022-10-27-how_to_use_the_js_sdk.md) --- # A Faster, Smarter New Website Design March 11, 2026 · 2 min read [![Nicu Micle](https://github.com/nicumicle.png)](/blog/authors/nicumicle.md) [Nicu Micle](/blog/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") We just shipped a major update to the Simple JWT Login website. The plugin hasn't changed - but everything around it has. From the homepage to the blog to the docs navigation, here's a look at what's new and why we made these changes. ## Refreshed UI[​](#refreshed-ui "Direct link to Refreshed UI") The entire visual design has been overhauled. Every page - homepage, contact, donate, blog - now uses a consistent design language with refined typography, better spacing, and clear calls to action. The homepage in particular got a lot of attention. Feature cards now have sharper copy that explains *what the feature does* rather than just naming it. The stats section (active installs, downloads, ratings) gives newcomers quick confidence, and the CTA buttons are more prominent. The blog also has a custom layout: post cards show the author, date, tags, and a description at a glance - no more barebones list. ## Built-in Search[​](#built-in-search "Direct link to Built-in Search") The site now has **full-text local search** powered by [`@easyops-cn/docusaurus-search-local`](https://github.com/easyops-cn/docusaurus-search-local). It indexes docs and blog posts, works entirely client-side (no external service), and is available from any page. If you've ever tried to find a specific configuration option or remember which doc covers token revocation - just search for it now. ## LLMs.txt Support[​](#llmstxt-support "Direct link to LLMs.txt Support") The site now generates an `llms.txt` file (and `llms-full.txt`) via the [`@signalwire/docusaurus-plugin-llms-txt`](https://github.com/signalwire/docusaurus-plugin-llms-txt) plugin. This is a [community standard](https://llmstxt.org/) for making documentation AI-friendly. If you're using an AI assistant to help integrate Simple JWT Login into your app, it can now read structured, clean content from this site rather than parsing raw HTML. ## Release Notes[​](#release-notes "Direct link to Release Notes") The [Releases](/releases.md) section is now live with structured changelogs for recent plugin versions (3.6.2, 3.6.3, 3.6.4, 3.6.5). Going forward, every plugin release will have a corresponding entry there. *** The plugin itself hasn't changed - but if you haven't visited the docs in a while, it's worth a look. And if you run into anything that feels off or missing, [open an issue on GitHub](https://github.com/nicumicle/simple-jwt-login/issues). **Tags:** * [News](/blog/tags/tags/news.md "Plugin news") * [WordPress Plugin](/blog/tags/tags/wordpress-plugin.md "WordPress plugin tips, features, and usage guides") [Edit this page](https://github.com/simple-jwt-login/website/tree/main/blog/2026-03-11-new-website-design.md) --- [Release](/blog/tags/tags/release.md) ## [Release JavaScript SDK](/blog/simple-jwt-login-js-sdk-0.1.1.md)  ·  1 min read The official Simple JWT Login JavaScript SDK is now available, making it easy to authenticate against the WordPress REST API from JS apps. ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/blog/simple-jwt-login-js-sdk-0.1.1.md) --- # Export-Import Add-on Released March 4, 2023 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/blog/authors/nicumicle.md) [Nicu Micle](/blog/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") We just released the `beta` version for export-import add-on. You can [Download](https://github.com/simple-jwt-login/export-import/archive/refs/heads/master.zip) it for **free** from GitHub and test it. ## Installation[​](#installation "Direct link to Installation") 1. Download the add-on from 2. Upload the zip file into your WordPress 3. Activate the plugin 4. Export or import data ## Feedback[​](#feedback "Direct link to Feedback") Feel free to test it, and if you find any issues or you want to suggest an improvement, please open an issue at **Tags:** * [Release](/blog/tags/tags/release.md "Plugin Releases") * [Add-on](/blog/tags/tags/add-on.md "Plugin Addons") [Edit this page](https://github.com/simple-jwt-login/website/tree/main/blog/2023-03-04-import-export.md) --- # Release JavaScript SDK October 25, 2022 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/blog/authors/nicumicle.md) [Nicu Micle](/blog/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") Finally, the JavaScript SDK for Simple JWT Login has been released. You can now use it in your projects: ``` npm install "simple-jwt-login" ``` or if you prefer yarn: ``` yarn add "simple-jwt-login" ``` You can find the package code on github: . Feel free to star the repository, check the code, create issues or even share it on social media. Now, with just a few lines of code, you are able to call Simple-JWT-Login endpoints. Here is a simple register example using the JS SDK: ``` import { SimpleJwtLogin } from "simple-jwt-login"; const simpleJwtLogin = new SimpleJwtLogin( "http://your-domain.com", "/simple-jwt-login/v1", "AUTH_KEY" ); let params = { email: "me@mydomain.com", password: "my-secret-password", nickname: "coolnickname", }; let result = simpleJwtLogin.registerUser(params, "MY_AUTH_KEY"); ``` And voilà. A new user is registered. With this SDK, with just a few lines of code, you can: * Autologin to WordPress * Delete a user * Register a user * Reset user password * Change user password * Authenticate into WordPress * Refresh a token * Validate a token * Revoke a token **Tags:** * [Release](/blog/tags/tags/release.md "Plugin Releases") [Edit this page](https://github.com/simple-jwt-login/website/tree/main/blog/2022-10-25-release-js-sdk.md) --- # MailPoet add-on released April 25, 2022 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/blog/authors/nicumicle.md) [Nicu Micle](/blog/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The first add-on for Simple JWT Login plugin has been released. MailPoet add on allows you to generate Autologin links in your newsletters. ![Simple JWT Login MailPoet add-on banner](https://ps.w.org/simple-jwt-login-mailpoet/assets/banner-1544x500.png) The MailPoet add-on allows you to automatically login users from the newsletter sent by MailPoet into a WordPress website using a JWT. This add-on will generate short codes that can be used in your MailPoet templates. Check more details in the documentation. [Read more about MailPoet](/docs/mailpoet.md) **Tags:** * [News](/blog/tags/tags/news.md "Plugin news") * [Add-on](/blog/tags/tags/add-on.md "Plugin Addons") [Edit this page](https://github.com/simple-jwt-login/website/tree/main/blog/2022-04-25-mailpoet-addon.md) --- # Welcome to the New Simple JWT Login Site February 27, 2022 · 2 min read [![Nicu Micle](https://github.com/nicumicle.png)](/blog/authors/nicumicle.md) [Nicu Micle](/blog/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") I'm very excited about this new website for Simple JWT Login, using [**Docusaurus 2**](https://docusaurus.io/). Docusaurus offered me a simple way, to write documentation, and also build the website in the same place. The learning curve was fast, and I enjoyed writing code in React. ## Previous website[​](#previous-website "Direct link to Previous website") Previously, I've used [docsify](https://docsify.js.org/) ( Also, a very cool site documentation generator) and the website has been made in PHP. It was very hard to do changes, and add new pages because that involved a lot of coding, writing routes, and loading content. ## About the blog[​](#about-the-blog "Direct link to About the blog") While writing documentation, it came to my mind that it will also be cool to start a blog. In this blog I'm planning to write real world use-cases of the plugin and write announcements about the plugin. So, if you are interested on what features have been implemented, or what tips\&tricks you can use while you develop your website, keep an eye on this blog. Also, I'm planning to publish the documentation to GitHub, so that, anybody can add/modify the things there. In fact, this documentation is made for you to understand. I hope that, with the help of the community, there will be much easier for new users to use this plugin. **Tags:** * [News](/blog/tags/tags/news.md "Plugin news") [Edit this page](https://github.com/simple-jwt-login/website/tree/main/blog/2022-02-27-hello-docusaurus-v2.md) --- # JWT Security Hardening Guide March 10, 2026 · 8 min read [![Nicu Micle](https://github.com/nicumicle.png)](/blog/authors/nicumicle.md) [Nicu Micle](/blog/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") Installing Simple JWT Login takes minutes. Configuring it securely for production takes a bit more thought. The plugin ships with most sensitive features **disabled by default**, which is the right approach - but it also means the defaults aren't always sufficient for a hardened deployment. This guide works through every security-relevant setting in Simple JWT Login, explains the trade-offs, and gives you a concrete checklist to work from before you go live. ## 1. Choose the Right Signing Algorithm[​](#1-choose-the-right-signing-algorithm "Direct link to 1. Choose the Right Signing Algorithm") The algorithm you pick determines how tokens are signed and verified. **HMAC algorithms (HS256, HS384, HS512)** use a shared secret. Anyone who knows the secret can both sign and verify tokens. This is fine when only your WordPress server generates and validates tokens. **RSA algorithms (RS256, RS384, RS512)** use a public/private key pair. WordPress signs tokens with the private key; anyone can verify them with the public key - without ever seeing the private key. Choose RS256 when: * A third-party service (external API, CDN, serverless function) needs to verify tokens independently * Your team wants to publish the verification key without exposing signing capability For most applications, **HS256 is the right default**. If you go this route, the decryption key is everything - treat it accordingly. **Configuration:** ``` Settings > Simple JWT Login > General > JWT Algorithm ``` *** ## 2. Use a Strong Decryption Key[​](#2-use-a-strong-decryption-key "Direct link to 2. Use a Strong Decryption Key") The decryption key is the foundation of your token security. If it's weak or guessable, an attacker can forge valid tokens for any user, including administrators. Rules for production keys: * **Minimum 32 characters**, ideally 64+ * Use a cryptographically random generator, not a human-chosen phrase * Never commit it to version control * Rotate it if you suspect compromise (this will invalidate all existing tokens - have a plan for active sessions) Generate a suitable key from your terminal: ``` openssl rand -base64 48 ``` Store it in an environment variable and read it into your plugin configuration via `wp-config.php` if possible, rather than keeping it only in the database. *** ## 3. Set a Short Token Expiration[​](#3-set-a-short-token-expiration "Direct link to 3. Set a Short Token Expiration") Long-lived tokens are a liability. If a token is stolen, the attacker has access for its entire lifetime. The shorter the window, the lower the blast radius. **Recommended starting points:** | Application type | Token TTL | | ---------------------------------- | ------------- | | Web SPA (frequent use) | 15–60 minutes | | Mobile app | 1–24 hours | | Server-to-server | 5–15 minutes | | Auto-login links (email campaigns) | 10–30 minutes | Pair short expiration with a **token refresh** flow so legitimate users aren't constantly forced to re-authenticate. ``` Settings > Simple JWT Login > General > JWT Expiration (seconds) ``` *** ## 4. Restrict Operations with Auth Codes[​](#4-restrict-operations-with-auth-codes "Direct link to 4. Restrict Operations with Auth Codes") Auth Codes are optional API keys that gate specific plugin operations: auto-login, user registration, user deletion, and password resets. If an operation requires an Auth Code and the caller doesn't provide a valid one, the request is rejected - regardless of whether a valid JWT is present. **Always use Auth Codes for:** * **User registration** - without one, anyone who discovers your endpoint can create WordPress accounts * **User deletion** - even with JWT auth, an extra key adds a meaningful barrier * **Auto-login** - prevents token-crafting attacks against your autologin endpoint Auth Code configuration lets you: * Assign each code a **WordPress role** (new users created with that code get that role) * Set an **expiration date** (one-time integrations, temporary access) * Create **multiple codes** for different clients or systems ``` Settings > Simple JWT Login > Auth Codes ``` A practical pattern: one Auth Code per external system that interacts with your API. If a system is compromised, revoke its code without affecting others. *** ## 5. Enable Endpoint Protection[​](#5-enable-endpoint-protection "Direct link to 5. Enable Endpoint Protection") The WordPress REST API leaks more data than most developers realise. Endpoints like `/wp/v2/users` expose usernames and user IDs publicly by default. Simple JWT Login's endpoint protection feature lets you require a valid JWT for any REST route. **Two protection modes:** **Protect all, whitelist exceptions:** Start from a closed position. Every REST request requires a JWT unless you explicitly whitelist the route. Recommended for private APIs and admin tools. **Protect specific routes:** Only named routes require authentication. Everything else is public. Suitable for content sites that need public read access but authenticated writes. Configure per-HTTP-method granularity. A common setup for a content API: | Route | GET | POST | PUT | DELETE | | -------------- | --------- | --------- | --------- | --------- | | `/wp/v2/posts` | Public | Protected | Protected | Protected | | `/wp/v2/users` | Protected | Protected | Protected | Protected | | `/wp/v2/media` | Public | Protected | Protected | Protected | ``` Settings > Simple JWT Login > Protect Endpoints ``` *** ## 6. Restrict Auto-Login by IP Address[​](#6-restrict-auto-login-by-ip-address "Direct link to 6. Restrict Auto-Login by IP Address") Auto-login is powerful and therefore worth extra hardening. If you're using it exclusively for server-side integrations (e.g., generating login links from a specific application server), lock it down to that server's IP address. ``` Settings > Simple JWT Login > Auto Login > Allow auto-login only from these IPs ``` This renders stolen auto-login links useless from any other network, even if the token itself hasn't expired. For email campaign auto-login where users click from arbitrary IPs, leave IP restriction disabled - but compensate with a short token TTL (10–15 minutes is reasonable for a one-time login link). *** ## 7. Restrict Registration by IP and Email Domain[​](#7-restrict-registration-by-ip-and-email-domain "Direct link to 7. Restrict Registration by IP and Email Domain") Two independent controls protect the registration endpoint: **IP allowlist:** Only allow registration requests from known origins - your front-end server, your CI pipeline, etc. ``` Settings > Simple JWT Login > Register User > Allow register only from these IPs ``` **Email domain allowlist:** Restrict registrations to specific email domains. Useful for internal tools or invite-only platforms where only company email addresses should be allowed. ``` Settings > Simple JWT Login > Register User > Allowed email domains ``` Example: allow only `@yourcompany.com` and `@partner.com` addresses. Any registration attempt with a Gmail or other address is rejected at the plugin level before WordPress processes it. *** ## 8. Use Token Revocation for Logout and Password Changes[​](#8-use-token-revocation-for-logout-and-password-changes "Direct link to 8. Use Token Revocation for Logout and Password Changes") JWT tokens are stateless by design, which means a standard logout (just deleting the client-side token) doesn't actually invalidate the token server-side. If the token was copied before logout, it remains valid until expiry. Simple JWT Login's revoke endpoint adds server-side blacklisting: ``` curl -X DELETE "https://example.com/wp-json/simple-jwt-login/v1/auth/revoke" \ -H "Authorization: Bearer " ``` **Call this endpoint on:** * User-initiated logout * Password change * Account suspension or deletion * Any security event that should terminate existing sessions This won't help if you don't call it, so it's worth building into your logout flow as a required step rather than a best-effort one. *** ## 9. Configure CORS Carefully[​](#9-configure-cors-carefully "Direct link to 9. Configure CORS Carefully") Simple JWT Login can add `Access-Control-Allow-Origin: *` headers to remove cross-origin friction during development. In production, this setting is a security liability - it allows any website to make authenticated requests to your API on behalf of your users. **For production:** 1. Disable the wildcard CORS setting in the plugin. 2. Configure CORS at the web server level (Apache or Nginx) to allow only your specific front-end origin(s). **Apache example:** ``` SetEnvIf Origin "https://yourfrontend.com" CORS_ALLOWED=1 Header set Access-Control-Allow-Origin "https://yourfrontend.com" env=CORS_ALLOWED Header set Access-Control-Allow-Headers "Authorization, Content-Type" Header set Access-Control-Allow-Methods "GET, POST, PUT, DELETE, OPTIONS" ``` **Nginx example:** ``` add_header Access-Control-Allow-Origin "https://yourfrontend.com"; add_header Access-Control-Allow-Headers "Authorization, Content-Type"; add_header Access-Control-Allow-Methods "GET, POST, PUT, DELETE, OPTIONS"; ``` *** ## 10. Disable What You Don't Use[​](#10-disable-what-you-dont-use "Direct link to 10. Disable What You Don't Use") Every enabled feature is an attack surface. Simple JWT Login follows a deny-by-default approach, but over time it's easy to enable features for testing and forget to turn them off. Before going to production, audit your settings and disable: * **Auto-login** - if you're not using magic links * **Register users** - if registration happens through WordPress's built-in flow * **Delete users** - unless your application explicitly needs it * **Reset password** - if you're using a separate password management system * **Change password** - same as above The fewer endpoints active, the smaller the attack surface. *** ## Security Hardening Checklist[​](#security-hardening-checklist "Direct link to Security Hardening Checklist") Use this before every production deployment: * Decryption key is 32+ characters, randomly generated, not in version control * Algorithm selected matches your use case (HS256 for simple, RS256 for shared verification) * Token expiration is set to the shortest practical TTL for your application * Auth Codes are enabled for registration, deletion, and auto-login * Each Auth Code is scoped to the minimum required role * Endpoint protection is configured - protect all with whitelist, or named routes * Auto-login IP restriction is set if used for server-side integrations only * Registration IP and email domain restrictions are configured if applicable * Token revocation is integrated into your logout and password-change flows * Wildcard CORS is disabled; web server handles CORS with specific origins * All unused features (register, delete, auto-login, reset password) are disabled * Auth Code expiration dates are set for time-limited integrations *** ## Conclusion[​](#conclusion "Direct link to Conclusion") Simple JWT Login's security posture is only as strong as its configuration. The defaults are safe - nothing is enabled you didn't ask for - but a truly hardened production setup requires deliberate choices about algorithms, key strength, Auth Codes, endpoint protection, and CORS. Work through the checklist above before launch and revisit it whenever you enable a new feature. The goal isn't paranoia; it's ensuring that each exposed capability is intentional, scoped, and monitored. The [full documentation](/docs.md) covers every setting in detail, and the [error codes reference](/docs/error-codes.md) is useful for debugging unexpected rejections when you tighten restrictions and something stops working. **Tags:** * [Tutorial](/blog/tags/tags/tutorial.md "Tutorials and guides for Simple JWT Login") * [Security](/blog/tags/tags/security.md "WordPress REST API security and authentication best practices") [Edit this page](https://github.com/simple-jwt-login/website/tree/main/blog/2026-03-10-security-hardening-guide.md) --- # Simple JWT Login in the news August 23, 2022 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/blog/authors/nicumicle.md) [Nicu Micle](/blog/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") Simple-JWT Login got published on wpglob.com in an article about "Best List of Password Management Plugins for WordPress". We are happy that we are listed along some other cool plugins. Fee free to read the article at: If you want to promote your WordPress plugin, just visit the WPGLob page at: [Promote WordPress plugin](https://wpglob.com/promote-wordpress-plugin/). **Tags:** * [News](/blog/tags/tags/news.md "Plugin news") [Edit this page](https://github.com/simple-jwt-login/website/tree/main/blog/2022-08-23-wp-glob-article.md) --- ## A[​](#A "Direct link to A") * [Add-on2](/blog/tags/tags/add-on.md "Plugin Addons") *** --- [Release](/blog/tags/tags/release.md)[Add-on](/blog/tags/tags/add-on.md) ## [Export-Import Add-on Released](/blog/simple-jwt-login-export-import-add-on.md)  ·  1 min read The Export-Import add-on for Simple JWT Login lets you copy your full configuration - Auth Codes, protection rules, and settings - between WordPress sites. ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/blog/simple-jwt-login-export-import-add-on.md) --- [Tutorial](/blog/tags/tags/tutorial.md)[Headless WordPress](/blog/tags/tags/headless-wordpress.md)[JWT Authentication](/blog/tags/tags/jwt-authentication.md)[Security](/blog/tags/tags/security.md) ## [Headless WordPress: JWT Auth Done Right](/blog/headless-wordpress-jwt-authentication.md)  ·  8 min read Add production-ready JWT authentication to your headless WordPress setup - from token generation to protected endpoints. ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/blog/headless-wordpress-jwt-authentication.md) --- [Tutorial](/blog/tags/tags/tutorial.md)[Headless WordPress](/blog/tags/tags/headless-wordpress.md)[JWT Authentication](/blog/tags/tags/jwt-authentication.md)[Security](/blog/tags/tags/security.md) ## [Headless WordPress: JWT Auth Done Right](/blog/headless-wordpress-jwt-authentication.md)  ·  8 min read Add production-ready JWT authentication to your headless WordPress setup - from token generation to protected endpoints. ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/blog/headless-wordpress-jwt-authentication.md) --- [News](/blog/tags/tags/news.md)[WordPress Plugin](/blog/tags/tags/wordpress-plugin.md) ## [A Faster, Smarter New Website Design](/blog/new-website-design-2026.md)  ·  2 min read We've redesigned the Simple JWT Login website with a cleaner UI, built-in search, AI-friendly content, and improved SEO. ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/blog/new-website-design-2026.md) --- [Release](/blog/tags/tags/release.md)[Add-on](/blog/tags/tags/add-on.md) ## [Export-Import Add-on Released](/blog/simple-jwt-login-export-import-add-on.md)  ·  1 min read The Export-Import add-on for Simple JWT Login lets you copy your full configuration - Auth Codes, protection rules, and settings - between WordPress sites. ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/blog/simple-jwt-login-export-import-add-on.md) --- [Tutorial](/blog/tags/tags/tutorial.md)[Headless WordPress](/blog/tags/tags/headless-wordpress.md)[JWT Authentication](/blog/tags/tags/jwt-authentication.md)[Security](/blog/tags/tags/security.md) ## [Headless WordPress: JWT Auth Done Right](/blog/headless-wordpress-jwt-authentication.md)  ·  8 min read Add production-ready JWT authentication to your headless WordPress setup - from token generation to protected endpoints. ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/blog/headless-wordpress-jwt-authentication.md) --- [Tutorial](/blog/tags/tags/tutorial.md)[Headless WordPress](/blog/tags/tags/headless-wordpress.md)[JWT Authentication](/blog/tags/tags/jwt-authentication.md)[Security](/blog/tags/tags/security.md) ## [Headless WordPress: JWT Auth Done Right](/blog/headless-wordpress-jwt-authentication.md)  ·  8 min read Add production-ready JWT authentication to your headless WordPress setup - from token generation to protected endpoints. ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/blog/headless-wordpress-jwt-authentication.md) --- [News](/blog/tags/tags/news.md)[WordPress Plugin](/blog/tags/tags/wordpress-plugin.md) ## [A Faster, Smarter New Website Design](/blog/new-website-design-2026.md)  ·  2 min read We've redesigned the Simple JWT Login website with a cleaner UI, built-in search, AI-friendly content, and improved SEO. ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/blog/new-website-design-2026.md) --- [Tutorial](/blog/tags/tags/tutorial.md)[WPGraphQL](/blog/tags/tags/wpgraphql.md)[JWT Authentication](/blog/tags/tags/jwt-authentication.md)[Headless WordPress](/blog/tags/tags/headless-wordpress.md) ## [Authenticate WPGraphQL with JWT Tokens](/blog/wpgraphql-jwt-authentication.md)  ·  6 min read A step-by-step guide to securing your WPGraphQL API with JWT tokens - setup, authenticated queries, mutations, and token handling. ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/blog/wpgraphql-jwt-authentication.md) --- # 5 Standout Features of Simple JWT Login March 10, 2026 · 5 min read [![Nicu Micle](https://github.com/nicumicle.png)](/blog/authors/nicumicle.md) [Nicu Micle](/blog/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") JWT authentication for WordPress doesn't have to be complicated. Simple JWT Login has been quietly powering headless WordPress sites, mobile backends, and SPA integrations for years - and it does so with a level of configurability that most teams never fully explore. Here are the five features I consider the most powerful, and why they matter for real-world projects. ## 1. Auth Codes - Fine-Grained API Key Control[​](#1-auth-codes---fine-grained-api-key-control "Direct link to 1. Auth Codes - Fine-Grained API Key Control") Most JWT plugins treat authentication as binary: you either have a valid token or you don't. Simple JWT Login goes further with **Auth Codes** - optional API keys that gate specific operations like registration, auto-login, or user deletion. Each Auth Code can be scoped to a specific action, assigned a WordPress user role, and even given an expiration date. This means you can issue a time-limited code to an external system for a batch user import, let it expire automatically, and never worry about revoking it manually. ``` # Register a user only when a valid auth_code is present curl -X POST "https://example.com/wp-json/simple-jwt-login/v1/users" \ -H "Content-Type: application/json" \ -d '{ "email": "jane@example.com", "password": "securepassword", "auth_code": "YOUR_AUTH_CODE" }' ``` The practical use case: you're integrating a third-party signup funnel. You issue it a restricted Auth Code that only allows registration, with the `subscriber` role. The funnel can create users - nothing else. That's a meaningful security boundary with zero custom code. *** ## 2. Auto-Login with Dynamic Redirects[​](#2-auto-login-with-dynamic-redirects "Direct link to 2. Auto-Login with Dynamic Redirects") Auto-login is the feature that consistently surprises people. Send a user a URL with a valid JWT, and Simple JWT Login will authenticate them silently and redirect them wherever you need - no password prompt, no login page friction. What makes it genuinely powerful is the **redirect URL variables**. Your redirect target can be dynamically built using the authenticated user's data: | Variable | Value | | --------------------- | -------------------- | | `{{user_id}}` | WordPress user ID | | `{{user_email}}` | User's email address | | `{{user_login}}` | Username | | `{{user_first_name}}` | First name | | `{{site_url}}` | Your site's base URL | ``` https://example.com/?JWT=&redirectUrl={{site_url}}/dashboard/?uid={{user_id}} ``` Real-world application: email marketing campaigns. Generate a signed JWT per subscriber, embed it in your campaign link, and drop users directly into their account dashboard - already logged in. The MailPoet add-on takes this even further by providing a shortcode that generates these links automatically inside your email templates. You also get a **fail-safe redirect** for invalid or expired tokens, so users with stale links don't hit a blank error page. *** ## 3. Endpoint Protection - Protect Your Entire REST API[​](#3-endpoint-protection---protect-your-entire-rest-api "Direct link to 3. Endpoint Protection - Protect Your Entire REST API") WordPress's REST API is powerful, but by default it exposes a lot of data publicly. Simple JWT Login's **Endpoint Protection** feature lets you put a JWT requirement in front of any REST route - or all of them at once. Two modes are available: * **Protect all, whitelist exceptions**: Every REST request must carry a valid JWT unless the route is explicitly whitelisted. * **Protect only listed routes**: Specific sensitive endpoints require a JWT; everything else remains public. Both modes support per-HTTP-method granularity. You might want `GET /wp-json/wp/v2/posts` to stay public while `POST` and `DELETE` on the same route require authentication. That's one configuration, no custom middleware. ``` Protected: POST /wp-json/wp/v2/posts Protected: DELETE /wp-json/wp/v2/posts/{id} Public: GET /wp-json/wp/v2/posts ``` Route matching supports both exact paths and prefix patterns (`starts-with`), which makes it easy to protect entire feature namespaces - for example, locking down everything under `/wp-json/woocommerce/` with a single rule. *** ## 4. WordPress Hooks & Filters - Deep Customization Without Forking[​](#4-wordpress-hooks--filters---deep-customization-without-forking "Direct link to 4. WordPress Hooks & Filters - Deep Customization Without Forking") Simple JWT Login ships with **16 hooks** that let you tap into every significant operation. This is the feature that separates it from simpler JWT plugins and makes it production-grade for complex applications. A few practical examples: **Add custom claims to the JWT payload:** ``` add_filter('simple_jwt_login_jwt_payload', function($payload, $user) { $payload['role'] = implode(',', $user->roles); $payload['company_id'] = get_user_meta($user->ID, 'company_id', true); return $payload; }, 10, 2); ``` **Send a welcome email after registration:** ``` add_action('simple_jwt_login_register_hook', function($user, $request) { wp_mail( $user->user_email, 'Welcome aboard!', 'Your account is ready. Log in at ' . get_site_url() ); }, 10, 2); ``` **Customize the authentication response:** ``` add_filter('simple_jwt_login_response_auth', function($response, $user, $jwt) { $response['avatar_url'] = get_avatar_url($user->ID); $response['display_name'] = $user->display_name; return $response; }, 10, 3); ``` No monkey-patching, no plugin forks - just clean WordPress action and filter hooks that survive updates. *** ## 5. Multiple JWT Delivery Methods[​](#5-multiple-jwt-delivery-methods "Direct link to 5. Multiple JWT Delivery Methods") APIs get consumed in many different environments: browser SPAs, mobile apps, server-to-server calls, legacy form-based flows. Simple JWT Login supports **five distinct ways** to pass a JWT, so you're never forced to restructure your client to match the plugin. | Method | How to use | | -------------------- | ------------------------------------- | | Authorization header | `Authorization: Bearer ` | | Query parameter | `?JWT=` | | Request body | `{"JWT": ""}` | | Cookie | `simple-jwt-login-token` | | Session | `$_SESSION['simple-jwt-login-token']` | The plugin processes them in a defined priority order (Header > Cookie > Session > Request body), so if multiple sources are present, behavior is predictable. For browser-based apps that need to avoid storing tokens in `localStorage`, the cookie delivery method is especially useful - pair it with an `HttpOnly` cookie set server-side and you have a solid defense against XSS token theft. *** ## Conclusion[​](#conclusion "Direct link to Conclusion") Simple JWT Login earns its place in a production WordPress stack because it's thoughtfully layered. You can use it at face value - just generate and validate tokens - or you can reach into Auth Codes, hooks, endpoint protection, and dynamic redirects to build something genuinely sophisticated. The plugin is free, actively maintained, and the [full documentation](/docs.md) covers every configuration option in detail. If you're building anything beyond a basic WordPress blog, it's worth an afternoon to set up properly. **Tags:** * [Tutorial](/blog/tags/tags/tutorial.md "Tutorials and guides for Simple JWT Login") * [JWT Authentication](/blog/tags/tags/jwt-authentication.md "Articles about JSON Web Token (JWT) authentication") * [WordPress Plugin](/blog/tags/tags/wordpress-plugin.md "WordPress plugin tips, features, and usage guides") * [Security](/blog/tags/tags/security.md "WordPress REST API security and authentication best practices") [Edit this page](https://github.com/simple-jwt-login/website/tree/main/blog/2026-03-10-top-features-simple-jwt-login.md) --- # Authenticate WPGraphQL with JWT Tokens March 10, 2026 · 6 min read [![Nicu Micle](https://github.com/nicumicle.png)](/blog/authors/nicumicle.md) [Nicu Micle](/blog/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") GraphQL and headless WordPress are a natural match. WPGraphQL gives you a flexible, typed query layer over all your WordPress data. But like the REST API, it's unauthenticated by default - anyone can query it. Simple JWT Login solves that. In this guide I'll walk through connecting Simple JWT Login to WPGraphQL so your GraphQL operations can carry a JWT, granting access to protected data and enabling authenticated mutations like creating posts or updating user profiles. ## Prerequisites[​](#prerequisites "Direct link to Prerequisites") You'll need two plugins installed and active: * **WPGraphQL** - available at [wpgraphql.com](https://www.wpgraphql.com) * **Simple JWT Login** - available in the [WordPress plugin repository](https://wordpress.org/plugins/simple-jwt-login/) No additional bridge plugin is required. Simple JWT Login's WPGraphQL integration is built in. *** ## How It Works[​](#how-it-works "Direct link to How It Works") The integration is straightforward: Simple JWT Login generates and validates JWTs using its standard `/auth` endpoint. When a request hits the WPGraphQL endpoint (`/wp-json/graphql` or `/graphql`), Simple JWT Login intercepts it, validates the bearer token, and - if valid - sets the current WordPress user context before WPGraphQL resolves the query. From WPGraphQL's perspective, the request simply arrives as an authenticated WordPress user. Every resolver that checks `current_user_can()` or relies on `wp_get_current_user()` works exactly as it would in a browser session. *** ## Step 1 - Configure Simple JWT Login[​](#step-1---configure-simple-jwt-login "Direct link to Step 1 - Configure Simple JWT Login") Navigate to **Simple JWT Login** in your WordPress admin. The core settings you need: **General tab:** * Set a strong **JWT Decryption Key** * Choose **HS256** as your algorithm (or RS256 for asymmetric setups) * Set a sensible **JWT expiration** (e.g. 3600 seconds / 1 hour) **WPGraphQL tab:** Enable the WPGraphQL integration: ``` Settings > Simple JWT Login > WPGraphQL > Enable WPGraphQL authentication ``` That's the only required toggle. The plugin will now validate JWT tokens on every request to your GraphQL endpoint. *** ## Step 2 - Obtain a JWT[​](#step-2---obtain-a-jwt "Direct link to Step 2 - Obtain a JWT") Use the standard auth endpoint to get a token: ``` curl -X POST "https://example.com/wp-json/simple-jwt-login/v1/auth" \ -H "Content-Type: application/json" \ -d '{ "email": "editor@example.com", "password": "their_password" }' ``` Response: ``` { "success": true, "data": { "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." } } ``` *** ## Step 3 - Make Authenticated GraphQL Queries[​](#step-3---make-authenticated-graphql-queries "Direct link to Step 3 - Make Authenticated GraphQL Queries") Pass the token as a bearer token in the `Authorization` header on every GraphQL request: ``` curl -X POST "https://example.com/graphql" \ -H "Content-Type: application/json" \ -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." \ -d '{ "query": "{ viewer { id name email roles { nodes { name } } } }" }' ``` Without the token, `viewer` returns `null`. With it, you get the full authenticated user object: ``` { "data": { "viewer": { "id": "dXNlcjoyNQ==", "name": "Jane Editor", "email": "editor@example.com", "roles": { "nodes": [{ "name": "editor" }] } } } } ``` *** ## Step 4 - Authenticated Mutations[​](#step-4---authenticated-mutations "Direct link to Step 4 - Authenticated Mutations") This is where the integration becomes genuinely useful. Many WPGraphQL mutations require an authenticated user. Creating a post, for example: ``` curl -X POST "https://example.com/graphql" \ -H "Content-Type: application/json" \ -H "Authorization: Bearer eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." \ -d '{ "query": "mutation CreatePost($input: CreatePostInput!) { createPost(input: $input) { post { id title status } } }", "variables": { "input": { "title": "My First API Post", "content": "Written via GraphQL with JWT auth.", "status": "PUBLISH", "clientMutationId": "create-post-1" } } }' ``` Without authentication, this mutation returns a permission error. With a valid JWT for a user who has the `editor` or `administrator` role, it succeeds and returns the created post. *** ## Using the Integration in a JavaScript Client[​](#using-the-integration-in-a-javascript-client "Direct link to Using the Integration in a JavaScript Client") In a Next.js or React app, you'll typically store the JWT after login and attach it to every GraphQL request. Here's how that looks with a simple fetch-based client: ``` const GQL_ENDPOINT = 'https://example.com/graphql'; async function graphqlRequest(query, variables = {}, token = null) { const headers = { 'Content-Type': 'application/json' }; if (token) { headers['Authorization'] = `Bearer ${token}`; } const response = await fetch(GQL_ENDPOINT, { method: 'POST', headers, body: JSON.stringify({ query, variables }), }); return response.json(); } // Login and get a token async function login(email, password) { const response = await fetch( 'https://example.com/wp-json/simple-jwt-login/v1/auth', { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ email, password }), } ); const data = await response.json(); return data.data.jwt; } // Example usage const token = await login('editor@example.com', 'password'); const { data } = await graphqlRequest( `{ viewer { name email } }`, {}, token ); console.log(data.viewer); // { name: 'Jane Editor', email: 'editor@example.com' } ``` If you're using Apollo Client, set the token in your auth link: ``` import { ApolloClient, InMemoryCache, createHttpLink } from '@apollo/client'; import { setContext } from '@apollo/client/link/context'; const httpLink = createHttpLink({ uri: 'https://example.com/graphql' }); const authLink = setContext((_, { headers }) => { const token = localStorage.getItem('jwt'); // or however you store it return { headers: { ...headers, authorization: token ? `Bearer ${token}` : '', }, }; }); const client = new ApolloClient({ link: authLink.concat(httpLink), cache: new InMemoryCache(), }); ``` *** ## Enriching Queries with Custom JWT Claims[​](#enriching-queries-with-custom-jwt-claims "Direct link to Enriching Queries with Custom JWT Claims") Sometimes you want to avoid an extra `viewer` query on page load by embedding user metadata directly in the token. Use the `simple_jwt_login_jwt_payload` filter to add whatever your front-end needs: ``` add_filter('simple_jwt_login_jwt_payload', function($payload, $user) { $payload['wp_roles'] = $user->roles; $payload['display_name'] = $user->display_name; $payload['avatar_url'] = get_avatar_url($user->ID, ['size' => 48]); return $payload; }, 10, 2); ``` Your Apollo or fetch client can decode the JWT (it's just base64) and read these values without any extra network request: ``` function decodeJwtPayload(token) { const base64 = token.split('.')[1].replace(/-/g, '+').replace(/_/g, '/'); return JSON.parse(atob(base64)); } const payload = decodeJwtPayload(token); console.log(payload.display_name); // "Jane Editor" console.log(payload.wp_roles); // ["editor"] ``` *** ## Protecting the GraphQL Endpoint Itself[​](#protecting-the-graphql-endpoint-itself "Direct link to Protecting the GraphQL Endpoint Itself") By default, WPGraphQL allows unauthenticated introspection queries, which exposes your full schema to anyone. You can lock this down at two levels: **WPGraphQL side:** Disable public introspection in WPGraphQL settings. **Simple JWT Login side:** Add the GraphQL endpoint to your protected routes: ``` Settings > Simple JWT Login > Protect Endpoints Add route: /graphql Methods: GET, POST ``` This ensures every GraphQL request - including introspection - must carry a valid JWT. Ideal for private internal APIs. *** ## Token Refresh for Long-Running Sessions[​](#token-refresh-for-long-running-sessions "Direct link to Token Refresh for Long-Running Sessions") GraphQL apps often run as SPAs where the user stays on the page for extended periods. Implement proactive token refresh to avoid mid-session 401s: ``` function isTokenExpiringSoon(token, bufferSeconds = 300) { const { exp } = decodeJwtPayload(token); return (exp - bufferSeconds) < (Date.now() / 1000); } async function refreshToken(currentToken) { const response = await fetch( 'https://example.com/wp-json/simple-jwt-login/v1/auth/refresh', { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ JWT: currentToken }), } ); const data = await response.json(); return data.data.jwt; } // Before each GraphQL request: if (isTokenExpiringSoon(storedToken)) { storedToken = await refreshToken(storedToken); // persist updated token } ``` *** ## Conclusion[​](#conclusion "Direct link to Conclusion") Simple JWT Login and WPGraphQL complement each other cleanly. WPGraphQL handles the query layer; Simple JWT Login handles identity. The integration requires no extra plugins, just a single settings toggle, and the result is a fully authenticated GraphQL API that honours WordPress's existing user roles and capabilities. From there, the hooks system gives you room to customize the JWT payload, and the endpoint protection feature lets you lock down the GraphQL route to authenticated traffic only. It's a solid foundation for any headless WordPress application built on GraphQL. **Tags:** * [Tutorial](/blog/tags/tags/tutorial.md "Tutorials and guides for Simple JWT Login") * [WPGraphQL](/blog/tags/tags/wpgraphql.md "Integrating Simple JWT Login with WPGraphQL") * [JWT Authentication](/blog/tags/tags/jwt-authentication.md "Articles about JSON Web Token (JWT) authentication") * [Headless WordPress](/blog/tags/tags/headless-wordpress.md "Articles about headless WordPress architecture and JWT authentication") [Edit this page](https://github.com/simple-jwt-login/website/tree/main/blog/2026-03-10-wpgraphql-jwt-authentication.md) --- [feature](/releases/tags/feature.md)[bugfix](/releases/tags/bugfix.md)[breaking-change](/releases/tags/breaking-change.md) ## [New Plugin Release 4.0.0](/releases/simple-jwt-login-release-4.0.0.md)  ·  7 min read Released version 4.0.0 - major redesign, new features, OAuth expansion, 2FA, API Keys, Audit Logs, Webhooks, and more ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-4.0.0.md) --- ### 2026[​](#2026 "Direct link to 2026") * [March 14](/releases/simple-jwt-login-release-3.6.5.md) [ - ](/releases/simple-jwt-login-release-3.6.5.md) [New Plugin Release 3.6.5](/releases/simple-jwt-login-release-3.6.5.md) * [June 5](/releases/simple-jwt-login-release-4.0.0.md) [ - ](/releases/simple-jwt-login-release-4.0.0.md) [New Plugin Release 4.0.0](/releases/simple-jwt-login-release-4.0.0.md) --- # Authors * [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) ## [Nicu Micle](/releases/authors/nicumicle.md) 21 Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") --- [feature](/releases/tags/feature.md)[bugfix](/releases/tags/bugfix.md)[breaking-change](/releases/tags/breaking-change.md) ## [New Plugin Release 4.0.0](/releases/simple-jwt-login-release-4.0.0.md)  ·  7 min read Released version 4.0.0 - major redesign, new features, OAuth expansion, 2FA, API Keys, Audit Logs, Webhooks, and more ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-4.0.0.md) --- [feature](/releases/tags/feature.md) ## [New Plugin Release 3.6.0](/releases/simple-jwt-login-release-3.6.0.md)  ·  1 min read Released version 3.6.0 ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-3.6.0.md) --- [bugfix](/releases/tags/bugfix.md) ## [New Plugin Release 3.5.3](/releases/simple-jwt-login-release-3.5.3.md)  ·  1 min read Released version 3.5.3 ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-3.5.3.md) --- [bugfix](/releases/tags/bugfix.md)[security](/releases/tags/security.md) ## [New Plugin Release 3.4.7](/releases/simple-jwt-login-release-3.4.7.md)  ·  1 min read Released version 3.4.7 ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-3.4.7.md) --- [feature](/releases/tags/feature.md) ## [New Plugin Release 3.6.0](/releases/simple-jwt-login-release-3.6.0.md)  ·  1 min read Released version 3.6.0 ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-3.6.0.md) --- [bugfix](/releases/tags/bugfix.md) ## [New Plugin Release 3.5.3](/releases/simple-jwt-login-release-3.5.3.md)  ·  1 min read Released version 3.5.3 ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-3.5.3.md) --- [bugfix](/releases/tags/bugfix.md)[security](/releases/tags/security.md) ## [New Plugin Release 3.4.7](/releases/simple-jwt-login-release-3.4.7.md)  ·  1 min read Released version 3.4.7 ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-3.4.7.md) --- # New Plugin Release 3.4.4 April 3, 2022 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.4.4` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update brings new hooks for customizing responses, a fix for empty JWT headers, and a new OpenAPI spec. ## New Features[​](#new-features "Direct link to New Features") * New hooks have been added to allow customization of all success responses * New [OpenAPI](https://github.com/nicumicle/simple-jwt-login/blob/v3/postman/openapi.yaml) spec file has been added ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Do not add empty JWT to the Authorization header ## Compatibility[​](#compatibility "Direct link to Compatibility") * The plugin has been tested with WordPress 5.9 *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) * [feature](/releases/tags/feature.md) --- # New Plugin Release 3.4.5 April 11, 2022 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.4.5` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update introduces two new Autologin features: a redirect on failure and a shortcode for displaying error details. ## New Features[​](#new-features "Direct link to New Features") * Add Redirect on Fail Autologin * Shortcode for displaying Autologin errors ## Redirect on Fail[​](#redirect-on-fail "Direct link to Redirect on Fail") This feature allows you to set a redirect URL for when Autologin fails - for example, when the JWT is invalid or expired - so you can show users a helpful error page instead of a blank screen. ## Shortcode for Autologin Errors[​](#shortcode-for-autologin-errors "Direct link to Shortcode for Autologin Errors") The new shortcode lets you display the autologin error code or message directly on any page: ``` [simple-jwt-login:request key="error_code"] ``` ``` [simple-jwt-login:request key="error_message"] ``` You can also use it to read any query parameter from the URL. For example, given: ``` https://simplejwtlogin.com?my_parameter=test&error_code=21&error_message=This is an error ``` * `[simple-jwt-login:request key="error_code"]` → `21` * `[simple-jwt-login:request key="error_message"]` → `This is an error` * `[simple-jwt-login:request key="my_parameter"]` → `test` note These shortcodes strip all HTML tags from the output. *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [feature](/releases/tags/feature.md) --- # New Plugin Release 3.4.7 October 4, 2022 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.4.7` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This is a **security release** following a WordPress team review. We recommend updating immediately. ## Security Fixes[​](#security-fixes "Direct link to Security Fixes") * Remove code vulnerability from the JWT library * Fix local file inclusion risk * Variables sanitization across the plugin ## Improvements[​](#improvements "Direct link to Improvements") * Apply PHPCS checks to the entire plugin folder, not only the `src/` directory * Keep the current active tab when plugin settings are saved ## Compatibility[​](#compatibility "Direct link to Compatibility") * The plugin has been tested with WordPress 6.0.2 *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) * [security](/releases/tags/security.md) --- # New Plugin Release 3.4.8 November 5, 2022 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.4.8` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update brings new filter hooks, improved security through request sanitization, and a bug fix for passwords with special characters. ## New Features[​](#new-features "Direct link to New Features") * Add `simple_jwt_login_generate_payload` filter to allow customization of the authentication payload * `/auth/validate` endpoint now supports both `GET` and `POST` methods ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Fix password that contains special characters [#50](https://github.com/nicumicle/simple-jwt-login/issues/50) ## Improvements[​](#improvements "Direct link to Improvements") * Change how the user is logged in when using the Protect Endpoints feature * Refactor `RouteService::getUserFromJWT` method * Sanitize all data from incoming requests * Update License to GPL v3 *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) * [feature](/releases/tags/feature.md) --- # New Plugin Release 3.4.9 December 4, 2022 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.4.9` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update introduces several new features around password handling, autologin flexibility, and a new plugin lifecycle hook. ## New Features[​](#new-features "Direct link to New Features") * Add a strength indicator for the JWT decryption key * Allow setting a custom length for randomly generated passwords (default: 10 characters) * Allow sending base64-encoded `password` and `passhash` on the `/auth` endpoint * Add query parameters filter on autologin redirect * Add the `simple_jwt_login_before_endpoint` hook, fired before all plugin routes are initialized ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Fix `includeRequestParameters` building incorrect redirect URLs *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) * [feature](/releases/tags/feature.md) --- # New Plugin Release 3.5.0 January 5, 2023 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.5.0` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update fixes compatibility issues with Protect Endpoints, improves Reset Password, and drops legacy PHP support. ## New Features[​](#new-features "Direct link to New Features") * Search user by email on Reset Password [#31](https://github.com/nicumicle/simple-jwt-login/issues/31) ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Fix: unable to create a post when Protect Endpoints is enabled for all endpoints [#62](https://github.com/nicumicle/simple-jwt-login/issues/62) ## Improvements[​](#improvements "Direct link to Improvements") * Switch `get_user_by_email` to `get_user_by()` due to WordPress deprecation * Remove `convertUserToArray` method from `WordPressData` * Drop support for PHP 5.3 and PHP 5.4 *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) * [feature](/releases/tags/feature.md) --- # New Plugin Release 3.5.1 October 1, 2023 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.5.1` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update resolves PHP 8.2 warnings and adds WordPress 6.3 compatibility. ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Fix warnings and failed tests on PHP 8.2 ## Improvements[​](#improvements "Direct link to Improvements") * Publish code coverage to Codecov ## Compatibility[​](#compatibility "Direct link to Compatibility") * Update WordPress 6.3 compatibility *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) --- # New Plugin Release 3.5.2 November 2, 2023 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.5.2` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update adds `iss` support to the JWT payload, tightens revoked token enforcement, and fixes several bugs. ## New Features[​](#new-features "Direct link to New Features") * Add `iss` (issuer) claim to the JWT payload with a configurable value ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Fix: user could change their password using a revoked JWT * Fix: protected endpoints could be accessed with a revoked token [#75](https://github.com/nicumicle/simple-jwt-login/issues/75) * Fix user meta not being saved correctly on user registration [#86](https://github.com/nicumicle/simple-jwt-login/issues/86) * Change route priorities from floats to integers to fix the PHP deprecation warning "Implicit conversion from float to int loses precision" *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) * [feature](/releases/tags/feature.md) --- # New Plugin Release 3.5.3 November 16, 2023 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.5.3` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This is a maintenance release with a minor fix and WordPress 6.4 compatibility. ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Fix License declaration in `composer.json` ## Compatibility[​](#compatibility "Direct link to Compatibility") * Update WordPress 6.4 compatibility *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) --- # New Plugin Release 3.5.4 May 3, 2024 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.5.4` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update adds OAuth support for Google login and fixes the HTTP status code returned for expired tokens. ## New Features[​](#new-features "Direct link to New Features") * Add OAuth support for Google [#97](https://github.com/nicumicle/simple-jwt-login/issues/97) ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Fix incorrect status code returned for expired tokens [#102](https://github.com/nicumicle/simple-jwt-login/issues/102) ## Compatibility[​](#compatibility "Direct link to Compatibility") * Update WordPress 6.5 compatibility *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) * [feature](/releases/tags/feature.md) --- # New Plugin Release 3.5.5 May 4, 2024 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.5.5` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This is a maintenance release with documentation updates and a Protect Endpoints refactor. ## Improvements[​](#improvements "Direct link to Improvements") * Update README * Refactor Protect Endpoints for better code structure Read more about Protect Endpoints [here](/docs/protect-endpoints.md). *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) --- # New Plugin Release 3.5.6 August 3, 2024 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.5.6` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update adds WordPress 6.6 compatibility and fixes revoked token validation when the JWT middleware is enabled. ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Fix revoked token validation when the JWT middleware is enabled [#110](https://github.com/nicumicle/simple-jwt-login/issues/110) ## Compatibility[​](#compatibility "Direct link to Compatibility") * Update WordPress 6.6 compatibility *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) --- # New Plugin Release 3.5.7 December 22, 2024 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.5.7` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This is a compatibility release for WordPress 6.7. ## Compatibility[​](#compatibility "Direct link to Compatibility") * Update WordPress 6.7 compatibility *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) --- # New Plugin Release 3.5.8 February 14, 2025 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.5.8` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update improves redirect security and ensures the JWT middleware only runs once per request. ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Use `wp_safe_redirect` for all plugin redirects to prevent open redirect vulnerabilities [#115](https://github.com/nicumicle/simple-jwt-login/issues/115) * Ensure the JWT middleware only runs once per request [#125](https://github.com/nicumicle/simple-jwt-login/issues/125) *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) --- # New Plugin Release 3.6.0 March 24, 2025 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.6.0` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update brings better flexibility for Protect Endpoints, WPGraphQL authentication support, username/email login parity with WordPress, and PHP 8.3/8.4 CI coverage. ## New Features[​](#new-features "Direct link to New Features") * Support for configuring allowed request methods per protected endpoint [#129](https://github.com/nicumicle/simple-jwt-login/issues/129) * **Beta:** WPGraphQL Authentication - users can now authenticate when performing queries with WPGraphQL [#32](https://github.com/nicumicle/simple-jwt-login/issues/32) * Authenticate by username or email, matching the default WordPress login behavior [#19](https://github.com/nicumicle/simple-jwt-login/issues/19) ## Improvements[​](#improvements "Direct link to Improvements") * CI updates - plugin code is now syntax-checked against PHP 8.3 and 8.4 * Code refactoring and UI improvements *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [feature](/releases/tags/feature.md) --- # New Plugin Release 3.6.1 April 1, 2025 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.6.1` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update strengthens the Protect Endpoints feature with JWT validation and restores backward compatibility for existing configurations. ## New Features[​](#new-features "Direct link to New Features") * Validate JWT on protected endpoints [#141](https://github.com/nicumicle/simple-jwt-login/issues/141) ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Fix backward compatibility for Protect Endpoints - adds `match` / `start_with` matching options for endpoint rules [#143](https://github.com/nicumicle/simple-jwt-login/issues/143) Read more about Protect Endpoints [here](/docs/protect-endpoints.md). *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) * [feature](/releases/tags/feature.md) --- # New Plugin Release 3.6.2 April 9, 2025 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.6.2` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update fixes issues with the Protect Endpoints feature blocking WordPress admin requests and missing JWT session lookup. ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Fix: Protect Endpoints was incorrectly blocking WordPress backend (admin) endpoints [#146](https://github.com/nicumicle/simple-jwt-login/issues/146) * Ensure Protect Endpoints searches for the JWT in the PHP session Read more about Protect Endpoints [here](/docs/protect-endpoints.md). *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) --- # New Plugin Release 3.6.3 April 15, 2025 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.6.3` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This update includes a fix for the Protect Endpoints feature. ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Fix protect endpoints [#149](https://github.com/nicumicle/simple-jwt-login/issues/149) Read more about Protect Endpoints [here](/docs/protect-endpoints.md). *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) --- # New Plugin Release 3.6.4 April 17, 2025 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.6.4` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This is a compatibility release for WordPress 6.8. ## Compatibility[​](#compatibility "Direct link to Compatibility") * Update WordPress 6.8 compatibility *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) --- # New Plugin Release 3.6.5 March 14, 2026 · One min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `3.6.5` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This is a **security and maintenance release**. We strongly recommend updating immediately. ## Security Fix[​](#security-fix "Direct link to Security Fix") This release addresses a **Stored Cross-Site Scripting (XSS)** vulnerability identified as **CVE-2025-58648**. Stored XSS vulnerabilities allow an attacker to inject malicious scripts that are persisted on the server and executed in the browsers of other users. This fix prevents unsanitized input from being stored and rendered as HTML. If you are running an older version, please update as soon as possible to protect your site and users. * Fix CVE-2025-58648 - Stored Cross-Site Scripting vulnerability ([PR #162](https://github.com/nicumicle/simple-jwt-login/pull/162)) ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Fix Reset Password: the function was not applying base64 encoding logic, preventing users from using special characters in their passwords ([#161](https://github.com/nicumicle/simple-jwt-login/issues/161), [PR #163](https://github.com/nicumicle/simple-jwt-login/pull/163)) * Fix PHP session initialization warning ([#159](https://github.com/nicumicle/simple-jwt-login/issues/159)) ## Compatibility[​](#compatibility "Direct link to Compatibility") * Update WordPress 6.9 Compatibility *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [bugfix](/releases/tags/bugfix.md) * [security](/releases/tags/security.md) --- # New Plugin Release 4.0.0 June 5, 2026 · 7 min read [![Nicu Micle](https://github.com/nicumicle.png)](/releases/authors/nicumicle.md) [Nicu Micle](/releases/authors/nicumicle.md) Creator of Simple JWT Login [](https://x.com/nicumicle "X")[](https://github.com/nicumicle "GitHub") The version `4.0.0` has been released today on [WordPress](https://wordpress.org/plugins/simple-jwt-login). This is a **major release** packed with new features, a completely redesigned admin interface, expanded OAuth provider support, and important security and usability improvements. Please read the breaking changes section carefully before upgrading. ## New Features[​](#new-features "Direct link to New Features") ### Completely Redesigned Admin Interface[​](#completely-redesigned-admin-interface "Direct link to Completely Redesigned Admin Interface") The plugin settings interface has been completely redesigned to provide a cleaner, more modern, and intuitive user experience. Settings are now better organized, easier to discover, and simpler to configure, reducing the need to consult documentation for common setup tasks. The refreshed layout improves navigation and helps users configure JWT authentication more efficiently. The new admin UI also includes full **Light** and **Dark Mode** support, automatically adapting to your preferred WordPress admin theme for a consistent and comfortable experience. Behind the scenes, all frontend assets (CSS, JavaScript, and images) have been reorganized into a dedicated `assets/` directory, resulting in a cleaner, more maintainable plugin structure and improved developer experience. ### Audit Logs[​](#audit-logs "Direct link to Audit Logs") A new **Audit Logs** section gives you visibility into authentication events across your WordPress site. You can now track login attempts, token refreshes, user registrations, password resets, and more - all with timestamps and relevant metadata. Audit log entries are stored in a dedicated database table and can be browsed directly from the plugin settings. ### Webhooks[​](#webhooks "Direct link to Webhooks") **Outbound webhooks** are now supported. You can configure HTTP callbacks that fire on key plugin events - such as user login, registration, authentication, and more. Each webhook call result is optionally logged, giving you a full audit trail of outbound notifications. ### API Keys (X-API-Key)[​](#api-keys-x-api-key "Direct link to API Keys (X-API-Key)") A new **API Keys** management system lets you create and manage `X-API-Key` tokens that grant authenticated access to WordPress REST endpoints. This is useful for machine-to-machine integrations where you need stable, long-lived credentials without issuing JWTs. Key features include: * Full CRUD interface for managing keys (create, update, list, delete, revoke) * Configurable permissions per key * JWT authentication is also accepted on the API Keys endpoint (in addition to cookie-based login) ### Expanded OAuth Provider Support[​](#expanded-oauth-provider-support "Direct link to Expanded OAuth Provider Support") In addition to Google, version 4.0.0 adds OAuth login support for three new providers: * **Auth0** - enterprise-grade identity management * **Facebook** - social login via Facebook OAuth * **GitHub** - developer-friendly login via GitHub OAuth All providers are configurable under the new **Integrations** section. ### Two-Factor Authentication (2FA)[​](#two-factor-authentication-2fa "Direct link to Two-Factor Authentication (2FA)") The plugin now integrates with WordPress 2FA plugins. When 2FA is enabled on a user account, the authentication flow enforces the second-factor check before issuing a JWT. This integration is detected automatically at runtime based on the 2FA plugin installed on your site. ### JWT Custom Claims[​](#jwt-custom-claims "Direct link to JWT Custom Claims") You can now define **custom JWT payload claims** directly from the plugin settings. This allows you to embed additional user metadata or application-specific data into every token your site issues, without writing custom code. ### Multiple JWT Decryption Keys[​](#multiple-jwt-decryption-keys "Direct link to Multiple JWT Decryption Keys") The plugin now supports configuring **multiple JWT decryption keys** with rules based on the JWT header or payload. This enables key rotation strategies and multi-tenant scenarios where different tokens are signed with different keys. ### Refresh Token Handling[​](#refresh-token-handling "Direct link to Refresh Token Handling") Authentication responses now include a **refresh token** alongside the access JWT. A dedicated endpoint lets clients exchange an expired access token for a new one using the refresh token, without requiring the user to re-authenticate. ### Enable/Disable Revoke and Validate Token Endpoints[​](#enabledisable-revoke-and-validate-token-endpoints "Direct link to Enable/Disable Revoke and Validate Token Endpoints") The token revocation and validation endpoints can now be individually toggled on or off from the plugin settings, giving you fine-grained control over which JWT operations are exposed on your site. ### WordPress Default Emails on Register and Password Change[​](#wordpress-default-emails-on-register-and-password-change "Direct link to WordPress Default Emails on Register and Password Change") You can now opt in to sending **WordPress default notification emails** when a user registers via the plugin or changes their password through the reset-password endpoint. Previously this was not configurable and the default WP emails were suppressed. ### Try Now Feature[​](#try-now-feature "Direct link to Try Now Feature") A new **"Try Now"** button in the plugin settings lets you test your JWT configuration directly from the admin panel, without needing an external REST client. ### OpenAPI Specification[​](#openapi-specification "Direct link to OpenAPI Specification") The old Postman collection has been replaced with a full **OpenAPI (Swagger) specification** (`openapi/openapi.yaml`). This provides a standardized, machine-readable API contract that works with any OpenAPI-compatible tooling. ### User Identification Moved to General Settings[​](#user-identification-moved-to-general-settings "Direct link to User Identification Moved to General Settings") The **User Identification** setting (how the plugin resolves which WordPress user a JWT refers to) has been moved from individual endpoint settings to a single place under **General Settings**. This eliminates duplication and ensures consistent behavior across all endpoints. ### Search on Hooks View[​](#search-on-hooks-view "Direct link to Search on Hooks View") The hooks/actions reference view now includes a **search field**, making it easy to find specific action hooks when building integrations. *** ## Bug Fixes[​](#bug-fixes "Direct link to Bug Fixes") * Fix double encoding for Reset Password email body ([#165](https://github.com/nicumicle/simple-jwt-login/issues/165)) - the email body was being base64-encoded twice, producing garbled content in some mail clients * Fix passwords with special characters on register, authenticate, and reset password - special characters in passwords no longer break authentication due to incorrect `wp_slash()` handling * Replace variables in reset password email subject - template variables (e.g. `{site_name}`) are now correctly substituted in the email subject line, not just the body * Fix reset password response - the endpoint now returns a consistent and correctly structured JSON response * Fix OAuth + 2FA integration - OAuth login flows now correctly trigger the 2FA check when the authenticated user has 2FA enabled * Fix "Try Now" when permalink is disabled - the feature now works correctly on WordPress installations using plain (query string) permalinks * Fix WordPress data dependency issue affecting some edge cases in the authentication flow * Fix CSS compatibility for WordPress 7.0 * Fix status codes - HTTP response codes are now accurate and consistent across all endpoints (e.g. `401` for unauthorized, `403` for forbidden, `422` for validation errors) * Fix validation error responses - invalid request payloads now return structured error messages instead of generic failures * Address WordPress Plugin Checker issues - the plugin now passes the official WordPress Plugin Check tool with no critical errors *** ## Breaking Changes[​](#breaking-changes "Direct link to Breaking Changes") Version 4.0.0 introduces several breaking changes. If you are upgrading from version 3.x, review each item below and update your client applications accordingly. ### Settings Structure Reorganized in the Database[​](#settings-structure-reorganized-in-the-database "Direct link to Settings Structure Reorganized in the Database") The internal format of the plugin's settings record in the WordPress options table has been restructured. **A settings migration runs automatically on plugin activation**, but if you have custom code that reads `simple_jwt_login_settings` directly from the database, it will need to be updated to match the new structure. ### Register User Response Format Changed[​](#register-user-response-format-changed "Direct link to Register User Response Format Changed") The register endpoint response has changed: **Before (3.x):** ``` { "success": true, "ID": 1, "user_login": "john", ... } ``` **After (4.0.0):** ``` { "success": true, "data": { "id": 1, "user_login": "john", ... } } ``` Update any client code that reads fields directly from the register response root. ### Old `/register` Endpoint Removed[​](#old-register-endpoint-removed "Direct link to old-register-endpoint-removed") The legacy `GET/POST /simple-jwt-login/v1/register` endpoint has been removed. All user registration must now go through the `POST /simple-jwt-login/v1/users` route. Update your integrations accordingly. ### User Identification Removed from Delete User Settings[​](#user-identification-removed-from-delete-user-settings "Direct link to User Identification Removed from Delete User Settings") The "User Identification" field has been removed from the Delete User endpoint settings. The plugin now uses the single **General Settings > User Identification** value for all endpoints. If you had a different identification strategy configured specifically for delete, review your General Settings to ensure the correct value is set. ### Refresh Token Added to Authentication Response[​](#refresh-token-added-to-authentication-response "Direct link to Refresh Token Added to Authentication Response") The authenticate endpoint now returns a `refresh_token` field in addition to the JWT. While this is additive, clients that strictly validate the response shape (e.g. with JSON Schema) may need to be updated to allow the new field. ### 2FA Enforcement on Authentication[​](#2fa-enforcement-on-authentication "Direct link to 2FA Enforcement on Authentication") If your site has a 2FA plugin installed and a user has 2FA enabled, the JWT authentication flow now **requires** the second factor before issuing a token. Applications that bypassed 2FA by using the plugin's authentication endpoint will now be blocked until they implement the 2FA challenge/response flow. *** If you encounter any issues after updating, please open an [issue](https://github.com/nicumicle/simple-jwt-login/issues) on GitHub. **Tags:** * [feature](/releases/tags/feature.md) * [bugfix](/releases/tags/bugfix.md) * [breaking-change](/releases/tags/breaking-change.md) --- ## B[​](#B "Direct link to B") * [breaking-change1](/releases/tags/breaking-change.md) * [bugfix19](/releases/tags/bugfix.md) *** --- [feature](/releases/tags/feature.md)[bugfix](/releases/tags/bugfix.md)[breaking-change](/releases/tags/breaking-change.md) ## [New Plugin Release 4.0.0](/releases/simple-jwt-login-release-4.0.0.md)  ·  7 min read Released version 4.0.0 - major redesign, new features, OAuth expansion, 2FA, API Keys, Audit Logs, Webhooks, and more ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-4.0.0.md) --- [feature](/releases/tags/feature.md)[bugfix](/releases/tags/bugfix.md)[breaking-change](/releases/tags/breaking-change.md) ## [New Plugin Release 4.0.0](/releases/simple-jwt-login-release-4.0.0.md)  ·  7 min read Released version 4.0.0 - major redesign, new features, OAuth expansion, 2FA, API Keys, Audit Logs, Webhooks, and more ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-4.0.0.md) --- [bugfix](/releases/tags/bugfix.md) ## [New Plugin Release 3.5.8](/releases/simple-jwt-login-release-3.5.8.md)  ·  1 min read Released version 3.5.8 ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-3.5.8.md) --- [bugfix](/releases/tags/bugfix.md)[feature](/releases/tags/feature.md) ## [New Plugin Release 3.5.2](/releases/simple-jwt-login-release-3.5.2.md)  ·  1 min read Released version 3.5.2 ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-3.5.2.md) --- [bugfix](/releases/tags/bugfix.md)[feature](/releases/tags/feature.md) ## [New Plugin Release 3.4.4](/releases/simple-jwt-login-release-3.4.4.md)  ·  1 min read Released version 3.4.4 ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-3.4.4.md) --- [feature](/releases/tags/feature.md)[bugfix](/releases/tags/bugfix.md)[breaking-change](/releases/tags/breaking-change.md) ## [New Plugin Release 4.0.0](/releases/simple-jwt-login-release-4.0.0.md)  ·  7 min read Released version 4.0.0 - major redesign, new features, OAuth expansion, 2FA, API Keys, Audit Logs, Webhooks, and more ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-4.0.0.md) --- [bugfix](/releases/tags/bugfix.md)[feature](/releases/tags/feature.md) ## [New Plugin Release 3.4.9](/releases/simple-jwt-login-release-3.4.9.md)  ·  1 min read Released version 3.4.9 ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-3.4.9.md) --- [bugfix](/releases/tags/bugfix.md)[security](/releases/tags/security.md) ## [New Plugin Release 3.6.5](/releases/simple-jwt-login-release-3.6.5.md)  ·  1 min read Released version 3.6.5 - security patch, bug fixes, and WordPress 6.9 compatibility ![Nicu Micle](https://github.com/nicumicle.png)Nicu Micle [Read more →](/releases/simple-jwt-login-release-3.6.5.md) --- [Skip to main content](#__docusaurus_skipToContent_fallback) ⭐️ If you like Simple-JWT-Login, give it a star on [GitHub](https://github.com/nicumicle/simple-jwt-login). [![Simple-JWT-Login Logo](/assets/favicons/favicon.ico)![Simple-JWT-Login Logo](/assets/favicons/favicon.ico)](/) [**Simple JWT Login**](/)[Docs](/docs.md "Docs")[API Reference](/api/v4/simple-jwt-login.md)[Blog](/blog.md "Blog")[Ecosystem](/ecosystem "Ecosystem") Search [4.x](/docs.md) * [4.x](/docs.md) * [3.x](/docs/3.0.0.md) [](https://github.com/nicumicle/simple-jwt-login "GitHub") # Search the documentation This project is supported by: [![DigitalOcean](https://opensource.nyc3.cdn.digitaloceanspaces.com/attribution/assets/SVG/DO_Logo_horizontal_blue.svg)](https://www.digitalocean.com/ "DigitalOcean - cloud infrastructure sponsor") ![](/assets/favicons/favicon.ico)Simple JWT Login JWT authentication for WordPress - REST API, headless WP, WPGraphQL, and WP-CLI. Free and open-source, forever. [](https://github.com/nicumicle/simple-jwt-login "GitHub")[](https://discord.gg/c4AeefD8Dr "Discord")[](https://twitter.com/simplejwtlogin "X (Twitter)") ### Project * [Documentation](/docs.md) * [API Reference](/api/v4/simple-jwt-login.md) * [Releases](/releases.md) * [Donate](/donate) ### Explore * [Deploy WordPress](/deploy-wordpress) * [Demos](/demos) * [Ecosystem](/ecosystem) ### Get Help * [WordPress Plugin Page](https://wordpress.org/plugins/simple-jwt-login) * [Support Forum](https://wordpress.org/support/plugin/simple-jwt-login) * [Report an Issue](https://github.com/nicumicle/simple-jwt-login/issues) * [Contact](/contact) ### Connect * [GitHub Repository](https://github.com/nicumicle/simple-jwt-login) * [Discord Community](https://discord.gg/c4AeefD8Dr) * [X (Twitter)](https://twitter.com/simplejwtlogin) * [Blog](/blog.md) --- # Autologin ``` GET /simple-jwt-login/v1/autologin ``` Authenticate and automatically log in a user to WordPress using a valid JSON Web Token (JWT). ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 Successful login. The user will be redirected to the WordPress website. Invalid request or authentication failure. --- # Change user password ``` PUT /simple-jwt-login/v1/users/reset_password ``` Change user password ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 User password has been changed. Error. --- # Delete user ``` DELETE /simple-jwt-login/v1/users ``` Delete user ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 Successfully deleted Error. --- # Authenticate ``` POST /simple-jwt-login/v1/auth ``` Authenticate ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 Successfully authenticated Error. --- # Refresh expired JWT ``` POST /simple-jwt-login/v1/auth/refresh ``` Refresh expired JWT ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 Token has been refreshed succcessfully Error --- # Register user ``` POST /simple-jwt-login/v1/users ``` Register WordPress user ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 User Registered Error. --- # Revoke JWT ``` POST /simple-jwt-login/v1/auth/revoke ``` Revoke JWT ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 Token has been revoked Error --- # Send reset password code ``` POST /simple-jwt-login/v1/users/reset_password ``` Send reset password code ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 Successfully send the reset password code Error. --- Version: 3.6.5 # Simple-JWT-Login ![Simple-Jwt-Login Logo](https://raw.githubusercontent.com/nicumicle/simple-jwt-login/refs/heads/master/wordpress.org/assets/icon-128x128.png)![Simple-Jwt-Login Logo](https://raw.githubusercontent.com/nicumicle/simple-jwt-login/refs/heads/master/wordpress.org/assets/icon-128x128.png) This is the Simple-JWT-Login WordPress plugin API Documentation. ## Introduction[​](#introduction "Direct link to Introduction") This API is documented in **OpenAPI format**. You can either open it in [swagger editor](https://editor.swagger.io/) or you can view it on this website. Also, you open it in postman, and you will be able to do local tests. ## Server[​](#server "Direct link to Server") You can access the Simple-JWT-Login API in two modes: * using permalink: https\://{domain}/wp-json/simple-jwt-login/v1/{endpoint} * using rest\_route: https\://{domain}/?rest\_route=/simple-jwt-login/v1/{endpoint} ## Cross-Origin Resource Sharing[​](#cross-origin-resource-sharing "Direct link to Cross-Origin Resource Sharing") This API features Cross-Origin Resource Sharing (CORS) implemented in compliance with [W3C spec](https://www.w3.org/TR/cors/). And that allows cross-domain communication from the browser. All responses have a wildcard same-origin which makes them completely public and accessible to everyone, including any code on any site. ### License [GPL 3.0](https://github.com/nicumicle/simple-jwt-login/blob/v3/LICENSE) --- # Validate JWT ``` GET /simple-jwt-login/v1/auth/validate ``` Validate JWT ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 Validate token Error. --- # Auto-login user into WordPress ``` GET /autologin ``` Validates the supplied JWT, resolves the matching WordPress user, and redirects the browser to the site (or to `redirectUrl` if provided and allowed by settings). **Requirements** * Auto-login must be enabled in the plugin settings. * The JWT must be valid, not expired, and not revoked. * If "Auto-Login Requires Auth Code" is enabled, `AUTH_KEY` must be provided. * The calling IP must pass any IP allow-list configured in the plugin settings. **JWT delivery** The JWT can be supplied via: * `JWT` query parameter (default) * `JWT` in request body * `Authorization: Bearer ` header (when enabled in plugin General Settings) * Cookie or session (when enabled in plugin General Settings) **Success behaviour** The response is an HTTP redirect (302) to the WordPress home URL or the custom `redirectUrl`. The browser session is authenticated as the resolved user. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 * 401 * 403 * 404 * 422 * 500 Login successful. Two possible responses depending on the plugin's "Redirect after auto-login" setting: * **Redirect (default)**: The browser is redirected (302) to the WordPress home URL, dashboard, or a custom URL. The response body is empty HTML. * **No redirect**: When "No redirect" is configured, returns a JSON body: `{"success": true, "message": "User was logged in."}`. Bad request. The JWT has a structural encoding error (wrong number of segments, invalid base64 encoding of header, claims, or signature). Unauthorized. One of: * The JWT algorithm is unsupported or not allowed (`error_code` 6-10). * The JWT signature verification failed (`error_code` 11). * The JWT has `nbf`/`iat` violations or is expired (`error_code` 12-14). * The JWT has been revoked (`error_code` 55). * The JWT is structurally invalid for auto-login (`error_code` 25). * The `iss` claim is not on the allowed-issuer list (`error_code` 68). * The provided auth code is wrong (`error_code` 27). Forbidden. One of: * Auto-login is disabled in the plugin settings (`error_code` 26). * The client IP address is not on the allow-list (`error_code` 28). The WordPress user identified by the JWT payload could not be found. Unprocessable entity. One of: * The JWT is completely absent from the request (`error_code` 23). * The auth code is required by the plugin settings but was not provided (`error_code` 94). * The JWT is a short-lived interim token issued during a 2FA challenge and cannot be used for auto-login (`error_code` 110). Internal server error. Typically caused by an OpenSSL signing/verification failure or an unexpected internal error. --- # Change user password ``` PUT /user/reset_password ``` Sets a new password for the user. Two authentication modes are supported: **Code-based (default)** Provide `email`, the one-time `code` received by email (from `POST /user/reset_password`), and `new_password`. **JWT-based (optional)** When "Allow Reset Password with JWT" is enabled in the plugin settings, provide a valid `JWT` and `new_password`. The `code` field is not required in this mode. Note: JWTs that were themselves issued via a reset-password flow cannot be reused to change a password again. **Requirements** * Password reset must be enabled in the plugin settings. * If "Reset Password Requires Auth Code" is enabled, `AUTH_KEY` must be provided. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 401 * 403 * 404 * 422 * 500 Password changed successfully. Unauthorized. One of: * The JWT is invalid, expired, or does not match the provided email (`error_code` 93). * The provided auth code is wrong (`error_code` 27). Forbidden. Password reset is disabled in the plugin settings (`error_code` 56). No WordPress user with the provided email address was found. Unprocessable entity. One of: * The `email` field is missing (`error_code` 59). * The `new_password` field is missing (`error_code` 61). * JWT-based reset is enabled but neither `code` nor a JWT was provided (`error_code` 53). * JWT-based reset is disabled and the `code` field is missing (`error_code` 60). * The email address format is invalid (`error_code` 95). * The one-time reset code is invalid or expired (`error_code` 62). * The auth code is required but was not provided (`error_code` 94). Internal server error. --- # Create an API key ``` POST /api-keys ``` Generates a new API key for the authenticated WordPress user. The full key value (`sjl_` prefix + 32 hex characters) is returned **only in this response** - it cannot be retrieved again. Store it securely immediately. **Permissions** One or more of: `read`, `create`, `update`, `delete`. These map to the HTTP methods the key may be used to authenticate: GET, POST, PUT/PATCH, and DELETE respectively. **Requirements** * An active WordPress session is required. * `name` is required and must be non-empty. * At least one permission must be specified. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 * 401 * 500 API key created. The `key` field contains the full plaintext key - save it now as it will not be returned again. Bad request. `name` is empty, no permissions were provided, or a permission value is unrecognised. Unauthorized. No active WordPress session. Internal server error. The database insert for the new API key failed. --- # Permanently delete an API key ``` DELETE /api-keys/:id ``` Permanently removes the API key record from the database. This action is irreversible. To merely disable a key while keeping its record, use `POST /api-keys/{id}/revoke` instead. Regular users may only delete their own keys. Administrators may delete any key. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 401 * 403 * 404 * 500 API key permanently deleted. Unauthorized. No active WordPress session. Forbidden. The authenticated user does not own this API key and does not have administrator privileges. No API key with the provided ID was found. Internal server error. The database delete operation failed. --- # Delete a WordPress user ``` DELETE /users ``` Permanently deletes the WordPress user identified by the JWT payload. The JWT is decoded to extract the user identifier (email, ID, or login, depending on plugin settings), the user is looked up, and `wp_delete_user()` is called. **Requirements** * User deletion must be enabled in the plugin settings. * The JWT must be valid, not expired, and not revoked. * If "Delete Requires Auth Code" is enabled, `AUTH_KEY` must be provided. * The calling IP must pass any IP allow-list configured in the plugin settings. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 * 401 * 403 * 404 * 422 * 500 User deleted successfully. Bad request. The JWT has a structural encoding error (wrong number of segments, invalid base64 encoding of header, claims, or signature). Unauthorized. One of: * The JWT signature verification failed or algorithm is unsupported (`error_code` 6-11). * The JWT has `nbf`/`iat` violations or is expired (`error_code` 12-14). * The JWT has been revoked (`error_code` 55). * The provided auth code is wrong (`error_code` 27). Forbidden. One of: * User deletion is disabled in the plugin settings (`error_code` 39). * The client IP address is not on the allow-list (`error_code` 41). The WordPress user identified by the JWT payload could not be found. Unprocessable entity. One of: * The JWT is completely absent from the request (`error_code` 42). * The auth code is required but was not provided (`error_code` 94). Internal server error. --- # Authenticate and obtain a JWT ``` POST /auth ``` Validates the user's WordPress credentials and returns a signed JWT. An optional refresh token is also returned when the refresh-token feature is enabled in the plugin settings. **Credentials** Supply either `email` or `username` (not both), plus one of: * `password` — plaintext password (verified with `wp_check_password`) * `password_hash` — the hashed password as stored in the WordPress database (must be enabled in the plugin settings) **Requirements** * Authentication must be enabled in the plugin settings. * If "Authentication Requires Auth Code" is enabled, `AUTH_KEY` must be provided. **Two-Factor Authentication** When the authenticated user has Two-Factor Authentication enabled and the 2FA integration is active, the endpoint returns HTTP 200 with a challenge response instead of a regular JWT. The `two_factor_required` field is `true` and `jwt` contains a short-lived interim token. Submit that interim token together with the 2FA code to `POST /auth/2fa` to obtain the final JWT. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 401 * 403 * 422 * 500 Authentication successful. Returns a signed JWT and an optional refresh token. **Two-Factor challenge**: when the user has 2FA enabled, this response is returned instead of a regular JWT. `two_factor_required` will be `true` and `jwt` will contain a short-lived interim token. Submit it with the 2FA code to `POST /auth/2fa` to obtain the final JWT. Unauthorized. One of: * The provided credentials (password or password hash) are incorrect (`error_code` 48). * The provided auth code is wrong (`error_code` 27). Forbidden. One of: * Authentication is disabled in the plugin settings (`error_code` 45). * The client IP address is not on the allow-list configured in the plugin settings (`error_code` 41). Unprocessable entity. One of: * The `email`, `username`, or `login` field is missing (`error_code` 46). * The `password` or `password_hash` field is missing (`error_code` 47). * The `password_hash` field was provided but "Allow login with password hash" is not enabled in the plugin settings (`error_code` 113). * The auth code is required but was not provided (`error_code` 94). Internal server error. Typically an OpenSSL signing failure when generating the JWT. --- # List API keys ``` GET /api-keys ``` Returns a paginated list of API keys owned by the authenticated WordPress user. Administrators (`manage_options` capability) see all keys across all users. Regular users see only their own keys. The full key value is never returned; only the first 8-character prefix is shown (followed by `****`) to help identify keys without exposing secrets. **Requirements** * An active WordPress session is required (cookie-based auth or equivalent). ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 401 Paginated list of API keys. Unauthorized. No active WordPress session. Log in to WordPress before calling this endpoint. --- # Exchange OAuth authorization code for a WordPress JWT (GET) ``` GET /oauth/token ``` Browser-redirect flow: exchanges a provider authorization code for a WordPress session and redirects the browser to the WordPress admin (or login page on failure). The provider must be enabled in the plugin settings. Supported providers: `google`, `auth0`, `facebook`, `github`. **Google flow** - pass `provider=google` with `code`. **Auth0 flow** - pass `provider=auth0` with `code`. **Facebook flow** - pass `provider=facebook` with `code`. **GitHub flow** - pass `provider=github` with `code`. If the OAuth identity matches an existing WordPress user (by email), the user is logged in. If no match is found and "Register on OAuth login" is enabled, a new user is created automatically. On failure the browser is redirected to the WordPress login page. > **Note**: this endpoint is designed for browser redirect callbacks (OAuth consent screen redirect\_uri). To obtain a JWT programmatically, use `POST /oauth/token` instead. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 * 403 * 500 Browser redirected to the WordPress admin URL after a successful login, or to the WordPress login page on failure. The response body is empty HTML. Bad request. The `code` parameter is missing, or the provider slug is unrecognised. (`error_code` 69 for invalid provider slug.) Forbidden. The requested OAuth provider is not enabled in the plugin settings. Internal server error. --- # Exchange OAuth token for a WordPress JWT (POST) ``` POST /oauth/token ``` API flow: exchanges a provider-issued token for a WordPress JWT and returns the WordPress user profile. Use this variant for programmatic API clients. The provider must be enabled in the plugin settings. Supported providers: `google`, `auth0`, `facebook`, `github`. **Google** - supply `code` (authorization code) or `id_token` (Google Sign-In ID token). The `id_token` path returns a WordPress JWT directly; the `code` path returns the raw Google token response for the client to handle. **Auth0** - supply `code` (authorization code). **Facebook** - supply `access_token` (Facebook user access token). Returns a WordPress JWT. **GitHub** - supply `access_token` (GitHub user access token). Returns a WordPress JWT. If the OAuth identity matches an existing WordPress user (by email), a WordPress JWT is returned. If no match is found and "Register on OAuth login" is enabled, a new user is created automatically. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 * 401 * 403 * 404 * 500 OAuth login successful. Returns the WordPress user and a JWT. Bad request. One of: * The `provider` slug is unrecognised (`error_code` 69). * Required parameters are missing - `code` for Google/Auth0/Facebook/GitHub, or `id_token` for Google, or `access_token` for Facebook/GitHub (`error_code` 71 Google, 75 Auth0, 97 Facebook, 101 GitHub). * The authorization code or access token was rejected by the provider (`error_code` 72 Google code, 79 Auth0 code, 98 Facebook code, 102 GitHub code; or 73 Google id\_token, 80 Auth0 token, 99 Facebook token, 103 GitHub token). * The OAuth identity email did not match any WordPress user and auto-register is disabled - Facebook (`error_code` 100) or GitHub (`error_code` 104). Unauthorized. The Google `id_token` or Auth0 token is invalid or rejected by the provider (`error_code` 73, 80). Forbidden. The requested OAuth provider is not enabled in the plugin settings. The Google or Auth0 identity email does not match any WordPress user and automatic registration is disabled (`error_code` 74 Google, 78 Auth0). Internal server error. --- # Refresh an expired JWT ``` POST /auth/refresh ``` Exchanges a valid refresh token for a new JWT (and a new refresh token). The original refresh token is invalidated after use. **Requirements** * The refresh-token feature must be enabled in the plugin settings. * The refresh token must exist in the database and not have exceeded the maximum token age configured in the plugin settings. * If "Authentication Requires Auth Code" is enabled, `AUTH_KEY` must be provided. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 401 * 403 * 422 * 500 JWT refreshed successfully. Returns a new JWT and a new refresh token. Unauthorized. One of: * The refresh token was not found in the database (expired, already rotated, or never issued) (`error_code` 51). * A JWT was supplied alongside the refresh token but has been revoked - revoked JWTs cannot be used to obtain new tokens (`error_code` 55). * The WordPress user linked to the refresh token no longer exists (`error_code` 55). * The provided auth code is wrong (`error_code` 27). Forbidden. One of: * The refresh-token feature is disabled in the plugin settings (`error_code` 81). * Authentication is disabled in the plugin settings (`error_code` 45). * The client IP address is not on the allow-list (`error_code` 41). Unprocessable entity. One of: * The `refresh_token` field is absent from the request (`error_code` 51). * The auth code is required but was not provided (`error_code` 94). Internal server error. --- # Register a new WordPress user ``` POST /users ``` Creates a new WordPress user account. At minimum, `email` and `password` must be supplied. All standard WordPress user fields (display name, locale, etc.) are accepted and passed to `wp_insert_user()`. **Requirements** * User registration must be enabled in the plugin settings. * If "Register Requires Auth Code" is enabled, `AUTH_KEY` must be provided. * The calling IP must pass any IP allow-list configured in the plugin settings. * The email address must be unique and well-formed. * If email domain restrictions are configured, the domain must match. **Success behaviour** Returns the new user's profile object, their roles, and optionally a JWT if "Generate JWT on register" is enabled in the plugin settings. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 * 401 * 403 * 409 * 422 * 500 User registered successfully. Bad request. Missing required fields (`email` or `password`), or an unclassified validation error. Unauthorized. The provided auth code is invalid or missing when required. Forbidden. User registration is disabled in the plugin settings, or the client IP address is not on the allow-list. A WordPress user with the provided email address already exists. Unprocessable entity. One of: * The email address format is invalid (`error_code` 36). * The `user_login` exceeds 60 characters, or the email address (used as login when `user_login` is omitted) exceeds 60 characters (`error_code` 36). * The email domain is not permitted by the plugin's domain allow-list (`error_code` 37). Internal server error. WordPress `wp_insert_user()` returned an error, or an unexpected internal failure occurred. --- # Revoke an API key ``` POST /api-keys/:id/revoke ``` Soft-deletes (revokes) an API key by recording a `revoked_at` timestamp. The key record is retained in the database but is rejected by the authentication middleware. To permanently remove the record, use `DELETE /api-keys/{id}`. Regular users may only revoke their own keys. Administrators may revoke any key. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 401 * 403 * 404 * 500 API key revoked successfully. Unauthorized. No active WordPress session. Forbidden. The authenticated user does not own this API key and does not have administrator privileges. No API key with the provided ID was found. Internal server error. The database revoke operation failed. --- # Revoke a JWT ``` POST /auth/revoke ``` Marks the provided JWT as revoked in the database. Once revoked, the token is rejected by all plugin endpoints that check for revocation (autologin, validate, refresh, etc.). **JWT delivery** The JWT to revoke can be passed via: * `JWT` field in the request body * `Authorization: Bearer ` header (when enabled in plugin General Settings) **Requirements** * Token revocation must be enabled in the plugin settings. * The JWT must be structurally valid (it does not need to be un-expired). * If "Authentication Requires Auth Code" is enabled, `AUTH_KEY` must be provided. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 * 401 * 403 * 404 * 422 * 500 Token revoked successfully. Bad request. The JWT has a structural encoding error (wrong number of segments, invalid base64 encoding of header, claims, or signature). Unauthorized. One of: * The JWT signature verification failed or algorithm is unsupported (`error_code` 6-11). * The token was already revoked (`error_code` 55). * The provided auth code is wrong (`error_code` 27). Forbidden. One of: * Authentication is disabled in the plugin settings (`error_code` 45). * Token revocation is disabled in the plugin settings (`error_code` 83). * The client IP address is not on the allow-list (`error_code` 41). The WordPress user identified by the JWT payload could not be found. Unprocessable entity. One of: * The JWT is completely absent from the request (`error_code` 53). * The auth code is required but was not provided (`error_code` 94). Internal server error. --- # Send reset password email ``` POST /user/reset_password ``` Sends a one-time reset code to the user's registered email address. The code must then be supplied to `PUT /user/reset_password` together with the new password. **Requirements** * Password reset must be enabled in the plugin settings. * If "Reset Password Requires Auth Code" is enabled, `AUTH_KEY` must be provided. * The email address must belong to an existing WordPress user. **Flow** 1. Call `POST /user/reset_password` with `email` (and `AUTH_KEY` if required). 2. The user receives an email containing a one-time `code`. 3. Call `PUT /user/reset_password` with `email`, `code`, and `new_password`. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 401 * 403 * 404 * 422 * 500 Reset password email sent successfully. Unauthorized. The provided auth code is wrong (`error_code` 27). Forbidden. Password reset is disabled in the plugin settings (`error_code` 56). No WordPress user with the provided email address was found. Unprocessable entity. One of: * The `email` field is missing (`error_code` 63). * The email address format is invalid (`error_code` 96). * The auth code is required but was not provided (`error_code` 94). Internal server error (e.g. email sending failure). --- Version: 4.0.0 # Simple-JWT-Login ![Simple JWT Login Logo](https://simplejwtlogin.com/assets/favicons/android-chrome-192x192.png)![Simple JWT Login Logo](https://simplejwtlogin.com/assets/favicons/android-chrome-192x192.png) **Simple-JWT-Login** is a free, open-source WordPress plugin that adds JSON Web Token (JWT) authentication to the WordPress REST API. It lets mobile apps, single-page applications, and external services securely interact with your WordPress site - without exposing admin credentials. With Simple-JWT-Login you can: * **Authenticate** users and receive a signed JWT * **Auto-login** users via a tokenized link * **Register** and **delete** users programmatically * **Reset and change passwords** through the REST API * **Protect any REST endpoint** so it requires a valid JWT * **Refresh, validate, and revoke** tokens to manage session lifecycle Whether you're building a headless WordPress site, a React/Vue front-end, a mobile app, or a third-party integration, Simple-JWT-Login provides a clean, standards-based authentication layer. ## API Format[​](#api-format "Direct link to API Format") This API is documented in **OpenAPI format**. You can open it in [Swagger Editor](https://editor.swagger.io/), view it on this website, or import it into Postman for local testing. ## Server[​](#server "Direct link to Server") You can access the Simple-JWT-Login API in two modes: * using permalink: `https://{domain}/wp-json/simple-jwt-login/v1/{endpoint}` * using rest\_route: `https://{domain}/?rest_route=/simple-jwt-login/v1/{endpoint}` ## Authentication[​](#authentication "Direct link to Authentication") Most endpoints accept a JWT via the `JWT` query parameter, request body field, or `Authorization: Bearer ` header. API key management endpoints require an active WordPress session (cookie-based auth or equivalent). ## Cross-Origin Resource Sharing[​](#cross-origin-resource-sharing "Direct link to Cross-Origin Resource Sharing") This API features Cross-Origin Resource Sharing (CORS) implemented in compliance with [W3C spec](https://www.w3.org/TR/cors/). All responses have a wildcard same-origin which makes them completely public and accessible to everyone, including any code on any site. ## Error Response Format[​](#error-response-format "Direct link to Error Response Format") All error responses share a common envelope: ``` { "success": false, "data": { "message": "Human-readable error description", "error_code": 42 } } ``` The `error_code` field maps to a specific internal error constant that can be used for programmatic error handling. ## Authentication[​](#authentication "Direct link to Authentication") * HTTP: Bearer Auth * API Key: QueryJWT * API Key: WordPressSession JWT passed in the `Authorization` header as `Bearer `. The header key name is configurable in plugin General Settings (default: `Authorization`). This scheme must be enabled in the plugin General Settings under "JWT from Header". | Security Scheme Type: | http | | -------------------------- | ------ | | HTTP Authorization Scheme: | bearer | | Bearer format: | JWT | JWT passed as a URL query parameter. The parameter name defaults to `JWT` but is configurable in plugin General Settings under "Request Keys". | Security Scheme Type: | apiKey | | --------------------- | ------ | | Query parameter name: | JWT | Active WordPress session cookie. Required for all `/api-keys` endpoints. The user must be authenticated in WordPress before calling API key management endpoints. | Security Scheme Type: | apiKey | | ---------------------- | --------------------- | | Cookie parameter name: | wordpress\_logged\_in | ### Contact ### License [GPL 3.0](https://github.com/nicumicle/simple-jwt-login/blob/master/LICENSE) --- # Update an API key ``` PUT /api-keys/:id ``` Updates the `name`, `permissions`, and/or `expires_at` of an existing API key. Regular users may only update their own keys. Administrators (`manage_options`) may update any key. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 * 401 * 403 * 404 * 500 API key updated successfully. Bad request. `name` is empty, no permissions were provided, or a permission value is unrecognised. Unauthorized. No active WordPress session. Forbidden. The authenticated user does not own this API key and does not have administrator privileges. No API key with the provided ID was found. Internal server error. The database update for the API key failed. --- # Validate a JWT and retrieve user details ``` GET /auth/validate ``` Verifies the JWT signature, checks expiry and revocation status, and returns the decoded token information together with the matching WordPress user profile and roles. **JWT delivery** The JWT can be passed via: * `JWT` query parameter * `Authorization: Bearer ` header (when enabled in plugin General Settings) * Cookie or session (when enabled in plugin General Settings) **Requirements** * Token validation must be enabled in the plugin settings. * If "Authentication Requires Auth Code" is enabled, `AUTH_KEY` must be provided. ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 * 401 * 403 * 422 * 500 JWT is valid. Returns the decoded token and the associated WordPress user. Bad request. The JWT has a structural encoding error (wrong number of segments, invalid base64 encoding of header, claims, or signature). Unauthorized. One of: * The JWT signature verification failed or algorithm is unsupported (`error_code` 6-11). * The JWT has `nbf`/`iat` violations or is expired (`error_code` 12-14). * The JWT has been revoked (`error_code` 55). * The provided auth code is wrong (`error_code` 27). Forbidden. JWT validation is disabled in the plugin settings (`error_code` 82). Unprocessable entity. One of: * The JWT is completely absent from the request (`error_code` 53). * The auth code is required but was not provided (`error_code` 94). Internal server error. --- # Validate a JWT and retrieve user details (POST variant) ``` POST /auth/validate ``` Identical to `GET /auth/validate` but accepts the JWT in the request body instead of as a query parameter. Use this variant when the JWT is too long for a URL, or when sending it in the body is preferred for security reasons. **JWT delivery** The JWT can be passed via: * `JWT` field in the request body * `Authorization: Bearer ` header (when enabled in plugin General Settings) ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 * 401 * 403 * 422 * 500 JWT is valid. Returns the decoded token and the associated WordPress user. Bad request. The JWT has a structural encoding error (wrong number of segments, invalid base64 encoding of header, claims, or signature). Unauthorized. The JWT signature verification failed, is expired, or has been revoked. The provided auth code is wrong. Forbidden. JWT validation is disabled in the plugin settings (`error_code` 82). Unprocessable entity. The `JWT` field is absent from the request body (`error_code` 53), or the auth code is required but not provided (`error_code` 94). Internal server error. --- # Verify Two-Factor Authentication code ``` POST /auth/2fa ``` Completes the Two-Factor Authentication challenge issued by `POST /auth`. When credentials are valid but the user has 2FA enabled, `POST /auth` returns an interim JWT (`two_factor_required: true`). This endpoint accepts that interim token together with the user's 2FA code and, on success, returns the final signed JWT. **Requirements** * Authentication must be enabled in the plugin settings. * The Two-Factor Authentication plugin must be installed and active. * The interim JWT must be provided via the `Authorization: Bearer` header or the `JWT` body field. * The `code` field must contain the TOTP code, email token, or backup code, depending on the user's configured 2FA provider. **JWT delivery** The interim JWT can be passed via: * `JWT` field in the request body * `Authorization: Bearer ` header (when enabled in plugin General Settings) ## Request[​](#request "Direct link to request") ## Responses[​](#responses "Direct link to Responses") * 200 * 400 * 403 * 404 * 422 * 500 2FA verification successful. Returns a signed JWT and optional refresh token. Bad request. One of: * The interim JWT payload is missing required 2FA claims (`error_code` 106). * The 2FA session nonce is invalid or expired (`error_code` 107). * Too many failed attempts - rate limited (`error_code` 108). * The 2FA code is incorrect (`error_code` 109). Forbidden. One of: * Authentication is disabled in the plugin settings (`error_code` 45). * The Two-Factor Authentication plugin is not active (`error_code` 105). The WordPress user referenced by the interim JWT could not be found. Unprocessable entity. The interim JWT is missing from the request (not supplied via `Authorization: Bearer` header or `JWT` body field). Internal server error. Typically an OpenSSL signing failure when generating the final JWT. --- # Introduction **Simple-JWT-Login** is a free, open-source WordPress plugin that adds JSON Web Token (JWT) authentication to the WordPress REST API. It lets mobile apps, single-page applications, and external services securely interact with your WordPress site - without exposing admin credentials. With Simple-JWT-Login you can: * **Authenticate** users and receive a signed JWT * **Auto-login** users via a tokenized link * **Register** and **delete** users programmatically * **Reset and change passwords** through the REST API * **Protect any REST endpoint** so it requires a valid JWT * **Refresh, validate, and revoke** tokens to manage session lifecycle Whether you're building a headless WordPress site, a React/Vue front-end, a mobile app, or a third-party integration, Simple-JWT-Login provides a clean, standards-based authentication layer. ## Requirements[​](#requirements "Direct link to Requirements") Before installing Simple-JWT-Login, ensure your environment meets the following minimum requirements: * PHP **5.5** or higher * WordPress **4.4.0** or higher ## License[​](#license "Direct link to License") Simple-JWT-Login is open-source and distributed under the [GPL 3.0](https://github.com/nicumicle/simple-jwt-login/blob/master/LICENSE) License. ## Installation Guide[​](#installation-guide "Direct link to Installation Guide") Setting up Simple-JWT-Login is quick and easy. Choose one of the following installation methods: ### Method 1: Install from WordPress.org (Recommended)[​](#method-1-install-from-wordpressorg-recommended "Direct link to Method 1: Install from WordPress.org (Recommended)") * Go to the **Plugins** menu in WordPress and click "**Add New**". ![Add new plugin](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAB1YAAABlCAMAAADJXfFFAAADAFBMVEUdIycKS3gQDhDv7/CcoqeMj5TDxMfw8PH///8YDhT9/v7FxcUjIyYdIy3q6+sdKFrx8OHGx8dkaXAdJjzm5uf9/PicoZ4qIyc0NDQdKFQiX6gdJkh5nqdCQUPExMRIJyc7Ozyf4/HnsnLPjU3p8PEmbrEhJytSLCcuKSkvdbt2qt1UJycXDhRwSi2coIYeJTSJb43f3d8qTHVnq+vEhERfKie47fGVoaeW2PGWVyn//uc/KCfw1ZZtm87m3qqgenqdYC/sxoeJyeocLW08UJZJSUvF7/9oLCXf7/HpzJVcX2HG7vF+OyeNc1HFnIzT6Lzw7+o4JyjU8/nHl3MePX/O0NJwb3Lj/f/T09WW0+3uwaaAk6ecoJP/679qTTqJoKclVJoVUX5zk6ViiaHv0bG41ulZiaaZlIwVf8ewbzTw2bcsU4RZOykuMDK2iXIgPGDXnmCBaE6IbXtpkatniLr/+9sbT5G56dpvtOtobnb3xpjb4eZGbZCMTSmckoDx4b9cRjkdNH3n1aJugJPZ2doVbLerf2/J4e4kNUhMk9F7VjbgzLXw7dj10aNUWIVodYSTfn3u/v+Uhmj/9M/u5N3ouZjw7bHRuaBTnNjSo3yj1+52entHOi9Ic5vX5e7jsoiAgIBaoeJLq+ZcbYD058ey5P/KysseLk+QlZv1//+RyvGJud7ZqpNqf67w69DI5M1yNScnY5mr5OA7U3iEiYiHvfBow/BFickxQ2e15e+Yzvs7gsN5vuffpWemYSxIXm2Yelqn2f319fWXweBteaJmQy2pzu0wPEpRfqFiX1LbsoaIlXurq7O6koy2dzyD1O9+m71cNko5R1vc6tDp57cdMF/n2skwmdmEqs2bkHJyX37awq2thH0zXojFq7TInXrDwMI/aKh1cpBvlpGcsdgmhMpdfrREM1dhcpiIYj9rksRdUUvJ0qZYtOcdQ3C8urz/+ei93besxt7k8ft+dXAaGhqrl4Zhp9rw2sminqCe1c2Ylb09g6gIAAiDnpZQnMDVLbMAAAAACXBIWXMAAAsTAAALEwEAmpwYAAAVn0lEQVR42u3dC1xM6ePH8eM/Y2d+08wo0zRqECmStcmiXW0uRSqiUKKopCXlTtikZKlExbLRDT9W5NqyLqtW7peV67qtu2Vdll1r/dbefv/X73nOzDRTnaHRReX7fu3L1Mw0nabhs89znnOG+Rf1fwwAAABUHrIKAACArAIAACCrAAAAyCoAAAAgqwAAAG80q7J9c9c78kev+skWzw4AAAC3huVwZlWyPSDteAtb+6P75o4eIcbTBgAAwJlVIxWT5iZGJuTCiDOr9rNmxyWuabjebIdf1u6RXi8ZsCZm1ez2S1qr4DcJAAC1Jqukqc1NmhPcWbWftaTFLEc+y8zraKiXQt/DTRg5O7JyG2R/bk2m33Gfit25YwBfY/SIin+P1hhvAwBANWbVxGjdulvNmxs1N+LMasS3zT7W5Mtskm3uyAV6qxoYNDtSuc/T5zU3R6IOpdmkijyCcgpfa7ZlBb+H7GO+WXv85gEA4CU5Wm6lZwSmdOn06qyuk8pFB3zpsJUrq7k/tO+YmRqwxLOxp+fI99qQQeK3lnqqOvrwhKaz7zeld9IxZ/qHFt36MJLVPZ0Y86HjWwqohR9yDT/pmHg9/WOJTlcvXM4xTucoYaOmOlnV/Z5N/HZkNqt4ViUzFnV+5TMFAAD1SfCAfuRPm26dK5dVizIPoMrqAaFcJOKtIxPBXFmNWGIrlu0LSBtBZ11JkWRNji3QU9W465N2NzVzLJ9V1+k9mEZDY7cxg7fGMK3nfNmDcyK2dW4oHadKdo/k871K7mD/YllkbkFPn4pnNdOzdYsdTQzIqmCiAlkFAEBWDc5q7nFFmaySxUoOIpYD2b3KkVXJsQX7LO2P8flXnJjrjmQYqTx+vUjMXdVZjmakq/zyWZUVtGKiBjwLZ2zi2zGM65c9uLY1N3RSYpz6I/57JTtplWfIwJb9ugpmddwOsoTJr7cBWU3e2oN9pmRTE5auaNPWw5JJ6ukjWV2InbAAAPU+qx2fSS/OVwze2o+xGLCNsfGw/PmgNPmZFb2D65enVOO7fxKkV8mIMj/M+GpYp0YZN3xN0+88i05uT0erbUfdjb54SqzJKtmjKhUKhSKhSGrCOVpV/hAXuoCJcKQxutCUHxjZKHP3t056qkp3i+4OCIwsm1Umycp2l9WuwtbLrRT6sqokvVsgLpkNfqh7m/2LQkWFs9piFfnD05PraSSLhtmskkuxTlYLk+IjaVb3dmuf6zKRPLdKl9h+5kPD8boDAKjvWXXNGGQbERaudAmXLJeGS1ZPlBWcyOqYYWU+tBPbWcpiwAKZXU8n1y9bNbmdQLI60edCxqJImZ2VgmZ1y8PWezWj3oZkgGqkGa0aca4ENv/hbNMihTk7L0sGrWaHf/72fvmdq5qqEqSrpdcD06xadDtbcCr48VkXGn7OrMrIgJgfyC7ozU2dS089obO497b6J6tcVmUf63yBdsgqmTExN28iySo7tG/rcd/lVNTju6cG/7oNrzsAgPqa1YHsQp9undl54KSetssLG/31d6H5wW8Gk2jRSWAybckOBYnEZmI6a0rvSkrRKCOckbw/Uczs7elEs0qmOKM0lSKj1eYm6w6QwarwADlyVU9WyUIlSTafT8a/EY6BkdmzubK6Q1NV2tUd5bI6Z/rkX/s1+mvy9Bh9We24KoBvtuM5Ow7uGEQepkh7fGz+1himWrMqDt5a5NLpQktvU1NpfOekwl0T21q1XemD1x0AQH0fre71cKIjKkuL+JT0Xo9Tfu1DE0mzGjVghEu45sgTX/+cRe1oQPVltZ86qya3yCzwOrlIKPc1MeEcrdJJYDIj+3PQe2ebMOYjr9wfeYVrEti+pKqkqyUTtpJjRQy7TEnm8gvZW/nixuPOjN59q9dLUieJcNRdCxy8lfP+Bu9bfUlWJUljwzqZ56km0YOTn/UY/OtdLGECAKj/WVWPVn1c/7rbSrnx5AnbwWQASLOqdCnWzFru9Yh81Wi1n3bJkpG/gO5aFXzKfdwqWbKUzV9iq5yyZLuXWJLtFeHoxbVkiTaOpk1zqbZr7IJEZ3aTpaRSNu7seFpPVic0pcuiqHNZs5Zoyx3BXVX9x60avBKYPDnmLoJOzK749vazisSuGd06ywq2xOBlBwDwluxbPcXYzyBHfu4irVLvWxWTT9RzwExSfNzujYs6k32r49h9qy/L6i0Tf7lQRCaBRXJ/fQfY7A4ii5CuPzxG0jUh7lhgHNcBNnqymuuc451M725xnlRqzh52BKgnq5JZpI5xYkY2K+iKk/Z8hLICAY/H8w6v+FmWxhl63Cp5cpiovuS5fJRD13rZv0+eyb0ca48BAKDerQSOICuBx5Pdjm3JP/tRdJ8jXQl8l2Q1qm84uVsfOuzbaH2R/7gPWQnsnX7kVVldJycHrQrpmiW5iRH36SBGZJNZ4MRzTWmOLjT14jwdhJ6sGkQZSidn6ekgKnweJHYieJLCgG+CsywBAEBF0JWrFgYOsRqqjloVsv/JHUz0nbwwlMzOkv2dRQrm+pL7nCcvrIqsknGqo3rsKTYgqwZVFVkFAICKSHQuVNi/aGXYGQwamhjxhHIhPXCVhJV3S9+p9putOUzPCPFeG/t9ek61r8pp69aVyir5KfalZvoZ8Kau5NsZVlVkFQAAKsC1Zfxh0gyFwafaPyASqoiEB4z0vzGcrTLU0WxHpETfG8PpLsutRFYN1aipgVUFAABg8DbmepgfR1UBAKCWK5tVMgzeN5csJVq/6rgtnh0AAIBKZhUAAACQVQAAAGQVAAAAWQUAAABkFQAAAFkFAABAVquGAAAA6q53hLXDO1W+Oe+U/VGRVQAAQFaRVQAAQFaRVWQVAABZRVaRVQAAQFaRVQAAQFaRVWQVAABZRVaRVQAAQFaRVQAAQFa1VjqLkFUAAKgzWZWnP2889+CGCqVry+9+M8+4lXza9dZA4Wdp+6syq6JBdvSBx3+FrAIAQF3M6spDCfLYtLyKlOuz7pfdjfsfGqj5fFr3/UK5w2JkFVkFAEBWdTs27KAwNm3m3CPC4R1Gp+5/2t8vdeMG4drZfuw1ZqtSL7PtXDmVXHSd/1XXa0GrMs8MGT65cerGzzp8Qe+YSsa7K0bOzjz0hVC+6fnMMwMrn9VRaTNHutGsfjJ3dCbZEGQVAABq/2h10Z2Dv7Ejz4MbRnX4YvjkjYvlNx/9tjZt/7TuGxcvOuRGrtkwnLRTkzzhCueu8+0WPx1vJ6KjVZJVcscNsWlfC1cccpOvcN5AvubpIM0Yc1lj1uaBBmd1eIcj8k2PFtOsPviCbKV67ll+U/WIzouRVQAAqIVLlmJ/9xsZJlq0eYhQnuw2vIMbKSXZXbrCbhGZ7e167Wt6zbTuX9OijS+g9z9Bsko+/WTzEHVW6R2FKx9tWEGK+MnUxYvuhG2Q/6bZ/TqeNnDN/oqPVlXV/Ip8mw0krW40q1OHkDFyXslMNL39gRtGqwAAUDtXAj+9Ojnvk6ns8I9GdPjzmYTzssb04iudrGpHq+RTElN1VtkvJe1TZXWIPHl2qnYSmMwUN25sJzJ4Epj0lXz31C/UWZVr97Yu8iOdzsMkMAAA1MKsdr1B53dPPKKjVdHS39isslO+QnqNOrSqrGr3rZYZrW5mR6uL1Vk1/k349OajkqXFyzimgCsyCbxCNY+szuq0ktEqOw3svBhZBQCAWphV+c0pCaIt3e3ovtWxZN8qiah8kPMQ+dUwust02g03naxqVgJ3ne885LP5duTqPJF63+paspZYndWVmwfKVzwq6V7X8Wv2v86SpbF3MoRrTw6hWU3NEC075KazIPmQG5YsAQBArZwEfpq+qnHq5SElK4FJsaYVk8NTh7ALfO8u1skqe9xqgBsZsAY8p3cQnfCz010JrMrq0/7P6RLeEsPvil4nq6JR7AapVgL7lVoJPOoIVgIDAEC9OcsSOwlccycvpJPAOG61CkwJaVCDQqbgrxsAIKvIav3N6pTQ6Jp8qUWHoqsAgKwiq/U3qyHRNftaiw7B3zcAQFbr+TvYTEgNcOSPfp71Nma1QU2/2Brg7xsAIKv1OquybEd+4OGOQXy+l4/u9eZDBYKl6QvKJW/O9B7spc13fV6aRsn7VuJqzarxh5L3kVUAAGS1VmVVGcrnq7PKX+JUKqsTe++7fL5HLcrqR+3YW+3PPQirQFYnNtlljawCACCrNZlV++zAEWxS+fTSS6Gb1Vbk5hcelrUpq5KjzZo1ayJmcu1endVTjIU7sgoAgKzWZFZ/DlJnNe3/yWXg4TJZZaK2xjAXLucYp0cykmMJ3skPSVaLw6RXDzM2a//OWXrTiZFkh0mTvcSMbCq5eQGjdEkP87DMD5OmH6mGrDZqSS/HPhRfyHhlVv/4MwyTwAAAb4CJqFZUVWRS1ZujeUT9WZVk81Wu3G9KL7zEZbLquidc9r7HT9vzrBTBW+efc/5u25wuoyalZBSKbaxP/JSd0IrJj57fe+r5D5m9sZPO2cV3VubFevUevGfFTz/2rbasCtb2Y5KwbxUAoJbyN60VWTX1r+rN0Tyi/qwqp6iqGni4EZvVK05ls9rylOQcWSO8y8PS5rttTG5q5Jzp4YxkeU8n+qlkuYflDCtbRlZgpTgaxzDBA/opXSaKmb3dOlfPJLA6q4JOjI06q63EbekVn/cx/4BcGA+Ks018sDWmEfmkFUNu6WkZtbUoq/XRH3PovYxvxtnanzvj/urKDbPown7B5H9X+GWk/hJkFQDeeqYmpm9+vCoiW6HenHeqZnO0j6g/q+Y/qKaAH4pJVsnCpW/blB+tMhMu51jzPrK8cPBi/0m2qn2rSR5O7L5Vm+/ODu3EsNVVTkmw5m0hWW3FSFaT1L6JrBqfIpPRTcSJWTpZTcxKbHzch7lNWmocLpYczRIztwfqqVx/iz2cWd0UdZreOoZzCdSo7eT0Sfl21uWz2v+eO7IKAG9lV/1N3nnTTPxNq3hzdB7xVVktsmVoVkeUz2rw+RhlwYlIZm+8JWO/LyDMo42+rCbFjxAHn9dkVVGtWd0SUzIJXCqrVj5KO2tBfHtGJ6vM9QR6obr5AjlqqGcb+xnclVv4fcgT7qw2mNdXf1Z7teR5p0fsLJ/VpWEYrQIA1Gvck8CBZ0OX3OecBJaRlcB0wMokxVvOKlIwg6d/o82qZhJYwchmWMkKyOSvhSqrJMJkEnhGtWX1j3AxOaq2fFaNezB7rVX302aVLG4iwYyRzCi5b6dxu7grN8wicB4ZyBqP7hg1lzQyeU3IPymqrOanXFJl9eqaEJuMhZOfCNam7BTE9vpAlVW2vySrY8mHW77fKfjjTkj+3DH0C5blz70eNQNZBQB4O7KqWrJEs7o7qNySJfVxq+Z5y46HJixqZ3O+qPeP52NKsmp94nh2QieS0vnk6h6S1WMnrTmyJYbNKrtkKacaD7CROQs4svr5NmWe6hOdrA7uS0ed3zCrBYJC8eA9Lxk8el+7FJtymk4FZyxNs+iy9vvl7le3q7I673HEaVrJsSkF0uJ5A4vvCYZ1vCRYRiPMZtX76vad2qx6p7VNuDhTldWoAsEm3WEssgoAUI+zSg6woTVdkpV4TLVyiessSxHkCJqAx33oETQXi8Ta0WrpA2wmbHS/OPqvD9msMvlh3ul3q+t0EK2PPngm4MrqR+1c97wsq2tjGNmaoAR9WSVN9U67pJr4JY2kk7qaSeB5OcXz+pJK9h/jTsaoLYfZ9C3++Hbf4kuCkn2rL9y1WVXFWZVVMntMr0VWAQDeiqzaa46wYemeDqIWnhNYu2RJwJ1VyzldXpZVwcLxkWSEvv0gd+U2kQQus9izkMzi0qzSsWhJVgdu+f5S8Rjraw1CQkKiTq9N+evBlx1Od9gp0EwCC9gvUWeV7SiyCgDwFma1Tr2DzSuz2s715VklE70Xfx8hznXhqtzCyexboj7hHK0OFAyLWDPGuvgeu2rJu/vHbd37/3O7C3dWMVoFAEBW62xWbSq8b9XBgUbROJxpa81RuWHBH9D9q2PcufatDhR4FzcYYz2qV4Hg4pkcwaaQfwtGdVQ1Viera1OeSMmaYO/u90r2rSKrAADIah3KaqE42J29ia4E/oZh1/h+ZMmZ1S39ZOya3EKx9mTBDXQWLLFHmY7qdZquBA6lK4FTQmxmlmSVDEPHWHunp4TkF5DTJ/Y6TQ7HeSIok1VB+nayeHgn74/MkPzUMTxkFQAAWa1jWf3Ikh6qmtye0R63mlzquFWd0WonccQRsjIphtlVrZXj8aRSU9Nr93g8AY5bBQBAVutUVsmULpOYJZb5aM6yNI6cZclH70pgcoSOLaNzmE21ZFVavFF+IOCJFFkFAEBW61hWyereLHHirF/7ac4JrEh88Fj/SuA4W8m5zQmCas5qMq93b+toZBUAAFmtzVmtqG7tLrQUvLk3lOFJPxX+5z/CT6Vcs8DIKgAAslpXsmp8g12LVKhgh6hvLqv+NKv+pjwKWQUAQFbraFatfLITBIJlkZIkwRvNqi/Nqq+pVCotF1ZkFQAAWa0rWR3bnrHvTd75Lb/vm86qWCxc5+BgamrKlhVZBQCox1l9t/7uW136+09l3qe85rPKU2dVdOCA6AApqxRZBQDAaLUuL1kyQEh01VeVZlWhWNVk1aommXK5oFRXo0PwIgQAqEdZfRdZLWVKaHTVV9XUV2ir1rvFSZ6p9kib6NApeBECAGC0Wm+zKpgS0qDq/SwcV6KFQOeGEFQVAABZrc9ZFVT1ciVTqVzuL2yiRQ9gxSsPAABZRVZfJ6tSqaentFRW/ZFVAABkFVl9zdEqz7OFp7SFltAXWQUAQFaR1dc8cWFzKemqblYxWgUAQFaR1ddcCGy67hepZzOt3iJkFQAAWUVWX3sWuHRX/XhYsgQAgKwiq5XpKq9xb7VMB18HZBUAAFlFVivTVZFQRW56ax3nG8QBAEA9yeq7yGq171/1Pfnnn2bEnyd/8TVFVQEAcKp9ZLVSJ9t3+FTFwRRjVQCAep3VdzEJXANd1YWXHQAATrWPrAIAACCrAAAAyCqyCgAAdTCr7yKrAAAAyCoAANQch5PrG0Ip6086GJDVCccVyCoAAKirut5XLoRS5L7rHTiyyn2AzYQAvpcCWQUAANZJX2S0PN+TFc5qhCO/FnXVsF++d7T6g6XulfpfM2v2gmecUyUvyaU5pR+3Jv8ns2p/ktf66d3L/G5qozqxkQBvynqMVbnGq+u5ssp58sIJQfwyXTUfSv/h6R9ZK7P6eR/XLq3+u5z92HiQnfpaj82V6MiJzep/ZGM7hFXBK3JL9zz1RyucX7ur3n8/qYmfZOGPHxj2HRb+eFr9kXHATvbyxqVSP+SoO3vU97y2sQqezBuXXu/ruLfuj3tdqmMjAeqZhmgol4Zln6j/AVerk3hYdNz0AAAAAElFTkSuQmCC "Add new plugin") * Search for "**Simple JWT Login**" and select "**Install Now**". ![Search for Simple-JWT-Login plugin](/assets/images/search_simple-jwt-login-plugin-cd661449b75fea062cadc9b06a95ec56.png "Search for simple-jwt-login") * **Activate** the plugin when prompted. ![Activate the plugin](/assets/images/activate-simple-jwt-login-plugin-1791dcddc527f822646b147e96592331.png "Activate the plugin") ### Method 2: Download and Install Manually[​](#method-2-download-and-install-manually "Direct link to Method 2: Download and Install Manually") * Access . * Click "**Download**" to get the latest Simple-JWT-Login plugin version. ![Download the plugin](/assets/images/download_from_wordpress.org-ee53800943f2461fe90cb5310aa519de.png "Download the plugin") * Upload the `.zip` file via the WordPress plugin uploader (**Plugins → Add New → Upload Plugin**). ![Upload the plugin zip](/assets/images/upload_plugin_file_in_wordpress-050749b961348bd6978a04aacb324987.png "Upload plugin zip file") * Click "**Install Now**" and **Activate** the plugin. ![Activate the plugin](/assets/images/activate-simple-jwt-login-plugin-1791dcddc527f822646b147e96592331.png "Activate the plugin") Now that you've installed **Simple-JWT-Login**, check out the **Configuration Guide** to set up your JWT secret key and enable the features you need. --- # Exchange id\_token with a WordPress JWT ## Overview[​](#overview "Direct link to Overview") The Exchange OAuth Code with Google ID Token route in Simple JWT Login enables the exchange of the OAuth code obtained during the OAuth flow with a Google ID Token. This process facilitates secure user authentication and authorization with Google services. Below are the parameters and details required for this operation. This can be used when the OAuth process is happening in a different APP, and you need to obtain the `access_token` or the `id_token`. note To ensure a smooth process, it's crucial to use the identical `redirect_uri` in WordPress as the one utilized in the OAuth flow. ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `POST` **ENDPOINT**: `/simple-jwt-login/v1/oauth/token` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/oauth/token&provider=google&code={{code}}` | Parameter | Type | Description | | --------- | ------------------- | ---------------------------------------------------------------- | | provider | `required` `string` | Specifies the identity provider. Set this parameter to 'google'. | | id\_token | `required` `string` | The OAuth `id_token` obtained from the OAuth flow. | ## Request Example[​](#request-example "Direct link to Request Example") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST 'https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/oauth/token&provider=google&id_token={{id_token}}' ``` ## Example Response[​](#example-response "Direct link to Example Response") ### Success[​](#success "Direct link to Success") ``` { "success": true, "data" : { "jwt": "simplejwtlogin jwt here" } } ``` ### Error[​](#error "Direct link to Error") ``` { "success": false, "data": { "message": "The code or jwt parameter is missing from request.", "errorCode": 71 } } ``` --- # OAuth Login ## Enable OAuth on WordPress login[​](#enable-oauth-on-wordpress-login "Direct link to Enable OAuth on WordPress login") This ensures a seamless integration between your WordPress site and Google authentication, allowing for a secure and effective OAuth process. Once this option is enabled, on the WordPress login/register screens there will appear a new button: `Continue with Google`. To enable OAuth on WordPress, it's crucial to ensure that you have the correct `return_uri` configured in Google. note Please make sure to set the following `return_uri` for "Authorized redirect URIs" in : ``` {{your_site}}/?rest_route=/simple-jwt-login/v1/oauth/token&provider=google ``` To enable the `Continue with Google` button on your login screen, make sure you check the option `Enable OAuth on WordPress login` from WordPress. ## Create user if not exists[​](#create-user-if-not-exists "Direct link to Create user if not exists") If you will have google users that may not have an account on WordPress, you can select the `Create user if not exists` option from WordPress. If somebody uses the OAuth flow, and if there is no user with `user_email` equal with email from google, it will automatically create a random user, with this email and a random password. For example, a new user can have: ``` { "user_login": "user_23werowe", "user_email": "some_email@google.com", "password": "some-random-generated-password" } ``` ## Screenshot[​](#screenshot "Direct link to Screenshot") ![Google OAuth WordPress](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAWMAAAHZCAMAAABkTarAAAADAFBMVEXw8PGMj5Tp6erMzMzv7/Dt7e7DxMf///8icbEAc6r+//87kbwOeq7D2eS00eD6//////79/v1ZocT///mWwdfh6O3S4en//u94sc1oqcmlydvqQjY/Rk6IudTw8Oz8vQtDhvXw8PD29/dKmcAsirc2qVWvdVNFifp3ZJLj4uNeZ3Lr8fL83aUegrLZnmjswZPZ2NvM+/+admz5z5Xt/v8WFBf0Qzfc7/ErMjlXjsE3sFe9g1aSxeqUYVRHVXPZ/P5agLW45/H/+cR3uvQmdsr0+/9ipuHS7fHl7/Hv47jt69pEc7O+9f/k/f5aYWnD7PKc2vxusOyAYnzw7NJ8s+Lu2K3w7uRnU13//ed5S2w3LHhMispHYp/814dNU4ZLTVJlZGmmblRCTl+G2/qsf2ep2+/+6addndmx8v0dgrLOn3ZRWpSoqrCUl5qe0PBFSE+6i2itWBbJjlx0Y1/3wYeFsdfhuZDesYZ4sc9okL+BibNcea7+7bmq5vzMqYnmx6GJb3F1LipfTILo8v1qbnLG3u0ic7tXa4hWXGRNpOzrtXtys+fc6fjw7MPF+P+FwfBGbKhblfd5qNFec6RaocVGgcLt4MLu4c5ZUlJxqdrpnEn98OsweLZog7L/+9e/6Pszi9SzloA0qVEmcbH99N5alM+glbTZiTofUaHf9f5cb5v//N4iIDG3+O3hqHH85sJKfLl/VV3s7Oy8p7jJ6e9YtvVrxPfl0bEiPHbz3rOOzvj2/O45gLuw1uqEocPu0aj5yXj6+/g9grqFaWBnaH6miXmjpanEl3Pdv8Oz48E1oORkdZaIzJlpv33zkIjl7uMdZrr44NtfS3Pg8O/uVURPF1Xwal6jy+V3UUhyn80mcLZvfZ6/1vzQ4f7/+tH3rqnj5e3q3dbyfnYjP402GhWf1LFcRkvBcChXJCIxIGnW79n5xsNbMxu/vdPbvpqwckLH0N1Ls2bilkTNtcGDsTj80VUupWLwq1ne1Yd7wMW7viVIppKkrmjYjnO27dyszd2D0Qe6AAAACXBIWXMAAAsTAAALEwEAmpwYAAAZAElEQVR42u2dd1xUZ77GJwZymALThxkCZCkaaYoUXVTARgkIYgMTDShWLGB3sXvF2IVYMTYSS2wbhdiNGmNcY78aE9tuTE822Zhssnf37r33j/u+50w5ZwoMOBSH5/kkOHPOOzPwnd953t9bzvuKRBAEQRAEQa1FPgF6qTRKTBQlleoDfEDEtfLWS8WsZFIiGfdYqvcGGRdJZ6DRG2rQ8ELXR2MIpRGt14GPCyyCRLBM5ae1PaP1U5GIXg/TcAFhqUbr6LRWQ8/DMp5A2vWEoCVOvTV6vT5EatDr/XwE34JBC1YNlEYmDjXB9DYYaz2TQg1+JsqhYpkfaDUoiEPEsgAT4CixHclMXhwgE69HKDcgXYsSh+rMbuBIUi6AdaHiULhyvRHLxAbuQS2EWcpcLBvEMkCupxWLxRrWMAziOsXZhAamXF/EMjY8faLETshYVsZ9LZBzWbHxwteInZSesxfYRX28mIW13lnE4qIA/lcD1Z20RXEXvdOIzQ09jTgKKZxTCuEufacRqywv1YtDwM8J6cXSeiEu4oeuVBwAgnVKJ5NRaAFOe7EAqlYmQ29nnZKyZuztNGKxj1XWB7eoS36cU5Ce4VA65KHScyMgMgPpcDMNgdAzIXpT68Tb+jtCh3IdihJbX+taCtJgp6jBXhyTK0AKinU08FQ22bIjxiF2/JheAgjk2hUqDGONQWrsEgqVrtdreWOoIVJTMzuU/33QShOBXHsLzyqMhT1Clu4InYNKz8eHDWS09mqRSkz7znRCn7AMffDjndfM4w//sdWmASQdS1ZEwfJiuUgA2QI/wH58+7BBLZOBZC2Jm4HN27QOzEIvTDbMfZtaC2MV+yL0JDuUgXVSfj+w0CyibJIKqx4L0vPG/oRZOE6OZWww8x22yEGbTmPXRMhRGsKCXAMSdFWw7WCDwHgNDrrYtHaP67lMWipGp4XI0fCHnm3p8dsVQrOQOTALkyNLuWtAj2aIyGGvJkVjZbxFDlJkoVkYKznancHajR40HWXHOhrMwo4evYBlSK1m4W18qbdtixwyXenm+FTZb9LxnVpgFlJL1sxeC2hOO2IsM8etzH6Tju/UGtusLtSURIOxIxnrKyvjDXCQIgvNwhLyerT0nGQc4sgsHGQWFuvWm1wHcsRYZYSmtW8WKpFds5CKjFkfGDsfxzzjDbCTpJkzNV6+4S0G4/oxDrVrFjJhrifoLTJYHsrAuLa8wuwA3vbMQsWNdYiM3XSCjowoC2PkFbXmxz4mbAZ7ZkGsIlRrxyx4xJEf19nO87a1BR3fKrx5aZ2Kb8cqS/yjnedEf4VV9SblWYWBF6N+/JaJjB/S6K8Q1dbvJrVN0zQ87FH89rTM0sL242Vx6HcT1d5/bOkE0lo36WScleitzaKIZxUGtnWC/mNHCpUJsgWNdZNOxaGMsjYLA69ljXEQkVPjeTYpssbMTyYccpKZUgkNr6bEeJ6otnFpvWB4SSc0C5kpcFVCs5DxOi8MGJeuQ7IowfCSQWgWKpPrWgb7vY3HtfyWSxR63WrNkH347boooVn4mX1EIxiK8rM0U7h5QsiORXXNd/OzHevXcpagsRlyMnD5RyjvBZjvVldzWmc/RQ5hn4TYOLU3C1zHC2PM26yzGaLi91lYjJednaK1M+RURB8HCMIYDRBnJiCH2KTIWr5V8J3aQF8QaqkjdUiO6w5kKXt7ks28V5VBMLpktlzvUHMmwt5FJkXiJqr7Dkg/vluYjdfPWzBKyuvMENwZgvuanLo/j70fV28zHVY46CQT3qhj8mjcn+eUArhIVNlMhxUOnmqs7srhIhv3mTrrFgE8yN4OJgGEWN01osL90vWQtoirtlRWxhvgaFYWrSBVWtaMi3Dfv7PrV3DrUKiExhvq4D5pP9M34Y31K+oPOYBvvNa3UIfy+t40WIdF1ID1hFhc3kUW47VZvcnbfDMU1hNq2BKFMm5dLJXZeG2WbzL2fPrpTetiAXG91xTiUmOdNMCuVVilyFjfrSGQQ8VSLknQ2bcK/uQArFPYwBROJbj67az0Zs6FyXqbKiRtDZKfzLLklU4vlQkXwzL48NaNhRU3OJQNgnW6dWTZf72BLM2i9/EWrH+MIH4iV5aa14a1n39IBatQQw2Sj4q30LHVevTriX2EgLALpNMXsTtV+PEyBx8/di2nIuyr4Pr9QaSssD9IY+5zw97ZW4R9biAIgiAIgiAIgiAIgiAIgiAIgiAIgiCoXvKAHMpFhJ+DapFLKHs+x0AO9ZynK8IYjGtn7AHGYAzGYAzGYAzGYAzGYAyBMRiDMRiDMRiDMRiDMRhDYAzGYAzGYAzGYAzGYAzGYOzujHfpJNaHfBez/6gjJGD8xDowIlXZYajc6uiQEb0pXIXtGXdj7Nsulfyl04clu+AXjfzW398/aZ7tZzwebWa8PXFDHBg/AePboz09PVLsnTKRVEwvMH0JrZDxoZiSwnKJ7/y8wtJ9io7TSpJ6XqosKbwfx0TmlSR1l2yPqfRfOmlaydIdjHrBtIL9O1hiC8iB0ZLtoyr9dxNQkf8xjg1VS9HPEulb+Lbrb4pj33brR4wlj05eKEmq7C3ZNaogKW+o/NCFgsJy40efm1aSP+/A5ILC3XK3Yzz18L7cxYoV+Wc2JhL3zOzS5nS7sTUL8k4xWz4PHD9hTa+Xu+dOzj+T0W5Dypi8gIxRh+kVPybvDzfH5/cl5wLTJWbGvKK+YREL8nJ4jCNvz1sxoRNhX6o9fq+3b7eKJZtGDJXH5vfMXcx99IHEzcG5cdMn7Niilbgd4w7DdkjYZ4p3MuM6bJCTx/0l3Flm7svzer2cw8Tmr2GmVyST8wRnXxLG9NH2xN70HOfHBQUFQ+W8omyF19vCWNEhM2tudTk53Zd6Ra/qU6xXxBLsxo8+PSJhH8PEJhXL3dArdr1ZuW7HgURSa/lXZJkYq7uNVZ67UEA8lIKjYGnE0zJJJGTVU4fSYqlmxrdHt2mzWMIreiimsrCAx3h7Iv3eNsRR/yeMyXdnZmz66EMxxDF8Z+YtLXabOFZP3ZDCqDuQgGR2jco8zcWtgsd4e+LmFGMcG8F1OGzMDGzi2OQVlq/j8D5BHMd+W1hQUJI0zkEcc+96KJE88iUe5Db5cewyffTjvJWSL1adHl+RtSL/rucX+6wYLxYyjsybkZ6xSsL68QzOj3MseYVnioBxl10c43cq9tEvlPh8m5fu9d+e2EM3MLG3euqwM7mTOcYK7qN9oxfvajf2li64I/eFuQVj9WOSQ8yIU48v8CeXJ6nc/ZNy+IyVJHconLCDB05Nj2yWW/IKix/Ty70/3ysuFPgnnaLvdOgCSSd6VZdLWNLEEciJYoYYlH/SZpYxw330gRElhft3dCSHZ8jRzkN/BRiDMRiDMRiDMRgLpZzxgVcr0gczlE3OWJmwNmFr60G8lfy5yqZmPGNtwhJJ67EEyZKEtTOamvEHCUtal/EuSfigqRl7bZW0LsaSrV5NztirtWUQXs3F+PdgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZg7PaMGTDGnELmKZ5TiLmxmOPtDnO8ca8C7rlxh3tuIDAGYzAGYzAGYzAGYzAGYwiMwRiMwRiMwRiMwRiMwRgknyLGxo09wLjxGBs3RABj59fx9vcvXHpXDsaNyLjb7oiM+bdzwLgxGZP1tclS/NwuIOpZlf4V3FYhK4Yl0/Xm1WS5eLLodlKA3Hd8ZUlFsnFjDzCuJ2Oyi8EpbheQuS8XB3+ewm4VQhbwV3fLX0OCdntigvZxHlnxfGzE58aNPcC4foz9S8ja7yncLiBzqzfHkZ0O6FYh2xPLP7swPIccpJsgkG0qTpNV5U0be4Bx/RgnaCPkjILbBYT8Q9b/Z7cKUU/dHTnnUur0iiy6mQfdHYUyNm7sAcb19mO6OQq7Cwh5TrcPoluFxMVOeDM1dt3kVDni2GWM6S4gQ6KDX6o+xW0V8lliUg79nzH7cX/qIOzGHmDcAMYKbheQudX+haVZ3FYh6g4VyeqpFVkMQ/IMmldQxoxxYw8wRn8FGIMxGIMxGIMxBMbuuQdL9MRJz7QaTZoY3Qz3g0T/KUzZesJVGfan6KZnPDGsdZlC2MSmZzxJ2boYKyc1PeNnWlvt9gwYgzEYgzEYgzEYgzEYgzEYg3GjSSEH48aUOvrs4Z1e740tjgPjRtKtbQ+2er2Wenbrzqp5EjBuDJP44vDyXzK9qpKHbCufuHWkHIwbIYoPH5N/tNPrtZUTt16Rf7RhpASMXS3f2Uflit92smthXZErPqrqC8Yur+/eXR7HbOJWrjsqV/92JQuMXa4ts4/G+e6hiKs6qX+zhDEYuxRy1bzzP5UOXZkcdpaHGIxdahc/Ha76g8YvoHTryn3IjxtL538JuH9/RnEW2nnorwBjMAZjMAZjMAZjMAbjlsMYcwoxN5Zxg7mxmOONexXc4V4FCIzBGIzBGIzBGIzBGIzBGAJjMAZjMAZjMAZjMAbjptSq9xqy+fF7q8DYeb3XsB2m32vWcRCHgwRMi9zIoqHbeDfHeF50jSenmmgHg121ImZXkwXjWselo0XBJomijYO2Y+75+yedzXoCxnPzyslhxYr8vmDMTBKdV5p0XmScfBB5e3Tu8Qtj5Q1nHPltRTLDkCWqx4Ex80yw0mTCSmWwcRIN2VOBxOCwZPWCaQX7dzAnpxX4779YWdgjmfGdn1dYuk8xM6+kcFtMZeHaON922ZXkCGMseuhCQSGN4NgkEsiKFeFk45FdFyu5PQVaM2NL/cdjrBg4IjNrTF5AxqjDcbH5PTclVug2Vq+UrMg/szExVdkhM/34vd3ax7dzfNv10G1MHCu3FM2lleD0ivmZWQcS/514yndqxZEFeTlgbM3424IC/8JTdA8Wwrtv7IROincOx5GdFnzbpUro0Q4b5PQh2d+CeoWC7LZgKUrfQLEic2B1TuywH0aU96o+RRZkT5WAsRXj26M3koX96V5OpPIbRxmvyMwiW94cSKRHKrIIY7qQPdlhwZfbbWGNpSjL+J0N8g492vUf0q733Hv0zG45GNt6ReyEvooOh9llCSyMT7djA1IhZEyt21KUZUx2IJp7L78vOdurOqfx67w+f5xth+ZrI99t0YwZ3267UyLzZqRnrJJYGMtX5N/1/GKfgPHYmuPVqXJLUYbdzWy3XD1+LSmUSvx4SU10XGtmPEnAeJKFMTGMHDXd0WKznMeY5BX+STl8xpcq/ZPuxzGWorwdMVjWJK/wH7amSRhX7QgOm+31YHlacMS7O1nGrx1bHFyzp9nbILzcLXriU9RfYcu4T789D5bfnHPl5javox8ZGY/c43Xl5pzmbkuHmdsgYQ1oS7ckxlc2ZXr1mbfnGOHLZ9znj9ual/ET9wk9DYxnNy/jp1eOvSJj24NjYOxyxuPOp6TcyrzC1nmvHVsVsQqMG7cNstNB1gbGLmNc1S8i/blMMG5VbWkwBmMwBmMwBmMwZjCHBXOxMBeLwZxCCIzBGIzBGIzBGIzBGIzBGAJjMAZjMAZjMAZjMAZjMAZjMAZjMAZjMAZjCIzBGIzBGIzBGIzBGIzBGGo0xlAtcgVjkWdNG8ihajxdgJgEMlSLXBHGlDLkUCIIgiAIgiAIgiAIgiAIgiAIgiAIgiAIciMFzZyT5uBUYLeVTfQ7zL/rNjxzJy/LDp99RHhw0y8R7L8b96TZZbx6wGir47Yln1CBkwdtXDh8aXe3YDxqkChjVEK63ZOD2/dzkrFtySdnnPt50Kx1aW7CWNRxXdrAN8vC16YHLViYHV76ccceXY4vDL/ac/C08A+LuTOrY4aHdxcypoWvnhFZSopE59r3JP/32xiTvVQTQbl37PHxuYXZ+3uS18RkZz88I6LBqfHYdDH8w+7sj1k9Pqa/wmDTi9jP2XRxePhw8nsFkbPuEseTS9PH30/fuLD4pQHdIzrO6ULITN4c4clSCjSead8zyEPImBSumbX/iLkk0cCY7kGzEjJGrU0/PqDYyJi8H53qRN4gd/7+I0EeQQvWpRF2gZ7sD1LopQu7I8wvop9Tc6m0Swb5vYIeP1ziHl6Rnb2sNG1gTHhZ2fDymXO6iFjGXWZ+eFbHOoDxDPnbrb2CFh64sLu5JA3t8Qk3Jw86ScoGTt5sYtyjCz1F32DgwuKNF8vKJvQbPGC2twf7IyOme8eHD4+YX8QWi+lOvcKOJT21cRw4fg5hXE6fzexhYhy06c0PiznG5SZEdhkXm0tSnWx/uX3PWhh3n3w//SQ5njF/2iAP9sf40kuai98M6GmHccZP6SL3qfM211yacyQoLGLwgLskcaOM20Tkkj94wOjANtwZO4yNXmEuSYHkXiorTTde9qsXEuOxMCYlZrLOQhjnphOrbUN/pA8uu9pvluVF9HMCx/dIo4wHvpvmNoxF5z4cPfDN4dnb0gIfl4WXsX58KTz84ZLc+aQC4s4IGVcvW7ZsXRpb5wVaSrIJxnDyD1d9BT2eRirQdBPj6rLsq3dpDVm27sjM4eFL77I/yC+wO4J8W6YXsZ+TQT6SvB35tdyw9RHoSYKoNKKWAnW0QYIWbHMQe8YvCSIVXHitdXntjINmlpFkDowhCIIgCIIgCIIgCIIgCIIgCIIgCIIgqNlE5qssC58RYX9accao7GXLsrMH8covOBsBaPVTxqhtSzy+8BY5nFbcUTgfmMzRTAe1upU73xK3HfdzSMlcqPCzdAYVO63Y/IxjTKYdDydTsMisrW1dZi0L398PDOtEvM48L4jMbGVxB47flrYpZpAxji3POMYvtT8TOL8HmdMq8kQcO6XB05axyi43Me647QfCj06pFBknIJuecYxnZpeVlc1Ju3RV0wWMnVLg/KuWOCZzVwnHOXUw5m56Cjx+cf8RMHYS8gwPy5TCUh2d4212B3YCspVXnBwQEJGrDfxctHphccd1R2qQWdRP5GYXes/NQFMtx04rtq3zyORgOsOztMvAi9lLRwMbBEEQBEEQBEEQBEEQBEEQBEEQJHK3PSNbOGH7h4PCnm2RCguq15/RMmR/k9qg6LCWuTl0WHRQPf6MFhLGdn85j7Cw4JbJODgszD5jj6eNsehZqz9NQf679ejRjRuPftzCPW02PeumjBXMlkefPv98Z6Ln73z5Y7NCdk/GSoZ5dIfQNapz5y+3II5dzVh9wwyYo3znVvNFslsyVii+7GyKYC6aO396iwY3GLuKsZIxRnHnO1/euPHp850JYniFSxkrmB+52L3ziCV76wZFjDrPpXGs/pQyZus5hYKyJdmbEnHsUsZjXrhDHfg8oySAJRIl4auUUIGxyxj/1wsvvP08P5Fwwifef2WNM+fnPkyu440UKxLk7s94yAtUNzh7UKbwxAbyyXvx8V+tEVDZLWd2/ZRSKzpynhZ79ZVOxhfN/Ft8/DA7wBVv/GcrYHyIZTyXOrGE+cvrPK2ikbjog32+z8bxqbzdR+7EFc8WMzN+/+DmlF2/yFsr4zEs410Mx/hFnv5MEXyVRQvF/i3+xDz1d/Hxvz+leDs+/gGBt+Lr+INj5e9/lew75ai6w9fxmVnUIjptX3SM4CXn2WJfx7PHfadw38uQn+MP7k7h3o05RK6QvcmE8YGfvybv5P6MhxDALOPfmUUZq79j4fRalHr67b1ZU5arf90bZwxQAuf9v47jGL/6yo7PFh2j5UaO+bpqyJRjlDFbbM1cevyzRUe5oD2xJvL7Y6Z3e5DFvc0be7MiPxnXiuLYLuNX/7qGGfPJuCnLGTM8Cocg5Ri/EX/wYPxyCaOesvxfhXtXfzLOUowcMjJm30Ci/q6Ke7fLi0Zyb3N+Cnn1wZGtwI+VfK/gIFOv+JX1Cj7jNULGr3QijEl0c+76r70///vl/9sbJ2AsIV5RJa+F8RVJa8gr/ucal1fIF7P6M0uZ1nljvh+a5Ru92uQVlDG5tIPNjMd8MpJ6xcFTki0pbPETfb87uFxCz3PFWMakzhuUQhjzveLjKX3i3qfFUn49sUPtKXH3/Pgfbbve5LftuhPGL77OVkPnFsXHn+jL1Xkc47mL4vf+t4mxeiqp+sppnXeiL0MrN9alaYAai3GM1e98T9/mAK3z4hRcnRe5KP7giU6R3x8lR+N3xrl5O+8f/2zb9Tpp5xHKpJmnZFZRt3ixvLFHleTqN/bGtZL+iutd275FIJMBPgqYYVa9Tq3ixb80LmI1Se5O5LSOtrSSudy1LYX898sR9PnH3/zv72gY91dK0F/huv7jaySQ32pLKF+/du16165v/bOK5BarGDB23TiIUnmNjWRCmagtfSgliZsS/W6uHM87f41Dy4pGdFdvjDW5fFz68t+JR3CI3+ra9foPzdhL767zKyRM8DfXjV7R9frl883lxe7MmIat5IfL31y79s3lm9xTMHY14xYkMAZjzNtsQXH89M0/fvoYP3Xz6J9Gxk/ZrRVg3AQCYzAGYzAGYzAGYzAGYzB2zS9X08YNVNOiQ8XD0y3kgbUVWvfaChAEQRAEQRAEQc7p/wE2cPFlltJl+gAAAABJRU5ErkJggg==) --- # Exchange OAuth Code with Google ID Token ## Overview[​](#overview "Direct link to Overview") The Exchange OAuth Code with Google ID Token route in Simple JWT Login enables the exchange of the OAuth code obtained during the OAuth flow with a Google ID Token. This process facilitates secure user authentication and authorization with Google services. Below are the parameters and details required for this operation. This can be used when the OAuth process is happening in a different APP, and you need to obtain the `access_token` or the `id_token`. note For this, it is important to use the same `redirect_uri` in WordPress as the one that has been used in the OAuth flow. ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `POST` **ENDPOINT**: `/simple-jwt-login/v1/oauth/token` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/oauth/token&provider=google&code={{code}}` | Parameter | Type | Description | | --------- | ------------------- | ---------------------------------------------------------------------------------------------------- | | provider | `required` `string` | Specifies the identity provider. Set this parameter to 'google'. | | code | `required` `string` | The OAuth code obtained from the OAuth flow. This code is used to authenticate the user with Google. | ## Request Example[​](#request-example "Direct link to Request Example") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST 'https://simplejwtlogin.com/?rest_route=simple-jwt-login/v1/oauth/token&code=my-code' ``` ## Response Example[​](#response-example "Direct link to Response Example") ### Success[​](#success "Direct link to Success") ``` { "success": true, "data": { "access_token": "access token from google", "expires_in": 3599, "scope": "openid https://www.googleapis.com/auth/userinfo.email", "token_type": "Bearer", "id_token": "id token from google" } } ``` ### Error[​](#error "Direct link to Error") ``` { "success": false, "data": { "message": "The code you provided is invalid.Bad Request.Invalid_grant", "errorCode": 72 } } ``` ``` { "success": false, "data": { "message": "The code you provided is invalid.Bad Request.Redirect_uri_mismatch", "errorCode": 72 } } ``` Security Considerations Always ensure secure communication with the API endpoint using HTTPS. Protect the confidentiality of the OAuth code during the exchange process. --- # Setup ## Create an application[​](#create-an-application "Direct link to Create an application") To enable Google authentication in your application, follow these step-by-step instructions to create a new project and obtain the necessary credentials from the Google Developer Console. 1. Navigate to Google Developer Console 2. Create a new project 3. Once the project has been created, go to "Credentials" and click on "+Create Credentials" 4. Select "OAuth client ID" 5. Choose Application Type "Web application" 6. Configure Authorized Redirect URIs: In the "Authorized redirect URIs" section, add the URL where the OAuth flow will redirect users after successful authentication. This URL is crucial for the OAuth process. 7. Copy `client_id`, `client_secret`, and `redirect_uri` note If you want to use OAuth on WordPress, you need to add int the `Authorized redirect URIs` the following URL: ``` http://{{your-wordpressdomain}}/?rest_route=/simple-jwt-login/v1/oauth/token&provider=google ``` Important Notes * Keep your credentials secure. Do not expose them in publicly accessible locations or version control systems. * If your application has multiple environments (e.g., development, production), create separate OAuth client IDs and redirect URIs for each environment. ## Google Setup In WordPress[​](#google-setup-in-wordpress "Direct link to Google Setup In WordPress") 1. Go to Simple-JWT-Login plugin -> Applications 2. Fill `client_id`, `client_secret`, `redirect_uri` 3. Change `Allow Google` to `Yes`. ## Screenshot[​](#screenshot "Direct link to Screenshot") ![WordPress Google Settings](/assets/images/app_google_settings-488c81a6ad4ed2b01d0c36ad64f51936.png) --- # Shortcode ## Shortcode Configuration[​](#shortcode-configuration "Direct link to Shortcode Configuration") To configure the shortcode, utilize the options provided by this plugin for generating the "Continue with Google" button: ``` [simple-jwt-login-oauth provider="google"] ``` The shortcode includes the following customization options: * **provider**: `required` Specifies the provider name, e.g., for Google, use `google` * **background**: Defines the background color style (e.g. `#c8c8c8`) * **color**: Specifies the text color style (e.g., `#f2f2f2`) * **width**: Sets the button width (e.g., `250px`) * **height**: Determines the button height (e.g., `40px`). * **border**: Specifies the button border style (e.g., `1px solid #000`) Example of full shortcode: ``` [simple-jwt-login-oauth provider="google" background="#c8c8c8" color="#f2f2f2" width="250px" height="40px" border="1px dotted blue"] ``` --- # Auth Codes Auth Codes are an optional security layer that adds a shared secret to your API requests. Think of them as API keys: a caller must include the correct `AUTH_CODE` value alongside their request, otherwise the plugin rejects it. You can require an Auth Code for any combination of the following operations: * Auto-login * Register User * Delete User * Reset Password and Change Password * Authenticate (JWT generation) caution Use long, random strings for Auth Code values. Short or predictable codes offer little protection. Treat them like passwords - store them securely and rotate them if they are compromised. ## Auth Code structure[​](#auth-code-structure "Direct link to Auth Code structure") Each Auth Code has three fields: | Field | Description | | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Authentication Key** | The actual code value that must be included in requests as the `AUTH_CODE` parameter. | | **WordPress User Role** | *(Optional)* When set, users registered using this code are assigned this role instead of the default role configured in Register Settings. Useful for creating multiple user tiers (e.g., "premium" vs "free") from a single endpoint. | | **Expiration Date** | *(Optional)* The date and time after which this code is no longer accepted. Format: `Y-M-D H:m:s` - e.g., `2025-12-31 23:59:59`. | note Leaving the expiration date blank means the code never expires. ## Screenshot[​](#screenshot "Direct link to Screenshot") ![Auth Codes settings screen for Simple JWT Login v3.0.0](/assets/images/screenshot-8-4dddff8ae7796deb0be673e5f9058a83.png) --- # Authentication Use this endpoint to exchange WordPress credentials for a signed JWT. The returned token can then be included in subsequent requests to protected endpoints or used to auto-login users. You can authenticate using any of the following combinations: * **email** + **password** - standard credential pair * **username** + **password** - use the WordPress username instead of email * **login** + **password** - mirrors the WordPress login page behaviour; accepts either email or username ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `POST` **ENDPOINT**: `/simple-jwt-login/v1/auth` **URL Example**: `http://{{yoursite}}/?rest_route=/simple-jwt-login/v1/auth&email={{email}}&password={{password}}` **PARAMETERS**: | Parameter | Type | Description | | -------------- | ------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | email | `required` `string` | User email address. It is **required** when the `username` or `login` is missing. | | username | `optional` `string` | WordPress username. It is **required** when the `email` or `login` is missing. | | login | `optional` `string` | WordPress username or email. Simulates the flow from WordPress login page. It is **required** when the `email` or `username` is missing. | | password | `required` `string` | User plain password. It is required if the `password_hash` is missing. | | password\_hash | `optional` `string` | User password hash that it is stored in the Database. It is required if the `password` is missing. | | AUTH\_CODE | `optional` `string` | Auth Code from the "Auth codes" section. Required only if the "Authentication Requires Auth Code" option is enabled. | | payload | `optional` `string` | Extra claims to merge into the JWT payload, as a JSON-encoded string, e.g. `{"department":"engineering"}`. Reserved claims (`iat`, `exp`, `email`, `id`, `site`, `username`) are always overridden by the authenticated user's data and cannot be set this way. | ## Request[​](#request "Direct link to Request") ``` { "email" : "test@simplejwtlogin.com", "password": "SomeSuperSecretPassword", "AUTH_CODE": "MySecretAuthCode" } ``` OR ``` { "username": "myuser", "password_hash" : "PasswordStoredInTheDB", "AUTH_CODE": "MySecretAuthCode" } ``` OR ``` { "login": "username or email", "password" : "SomeSuperSecretPassword", "AUTH_CODE": "MySecretAuthCode" } ``` With extra payload claims: ``` { "email" : "test@simplejwtlogin.com", "password": "SomeSuperSecretPassword", "payload": "{\"department\":\"engineering\",\"region\":\"eu\"}" } ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "data": { "jwt": "NEW_GENERATED_JWT_HERE" } } ``` ### 400[​](#400 "Direct link to 400") ``` { "success": false, "error" : "Error message" } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/auth \ -H "Content-type: application/json" \ -d '{"email":"test@simplejwtlogin.com","password":"mySecretPassword"}' ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->authenticate('email@simplejwtlogin.com', 'your password', 'AUTH CODE'); ``` ## Screenshot[​](#screenshot "Direct link to Screenshot") ![Authentication API settings screen for Simple JWT Login v3.0.0](/assets/images/screenshot-7-2f338df0aa647954e348da088f33fb87.png) ## Features[​](#features "Direct link to Features") ### JWT Payload parameters[​](#jwt-payload-parameters "Direct link to JWT Payload parameters") You can choose what parameters you want to include in the JWT payload. You can choose from: * **iat** : Timestamp when the JWT has been generated * **exp**: Timestamp when JWT will expire. If not added in the payload, JWT will never expire * **email**: The user email address * **id** : The user's ID * **site** : The site where the JWT has been generated * **username** : The user's username ### JWT time to live[​](#jwt-time-to-live "Direct link to JWT time to live") You can specify the time (in minutes) that the token will be valid for. By default, the token is valid for 60 minutes. ### Allow Authentication only from specific IP addresses[​](#allow-authentication-only-from-specific-ip-addresses "Direct link to Allow Authentication only from specific IP addresses") Restrict authentication requests to a whitelist of trusted IP addresses for an extra layer of security. Separate multiple entries with commas. ``` 192.0.1.1, 192.2.2.2 ``` The wildcard `*` is supported in any octet, which is useful for allowing an entire subnet or IP range (e.g., all addresses from a specific country or hosting provider): ``` 85.*.*.*, 86.*.*.* ``` ### Base64-encoded passwords[​](#base64-encoded-passwords "Direct link to Base64-encoded passwords") Enable this option when your passwords contain special characters that would otherwise be mangled in query string parameters. When active, the plugin expects the `password` (or `password_hash`) value to be Base64-encoded before sending. --- # Autologin The Autologin endpoint lets you log a user into WordPress by passing a valid JWT - no username or password form needed. This is ideal for: * **Magic-link emails** - generate a signed link and email it to the user * **SSO flows** - redirect users from an external system directly into WordPress * **Mobile apps** - open a webview session without re-prompting for credentials * **Cross-domain redirects** - seamlessly land users on a specific page after authentication The plugin validates the JWT, identifies the WordPress user from the token payload, creates the authenticated session, and redirects the user to the configured destination. ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `GET` **ENDPOINT**: `/simple-jwt-login/v1/autologin` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/autologin&JWT={{JWT}}&AUTH_KEY={{AUTH_KEY_VALUE}}` | Parameter | Type | Description | | ----------- | ------------------- | --------------------------------------------------------------------------------------------------- | | JWT | `required` `string` | Your JWT | | AUTH\_CODE | `optional` `string` | Auth Code from the "Auth codes" section. Required only if "Autologin require Auth code" is enabled. | | redirectURL | `optional` `string` | If provided, you will be redirected to this URL after successfully logged in. | Parameters can be sent as query params. ## Request[​](#request "Direct link to Request") ``` https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/autologin&JWT={{JWT}}&AUTH_KEY={{AUTH_KEY_VALUE}} ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") You will be redirected to the specified URL in the plugin settings ### 400[​](#400 "Direct link to 400") ``` { "success": false, "error" : "Error message" } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl 'https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/autologin&JWT=mysecretjwt&AUTH_KEY=mysecretauthcode' ``` ### PHP[​](#php "Direct link to PHP") Using the simple-jwt-login PHP Client: ``` $simpleJWT = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login-v1' ); $url = $simpleJWT->login('Your JWT'); header('Location: ' . $url); ``` ### JavaScript[​](#javascript "Direct link to JavaScript") ``` var JWT='myJWT'; var AUTH_CODE='MY_SECRET_AUTH_CODE'; window.location.href="https://simplejwt-login.com?rest_route=/simple-jwt-login/v1/autologin?JWT="+JWT+'&AUTH_CODE='+AUTH_CODE; ``` ## Screenshot[​](#screenshot "Direct link to Screenshot") ![Login user API settings screen for Simple JWT Login v3.0.0](/assets/images/screenshot-3-9cc2508a6beb95dc484c2b7de89fd4b6.png) ## Features[​](#features "Direct link to Features") ### How to send the JWT[​](#how-to-send-the-jwt "Direct link to How to send the JWT") The JWT can be delivered in any of the following ways: * **URL parameter** - append `&JWT=` to the autologin URL * **Authorization Header** - `Authorization: Bearer ` * **Cookie** - set a cookie containing the token * **Session** - pass the token via the PHP session If the JWT is present in more than one location, the last value encountered takes precedence. **Supported decryption algorithms**: `HS256`, `HS384`, `HS512`, `RS256`, `RS384`, `RS512` ### Redirect after login[​](#redirect-after-login "Direct link to Redirect after login") Once the user is authenticated, the plugin can redirect them to: * **Dashboard** - the WordPress admin panel * **Homepage** - the site's front page * **Custom URL** - any URL you define in the plugin settings (ideal for landing pages or app entry points) You can also append a `redirectUrl` query parameter to the autologin link to override the configured destination. Enable the **"Allow redirect to a specific URL"** option in the plugin settings to activate this. ### Dynamic redirect variables[​](#dynamic-redirect-variables "Direct link to Dynamic redirect variables") Use these placeholders in your custom or redirect URLs. The plugin replaces them with the actual values at redirect time. | Variable | Description | | --------------------- | ---------------------------------- | | `{{site_url}}` | The site URL | | `{{user_id}}` | The logged-in user's ID | | `{{user_email}}` | The logged-in user's email address | | `{{user_login}}` | The logged-in user's username | | `{{user_first_name}}` | The user's first name | | `{{user_last_name}}` | The user's last name | | `{{user_nicename}}` | The user's URL-friendly name | Example: ``` http://yourdomain.com/profile?uid={{user_id}}&name={{user_login}} ``` ### Redirect on failed login[​](#redirect-on-failed-login "Direct link to Redirect on failed login") Instead of showing a raw JSON error when autologin fails (e.g., expired or invalid token), you can redirect the user to a custom error page. Set the failure redirect URL in the plugin settings. On that page, use the `simple-jwt-login:request` shortcode to display the specific error message returned by the plugin: ``` [simple-jwt-login:request key="error_message"] ``` The `key` attribute maps to the query parameter appended to the redirect URL. Use multiple shortcodes if you need to display several parameters. ### IP address restrictions[​](#ip-address-restrictions "Direct link to IP address restrictions") To tighten security, you can restrict autologin to requests originating from specific IP addresses. Requests from any other IP will be rejected. *** ## FAQ[​](#faq "Direct link to FAQ") ### How do I tell the plugin which field in the JWT contains the WordPress user ID or email?[​](#how-do-i-tell-the-plugin-which-field-in-the-jwt-contains-the-wordpress-user-id-or-email "Direct link to How do I tell the plugin which field in the JWT contains the WordPress user ID or email?") In the plugin settings, set the **"JWT Parameter Key"** field to the name of the JWT payload property that holds the user identifier. For example, if your JWT payload looks like this: ``` { "sub": "1234567890", "name": "John Doe", "UserID": 123456 } ``` Set **JWT Parameter Key** to `UserID`. The plugin will use that value to look up the WordPress user. --- # Change password This endpoint completes the password reset flow by applying a new password. The user must supply the reset code they received by email (from the [Reset Password](/docs/3.0.0/reset-password.md) step), along with their email address and the desired new password. Alternatively, if **"Allow Reset password with JWT"** is enabled in the plugin settings, a valid JWT can be used instead of a reset code. **METHOD** : `PUT` **ENDPOINT** : `/simple-jwt-login/v1/users/reset_password` **URL Example** : `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/users/reset_password&email={{email}}&code={{code}}&new_password={{new_password}}&AUTH_KEY={{AUTH_KEY_VALUE}}` **PARAMETERS**: | Parameter | Type | Description | | ------------- | ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | email | `required` `string` | The email address that wants to reset the password. | | code | `required` `string` | The reset password code. | | new\_password | `required` `string` | The new user password. | | AUTH\_KEY | `optional` `string` | Required only when option "Reset password requires AUTH CODE". | | JWT | `optional` `string` | To reset the password with a JWT, enable "Allow Reset password with JWT" in the plugin settings. If a valid JWT is provided, the `code` parameter is no longer required. | ## Request[​](#request "Direct link to Request") ``` { "email" : "test@simplejwtlogin.com", "code": "MY_CODE", "new_password": "YOUR_SECRET_PASSWORD", "AUTH_KEY" : "MY_SECRET_AUTH_KEY" } ``` ## Response[​](#response "Direct link to Response") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "message": "User password has been changed." } ``` ### 400[​](#400 "Direct link to 400") ``` { "success": false, "data": { "message": "string", "errorCode": 0 } } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X PUT https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/users/reset_password \ -H "Content-type: application/json" \ -d '{"email":"test@simplejwtlogin.com", "code": "123", "new_password": "test"}' ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->changePassword('email@simplejwtlogin.com', 'new password', 'code', null, 'AUTH CODE'); ``` ### JavaScript[​](#javascript "Direct link to JavaScript") ``` var data = JSON.stringify({ "email":"test@simplejwtlogin.com", "code": "123", "new_password": "test" }); var xhr = new XMLHttpRequest(); xhr.withCredentials = true; xhr.addEventListener("readystatechange", function() { if(this.readyState === 4) { console.log(this.responseText); } }); xhr.open("PUT", "https://simplejwtlogin.com" + "/simple-jwt-login/v1/users/reset_password"); xhr.setRequestHeader("Content-Type", "application/json"); xhr.send(data); ``` ## Screenshot[​](#screenshot "Direct link to Screenshot") ![Change password screen for Simple JWT Login v3.0.0](/assets/images/screenshot-6-9a5714cd7a4a973ab72fdbde78ee7acf.png) --- # WP-CLI Add-on **Simple-JWT-Login CLI** is a [WP-CLI](https://wp-cli.org/) add-on that brings the full power of Simple JWT Login to your terminal. Generate tokens, inspect payloads, revoke sessions, and manage every plugin setting - all without opening the WordPress admin UI. It is the go-to companion for DevOps pipelines, staging-to-production migrations, automated testing, and any workflow where speed and scriptability matter. ## Requirements[​](#requirements "Direct link to Requirements") | Requirement | Minimum version | | ------------------------------------------------------------------- | ----------------------- | | WordPress | 4.4+ | | PHP | 5.5+ | | [Simple JWT Login](https://wordpress.org/plugins/simple-jwt-login/) | active on the same site | | [WP-CLI](https://wp-cli.org/) | any recent stable | > The add-on automatically deactivates itself if Simple JWT Login is not installed and active. ## Installation[​](#installation "Direct link to Installation") **From WordPress.org (recommended)** 1. In your WordPress admin go to **Plugins → Add New**. 2. Search for `Simple JWT Login CLI` and click **Install Now**. 3. Activate the plugin. **From zip** 1. Download the latest release zip from GitHub. 2. Go to **Plugins → Add New → Upload Plugin** and upload the zip. 3. Activate the plugin. Verify the commands are registered: ``` wp jwt --help wp jwt config --help ``` *** ## Commands[​](#commands "Direct link to Commands") ### `wp jwt login`[​](#wp-jwt-login "Direct link to wp-jwt-login") Authenticate a WordPress user and print a JWT token. > Authentication must be enabled in **Admin → Simple JWT Login → Authentication → Allow Authentication**. ``` wp jwt login [--username=] [--email=] [--login=] --password= [--format=] ``` | Option | Required | Description | | ------------ | ------------ | ---------------------------------------- | | `--username` | One of three | WordPress username | | `--email` | One of three | WordPress user email | | `--login` | One of three | Username or email (username tried first) | | `--password` | Yes | WordPress user password | | `--format` | No | `text` (default) or `json` | Priority when multiple identifiers are supplied: `--username` > `--email` > `--login`. **Examples** ``` # Authenticate by username wp jwt login --username=admin --password=secret # JSON output wp jwt login --username=admin --password=secret --format=json # {"jwt":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."} # Capture token for use in curl TOKEN=$(wp jwt login --username=admin --password=secret) curl -H "Authorization: Bearer $TOKEN" https://example.com/wp-json/wp/v2/posts ``` *** ### `wp jwt decode`[​](#wp-jwt-decode "Direct link to wp-jwt-decode") Decode a JWT payload and display its claims. The signature is **not** verified - use `wp jwt validate` for that. ``` wp jwt decode [--format=] ``` | Argument / Option | Required | Description | | ----------------- | -------- | -------------------------- | | `` | Yes | The JWT token to decode | | `--format` | No | `text` (default) or `json` | ``` wp jwt decode eyJhbGciOiJIUzI1NiJ9.eyJpZCI6MSwiZXhwIjoxOTk5OTk5fQ.sig # id 1 # exp 1999999 # Extract a single claim with jq TOKEN=$(wp jwt login --username=admin --password=secret) wp jwt decode "$TOKEN" --format=json | jq '.exp' ``` *** ### `wp jwt validate`[​](#wp-jwt-validate "Direct link to wp-jwt-validate") Verify a JWT signature against the plugin's decryption key and check that the token has not expired. ``` wp jwt validate [--format=] ``` | Argument / Option | Required | Description | | ----------------- | -------- | -------------------------- | | `` | Yes | The JWT token to validate | | `--format` | No | `text` (default) or `json` | The command always exits `0` - check the `valid` field to determine the result. ``` wp jwt validate "$TOKEN" --format=json # {"valid":true,"message":"Token is valid."} # Use in a shell script RESULT=$(wp jwt validate "$TOKEN" --format=json) if [ "$(echo "$RESULT" | jq -r '.valid')" = "true" ]; then echo "Token OK" else echo "Invalid: $(echo "$RESULT" | jq -r '.message')" fi ``` *** ### `wp jwt revoke`[​](#wp-jwt-revoke "Direct link to wp-jwt-revoke") Revoke a JWT token so it can no longer be used. The token signature is verified before revocation. ``` wp jwt revoke [--format=] ``` | Argument / Option | Required | Description | | ----------------- | -------- | -------------------------- | | `` | Yes | The JWT token to revoke | | `--format` | No | `text` (default) or `json` | ``` wp jwt revoke "$TOKEN" --format=json # {"success":true,"message":"Token has been revoked."} # Log in then immediately revoke TOKEN=$(wp jwt login --username=admin --password=secret) wp jwt revoke "$TOKEN" ``` *** ### `wp jwt config get`[​](#wp-jwt-config-get "Direct link to wp-jwt-config-get") Print the current value of a plugin setting. Use dot notation for nested keys. ``` wp jwt config get [--format=] ``` | Argument / Option | Required | Description | | ----------------- | -------- | ------------------------------------------------------------------- | | `` | Yes | Setting key; use dot notation for nested keys (e.g. `cors.enabled`) | | `--format` | No | `text` (default) or `json` | ``` wp jwt config get allow_authentication # 1 wp jwt config get jwt_algorithm # HS256 wp jwt config get cors.enabled # 1 wp jwt config get jwt_payload --format=json # ["iat","exp","id"] ``` *** ### `wp jwt config set`[​](#wp-jwt-config-set "Direct link to wp-jwt-config-set") Update a plugin setting and save it to the database. ``` wp jwt config set [--type=] [--force] ``` | Argument / Option | Required | Description | | ----------------- | -------- | ----------------------------------------------------------------------------------------------------------------------- | | `` | Yes | Setting key; use dot notation for nested keys (e.g. `cors.enabled`) | | `` | Yes | New value to store | | `--type` | No | `auto` (default), `string`, `int`, `bool`, or `json`. With `auto`, the type is inferred from the currently stored value | | `--force` | No | Skip plugin validation and save regardless of validation errors | ``` # Enable authentication wp jwt config set allow_authentication 1 # Change the JWT algorithm wp jwt config set jwt_algorithm RS256 # Set a 2-hour TTL wp jwt config set jwt_auth_ttl 7200 --type=int # Set the decryption key wp jwt config set decryption_key "my-super-secret" # Replace payload fields with a JSON array wp jwt config set jwt_payload '["iat","exp","id","email"]' --type=json ``` *** ### `wp jwt config list`[​](#wp-jwt-config-list "Direct link to wp-jwt-config-list") Show all stored settings as a flat key/value table or raw JSON. ``` wp jwt config list [--format=] ``` | Option | Required | Description | | ---------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | | `--format` | No | `text` (default) - one `key value` line per setting, nested objects expanded with dot notation; `json` - full settings object as pretty-printed JSON | ``` wp jwt config list # allow_authentication 1 # jwt_algorithm HS256 # cors.enabled 1 # ... wp jwt config list --format=json ``` *** ### `wp jwt config export`[​](#wp-jwt-config-export "Direct link to wp-jwt-config-export") Export the full plugin configuration as JSON to a file or stdout. ``` wp jwt config export [--file=] ``` | Option | Required | Description | | -------- | -------- | ------------------------------------------------------------------------- | | `--file` | No | Path to write the JSON output to. If omitted, output is printed to stdout | ``` # Print to stdout wp jwt config export # Save to a file wp jwt config export --file=jwt-config.json # Filter with jq wp jwt config export | jq '.jwt_algorithm' ``` *** ### `wp jwt config import`[​](#wp-jwt-config-import "Direct link to wp-jwt-config-import") Import plugin configuration from a JSON file produced by `wp jwt config export`. By default the entire settings object is replaced. Use `--merge` to update only the keys present in the file. The command shows a diff of every change and asks for confirmation unless `--yes` is passed. ``` wp jwt config import [--merge] [--dry-run] [--yes] [--force] ``` | Argument / Option | Required | Description | | ----------------- | -------- | ------------------------------------------------------------------- | | `` | Yes | Path to the JSON file to import | | `--merge` | No | Merge into existing settings instead of replacing the entire config | | `--dry-run` | No | Show what would change without saving anything | | `--yes` | No | Skip the confirmation prompt - useful in CI/CD pipelines | | `--force` | No | Skip plugin validation and save regardless of validation errors | ``` # Preview changes without saving wp jwt config import jwt-config.json --dry-run # Full import with confirmation wp jwt config import jwt-config.json # Non-interactive (CI pipelines) wp jwt config import jwt-config.json --yes ``` **Backup / restore workflow:** ``` # On the source site wp jwt config export --file=jwt-config.json # On the target site wp jwt config import jwt-config.json --yes ``` *** ## Common Workflows[​](#common-workflows "Direct link to Common Workflows") ### CI / CD token generation[​](#ci--cd-token-generation "Direct link to CI / CD token generation") ``` # Generate a token in your pipeline and use it to seed test data TOKEN=$(wp jwt login --username=admin --password="$WP_ADMIN_PASSWORD") curl -s -X POST https://my-site.com/wp-json/wp/v2/posts \ -H "Authorization: Bearer $TOKEN" \ -H "Content-Type: application/json" \ -d '{"title":"Hello World","status":"publish"}' ``` ### Staging-to-production config migration[​](#staging-to-production-config-migration "Direct link to Staging-to-production config migration") ``` # 1. Export from staging wp jwt config export --file=jwt-staging.json --url=https://staging.example.com # 2. Review the diff on production wp jwt config import jwt-staging.json --dry-run --url=https://example.com # 3. Apply wp jwt config import jwt-staging.json --yes --url=https://example.com ``` ### Automated token health check[​](#automated-token-health-check "Direct link to Automated token health check") ``` TOKEN=$(wp jwt login --username=healthcheck --password="$HC_PASSWORD") STATUS=$(wp jwt validate "$TOKEN" --format=json | jq -r '.valid') [ "$STATUS" = "true" ] && echo "JWT OK" || echo "JWT FAILED" ``` *** ## Troubleshooting[​](#troubleshooting "Direct link to Troubleshooting") | Error | Cause | Fix | | --------------------------------- | ---------------------------------------- | ------------------------------------------------------------------------ | | `Authentication is not enabled.` | Authentication section disabled | `wp jwt config set allow_authentication 1` | | `Wrong user credentials.` | Incorrect username/email or password | Verify your credentials | | `Could not decode token…` | Token is not a valid JWT | Check you are passing the full three-part token | | `Token is valid. / valid: false` | `wp jwt validate` reports invalid | The `message` field explains why (expired, bad signature, etc.) | | `Token has already been revoked.` | Revoking an already-revoked token | No action needed - it was already blocked | | `Setting "" not found.` | No stored value for that key | Setting uses plugin default; use `config set` to store an explicit value | | `Invalid JSON value: …` | Malformed JSON passed with `--type=json` | Validate with `jq . <<< "$VALUE"` before passing | | `Cannot read file: ` | File does not exist or is unreadable | Check the path and file permissions | | Plugin auto-deactivated | Simple JWT Login is not active | Install and activate Simple JWT Login first | *** ## Contributing[​](#contributing "Direct link to Contributing") Contributions are welcome! Open an issue on [GitHub](https://github.com/simple-jwt-login/simple-jwt-login-cli) before submitting a pull request. ``` # Clone the repository git clone https://github.com/simple-jwt-login/simple-jwt-login-cli.git cd simple-jwt-login-cli # Install dependencies composer install # Run unit tests (no Docker required) composer tests # Run the full quality suite composer run check-plugin ``` See the [README](https://github.com/simple-jwt-login/simple-jwt-login-cli) for more information. --- # Register a WordPress user with PHP and get the jwt ## Introduction[​](#introduction "Direct link to Introduction") This example walks through a complete PHP integration with Simple-JWT-Login: registering a new WordPress user, obtaining a JWT for that user, and using the token to create a WordPress post via the REST API. It covers the three most common steps in a headless WordPress workflow: 1. **Register** - create a new user account 2. **Authenticate** - exchange credentials for a JWT 3. **Use the JWT** - call a protected endpoint For this example, we can create a helper function, that will do the actual call: ``` "test". random_int(0, 10000). "@localhost.com", "password" => "my secret password", "first_name" => "my firstname", "last_name" => "my last name", ); try{ // Step 1: Register User $result = call("POST", $domain . "?rest_route=/simple-jwt-login/v1/users", $data, $headers); $responseJSON = json_decode($result, true); if ($responseJSON === false) { throw new \Exception("Response is not a JSON:", $result); } // In case of error, success will be false if (!$responseJSON['success']) { throw new \Exception($responseJSON['data']['message']); } $userID = $responseJSON['id']; echo "Your new user ID is: " . $userID . PHP_EOL; } catch (\Exception $exception) { // Unable to do the call echo "Error while registering the user: ". $exception->getMessage() . PHP_EOL; } ``` ## Step 2: Obtain a JWT[​](#step-2-obtain-a-jwt "Direct link to Step 2: Obtain a JWT") note Please note that, in order to use the Authentication endpoint, you need have "Allow Authentication: yes" in the plugin settings. ``` "test@localhost.com", "password" => "my secret password", ); try{ $result = call("POST", $domain . "?rest_route=/simple-jwt-login/v1/auth", $data, $headers); $responseJSON = json_decode($result, true); if ($responseJSON === false) { throw new \Exception("Auth response is not a JSON:", $result); } // In case of error, success will be false if (!isset($responseJSON['success']) || !$responseJSON['success']) { $error = isset($responseJSON['data']['message']) ? $responseJSON['data']['message'] : "Error while getting the JWT"; throw new \Exception($error); } if (!isset($responseJSON['data']['jwt'])) { throw new \Exception("The JWT is missing from API Response."); } // Your new JWT that you can use in other endpoints $jwt = $responseJSON['data']['jwt']; echo "Your new token is: ". $jwt; }catch (\Exception $exception) { echo "Error while trying to get the token: ". $exception->getMessage(). PHP_EOL; } ``` ## Step 3: Use the JWT to create a WordPress post[​](#step-3-use-the-jwt-to-create-a-wordpress-post "Direct link to Step 3: Use the JWT to create a WordPress post") note In order to use the JWT on all endpoint, you need to enable "All WordPress endpoints checks for JWT authentication" from the plugin General Settings. In this example, we will create a new WordPress post: ``` "Post Title", "excerpt" => "test", ); try { $result = call("POST", $domain . "?rest_route=/wp/v2/posts", $data, $headers); $responseJSON = json_decode($result, true); // Final Step: Post create response echo "Post create Response: " . print_r($responseJSON, true) . PHP_EOL; } catch (\Exception $exception){ echo "Unable to create post:" . $exception->getMessage(); } ``` ## Full example[​](#full-example "Direct link to Full example") The script below combines all three steps: register, authenticate, and create a post. ``` "test". random_int(0, 10000). "@localhost.com", "password" => "my secret password", "first_name" => "my firstname", "last_name" => "my last name", ); try { // Step 1: Register User $result = call("POST", $domain . "?rest_route=/simple-jwt-login/v1/users", $data, $headers); $responseJSON = json_decode($result, true); if ($responseJSON === false) { throw new \Exception("Response is not a JSON:", $result); } // In case of error, success will be false if (!$responseJSON['success']) { throw new \Exception($responseJSON['data']['message']); } $userID = $responseJSON['id']; // Step 2: Get a JWT $result = call("POST", $domain . "?rest_route=/simple-jwt-login/v1/auth", $data, $headers); $responseJSON = json_decode($result, true); if ($responseJSON === false) { throw new \Exception("Auth response is not a JSON:", $result); } // In case of error, success will be false if (!isset($responseJSON['success']) || !$responseJSON['success']) { $error = isset($responseJSON['data']['message']) ? $responseJSON['data']['message'] : "Error while getting the JWT"; throw new \Exception($error); } if (!isset($responseJSON['data']['jwt'])) { throw new \Exception("The JWT is missing from API Response."); } // Your new JWT that you can use in other endpoints $jwt = $responseJSON['data']['jwt']; // Step 3: Create a new WordPress post $headers = array( "Content-type: application/json", "Authorization: " . $jwt ); $data = array( "title" => "Post Title", "excerpt" => "test", ); $result = call("POST", $domain . "?rest_route=/wp/v2/posts", $data, $headers); $responseJSON = json_decode($result, true); // Final Step: Post have been created echo "Post have been created: " . print_r($responseJSON, true) . PHP_EOL; } catch (\Exception $exception) { echo "There was an error: " . $exception->getMessage() . PHP_EOL; } ``` --- # Code Examples Welcome to our Code Examples page, dedicated to unraveling the simplicity and power of Simple-JWT-Login. As we delve into the intricacies of this authentication solution, our goal is to provide you with clear and concise code snippets. Whether you're a seasoned developer or just starting your journey, these examples will guide you through the seamless integration of WordPress into your applications. Let's start this journey! --- # Configuration ## Server[​](#server "Direct link to Server") The Simple-JWT-Login REST API is accessible via two URL formats. Both are equivalent - choose the one that fits your WordPress permalink configuration: * **Pretty permalinks** (recommended): ``` https://{domain}/wp-json/simple-jwt-login/v1/{endpoint} ``` * **Query-string format** (works even without pretty permalinks): ``` https://{domain}/?rest_route=/simple-jwt-login/v1/{endpoint} ``` ## Request Parameters[​](#request-parameters "Direct link to Request Parameters") Parameters can be sent in any of the following ways: * **JSON request body** (recommended for POST/PUT/DELETE requests) * **Query string** (convenient for GET requests and quick testing) * **Form data** (`application/x-www-form-urlencoded`) ### Examples[​](#examples "Direct link to Examples") #### Sending JWT in header:[​](#sending-jwt-in-header "Direct link to Sending JWT in header:") ``` curl -X POST "http://localhost/wp/v2/users" -H "Authorization: YOUR_JWT" ``` #### Sending JWT as query parameters:[​](#sending-jwt-as-query-parameters "Direct link to Sending JWT as query parameters:") ``` curl -X POST "http://localhost/wp/v2/users?jwt=YOUR_JWT" ``` or ``` curl -X POST "http://localhost?rest_route=/wp/v2/users&jwt=YOUR_JWT" ``` #### Sending JWT as request body:[​](#sending-jwt-as-request-body "Direct link to Sending JWT as request body:") ``` curl -X POST "http://localhost/wp/v2/users" -H "Content-type: application/json" -d '{"JWT":"JYOUR JWT"}' ``` ## Initial Configuration[​](#initial-configuration "Direct link to Initial Configuration") 1. Go to **Settings → Simple JWT Login → General**. 2. Set a **JWT Decryption key** - this secret is used to sign and verify all tokens. 3. Choose a **JWT Decryption algorithm** (e.g., `HS256`). 4. Click **Save Changes**. caution Use a long, random string for the JWT Decryption key and include special characters. This key is equivalent to a master password - anyone who knows it can forge valid tokens. ## Where to send the JWT[​](#where-to-send-the-jwt "Direct link to Where to send the JWT") By default, the plugin looks for the JWT in the **request parameters** (query string or body). You can also enable additional sources: | Source | How to send the JWT | | ----------------------- | ------------------------------------------------ | | **REQUEST** *(default)* | Query param: `?JWT=your_jwt` or body field `JWT` | | **SESSION** | `$_SESSION['simple-jwt-login-token']` | | **COOKIE** | `$_COOKIE['simple-jwt-login-token']` | | **HEADER** | `Authorization: Bearer YOUR_JWT_HERE` | When a JWT is present in multiple locations, the source with the highest priority wins (HEADER > COOKIE > SESSION > REQUEST). note The recommended approach is to enable **HEADER** and always send the JWT as a `Bearer` token in the `Authorization` header. This is the most widely supported pattern and avoids tokens appearing in server logs. ## Allow JWT usage on all WordPress endpoints[​](#allow-jwt-usage-on-all-wordpress-endpoints "Direct link to Allow JWT usage on all WordPress endpoints") Enable **”All WordPress endpoints check for JWT authentication”** in the General settings to use JWT authentication on any WordPress REST route - not just the Simple-JWT-Login ones. When a JWT is found, the plugin first authenticates the request as the user identified by the token, then passes the request to WordPress. This lets you, for example, create posts or access protected data as a specific user. ``` curl -X POST "https://simplejwtlogin.com/wp-json/wp/v2/posts?content=PostContent&title=PostTitle" \ -H "Content-type: application/json" \ -d '{"JWT":"YOUR_JWT_HERE"}' ``` or ``` curl -X POST "https://simplejwtlogin.com/wp-json/wp/v2/posts" \ -H "Authorization: Bearer YOUR_JWT_HERE" \ --form title="Title" \ --form content="My content" \ --form type="page" ``` For the second example, you need to make sure that you allow search for JWT in the header( you can set this in: **General** settings -> **Get JWT token from** ) note When you pass the `JWT` parameter, it is not case-sensitive. You can also pass it as `jwt`. ## General settings screenshot[​](#general-settings-screenshot "Direct link to General settings screenshot") ![General settings screen for Simple JWT Login v3.0.0](/assets/images/screenshot-2-0a776cb1d186be450e8a74ae9daa6528.png) --- # CORS Simple-JWT-Login includes built-in Cross-Origin Resource Sharing (CORS) support, implemented in compliance with the [W3C CORS specification](https://www.w3.org/TR/cors/). CORS controls which external origins (domains, ports, protocols) are permitted to call the plugin's REST endpoints from a browser. Without CORS headers, browsers block cross-origin requests for security reasons. ## What the plugin does[​](#what-the-plugin-does "Direct link to What the plugin does") When CORS is enabled, the plugin adds a wildcard `Access-Control-Allow-Origin: *` header to all responses from its endpoints. This makes the endpoints publicly accessible from any origin, including front-end JavaScript running on a different domain than your WordPress site. This is the recommended configuration for: * **Headless WordPress** sites where the front-end lives on a separate domain * **Single-page applications (SPA)** built with React, Vue, Angular, etc. * **Mobile apps** using a WebView or HTTP client that enforces CORS ## When to be cautious[​](#when-to-be-cautious "Direct link to When to be cautious") A wildcard CORS policy is intentionally permissive. Because Simple-JWT-Login endpoints are protected by JWT authentication (and optionally by Auth Codes and IP restrictions), this is generally safe. However, if your site exposes sensitive unauthenticated endpoints, consider restricting access at the web server or firewall level in addition to using CORS. ## Screenshot[​](#screenshot "Direct link to Screenshot") ![CORS settings screen for Simple JWT Login v3.0.0](/assets/images/screenshot-10-1d0815ae2bcbfdef5b9deac92c291a0a.png) --- # Delete WordPress User The Delete User endpoint allows you to remove a WordPress user account via a REST API call authenticated with a JWT. This is useful for self-service account deletion flows in mobile apps or headless front-ends. Deletion is **disabled by default**. Enable it in the plugin settings before use. The plugin identifies which user to delete from the JWT payload. You can configure it to look for either: * **WordPress User ID** - the numeric user ID stored in the JWT * **Email address** - the user's email address stored in the JWT Configure the JWT payload key to use in the plugin settings under the **Delete User** tab. ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD** : `DELETE` **ENDPOINT** : `/simple-jwt-login/v1/users` **URL Example** : `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/users&JWT={{JWT}}&AUTH_KEY={{AUTH_KEY_VALUE}}` **PARAMETERS**: | Parameter | Type | Description | | ---------- | ------------------- | ------------------------------------------------------------------------------------------------------ | | JWT | `required` `string` | Your JWT | | AUTH\_CODE | `optional` `string` | Auth Code from the "Auth codes" section. Required only if "Delete User Requires Auth Code" is enabled. | ## Request[​](#request "Direct link to Request") ``` { "JWT": "YOUR_JWT_HERE", "AUTH_CODE" : "SUPER_SECRET_AUTH_CODE" } ``` ## Response[​](#response "Direct link to Response") ### 200[​](#200 "Direct link to 200") ``` { "message": "User was successfully deleted.", "id": 1 } ``` ### 400[​](#400 "Direct link to 400") ``` { "success": false, "error" : "Error message" } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X DELETE https://simplejwtlogin.com/simple-jwt-login/v1/users \ -H "Content-type: application/json" -d '{"JWT":"YOUR_JWT","AUTH_CODE":"SECRET_AUTH_CODE"}' ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJWT = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login-v1' ); $simpleJWT->delete('Your JWT'); ``` ### JavaScript[​](#javascript "Direct link to JavaScript") ``` var data = JSON.stringify({ "JWT":"YOUR_JWT", "AUTH_CODE":"SECRET_AUTH_CODE" }); var xhr = new XMLHttpRequest(); xhr.withCredentials = true; xhr.addEventListener("readystatechange", function() { if(this.readyState === 4) { console.log(this.responseText); } }); xhr.open("DELETE", "https://simplejwtlogin.com" + "/simple-jwt-login/v1/users"); xhr.setRequestHeader("Content-Type", "application/json"); xhr.send(data); ``` ## Screenshot[​](#screenshot "Direct link to Screenshot") ![Delete user API settings screen for Simple JWT Login v3.0.0](/assets/images/screenshot-5-b59369cd9f0ea7c27ff3992f41b7b8bd.png) ## Features[​](#features "Direct link to Features") ### Limit by IP address[​](#limit-by-ip-address "Direct link to Limit by IP address") You can limit the deletion of users to specific IP addresses for security reasons. You can set multiple IP addresses, separated by commas. Example: ``` 127.0.0.1, 123.123.123.123 ``` --- # Error codes Every error response from Simple-JWT-Login includes a numeric `errorCode` field. Use the table below to look up the meaning of a specific code and how to resolve it. Error responses follow this format: ``` { "success": false, "data": { "message": "Human-readable error message", "errorCode": 48 } } ``` | Error Code | Message | Description | | ---------- | -------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ | | 1 | Key may not be empty | JWT is missing from request | | 2 | Wrong number of segments | The JWT contains 3 parts, separated by dots(Header, Payload, Signature). So, your JWT does not have 2 dots in it. | | 3 | Invalid header encoding | The encoding of the first part of the JWT, is invalid. This means, that the first part of your JWT is incorrect. | | 4 | Invalid claims encoding | The second part of your JWT is invalid. | | 5 | Invalid signature encoding | The signature that you provided in "JWT Decryption key" is invalid. | | 6 | Empty algorithm | This means, that your JWT has no algorithm specified. | | 7 | Algorithm not supported | The algorithm present in your JWT, is not supported by this plugin. | | 8 | Algorithm not allowed | The provided algorithm is not allowed by this plugin. | | 9 | 'kid' invalid, unable to lookup correct key | Your JWT is malformed. | | 10 | 'kid' invalid, unable to lookup correct key | Your JWT is malformed. | | 11 | Signature verification failed | Invalid "JWT Decryption key" provided in config. | | 12 | Cannot handle token prior to ... | Check that this token has been created before 'now'. Timestamp verified from 'nbf'. | | 13 | Cannot handle token prior to ... | Check that this token has been created before 'now'. This prevents. Timestamp verified from 'iat'. | | 14 | Expired token | JWT is expired. | | 15 | Algorithm not supported | Algorithm not supported when JWT was signed. | | 16 | OpenSSL unable to sign data | Error while JWT is signed with OpenSSL. | | 17 | Unsupported sign function | Invalid Algorithm provided for JWT when signing | | 18 | Algorithm not supported | Invalid Algorithm while trying to verify the JWT | | 19 | OpenSSL error | This is a generic OpenSSL error. | | 20 | Null result with non-null input | Decoded JWT is null. | | 21 | Null result with non-null input | Encoded JWT is null | | 22 | Unknown JSON error | This is a generic error by JWT. More details are provided in the message. | | 23 | Wrong Request. | JWT is missing in the auto-login process. | | 24 | User not found. | This error occurs when the user is not found. For login and delete endpoint: there is no user in WordPress with the email or ID provided in JWT. | | 26 | Auto-login is not enabled on this website. | You have to enable auto-login from plugin settings. | | 27 | Invalid Auth Code provided. | The Auth code provided is invalid or missing. You should use one that you have saved in your plugin settings | | 28 | This IP is not allowed to auto-login. | You can not auto-login from this IP. Some IP's are specified in plugin settings that can auto-login into WordPress | | 29 | Unable to find property in JWT. | The user sub-key property can not be found in JWT | | 30 | Unable to find property in JWT. | The user key property can not be found in JWT | | 31 | Register is not allowed. | Register is disabled from settings | | 32 | Invalid Auth Code | Invalid auth code provided on register endpoint. You can use auth codes that are generated in your plugin settings. | | 33 | This IP is not allowed to register users. | You can not register users from this IP. The allowed IPs are saved in plugin settings | | 35 | Missing email or password. | Missing email or password from your register new user request | | 36 | Invalid email address. | The value provided for email is not a valid email. | | 37 | This website does not allow users from this domain. | The email domain is not allowed to register to this WordPress. The allowed domains are saved in plugin settings. | | 38 | User already exists. | The user that you are trying to create already exists. Try a different email address. | | 39 | Delete is not enabled. | The plugin delete endpoint is not enabled for this website. This can be enabled from plugin settings. | | 40 | Missing AUTH KEY | Missing Auth Key from Delete. You can find your generated auth keys in plugin settings. | | 41 | You are not allowed to delete users from this IP | You can not delete users only from the IPs that are set in plugin settings. | | 42 | The 'jwt' parameter is missing. | The JWT parameter is missing from the request. | | 43 | Invalid method for this route. | The route that you are calling does not exist. | | 44 | Invalid route name. | Route name is invalid. | | 45 | Authentication is not enabled. | Authentication enabled is set to "No" in the plugin settings. | | 46 | Authentication missing email. | Your request does not contain the email address. | | 47 | Authentication missing password. | Password is missing from the request. | | 48 | Authentication wrong credentials | Email or password is incorrect. | | 49 | JWT payload is not correct. | Check your JWT payload. After decoding it, it resulted null. it should be an JSON. | | 50 | JWT is too old to be refreshed. | The JWT generated time is too old. You can not refresh this token. | | 51 | JWT is missing from /auth/refresh | The JWT parameter was not sent to the /auth/refresh endpoint. | | 52 | Unable to create user. | There was an error while trying to create the user. | | 53 | The `jwt` parameter is missing. | The JWT is missing from reset password, revoke token or validate user | | 54 | WordPress user not found | Unable to find a valid user in the provided JWT. | | 55 | This JWT is invalid. | The JWT has been revoked. It can not be used anymore. | | 56 | Reset Password is not allowed. | The Reset Password endpoint is disabled. | | 57 | Route called with invalid request method. | The Reset Password endpoint is called with an invalid HTTP method. Only PUT and POST are allowed. | | 58 | Invalid Auth Code ( %s ) provided. | The Reset Password endpoint is called with an invalid AUTH CODE. | | 59 | Missing email parameter. | Missing or empty `email` parameter when calling the Reset Password endpoint. | | 60 | Missing code parameter. | Missing `code` parameter when calling change user password endpoint. | | 61 | Missing new\_password parameter. | Missing `new_password` when calling the change user password endpoint | | 62 | Invalid code provided. | The `code` and `user_email` does not match when calling the Reset Password endpoint. | | 63 | Missing email parameter. | Missing `email` parameter when calling the Send reset password endpoint. | | 64 | Wrong user. | User was not found while calling the Send reset password endpoint. | | 65 | Invalid flow type. | Invalid plugin settings for Reset password flow. | | 66 | You need to add the {{CODE}} variable in email body. | The `{{CODE}}` parameter is missing from Reset Password email body. | | 67 | Something is wrong. We can not save the settings. | Something is wrong with the plugin configuration. The `_wpnonce` field is missing or it is invalid. | | 68 | 'The JWT issuer(iss) is not allowed to auto-login. | The JWT is issued by an authorized issuer. | | 69 | The Oauth provider is invalid. | Invalid `provider` parameter provided. | | 70 | This Oauth provider is not available. | OAuth provided is not enabled or unavailable. | | 71 | The code or id\_token parameter is missing from request. | The code or `id_token` parameter is missing from request when connecting with Google OAuth. | | 72 | The code you provided is invalid. | The Google OAuth endpoint has received an invalid `code`. | | 73 | The provided id\_token is invalid | The Google OAuth endpoint has received an invalid `id_token`. | | 74 | Wrong user credentials. | The Google OAuth could not find a user in the provided JWT. | --- # Simple-JWT-Login Export-Import Add-on The Export-Import add-on lets you copy your Simple-JWT-Login configuration - including Auth Codes, protection rules, and all general settings - from one WordPress site to another in just a few steps. This is especially useful when setting up staging environments, migrating sites, or replicating a configuration across a network of sites. [Download](https://github.com/simple-jwt-login/export-import/archive/refs/heads/master.zip) ## Installation[​](#installation "Direct link to Installation") 1. Download the add-on from 2. Upload the zip file into your WordPress 3. Activate the plugin 4. Export or import data ## Screenshots[​](#screenshots "Direct link to Screenshots") ### Configuration[​](#configuration "Direct link to Configuration") ![Export Import add-on configuration screen for Simple JWT Login](https://github.com/simple-jwt-login/export-import/raw/master/wordpress.org/screenshot-1.png?raw=true) ## How to transfer settings[​](#how-to-transfer-settings "Direct link to How to transfer settings") **On the source site:** 1. Go to the Simple-JWT-Login settings page. 2. Click **Export** to generate a configuration snapshot. 3. Copy the generated code. **On the destination site:** 1. Install and activate both Simple-JWT-Login and the Export-Import add-on. 2. Go to the Simple-JWT-Login settings page. 3. Paste the copied code into the import field. 4. Click **Import** and confirm the prompt. The destination site will now have the same configuration as the source. --- # Hooks Simple JWT Login exposes **16 WordPress action and filter hooks** that let you extend or customize the plugin's behaviour without modifying its source code. Use them to enrich JWT payloads, send notifications, apply business logic, gate requests, or build fully custom flows on top of the plugin. Enable hooks first Hooks must be enabled individually in the plugin settings before they fire. **All hooks are disabled by default.** ## Quick Reference[​](#quick-reference "Direct link to Quick Reference") | Hook | Type | Triggered | | ----------------------------------------------------------------------------------------------------------------- | ------ | --------------------------------------------------- | | [`simple_jwt_login_before_endpoint`](#simple_jwt_login_before_endpoint) | action | Before any endpoint is processed | | [`simple_jwt_login_login_hook`](#simple_jwt_login_login_hook) | action | After a user logs in | | [`simple_jwt_login_redirect_hook`](#simple_jwt_login_redirect_hook) | action | Before the post-login redirect | | [`simple_jwt_login_register_hook`](#simple_jwt_login_register_hook) | action | After a new user is created | | [`simple_jwt_login_delete_user_hook`](#simple_jwt_login_delete_user_hook) | action | After a user is deleted | | [`simple_jwt_login_jwt_payload_auth`](#simple_jwt_login_jwt_payload_auth) | filter | Before the JWT is signed on `/auth` | | [`simple_jwt_login_no_redirect_message`](#simple_jwt_login_no_redirect_message) | filter | Before the no-redirect response on `/autologin` | | [`simple_jwt_login_reset_password_custom_email_template`](#simple_jwt_login_reset_password_custom_email_template) | filter | Before the reset-password email is sent | | [`simple_jwt_login_response_auth_user`](#simple_jwt_login_response_auth_user) | filter | Before the `/auth` response is returned | | [`simple_jwt_login_response_register_user`](#simple_jwt_login_response_register_user) | filter | Before the register response is returned | | [`simple_jwt_login_response_delete_user`](#simple_jwt_login_response_delete_user) | filter | Before the delete-user response is returned | | [`simple_jwt_login_response_refresh_token`](#simple_jwt_login_response_refresh_token) | filter | Before the refresh-token response is returned | | [`simple_jwt_login_response_send_reset_password`](#simple_jwt_login_response_send_reset_password) | filter | Before the send-reset-password response is returned | | [`simple_jwt_login_response_change_user_password`](#simple_jwt_login_response_change_user_password) | filter | Before the change-password response is returned | | [`simple_jwt_login_response_revoke_token`](#simple_jwt_login_response_revoke_token) | filter | Before the revoke-token response is returned | | [`simple_jwt_login_response_validate_token`](#simple_jwt_login_response_validate_token) | filter | Before the validate-token response is returned | *** ## Action Hooks[​](#action-hooks "Direct link to Action Hooks") Action hooks let you run side-effect code at a specific point in the request lifecycle. They do not return a value. ### `simple_jwt_login_before_endpoint`[​](#simple_jwt_login_before_endpoint "Direct link to simple_jwt_login_before_endpoint") Fires before a Simple JWT Login REST route is processed. Use it to validate requests, block specific callers, enforce policies (e.g. minimum password length), or log activity - for any endpoint. | Parameter | Type | Description | | ----------- | -------- | ---------------------------------- | | `$method` | `string` | HTTP method (`GET`, `POST`, …) | | `$endpoint` | `string` | Endpoint name (`auth`, `users`, …) | | `$request` | `array` | Full request parameters | Throw an `Exception` to abort the request with an error response. *** ### `simple_jwt_login_login_hook`[​](#simple_jwt_login_login_hook "Direct link to simple_jwt_login_login_hook") Fires after a user has been successfully authenticated and logged in. | Parameter | Type | Description | | --------- | --------- | ---------------------- | | `$user` | `WP_User` | The authenticated user | *** ### `simple_jwt_login_redirect_hook`[​](#simple_jwt_login_redirect_hook "Direct link to simple_jwt_login_redirect_hook") Fires before the user is redirected to the URL configured in the Login settings. Use it to implement dynamic redirect logic based on request parameters. | Parameter | Type | Description | | ---------- | -------- | --------------------------- | | `$url` | `string` | The configured redirect URL | | `$request` | `array` | Full request parameters | tip Enable **"Include request parameters in the redirect URL"** in Login settings to forward custom query parameters (e.g. `&page=dashboard`) that your hook can read. *** ### `simple_jwt_login_register_hook`[​](#simple_jwt_login_register_hook "Direct link to simple_jwt_login_register_hook") Fires after a new user has been created via the register endpoint. | Parameter | Type | Description | | ---------------------- | --------- | ---------------------------------------------------------------- | | `$user` | `WP_User` | The newly created user | | `$plain_text_password` | `string` | The user's plain-text password (available only at creation time) | *** ### `simple_jwt_login_delete_user_hook`[​](#simple_jwt_login_delete_user_hook "Direct link to simple_jwt_login_delete_user_hook") Fires immediately after a user has been deleted. | Parameter | Type | Description | | --------- | --------- | ---------------- | | `$user` | `WP_User` | The deleted user | *** ## Filter Hooks[​](#filter-hooks "Direct link to Filter Hooks") Filter hooks let you inspect and modify data before it is used or returned. Always return the (modified) value. ### `simple_jwt_login_jwt_payload_auth`[​](#simple_jwt_login_jwt_payload_auth "Direct link to simple_jwt_login_jwt_payload_auth") Fires on the `/auth` endpoint before the JWT is signed. Use it to add custom claims to the token. | Parameter | Type | Description | | ---------- | ------- | ----------------------------------- | | `$payload` | `array` | The JWT payload (modify and return) | | `$request` | `array` | Full request parameters | **Returns:** `array` - the modified payload. *** ### `simple_jwt_login_no_redirect_message`[​](#simple_jwt_login_no_redirect_message "Direct link to simple_jwt_login_no_redirect_message") Fires on the `/autologin` endpoint when **No Redirect** is selected. Use it to customize the JSON response returned to the client. | Parameter | Type | Description | | ---------- | ------- | ---------------------------------------- | | `$payload` | `array` | The response payload (modify and return) | | `$request` | `array` | Full request parameters | **Returns:** `array` - the modified response payload. *** ### `simple_jwt_login_reset_password_custom_email_template`[​](#simple_jwt_login_reset_password_custom_email_template "Direct link to simple_jwt_login_reset_password_custom_email_template") Fires when `POST /user/reset_password` is called. Use it to replace the default email template set in Reset Password settings with a fully custom HTML email. | Parameter | Type | Description | | ----------- | -------- | -------------------------- | | `$template` | `string` | The current email template | | `$request` | `array` | Full request parameters | **Returns:** `string` - the custom email template. *** ### Response Filters[​](#response-filters "Direct link to Response Filters") The following 8 filters fire immediately before their respective endpoint returns a JSON response. Use them to add, remove, or transform fields in the API response. #### `simple_jwt_login_response_auth_user`[​](#simple_jwt_login_response_auth_user "Direct link to simple_jwt_login_response_auth_user") Fires before the `POST /auth` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_register_user`[​](#simple_jwt_login_response_register_user "Direct link to simple_jwt_login_response_register_user") Fires before the `POST /users` (register) response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_delete_user`[​](#simple_jwt_login_response_delete_user "Direct link to simple_jwt_login_response_delete_user") Fires before the `DELETE /users` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_refresh_token`[​](#simple_jwt_login_response_refresh_token "Direct link to simple_jwt_login_response_refresh_token") Fires before the `POST /auth/refresh` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_send_reset_password`[​](#simple_jwt_login_response_send_reset_password "Direct link to simple_jwt_login_response_send_reset_password") Fires before the `POST /user/reset_password` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_change_user_password`[​](#simple_jwt_login_response_change_user_password "Direct link to simple_jwt_login_response_change_user_password") Fires before the `PUT /user/reset_password` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_revoke_token`[​](#simple_jwt_login_response_revoke_token "Direct link to simple_jwt_login_response_revoke_token") Fires before the `DELETE /auth` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_validate_token`[​](#simple_jwt_login_response_validate_token "Direct link to simple_jwt_login_response_validate_token") Fires before the `GET /auth/validate` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** ## Settings Screenshot[​](#settings-screenshot "Direct link to Settings Screenshot") ![Hooks settings panel](/assets/images/screenshot-9-4234d27648d7f5679142893980b43eb0.png) *** ## Code Examples[​](#code-examples "Direct link to Code Examples") ### Add custom claims to the JWT payload[​](#add-custom-claims-to-the-jwt-payload "Direct link to Add custom claims to the JWT payload") Enrich the token with user metadata - roles, plan, tenant ID - so downstream services don't need a separate lookup. ``` add_filter('simple_jwt_login_jwt_payload_auth', function (array $payload, array $request): array { $user = get_user_by('email', $request['email'] ?? ''); if ($user) { $payload['roles'] = $user->roles; $payload['display_name'] = $user->display_name; } return $payload; }, 10, 2); ``` *** ### Send a welcome email after registration[​](#send-a-welcome-email-after-registration "Direct link to Send a welcome email after registration") ``` add_action('simple_jwt_login_register_hook', function (WP_User $user, string $password): void { wp_mail( $user->user_email, 'Welcome to My Site', sprintf( "Hi %s,\n\nYour account is ready.\n\nEmail: %s\nPassword: %s", $user->display_name, $user->user_email, $password ) ); }, 10, 2); ``` *** ### Dynamic redirect URLs after login[​](#dynamic-redirect-urls-after-login "Direct link to Dynamic redirect URLs after login") Enable **"Include request parameters in the redirect URL"** in Login settings, then add `&page=dashboard` (or any value) to the login URL. The hook reads it and redirects accordingly. ``` add_action('simple_jwt_login_redirect_hook', function (string $url, array $request): void { $page = $request['page'] ?? null; $destinations = [ 'dashboard' => 'https://mysite.com/dashboard', 'profile' => 'https://mysite.com/profile', ]; wp_redirect($destinations[$page] ?? $url); }, 10, 2); ``` *** ### Block a specific email address on `/auth`[​](#block-a-specific-email-address-on-auth "Direct link to block-a-specific-email-address-on-auth") ``` add_action('simple_jwt_login_before_endpoint', function (string $method, string $endpoint, array $request): void { if ($method !== 'POST' || $endpoint !== 'auth') { return; } $blocked = ['banned@example.com']; if (in_array($request['email'] ?? '', $blocked, true)) { throw new Exception('This account has been suspended.'); } }, 10, 3); ``` *** ### Enforce a minimum password length on registration[​](#enforce-a-minimum-password-length-on-registration "Direct link to Enforce a minimum password length on registration") ``` add_action('simple_jwt_login_before_endpoint', function (string $method, string $endpoint, array $request): void { if ($method !== 'POST' || $endpoint !== 'users') { return; } $minLength = 8; $password = $request['password'] ?? ''; if (strlen($password) < $minLength) { throw new Exception("Password must be at least {$minLength} characters."); } }, 10, 3); ``` *** ### Add extra fields to the auth response[​](#add-extra-fields-to-the-auth-response "Direct link to Add extra fields to the auth response") ``` add_filter('simple_jwt_login_response_auth_user', function (array $response, WP_User $user): array { $response['user_id'] = $user->ID; $response['display_name'] = $user->display_name; $response['avatar_url'] = get_avatar_url($user->ID); return $response; }, 10, 2); ``` --- # MailPoet The Simple-JWT-Login MailPoet add-on lets you embed personalized, one-click login links inside your MailPoet email campaigns. When a subscriber clicks the link, they are automatically logged into your WordPress site - no password entry required. The add-on generates a shortcode that you drop into your MailPoet email template. Each time an email is sent, the shortcode is rendered into a unique, time-limited autologin URL for that recipient. [Download](https://wordpress.org/plugins/simple-jwt-login-mailpoet) ## Shortcode parameters[​](#shortcode-parameters "Direct link to Shortcode parameters") | Parameter | Description | | ------------- | --------------------------------------------------------------------------------------------------------------------- | | `text` | The visible link text (e.g., `"Log in to your account"`) | | `class` | CSS class(es) to apply to the link element | | `style` | Inline CSS styles for the link | | `validity` | How long the generated JWT is valid, in seconds. Default: `604800` (one week) | | `authCode` | The Auth Code required by the Autologin endpoint. Find your codes under **Simple-JWT-Login → Auth Codes**. | | `redirectUrl` | Overrides the redirect URL set in Simple-JWT-Login settings. The user will be sent here after a successful autologin. | ``` [custom:simple-jwt-login text="Login" class="myClassName" style="color:red;" validity="604800" authCode="1" redirectUrl="https://simplejwtlogin.com"] ``` ## Installation[​](#installation "Direct link to Installation") 1. Download the add-on from 2. Activate the plugin 3. Generate a short-code 4. Insert the shortcode in your email templates ## Screenshots[​](#screenshots "Direct link to Screenshots") ### Configuration[​](#configuration "Direct link to Configuration") ![MailPoet add-on configuration screen for Simple JWT Login](https://ps.w.org/simple-jwt-login-mailpoet/assets/screenshot-1.png) ### Email Template[​](#email-template "Direct link to Email Template") ![MailPoet email template with Simple JWT Login autologin shortcode](https://ps.w.org/simple-jwt-login-mailpoet/assets/screenshot-2.png) ### Email preview[​](#email-preview "Direct link to Email preview") ![Preview of a MailPoet newsletter email with autologin link](https://ps.w.org/simple-jwt-login-mailpoet/assets/screenshot-3.png) --- # Protect Endpoints The Protect Endpoints feature lets you require a valid JWT for any WordPress REST API route. Use it to lock down sensitive data - such as user profiles, private posts, or custom post types - so they can only be accessed by authenticated callers. When a protected endpoint is called without a valid JWT, the plugin returns a `403` error immediately, before WordPress processes the request. The following error will be displayed, when an endpoint is protected and no JWT is provided: ``` { "success": false, "data": { "message": "You are not authorized to access this endpoint.", "errorCode": 403, "type": "simple-jwt-login-route-protect" } } ``` ## Screenshot[​](#screenshot "Direct link to Screenshot") ![Protect endpoints settings screen for Simple JWT Login v3.0.0](/assets/images/screenshot-11-f3ad94b06cd8eeaee8728355a6855af9.png) ## Protection Modes[​](#protection-modes "Direct link to Protection Modes") You can choose between two protection modes: * **Protect all endpoints** * **Protect only specific endpoints** ### 1. Protect All Endpoints[​](#1-protect-all-endpoints "Direct link to 1. Protect All Endpoints") When enabled, this option secures all endpoints except those explicitly listed in the "Whitelist." To exclude an endpoint from protection, add it to the whitelist using the "Add Endpoints +" button. ### 2. Protect Only Specific Endpoints[​](#2-protect-only-specific-endpoints "Direct link to 2. Protect Only Specific Endpoints") This option protects only the endpoints listed in the "Protect Endpoints" section. To secure an endpoint, add it using the "Add Endpoint" button. ## Configuration Options[​](#configuration-options "Direct link to Configuration Options") ### Request Methods[​](#request-methods "Direct link to Request Methods") For each endpoint, you can define which HTTP request methods (GET, POST, PUT, DELETE, etc.) require authentication. Alternatively, selecting ALL will enforce the rule for every request method. ### Route Matching[​](#route-matching "Direct link to Route Matching") There are two ways to define how an endpoint is matched: * **Starts with**: The rule applies to any endpoint that begins with the specified path. * **Exact match**: The rule applies only if the accessed endpoint exactly matches the specified path. ### Example Configurations[​](#example-configurations "Direct link to Example Configurations") #### Example 1[​](#example-1 "Direct link to Example 1") Assume you specify `/wp/v2/users` with `ALL` and `Exact Match` in either the Protect or Whitelist settings. The rule applies to these URLs: * `http://yoursite.com/?rest_route=/wp/v2/users` * `http://yoursite.com/wp-json/wp/v2/users` #### Example 2[​](#example-2 "Direct link to Example 2") Assume you specify `/wp/v2/users` with `GET` and `Starts With` in either the Protect or Whitelist settings. The rule applies to these URLs when called with `GET` only: * `http://yoursite.com/?rest_route=/wp/v2/users` * `http://yoursite.com/?rest_route=/wp/v2/users/1` * `http://yoursite.com/wp-json/wp/v2/users` * `http://yoursite.com/wp-json/wp/v2/users/1` * `http://yoursite.com/wp-json/wp/v2/users/{any_other_path}` #### Example 3[​](#example-3 "Direct link to Example 3") Assume you specify `/wp/v2` with `ALL` and `Starts With` in either the `Apply only on Specific Endpoints`. This way, you are making all the endpoints under `/wp/v2*` protected and they will be accessible only with a JWT. For example, all these endpoints will be protected: * `/wp/v2/users` * `/wp/v2/posts` * `/wp/v2/comments` ## How to Pass the JWT[​](#how-to-pass-the-jwt "Direct link to How to Pass the JWT") The JWT token can be provided in multiple ways, depending on the options set in the plugin’s General settings: * Header * Request URI * Request Body * Session * Cookie ### Examples[​](#examples "Direct link to Examples") #### Sending JWT in header:[​](#sending-jwt-in-header "Direct link to Sending JWT in header:") ``` curl -X POST "http://localhost/wp/v2/users" -H "Authorization: YOUR_JWT" ``` #### Sending JWT as query parameters:[​](#sending-jwt-as-query-parameters "Direct link to Sending JWT as query parameters:") ``` curl -X POST "http://localhost/wp/v2/users?jwt=YOUR_JWT" ``` or ``` curl -X POST "http://localhost?rest_route=/wp/v2/users&jwt=YOUR_JWT" ``` #### Sending JWT as request body:[​](#sending-jwt-as-request-body "Direct link to Sending JWT as request body:") ``` curl -X POST "http://localhost/wp/v2/users" -H "Content-type: application/json" -d '{"JWT":"JYOUR JWT"}' ``` By following these instructions, you can efficiently protect and manage API access using Simple JWT Login. --- # Refresh token Use this endpoint to exchange an expired (or about-to-expire) JWT for a fresh one, without requiring the user to re-enter their credentials. This is the standard mechanism for keeping long-running sessions alive. note A token can only be refreshed within a configurable time window after it was originally issued. Once that window expires, the user must authenticate again with their credentials. **METHOD** : `POST` **ENDPOINT**: `/simple-jwt-login/v1/auth/refresh` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/auth/refresh&JWT={{YOUR_JWT}}` **PARAMETERS**: | Parameter | Type | Description | | ---------- | ------------------- | -------------------------------------------------------------------------------------------------------------------- | | JWT | `required` `string` | Your JWT | | AUTH\_CODE | `optional` `string` | Auth Code from the "Auth codes" section. Required only if the "Authentication Requires Auth Code" option is enabled. | ## Request[​](#request "Direct link to Request") ``` { "JWT" : "YOUR_JWT_HERE", "AUTH_CODE": "MySecretAuthCode" } ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "data": { "jwt": "NEW_GENERATED_JWT_HERE" } } ``` ### 400[​](#400 "Direct link to 400") ``` { "success": false, "error" : "Error message" } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/auth/refresh \ -H "Content-type: application/json" \ -d '{"JWT":"YOUR_EXPIRED_JWT"}' ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->refreshToken('your JWT here', 'AUTH CODE'); ``` ## Screenshot[​](#screenshot "Direct link to Screenshot") ![Refresh token API settings screen for Simple JWT Login v3.0.0](/assets/images/screenshot-7-2f338df0aa647954e348da088f33fb87.png) ## Features[​](#features "Direct link to Features") ### Refresh time to live[​](#refresh-time-to-live "Direct link to Refresh time to live") The **Refresh TTL** controls how long (in minutes) after the original token was issued a refresh is permitted. After that window closes, the user must authenticate again using their credentials. The default value is **2 weeks** (20,160 minutes). Adjust it in the plugin settings to match your application's security requirements. --- # Register User ## Description[​](#description "Direct link to Description") The Register User endpoint lets you create new WordPress users programmatically via the REST API. This is useful for headless registration forms, mobile app sign-ups, or any external system that needs to provision WordPress accounts without going through the standard WordPress UI. Registration is **disabled by default**. Enable it in the plugin settings before use. At minimum, a POST request with `email` and `password` is all that's needed. Additional profile fields are optional. ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `POST` **ENDPOINT**: `/simple-jwt-login/v1/users` **URL Example**: `https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/users&email=NEW_USER_EMAIL&password=NEW_USER_PASSWORD` **PARAMETERS**: | Parameter | Type | Description | | ----------------------- | -------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- | | email | `required` `string` | The user email address. | | password | `required` `string` | The plain-text user password. | | user\_login | `optional` `string` | The user’s login username. | | user\_nicename | `optional` `string` | The URL-friendly username. | | user\_url | `optional` `string` | The user URL. | | display\_name | `optional` `string` | The user’s display name. Default is the user’s username. | | nickname | `optional` `string` | The user’s nickname. Default is the user’s username. | | first\_name | `optional` `string` | The user’s first name. For new users, will be used to build the first part of the user’s display name if $display\_name is not specified. | | last\_name | `optional` `string` | The user’s last name. For new users, will be used to build the second part of the user’s display name if $display\_name is not specified. | | description | `optional` `string` | The user’s biographical description. | | rich\_editing | `optional` `string` | Whether to enable the rich-editor for the user. Accepts ‘true’ or ‘false’ as a string literal, not boolean. Default ‘true’. | | syntax\_highlighting | `optional` `string` | Whether to enable the rich code editor for the user. Accepts ‘true’ or ‘false’ as a string literal, not boolean. Default ‘true’. | | comment\_shortcuts | `optional` `string` | Whether to enable comment moderation keyboard shortcuts for the user. Accepts ‘true’ or ‘false’ as a string literal, not boolean. Default ‘false’. | | admin\_color | `optional` `string` | Admin color scheme for the user. Default ‘fresh’. | | use\_ssl | `optional` `boolean` | Whether the user should always access the admin over https. Default false. | | user\_registered | `optional` `string` | Date the user registered. Format is `Year-Month-Date Hours:Minutes:Seconds`. | | user\_activation\_key | `optional` `string` | Password reset key. Default empty. | | spam | `optional` `boolean` | Multisite only. Whether the user is marked as spam. Default false. | | show\_admin\_bar\_front | `optional` `string` | Whether to display the Admin Bar for the user on the site’s front end. Accepts ‘true’ or ‘false’ as a string literal, not boolean. Default ‘true’. | | locale | `optional` `string` | User’s locale. Default empty. | | user\_meta | `optional` `string` | Add user meta on user registration. It should be a JSON string. Example: `{"meta_key":"meta_value","meta_key2":"meta_value"}` | ## Request[​](#request "Direct link to Request") ``` { "email": "test@simplejwtlogin.com", "password": "string", "user_login": "myuser", "user_nicename": "myuser", "user_url": "https://simplejwtlogin.com", "display_name": "myuser", "nickname": "myuser", "first_name": "myuser", "last_name": "myuser", "description": "This is a sample description", "rich_editing": true, "syntax_highlighting": true, "comment_shortcuts": "false", "admin_color": "fresh", "use_ssl": true, "user_registered": "2022-01-31 23:15:30", "user_activation_key": "string", "spam": false, "show_admin_bar_front": true, "locale": "" } ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "id": 1, "message": "User was successfully created.", "user": { "ID": 1, "user_login": "myusser", "user_nicename": "My User", "user_email": "myuser@simplejwtlogin.com", "user_url": "https://simplejwtlogin.com", "user_registered": "2021-01-01 23:31:50", "user_activation_key": "test", "user_status": "0", "display_name": "myuser", "user_level": 10 }, "roles": [ "administrator" ], "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c" } ``` ### 400[​](#400 "Direct link to 400") ``` { "success": false, "data": { "message": "Error message string", "errorCode": 0 } } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/users' \ -H "Content-type: application/json" \ -d '{"email":"myemail@simplejwtlogin.com", "password":"test"}' ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->registerUser('email@simplejwtlogin.com', 'password', 'AUTH CODE'); ``` ### JavaScript[​](#javascript "Direct link to JavaScript") ``` var data = JSON.stringify({ "email": "email@simplejwtlogin.com", "password":"my-secret-passwor", "AUTH_CODE":"my-auth-code" }); var xhr = new XMLHttpRequest(); xhr.withCredentials = true; xhr.addEventListener("readystatechange", function() { if(this.readyState === 4) { console.log(this.responseText); } }); xhr.open("POST", "https://simplejwtlogin.com" + "/simple-jwt-login/v1/users"); xhr.setRequestHeader("Content-Type", "application/json"); xhr.send(data); ``` ## Screenshot[​](#screenshot "Direct link to Screenshot") ![Register user API settings screen for Simple JWT Login v3.0.0](/assets/images/screenshot-4-50464ac15022352da49519dd7c3fd6a7.png) ## Features[​](#features "Direct link to Features") ### User roles[​](#user-roles "Direct link to User roles") You can set the default role assigned to newly registered users (e.g., `subscriber`, `contributor`, `author`, `editor`, or any custom role). You can also assign a different role per **Auth Code** - when a user registers using a specific `AUTH_CODE`, they receive the role tied to that code. This makes it easy to support multiple user types from a single registration endpoint. ### Restrict registration[​](#restrict-registration "Direct link to Restrict registration") Limit registrations to: * **Specific IP addresses** - block registrations from untrusted origins * **Specific email domains** - e.g., only allow `@yourcompany.com` addresses ### Random password generation[​](#random-password-generation "Direct link to Random password generation") Enable “Generate a random password” to allow registration without a `password` field. The plugin generates a secure random password automatically. Password length is configurable between **6** and **255** characters. ### Auto-login after registration[​](#auto-login-after-registration "Direct link to Auto-login after registration") Enable “Initialize force login after register” to automatically log the new user in immediately after their account is created, following the same redirect flow configured in the Autologin settings. note This option has no effect if the Autologin feature is disabled. In that case, the endpoint simply returns the new user's data as a JSON response. ### Custom user meta[​](#custom-user-meta "Direct link to Custom user meta") Pass any number of custom metadata fields during registration by including a `user_meta` JSON parameter. Each key-value pair will be saved as WordPress user meta. Example: ``` { “email”: “user@example.com”, “password”: “secret”, “user_meta”: “{\”plan\”:\”premium\”,\”referral_source\”:\”landing_page\”}” } ``` *** ## FAQ[​](#faq "Direct link to FAQ") ### How do I configure the Register User endpoint?[​](#how-do-i-configure-the-register-user-endpoint "Direct link to How do I configure the Register User endpoint?") 1. Go to **Settings → Simple JWT Login** in your WordPress admin. 2. Open the **Register Settings** tab. 3. Enable registration and configure the desired role, restrictions, and options. 4. Save your settings, then send a `POST` request to the endpoint. --- # Reset password This endpoint initiates the password reset flow for an existing WordPress user. Depending on the plugin configuration, it can silently save a reset code to the database, send the standard WordPress reset email, or deliver a fully customized email template. **METHOD** : `POST` **ENDPOINT** : `/simple-jwt-login/v1/users/reset_password` **URL Example** : `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/users/reset_password&email={{email}}&AUTH_KEY={{AUTH_KEY_VALUE}}` **PARAMETERS**: | Parameter | Type | Description | | ---------- | ------------------- | -------------------------------------------------------------- | | email | `required` `string` | The email that requests the password change | | AUTH\_CODE | `optional` `string` | Required only when option "Reset password requires AUTH CODE". | ## Request[​](#request "Direct link to Request") ``` { "email" : "my_email", "AUTH_CODE" : "MY_SECRET_AUTH_KEY" } ``` ## Response[​](#response "Direct link to Response") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "message": "Reset password email has been sent." } ``` ### 400[​](#400 "Direct link to 400") ``` { "success": false, "data": { "message": "string", "errorCode": 0 } } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/users/reset_password \ -H "Content-type: application/json" \ -d '{"email":"test@simplejwtlogin.com", "AUTH_CODE": "123"}' ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->resetPassword('email@simplejwtlogin.com', 'AUTH CODE'); ``` ### JavaScript[​](#javascript "Direct link to JavaScript") ``` var data = JSON.stringify({ "email":"test@simplejwtlogin.com", "code": "123", "new_password": "test" }); var xhr = new XMLHttpRequest(); xhr.withCredentials = true; xhr.addEventListener("readystatechange", function() { if(this.readyState === 4) { console.log(this.responseText); } }); xhr.open("POST", "https://simplejwtlogin.com" + "/simple-jwt-login/v1/users/reset_password"); xhr.setRequestHeader("Content-Type", "application/json"); xhr.send(data); ``` ## Screenshot[​](#screenshot "Direct link to Screenshot") ![Reset password screen for Simple JWT Login v3.0.0](/assets/images/screenshot-6-9a5714cd7a4a973ab72fdbde78ee7acf.png) ## Features[​](#features "Direct link to Features") ### Reset password modes[​](#reset-password-modes "Direct link to Reset password modes") The plugin supports three delivery modes for the reset password flow: | Mode | Behaviour | | --------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | | **Silent (code only)** | Generates and saves a reset code to the database without sending any email. Use this when your front-end handles its own email delivery. | | **Default WordPress email** | Sends the standard WordPress password reset email. | | **Custom email** | Sends a fully customisable email (plain text or HTML) with your own subject and body. | ### Custom email template[​](#custom-email-template "Direct link to Custom email template") When using the custom email mode you can write your own subject and body. The body supports the following variables, which are replaced with real values at send time: | Variable | Description | | ---------------- | ------------------------------------------------------------------------------------ | | `{{CODE}}` | **Required.** The reset password code the user must submit to change their password. | | `{{NAME}}` | User's full name (first + last) | | `{{EMAIL}}` | User's email address | | `{{NICKNAME}}` | User's nickname | | `{{FIRST_NAME}}` | User's first name | | `{{LAST_NAME}}` | User's last name | | `{{SITE}}` | Website URL | | `{{IP}}` | IP address of the client that triggered the reset | Email body example: ``` Welcome {{LAST_NAME}}, Your reset code for {{SITE}} is {{CODE}}. This reset email has been generated from: {{IP}} ``` ### Hooks:[​](#hooks "Direct link to Hooks:") In order to use a custom email template for reset password, you can use the simple\_jwt\_login\_hook. ``` add_filter('simple_jwt_login_reset_password_custom_email_template', function($template, $request) { return " Hello {{FIRST_NAME}}, Here is your reset password code. Your code: {{CODE}} "; }, 10, 2); ``` --- # Revoke token Revoking a token immediately invalidates it - any subsequent request using that token will be rejected. Call this endpoint when a user logs out or when you need to terminate a specific session (e.g., after a password change or suspicious activity). note Once a token is revoked, it cannot be un-revoked. The user must authenticate again to obtain a new token. **METHOD** : `POST` **ENDPOINT**: `/simple-jwt-login/v1/auth/revoke` **URL Example** : `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/auth/revoke&JWT={{YOUR_JWT}}` **PARAMETERS**: | Parameter | Type | Description | | ---------- | ------------------- | -------------------------------------------------------------------------------------------------------------------- | | JWT | `required` `string` | Your JWT | | AUTH\_CODE | `optional` `string` | Auth Code from the "Auth codes" section. Required only if the "Authentication Requires Auth Code" option is enabled. | ## Request[​](#request "Direct link to Request") ``` { "JWT" : "YOUR_JWT_HERE", "AUTH_CODE": "MySecretAuthCode" } ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "message": "Token was revoked" } ``` ### 400[​](#400 "Direct link to 400") ``` { "success": false, "error" : "Error message" } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/auth/revoke \ -H "Content-type: application/json" \ -d '{"JWT":"YOUR_JWT"}' ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->revokeToken('Your JWT here', 'AUTH CODE'); ``` ## Screenshot[​](#screenshot "Direct link to Screenshot") ![Revoke token API settings screen for Simple JWT Login v3.0.0](/assets/images/screenshot-7-2f338df0aa647954e348da088f33fb87.png) --- # Validate token Use this endpoint to verify whether a JWT is valid. On success, the response includes the corresponding WordPress user's profile, their roles, and the decoded JWT header and payload. This endpoint is useful for: * **Server-side token verification** before granting access to resources * **Debugging** - inspect what user and claims a token resolves to * **Client-side session checks** - confirm a stored token is still accepted before making other API calls **METHOD** : `POST` **ENDPOINT**: `/simple-jwt-login/v1/auth/validate` **URL Example** : `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/auth/validate&JWT={{YOUR_JWT}}` **PARAMETERS**: | Parameter | Type | Description | | ---------- | ------------------- | -------------------------------------------------------------------------------------------------------------------- | | JWT | `required` `string` | Your JWT | | AUTH\_CODE | `optional` `string` | Auth Code from the "Auth codes" section. Required only if the "Authentication Requires Auth Code" option is enabled. | ## Request[​](#request "Direct link to Request") ``` { "JWT" : "YOUR_JWT_HERE", "AUTH_CODE": "MySecretAuthCode" } ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "data": { "user": { "ID": "1", "user_login": "myusser", "user_nicename": "My User", "user_email": "myuser@simplejwtlogin.com", "user_url": "https://simplejwtlogin.com", "user_registered": "2021-01-01 23:31:50", "user_activation_key": "test", "user_status": "0", "display_name": "myuser" }, "roles": [ "administrator" ], "jwt": [ { "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c", "header": { "typ": "JWT", "alg": "HS256" }, "payload": { "iat": 123123, "email": "myuser@simplejwtlogin.com", "id": 1, "site": "https://simplejwtlogin.com", "username": "myuser" } } ] } } ``` ### 400[​](#400 "Direct link to 400") ``` { "success": false, "error" : "Error message" } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/auth/validate \ -H "Content-type: application/json" \ -d '{"JWT":"YOUR_JWT"}' ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->validateToken('your JWT here', 'AUTH CODE'); ``` ## Screenshot[​](#screenshot "Direct link to Screenshot") ![Validate token API settings screen for Simple JWT Login v3.0.0](/assets/images/screenshot-7-2f338df0aa647954e348da088f33fb87.png) --- # WPGraphQL Simple-JWT-Login integrates with [WPGraphQL](https://wordpress.org/plugins/wp-graphql/) to bring JWT authentication to your GraphQL layer. Once configured, any GraphQL query or mutation can require a valid JWT, making it straightforward to build secure, headless WordPress applications. **Why use this integration?** * Authenticate GraphQL requests with the same JWT tokens used for REST API calls * Protect sensitive queries and mutations so only logged-in users can execute them * Works with any front-end framework (React, Vue, Next.js, etc.) or mobile client that supports HTTP headers ## Setup Guide[​](#setup-guide "Direct link to Setup Guide") ### Enable WPGraphQL Authentication[​](#enable-wpgraphql-authentication "Direct link to Enable WPGraphQL Authentication") Go to **Simple-JWT-Login Settings** and enable **WPGraphQL Authorization**. ![Enable WPGraphQL Authentication](/assets/images/screenshots/third-party-integrations/wpgraphql-enabled.png) ### Test an Unauthenticated Request[​](#test-an-unauthenticated-request "Direct link to Test an Unauthenticated Request") Try calling a **WPGraphQL endpoint** without authentication-you should receive an **Unauthorized error**: ![Unauthorized WPGraphQL Error Example](/assets/images/screenshots/third-party-integrations/wpgraphql-postman-unauthorized.png) ### Authenticate and Use JWT[​](#authenticate-and-use-jwt "Direct link to Authenticate and Use JWT") Once you authenticate and obtain a valid JWT, include it in your request headers. Now, your API calls will be **authenticated**: ![Authenticated WPGraphQL Request with JWT](/assets/images/screenshots/third-party-integrations/wpgraphql-postman-jwt.png) --- # Introduction **Simple-JWT-Login** is a free, open-source WordPress plugin that adds JSON Web Token (JWT) authentication to the WordPress REST API. It lets mobile apps, single-page applications, and external services securely interact with your WordPress site - without exposing admin credentials. With Simple-JWT-Login you can: * **Authenticate** users and receive a signed JWT * **Auto-login** users via a tokenized link * **Register** and **delete** users programmatically * **Reset and change passwords** through the REST API * **Protect any REST endpoint** so it requires a valid JWT * **Refresh, validate, and revoke** tokens to manage session lifecycle Whether you're building a headless WordPress site, a React/Vue front-end, a mobile app, or a third-party integration, Simple-JWT-Login provides a clean, standards-based authentication layer. ## Requirements[​](#requirements "Direct link to Requirements") Before installing Simple-JWT-Login, ensure your environment meets the following minimum requirements: * PHP **5.5** or higher * WordPress **4.4.0** or higher ## License[​](#license "Direct link to License") Simple-JWT-Login is open-source and distributed under the [GPL 3.0](https://github.com/nicumicle/simple-jwt-login/blob/master/LICENSE) License. ## Installation Guide[​](#installation-guide "Direct link to Installation Guide") Setting up Simple-JWT-Login is quick and easy. Choose one of the following installation methods: ### Method 1: Install from WordPress.org (Recommended)[​](#method-1-install-from-wordpressorg-recommended "Direct link to Method 1: Install from WordPress.org (Recommended)") * Go to the **Plugins** menu in WordPress and click "**Add New**". ![Add new plugin](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAB1YAAABlCAMAAADJXfFFAAADAFBMVEUdIycKS3gQDhDv7/CcoqeMj5TDxMfw8PH///8YDhT9/v7FxcUjIyYdIy3q6+sdKFrx8OHGx8dkaXAdJjzm5uf9/PicoZ4qIyc0NDQdKFQiX6gdJkh5nqdCQUPExMRIJyc7Ozyf4/HnsnLPjU3p8PEmbrEhJytSLCcuKSkvdbt2qt1UJycXDhRwSi2coIYeJTSJb43f3d8qTHVnq+vEhERfKie47fGVoaeW2PGWVyn//uc/KCfw1ZZtm87m3qqgenqdYC/sxoeJyeocLW08UJZJSUvF7/9oLCXf7/HpzJVcX2HG7vF+OyeNc1HFnIzT6Lzw7+o4JyjU8/nHl3MePX/O0NJwb3Lj/f/T09WW0+3uwaaAk6ecoJP/679qTTqJoKclVJoVUX5zk6ViiaHv0bG41ulZiaaZlIwVf8ewbzTw2bcsU4RZOykuMDK2iXIgPGDXnmCBaE6IbXtpkatniLr/+9sbT5G56dpvtOtobnb3xpjb4eZGbZCMTSmckoDx4b9cRjkdNH3n1aJugJPZ2doVbLerf2/J4e4kNUhMk9F7VjbgzLXw7dj10aNUWIVodYSTfn3u/v+Uhmj/9M/u5N3ouZjw7bHRuaBTnNjSo3yj1+52entHOi9Ic5vX5e7jsoiAgIBaoeJLq+ZcbYD058ey5P/KysseLk+QlZv1//+RyvGJud7ZqpNqf67w69DI5M1yNScnY5mr5OA7U3iEiYiHvfBow/BFickxQ2e15e+Yzvs7gsN5vuffpWemYSxIXm2Yelqn2f319fWXweBteaJmQy2pzu0wPEpRfqFiX1LbsoaIlXurq7O6koy2dzyD1O9+m71cNko5R1vc6tDp57cdMF/n2skwmdmEqs2bkHJyX37awq2thH0zXojFq7TInXrDwMI/aKh1cpBvlpGcsdgmhMpdfrREM1dhcpiIYj9rksRdUUvJ0qZYtOcdQ3C8urz/+ei93besxt7k8ft+dXAaGhqrl4Zhp9rw2sminqCe1c2Ylb09g6gIAAiDnpZQnMDVLbMAAAAACXBIWXMAAAsTAAALEwEAmpwYAAAVn0lEQVR42u3dC1xM6ePH8eM/Y2d+08wo0zRqECmStcmiXW0uRSqiUKKopCXlTtikZKlExbLRDT9W5NqyLqtW7peV67qtu2Vdll1r/dbefv/X73nOzDRTnaHRReX7fu3L1Mw0nabhs89znnOG+Rf1fwwAAABUHrIKAACArAIAACCrAAAAyCoAAAAgqwAAAG80q7J9c9c78kev+skWzw4AAAC3huVwZlWyPSDteAtb+6P75o4eIcbTBgAAwJlVIxWT5iZGJuTCiDOr9rNmxyWuabjebIdf1u6RXi8ZsCZm1ez2S1qr4DcJAAC1Jqukqc1NmhPcWbWftaTFLEc+y8zraKiXQt/DTRg5O7JyG2R/bk2m33Gfit25YwBfY/SIin+P1hhvAwBANWbVxGjdulvNmxs1N+LMasS3zT7W5Mtskm3uyAV6qxoYNDtSuc/T5zU3R6IOpdmkijyCcgpfa7ZlBb+H7GO+WXv85gEA4CU5Wm6lZwSmdOn06qyuk8pFB3zpsJUrq7k/tO+YmRqwxLOxp+fI99qQQeK3lnqqOvrwhKaz7zeld9IxZ/qHFt36MJLVPZ0Y86HjWwqohR9yDT/pmHg9/WOJTlcvXM4xTucoYaOmOlnV/Z5N/HZkNqt4ViUzFnV+5TMFAAD1SfCAfuRPm26dK5dVizIPoMrqAaFcJOKtIxPBXFmNWGIrlu0LSBtBZ11JkWRNji3QU9W465N2NzVzLJ9V1+k9mEZDY7cxg7fGMK3nfNmDcyK2dW4oHadKdo/k871K7mD/YllkbkFPn4pnNdOzdYsdTQzIqmCiAlkFAEBWDc5q7nFFmaySxUoOIpYD2b3KkVXJsQX7LO2P8flXnJjrjmQYqTx+vUjMXdVZjmakq/zyWZUVtGKiBjwLZ2zi2zGM65c9uLY1N3RSYpz6I/57JTtplWfIwJb9ugpmddwOsoTJr7cBWU3e2oN9pmRTE5auaNPWw5JJ6ukjWV2InbAAAPU+qx2fSS/OVwze2o+xGLCNsfGw/PmgNPmZFb2D65enVOO7fxKkV8mIMj/M+GpYp0YZN3xN0+88i05uT0erbUfdjb54SqzJKtmjKhUKhSKhSGrCOVpV/hAXuoCJcKQxutCUHxjZKHP3t056qkp3i+4OCIwsm1Umycp2l9WuwtbLrRT6sqokvVsgLpkNfqh7m/2LQkWFs9piFfnD05PraSSLhtmskkuxTlYLk+IjaVb3dmuf6zKRPLdKl9h+5kPD8boDAKjvWXXNGGQbERaudAmXLJeGS1ZPlBWcyOqYYWU+tBPbWcpiwAKZXU8n1y9bNbmdQLI60edCxqJImZ2VgmZ1y8PWezWj3oZkgGqkGa0aca4ENv/hbNMihTk7L0sGrWaHf/72fvmdq5qqEqSrpdcD06xadDtbcCr48VkXGn7OrMrIgJgfyC7ozU2dS089obO497b6J6tcVmUf63yBdsgqmTExN28iySo7tG/rcd/lVNTju6cG/7oNrzsAgPqa1YHsQp9undl54KSetssLG/31d6H5wW8Gk2jRSWAybckOBYnEZmI6a0rvSkrRKCOckbw/Uczs7elEs0qmOKM0lSKj1eYm6w6QwarwADlyVU9WyUIlSTafT8a/EY6BkdmzubK6Q1NV2tUd5bI6Z/rkX/s1+mvy9Bh9We24KoBvtuM5Ow7uGEQepkh7fGz+1himWrMqDt5a5NLpQktvU1NpfOekwl0T21q1XemD1x0AQH0fre71cKIjKkuL+JT0Xo9Tfu1DE0mzGjVghEu45sgTX/+cRe1oQPVltZ86qya3yCzwOrlIKPc1MeEcrdJJYDIj+3PQe2ebMOYjr9wfeYVrEti+pKqkqyUTtpJjRQy7TEnm8gvZW/nixuPOjN59q9dLUieJcNRdCxy8lfP+Bu9bfUlWJUljwzqZ56km0YOTn/UY/OtdLGECAKj/WVWPVn1c/7rbSrnx5AnbwWQASLOqdCnWzFru9Yh81Wi1n3bJkpG/gO5aFXzKfdwqWbKUzV9iq5yyZLuXWJLtFeHoxbVkiTaOpk1zqbZr7IJEZ3aTpaRSNu7seFpPVic0pcuiqHNZs5Zoyx3BXVX9x60avBKYPDnmLoJOzK749vazisSuGd06ywq2xOBlBwDwluxbPcXYzyBHfu4irVLvWxWTT9RzwExSfNzujYs6k32r49h9qy/L6i0Tf7lQRCaBRXJ/fQfY7A4ii5CuPzxG0jUh7lhgHNcBNnqymuuc451M725xnlRqzh52BKgnq5JZpI5xYkY2K+iKk/Z8hLICAY/H8w6v+FmWxhl63Cp5cpiovuS5fJRD13rZv0+eyb0ca48BAKDerQSOICuBx5Pdjm3JP/tRdJ8jXQl8l2Q1qm84uVsfOuzbaH2R/7gPWQnsnX7kVVldJycHrQrpmiW5iRH36SBGZJNZ4MRzTWmOLjT14jwdhJ6sGkQZSidn6ekgKnweJHYieJLCgG+CsywBAEBF0JWrFgYOsRqqjloVsv/JHUz0nbwwlMzOkv2dRQrm+pL7nCcvrIqsknGqo3rsKTYgqwZVFVkFAICKSHQuVNi/aGXYGQwamhjxhHIhPXCVhJV3S9+p9putOUzPCPFeG/t9ek61r8pp69aVyir5KfalZvoZ8Kau5NsZVlVkFQAAKsC1Zfxh0gyFwafaPyASqoiEB4z0vzGcrTLU0WxHpETfG8PpLsutRFYN1aipgVUFAABg8DbmepgfR1UBAKCWK5tVMgzeN5csJVq/6rgtnh0AAIBKZhUAAACQVQAAAGQVAAAAWQUAAABkFQAAAFkFAABAVquGAAAA6q53hLXDO1W+Oe+U/VGRVQAAQFaRVQAAQFaRVWQVAABZRVaRVQAAQFaRVQAAQFaRVWQVAABZRVaRVQAAQFaRVQAAQFa1VjqLkFUAAKgzWZWnP2889+CGCqVry+9+M8+4lXza9dZA4Wdp+6syq6JBdvSBx3+FrAIAQF3M6spDCfLYtLyKlOuz7pfdjfsfGqj5fFr3/UK5w2JkFVkFAEBWdTs27KAwNm3m3CPC4R1Gp+5/2t8vdeMG4drZfuw1ZqtSL7PtXDmVXHSd/1XXa0GrMs8MGT65cerGzzp8Qe+YSsa7K0bOzjz0hVC+6fnMMwMrn9VRaTNHutGsfjJ3dCbZEGQVAABq/2h10Z2Dv7Ejz4MbRnX4YvjkjYvlNx/9tjZt/7TuGxcvOuRGrtkwnLRTkzzhCueu8+0WPx1vJ6KjVZJVcscNsWlfC1cccpOvcN5AvubpIM0Yc1lj1uaBBmd1eIcj8k2PFtOsPviCbKV67ll+U/WIzouRVQAAqIVLlmJ/9xsZJlq0eYhQnuw2vIMbKSXZXbrCbhGZ7e167Wt6zbTuX9OijS+g9z9Bsko+/WTzEHVW6R2FKx9tWEGK+MnUxYvuhG2Q/6bZ/TqeNnDN/oqPVlXV/Ip8mw0krW40q1OHkDFyXslMNL39gRtGqwAAUDtXAj+9Ojnvk6ns8I9GdPjzmYTzssb04iudrGpHq+RTElN1VtkvJe1TZXWIPHl2qnYSmMwUN25sJzJ4Epj0lXz31C/UWZVr97Yu8iOdzsMkMAAA1MKsdr1B53dPPKKjVdHS39isslO+QnqNOrSqrGr3rZYZrW5mR6uL1Vk1/k349OajkqXFyzimgCsyCbxCNY+szuq0ktEqOw3svBhZBQCAWphV+c0pCaIt3e3ovtWxZN8qiah8kPMQ+dUwust02g03naxqVgJ3ne885LP5duTqPJF63+paspZYndWVmwfKVzwq6V7X8Wv2v86SpbF3MoRrTw6hWU3NEC075KazIPmQG5YsAQBArZwEfpq+qnHq5SElK4FJsaYVk8NTh7ALfO8u1skqe9xqgBsZsAY8p3cQnfCz010JrMrq0/7P6RLeEsPvil4nq6JR7AapVgL7lVoJPOoIVgIDAEC9OcsSOwlccycvpJPAOG61CkwJaVCDQqbgrxsAIKvIav3N6pTQ6Jp8qUWHoqsAgKwiq/U3qyHRNftaiw7B3zcAQFbr+TvYTEgNcOSPfp71Nma1QU2/2Brg7xsAIKv1OquybEd+4OGOQXy+l4/u9eZDBYKl6QvKJW/O9B7spc13fV6aRsn7VuJqzarxh5L3kVUAAGS1VmVVGcrnq7PKX+JUKqsTe++7fL5HLcrqR+3YW+3PPQirQFYnNtlljawCACCrNZlV++zAEWxS+fTSS6Gb1Vbk5hcelrUpq5KjzZo1ayJmcu1endVTjIU7sgoAgKzWZFZ/DlJnNe3/yWXg4TJZZaK2xjAXLucYp0cykmMJ3skPSVaLw6RXDzM2a//OWXrTiZFkh0mTvcSMbCq5eQGjdEkP87DMD5OmH6mGrDZqSS/HPhRfyHhlVv/4MwyTwAAAb4CJqFZUVWRS1ZujeUT9WZVk81Wu3G9KL7zEZbLquidc9r7HT9vzrBTBW+efc/5u25wuoyalZBSKbaxP/JSd0IrJj57fe+r5D5m9sZPO2cV3VubFevUevGfFTz/2rbasCtb2Y5KwbxUAoJbyN60VWTX1r+rN0Tyi/qwqp6iqGni4EZvVK05ls9rylOQcWSO8y8PS5rttTG5q5Jzp4YxkeU8n+qlkuYflDCtbRlZgpTgaxzDBA/opXSaKmb3dOlfPJLA6q4JOjI06q63EbekVn/cx/4BcGA+Ks018sDWmEfmkFUNu6WkZtbUoq/XRH3PovYxvxtnanzvj/urKDbPown7B5H9X+GWk/hJkFQDeeqYmpm9+vCoiW6HenHeqZnO0j6g/q+Y/qKaAH4pJVsnCpW/blB+tMhMu51jzPrK8cPBi/0m2qn2rSR5O7L5Vm+/ODu3EsNVVTkmw5m0hWW3FSFaT1L6JrBqfIpPRTcSJWTpZTcxKbHzch7lNWmocLpYczRIztwfqqVx/iz2cWd0UdZreOoZzCdSo7eT0Sfl21uWz2v+eO7IKAG9lV/1N3nnTTPxNq3hzdB7xVVktsmVoVkeUz2rw+RhlwYlIZm+8JWO/LyDMo42+rCbFjxAHn9dkVVGtWd0SUzIJXCqrVj5KO2tBfHtGJ6vM9QR6obr5AjlqqGcb+xnclVv4fcgT7qw2mNdXf1Z7teR5p0fsLJ/VpWEYrQIA1Gvck8CBZ0OX3OecBJaRlcB0wMokxVvOKlIwg6d/o82qZhJYwchmWMkKyOSvhSqrJMJkEnhGtWX1j3AxOaq2fFaNezB7rVX302aVLG4iwYyRzCi5b6dxu7grN8wicB4ZyBqP7hg1lzQyeU3IPymqrOanXFJl9eqaEJuMhZOfCNam7BTE9vpAlVW2vySrY8mHW77fKfjjTkj+3DH0C5blz70eNQNZBQB4O7KqWrJEs7o7qNySJfVxq+Z5y46HJixqZ3O+qPeP52NKsmp94nh2QieS0vnk6h6S1WMnrTmyJYbNKrtkKacaD7CROQs4svr5NmWe6hOdrA7uS0ed3zCrBYJC8eA9Lxk8el+7FJtymk4FZyxNs+iy9vvl7le3q7I673HEaVrJsSkF0uJ5A4vvCYZ1vCRYRiPMZtX76vad2qx6p7VNuDhTldWoAsEm3WEssgoAUI+zSg6woTVdkpV4TLVyiessSxHkCJqAx33oETQXi8Ta0WrpA2wmbHS/OPqvD9msMvlh3ul3q+t0EK2PPngm4MrqR+1c97wsq2tjGNmaoAR9WSVN9U67pJr4JY2kk7qaSeB5OcXz+pJK9h/jTsaoLYfZ9C3++Hbf4kuCkn2rL9y1WVXFWZVVMntMr0VWAQDeiqzaa46wYemeDqIWnhNYu2RJwJ1VyzldXpZVwcLxkWSEvv0gd+U2kQQus9izkMzi0qzSsWhJVgdu+f5S8Rjraw1CQkKiTq9N+evBlx1Od9gp0EwCC9gvUWeV7SiyCgDwFma1Tr2DzSuz2s715VklE70Xfx8hznXhqtzCyexboj7hHK0OFAyLWDPGuvgeu2rJu/vHbd37/3O7C3dWMVoFAEBW62xWbSq8b9XBgUbROJxpa81RuWHBH9D9q2PcufatDhR4FzcYYz2qV4Hg4pkcwaaQfwtGdVQ1Viera1OeSMmaYO/u90r2rSKrAADIah3KaqE42J29ia4E/oZh1/h+ZMmZ1S39ZOya3EKx9mTBDXQWLLFHmY7qdZquBA6lK4FTQmxmlmSVDEPHWHunp4TkF5DTJ/Y6TQ7HeSIok1VB+nayeHgn74/MkPzUMTxkFQAAWa1jWf3Ikh6qmtye0R63mlzquFWd0WonccQRsjIphtlVrZXj8aRSU9Nr93g8AY5bBQBAVutUVsmULpOYJZb5aM6yNI6cZclH70pgcoSOLaNzmE21ZFVavFF+IOCJFFkFAEBW61hWyereLHHirF/7ac4JrEh88Fj/SuA4W8m5zQmCas5qMq93b+toZBUAAFmtzVmtqG7tLrQUvLk3lOFJPxX+5z/CT6Vcs8DIKgAAslpXsmp8g12LVKhgh6hvLqv+NKv+pjwKWQUAQFbraFatfLITBIJlkZIkwRvNqi/Nqq+pVCotF1ZkFQAAWa0rWR3bnrHvTd75Lb/vm86qWCxc5+BgamrKlhVZBQCox1l9t/7uW136+09l3qe85rPKU2dVdOCA6AApqxRZBQDAaLUuL1kyQEh01VeVZlWhWNVk1aommXK5oFRXo0PwIgQAqEdZfRdZLWVKaHTVV9XUV2ir1rvFSZ6p9kib6NApeBECAGC0Wm+zKpgS0qDq/SwcV6KFQOeGEFQVAABZrc9ZFVT1ciVTqVzuL2yiRQ9gxSsPAABZRVZfJ6tSqaentFRW/ZFVAABkFVl9zdEqz7OFp7SFltAXWQUAQFaR1dc8cWFzKemqblYxWgUAQFaR1ddcCGy67hepZzOt3iJkFQAAWUVWX3sWuHRX/XhYsgQAgKwiq5XpKq9xb7VMB18HZBUAAFlFVivTVZFQRW56ax3nG8QBAEA9yeq7yGq171/1Pfnnn2bEnyd/8TVFVQEAcKp9ZLVSJ9t3+FTFwRRjVQCAep3VdzEJXANd1YWXHQAATrWPrAIAACCrAAAAyCqyCgAAdTCr7yKrAAAAyCoAANQch5PrG0Ip6086GJDVCccVyCoAAKirut5XLoRS5L7rHTiyyn2AzYQAvpcCWQUAANZJX2S0PN+TFc5qhCO/FnXVsF++d7T6g6XulfpfM2v2gmecUyUvyaU5pR+3Jv8ns2p/ktf66d3L/G5qozqxkQBvynqMVbnGq+u5ssp58sIJQfwyXTUfSv/h6R9ZK7P6eR/XLq3+u5z92HiQnfpaj82V6MiJzep/ZGM7hFXBK3JL9zz1RyucX7ur3n8/qYmfZOGPHxj2HRb+eFr9kXHATvbyxqVSP+SoO3vU97y2sQqezBuXXu/ruLfuj3tdqmMjAeqZhmgol4Zln6j/AVerk3hYdNz0AAAAAElFTkSuQmCC "Add new plugin") * Search for "**Simple JWT Login**" and select "**Install Now**". ![Search for Simple-JWT-Login plugin](/assets/images/search_simple-jwt-login-plugin-cd661449b75fea062cadc9b06a95ec56.png "Search for simple-jwt-login") * **Activate** the plugin when prompted. ![Activate the plugin](/assets/images/activate-simple-jwt-login-plugin-1791dcddc527f822646b147e96592331.png "Activate the plugin") ### Method 2: Download and Install Manually[​](#method-2-download-and-install-manually "Direct link to Method 2: Download and Install Manually") * Access . * Click "**Download**" to get the latest Simple-JWT-Login plugin version. ![Download the plugin](/assets/images/download_from_wordpress.org-ee53800943f2461fe90cb5310aa519de.png "Download the plugin") * Upload the `.zip` file via the WordPress plugin uploader (**Plugins → Add New → Upload Plugin**). ![Upload the plugin zip](/assets/images/upload_plugin_file_in_wordpress-050749b961348bd6978a04aacb324987.png "Upload plugin zip file") * Click "**Install Now**" and **Activate** the plugin. ![Activate the plugin](/assets/images/activate-simple-jwt-login-plugin-1791dcddc527f822646b147e96592331.png "Activate the plugin") Now that you've installed **Simple-JWT-Login**, check out the **Configuration Guide** to set up your JWT secret key and enable the features you need. --- # API Keys API Keys are long-lived credentials that authenticate REST requests to any WordPress endpoint when the API key middleware is enabled. Unlike JWTs - which expire and carry user claims in the token - an API key is an opaque secret that maps to a WordPress user and a set of permissions. Use API keys for: * **Server-to-server integrations** where a persistent credential is more practical than managing token expiry * **CI/CD pipelines** that need read or write access to WordPress content * **Third-party services** (webhooks, schedulers) that call your WordPress REST API ## Settings[​](#settings "Direct link to Settings") Go to **Settings → Simple JWT Login → API Keys** to configure. ![API Keys settings](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAC+CAMAAABedVxPAAADAFBMVEX4+frz9fZ6g4pxeoJsdX0mNUQdIyf////i5OeUlJS8wMTw8fP39/j+/v6ZoKbk5uj3+PlQV15/iI/q7O7Z3N+XnaS1ur6Lkpjh5OWFjJN2foaSmZ/n6ery8/SXnaMeHh66v8KDipGepKl9hYyPlpzKzdDd4OKgpquhqK3t7u/O0tS+wsaMk5mOlZuwtbp4gIe3u7+GjZR1foWVm6KTm6CmrLHY297l5unIzM9veICtsrdtdn7w8vPW2dxweYHo6uz5+fl8hIucoqeQmJ6BiZC3vMCpr7PV2NqKkZedo6h5gYjGys3e4eP19vavtLp3f4ducnRzfIOkqq/z9PUhJSnu8PHBxMh+ho2zuLy0ub3s7e/AxMj19veorbOkpaWxtrva3eDc3+GJkJfp6epKT1KHj5azt7qCiZHg4ePBxcnDxsr8/PzR1NbEyMx0fISNlJrN0NKboqczMzMxQE76+/vc3Ny/w8eEi5Lw8PLs7vCus7jm5ujLz9K5vsLR1NdBRknQ09atrrCNkJEqLzPT1tnN0NOqr7UnNkXm5+nQ0tbi4uOYn6Wjqq+srKw+QkdfanUxNThJVmLR0tPGxsb09fWssLbKy8vt7/BpbG4lKi7Z3N7CxMVeXl6lq7Dj5Oaio6S/wMJaWlolNEN/goR9ho2iqa5RXWl2dnY1OT07QETg4uRTVVdXXF+8wMWbm5s7SVbY2NllaW7r7Ozp6uza2txUV1qwsrMuMzfj5eZGSU1hYWEiIiLe3t8pOEfV1da7vL2+vr9mZmYmJiZgZGessLSKjY+ChYeLi4ueoKGlrLFOUVNmcXuQk5RiZmrPz9CWmJqZnaCQl53b3d9bX2MrKystPEpWYm2TlZdJTE3U1tlVWVz5+vpbZnIlNEM5PUF8fX7GyMt4e31ESEylp6lrb3NydXe0tLVDQ0OTmJ4iJysvLy+NlZ07OztxcXGGh4dqdH7LzM7f4OFUWmGmqaz3+Ph0eHupqqtCT1w+S1l2eXyFiY2oqKhHR0ckM0KnrbA5QkqO+8JHAAAACXBIWXMAAAsTAAALEwEAmpwYAAAd3UlEQVR42u2deVxUVf/HD8PMPWUs45CyjSib7CKb7CiCIuCGI4GKCyqPyeSeguYKbumTmZZormWamppKFo9Lppb6azM1y6SXttfTXo/V0/P8fq/X75x77xnuAK4BL7PP+49h7p0z55z7Pfe8OfO9d4BQAAAALQ/hD5bq+LsAAAC0CPFuDqp9q+4hAAAAWox78mX7VjkgFAAA0JI45DP7OmDlCwAALb36dSC02og4AABAy2J0IzQeYQAAgJYmntC7EAUAAGhp7oJ9AQAA9gUAANgXAAAA7AsAALAvAAAA2BcAAGBfAAAAsC8AAMC+AAAAYF8AAIB9AQAA9rXH9au9x8OL6+/9RZJW85+jJUmqfP3NduRvkvSC8tJoqT8h/xoonUZgAQDglu2b8HNrzgz7vVWVkrRmsazabTuXSdKJevZ9X5L+hbgCAMAt27doL1PvO++0/tnVbven0vJl8uJWXuh+Li23t+9mac0X7NlPn12q3L+JvCBJZwnZK31PTu2slLZ/ioADAMD17Psjk+9eps7WPe1275c+/o/0iWrf8ufYU619K6XKV7h8l0t7Ny+XPiLHpddI+RopK1S6VFHx+2YEHAAArmffHjzt0IM9vqPdu0eS1k6UpPuUvC/jUzv7StJOC3vymrSfsBzEW+SIdMn4qnSR5ErLNgW2Q7wBAOC69s1trWK39t0sbTOSOdLnSt73+ImPiJ19WSL4XDkh/RUzbyfGOdKm1czQ5GN+je4dBBwAAK5nX1dVvj/XaHZaXlK8uqZKyfty7PK+bddI+91IhXRh7dq1YS8S8o60urKyir1mXlshSVWIOAAAXNu+rp+p9rW75+FVSbq4c+dOSdp4FfuS0kpptPn+5VL/ior9vxPixm6R+IWQVecqKj6X/pmCiAMAwDXt68rveJjwWevoH+12n+MJXULekl6/mn3JxOXSHNefPl+2ZvTOeUROOZSyy3DnBkrSsr8h4AAAcE37buDy/U9TtLBJmoMwAwDAjdn3fi7fnzf88fp3VJzDly8AAOAG7fvT8dbnCgJmNUH9gdL21xBlAAC4IfsWv1XvJl8AAAAtYF8m39ZnERsAAGhh+37VuvUvCA0AALS0fd0CA3sjNAAAgL+uDgAAsK+CX1tyX2yTdMH/Xs0GrzP93j9eaas2V30p3vHmqvpD3UnRW67xqofXNd98wz2t14rFJe+PD422zkaieY0Ai/PjZt9iY8eE5LYuPa5bLCpU/uHS4WaCX690I90E4Pa174TxRTdlX929N2nfHl3rF+ne9iZqrHG8+kznFeUPv0719WjYnVtymBK2MXp9elw7MiDoRuzbsKdXOfJ6mknwLJd//j2IZAwipKtefijVK5i1RUPd08qGul2rTt7kLdg3MPVGx6Qh64OLSEIq7Atg33qY9f1ym9e+jUuzyex7o3ubBJsA1LCNKTXOLoi7QfvecCzraaZDdyLsW+jN/lhdAX8wsR299U72b+yY3KNr707xzWDfGx+ThrQJu6FisC/4q9l3+ISFsXX2ne+ZNsGVfUQ2kqBopjHl42Kxu2PUk8R1fEfSNXp2G7bc6qDuIi5+AabekUkTTAOcyIagSF2cxWbf6ZOi9X4i8+D0hC56vROz08IJBWGkA6uijbGvr95xvjw55RqVlhUT9HJ0zyIkgOkt0J14sZd7t/LZkufJlk9qRa0C2vRim3JF/PO8U5K/3re8aGhmXhuzslf0kJNcTUhcEqnyy9HnpPDuuAQFeHqznQkF0U+ocz7XPTmZLSkTypL7dSEOwdE6tk5tFRHj7tmFkBCXaP9prEzfaP+xQgBq2Mawv3lROFJr37H+ZqWTRSxeJD/RTW1WzTyowVJ22sVSPWptK0pMCuVSin2z2MgEtxrPHoIU+9aFUY5cifokN9MxdrqIt7ZOucl60VTta3Q546Ac6pP9nHgo+P7USCMbBV9+fqjh5TQ2JhxlHIg5w9F3ARFhzpCX6OxUSlJ6oQ6Hh9fQiKXivRNNtpFw6RvgyAdHDcvcmDxfzSGoY9EqwKeX/O0hl+CRjhkhttLcvp3987JT5DPPxH4/RBbDCuB2ta9/2I7kwcK+rmmtqnrq2hHdCGIq8OA/+JLDa9f0hH7TSanJMmG9sngSu1x07GN85JmioohAcm9pVarnLGFfp5ExNSRL2He4+9n42L7EQz+DuEUOlhenqbpiY1dX23JMtCznBkZMHxRZJOyrrLMSw9ySPImoqJV+NpnrqaxyudN6ZqYaO5ZbCl1dXXyUvaKHGvsOio0n91pk++aYyRNxxGP8zOmFicqcTwu1WM6SBXm5lsEbSHCUa6puFmtlPpkfXUXOBJtTTfPJ2MgsV3dhXzVszL6WgC0a+xb6uolOBi8kZJa3aFbYVwmWulMbS/WoNa2ImPSoW/s6Jd5LMmt6sYdSxb6aMHJXJsd1kX/mhIbMcLfFW9tzee1rH03Fvg6xLk7iUP1ZUHyUZaRuNlNcIT8/RHhta9+GtSjjUGQKChmXOEKEmcQwe7K877SyJ+OzNfbVd7K91zVxyPQgdSRc/B82x8bZwpI7tzyB/R4Th6B2kA+NUjpvpltMuK006+Y4r/nmCB+2WDBWp0eS+DwjrABuU/tmJaeQsh7CvoUZhBh1E0l25yrTwlZ8CczYxT7oEp+xhEzyLbAo01fsckliPyPZ/JzxhJJoiBH2HeHYTnPVja0nSUd/4pHsQIj7w7Iez3rNNWo+f4uWBenF9vYdSYiD3kFU1Mqd+T25yGZfxyzxvvg8xb62TtfZt/PIDepVN97t2b1IYTbvvTznjY67WNdIbCd5I5Gt6KZFsdUo23DP9chjGd5ZfiSDhSlVdZgIG8v76svMdfYdUHIPEZ1M1RlJSa5oVthXCZa6UxtL9ag1rYiYaOxLJnSuiiY9O1fp4xX7asLI+SA7x2uLhbiwZbzRa7GIt7bnsn3to6kMsnuQkYhDLexOUhKV9HFSELGkmcVHeh5em30b1qKMQyqvpftQEWZh3zNDWIS09nWwhaqQnTdFeap92S+t0F52YfHrIQ5BdJCfAErpvxMyWO8mSrNuZhSy31v6FBI5Ijd4pEcTXUoGoBnsG8QWM23LhH3j2LlMAnaRaTEJQaGTSpUzd6j8yZF5KUE/TZ2+YpecdYtkNxMPDyZmF3+93l3Yd+YYzT0PKcr1ISUvyqQqJ2af8EyODbEJQbQsm6BXml4/196+PrJFRUVyypHNYtW+5Xq5Iqehvsl6lgrle22drrNvylL/vDijbF/W7SwTiRvKXvS1ZR48zxLPBP48n1eXlUNa8eOP6TFRriqClM1kSQjVYSJsPPPAEPZNi87l6Umlk8T/A1dHi2hW2FcJlrpTG0v1qDWtiJho7ds3NmEpmRibkEPUvG9dGBWMs3MGkSi5zg9EvLU9l+1rH0157atzZCtocajmNEtYgFKfa7RTrrt8fojw2uzboBZ1HAL52A+fJMIs7Mt7MV2beagLlTwSY1T7zpLfJcIyPyNar08ShyA6aMs5u3RmD+OLRWnWzTI+hvoNLG02YNzCMCSCwW1rX4ujfNp6iLUv943/RDa7BpSm5AQpZ27nbKVsuS7Yv1yZvmKX1r6Tgj2KSm32HZHnoFn7JrrWXZUS9mWLHve4urWv2jKf2uM/cCPPzCWxzGxD3Imr7QoPm7ZqRfXsSxzlK+phI0ekmFX7ih7KKzKWrMzmq3Tj3JxAjX2Hs1qc1BUXW0H9vYzEFiprX9ahsWztyy0yJneETimQwd51r+IwW9jq2derYz+2tlU7yYIyw4+IZu3tq+7UxFIctaYVEROtfWc7ru9A7nFcn01sV91EGAVbXEjsNLt4a+qsu+pWF035N16bUp2ZiEMlAePCx6pPPUNjWsn2FeHlSm5kTORIpyprX/bLxm9offueYZtnWS/U4ZA7p763kFVlzKu76sbeJQYwMmyx0S9JHILoYJ194/hvy2pRmq992egv1rcjYTG+1aHdn3kSUgC3qX3HefH7ps4MFXlfx94kQcemac74rqRkvHLmds1hV1A6mkn3GBLEPMA+TNt2ae3bZhoxBtjs61TC1p22vG+SdzmxzLbZoCfTz4Ya4tBmodwAr9HWMnNKupFksVXgQj9SVeZO7knuWjfT1YrEJq9Izvt6W0jH8g5sCnZieuB7RQ85I0tJsWMSSc0n1QWhGvt6pG0gQ5RsY8oHTIMjyYJ0M+F5Xxdju5Es75s8vKrT+Hyje18jqT5L7itLMU5SHGYLW337krPRWaKTZHF0AXtUm7W3r7pTE0tx1JpWREy09m2XzC/m+Y4PU+2rhjFL0e2CDlX3jNPtIg+zpL1xgS3emjrlJutFU7EvCfOvFodKSqPSxP8tadsmMV/Wmggvo7ExkfO+8jgUZe4i8dHF9e07jfUiiPVCHQ65c+p7a9I8SJjezr5iAL1cyXSvJHEIooN19tVVk74TbKV53tdUTgawZXlNnj9JiXZ0MveEFsBtad8M+dRM6Oek3vOQVZYWXiNf+mBTKVHNKNZkOD5zxjWwXz5JSc8lCcnsCryyy86+HXXhMXE2+7KL03l19zwYCwscew232cCjn77NCJNeP+Eeuahco2iZL95MZ+Iy55L8pQFlvMI4fn1dnelqRWKTVyTf8/CEjl1rbxdVEsv1wPeKHsqSyugV0SaJlLIr9euJxr4kwV/f01O+fJMSodf7s2uMuWV6fs/DFnbPg5F9tHbRl7HfQOV+kV7h7JNv32cyZygOs4WtgX3JB9GpaidZyrUfi6DarL191Z3aWKpHrWlFxERrXzKSJ+O3sGW3Yl81jIVKHjQrIjOthKdvFkQleraxxVtbJ2+yXjTFYrJtwWBxqCmJk4jtlkRvZVEpwisnRRqOifw7Vx4HYj7jyBM69ezL7nlIG5LsJIZD7px478wxZZN87ewrwlKqm9CdlRaHoHawzr5JvskZbrbSPNEwyz9vEj+xotkHj5IMli2GFgC+aXxb4mUmt/AFuxtMqi9s0q66PNFyYSkIbZZqez+DMw7AvoAtsYxk1gTSbPY1j3dtyt6e7ZfQYpEJ9G/6G7WKniRFLn1x1gHYFxASoU/LMDebfYdGhjVlZ+/rF9dit65GjUlt+kotaXqvLQ446wDsCwAAAPYFAADYFwAAAOwLAACwLwAAANgXAABgXwAAgH0RBQAAgH0BAAD2BQAAAPsCAADsCwAAAPYFAADYFwAAwI3ZFwAAQIvD7EsBAAC0MLAvAADAvgAAAPsCAACAfQEAAPYFAAAA+wIAAOwLAAAA9gUAANgXAAAA7AsAALAvAADAvgAAAGBfAACAfQEAALSEfYvc35syZWsJadbG+5xcN3nyupNXMAwAANhXYfjhpzmHFy1sxrbnHdv9yqhRr+w+OA/jAACAfTltphhUprg0W9P/PSqeHX0EAwEAgH0pnWGTL9NvYXOtfI/WPT/wIkYCAAD7Fh1m1n1jQUrKgjfYk0UPNvrGRYbF9Xc9auirPDEYzHYvDDE81uD9Tse0Wwdrr9vT/huVn8tWaPdaJGSNAQB3in3PnDcYflCe6gyGw99oXnreYHj+seSzXLUfDv5D9j25W7u1u6Lu+WCJ8w7sCwD4q9n3w6cNhoeVp6UGw9Nb7ez72NZFhsNhjdZ1U/Zd94p268g6rX0fwtoXAPBXtO8UZt92ylM3Zt8pdvbtS90+NPzbKmceYrYeNjyaT785b5jyaAK3b6/3zj9qVuwbEv38lDdqKK364fzWjEbsO3mUdmvU5Ib27f/xudffYqU+vVi5cxXbvLy/8vhg2b4PvrZ9+QkrpW8uXzYP9gUA/FXsS3vzpTGzb6Bhq3fGhzuo44clPxjOuzH7nvd6zLDVmdu36DFDsun8b4Tt/E035dbse+kh+toJSk89EHJ6G6H9K4/sW71Ttu/pnSuW7H2Tztv245KdsC8A4I6x73t1mYddzL7v1bcvs2srbt9cw6MJG9hmOX+PYRYTrTctOm8o5vbtYWAJi0TD8BCDYQddev3Mw4H6ed9NtD/LBa+8qKYbXqb9N1O6T9rH7bvtbUr3LKPHT1H6NuwLALhj7PvN07arbo8x+2Zcbe1r5bdEbF1MCx9lF+MM/8Psy76b8W9DLrevn3K/2jddDAZKZ133qtvpikbWvizRu+oTOfMgSWtpf34d7qWXmX0tsp4lOvoILwz7AgDuFPuSRXZ3nFnr2ddsy/tS17FsvWtedNgvd6tsX3davkisfX9LSEgYMl9e+7o0Yt8rB7Vb7a1Xte+hlz7aR+cw+7IkRLk0iq9919wvFzjOCqyAfQEAd863Lfpe9dsWdfc8MPuW/uDtvdWwdLHhcNuRi2T7TuF5X6rmfaO9v3k+ge18z7uxvK/9ty2+oFe1755lVrqKr323j6JvnpPzvhVvpdArK+kjoy3O/WFfAMCd9E1jm3wXBVN7+zIf/3BW+bZF8XtsyzGFZhgWpX0o2zd762HbPQ+6f5/f+oYHDXnj8G8jG7MvfcSW6z1g94celLzvCVvmYfMnx09cYPatGL3m+D7ZvtbTcyovvs/ueZhz4U3YFwBwJ/2VnUGL/o//lZ0pi2Y0Y9svHtx9ZNSoI6fbf4FxAADAvgq137C/MPlhjLVZG+9Wwf7C5IEKK4YBAAD7AgAAgH0BAAD2BQAAAPsCAADsCwAAAPYFAADYFwAAAOwLAACwLwAAwL4AAABgXwAAgH0BAADAvgAAAPsCAACAfQEAAPYFAAAA+wIAAOwLAAAA9gUAANi3xWk37G7w52FYCqYqgH3vEDYewtj/iTg0DDEAsO8dwt0YeowXALAvZjPAeAHYF7MZYLwAgH0xmwHGC8C+mM0A4wUA7IvZjPECAPbFbAYYLwBgX8xmjBcAd6J9X9+E2QwwXgA0j33/MY89vDgH9gUYLwBgX8xm2BeAv45993320vZf2bfsf992afMVSo/MWX6S2ffBk5de2mylU5ef2PkZLz7s3OrnRr/Nfj5XuX8V+7H345feWlyxbfsRKopiNgOMFwA3Y99zlze8PecjumJeyI+jT9Gf1vwa8vGaTfT9iyuWvFVBpw58Uyk+bOBKunY0paceCDm9rZYOW/OI+fM5m6tPbbOKopjNAOMFwI3YdyBnDp1aWcuc+rm879e99PReSmsrN9HlbJ27ZzuzbzfVvhcptf6zVn6+/WU6bD+lK/hrlTWi6O0+m7//lv8Fw+8uqAdEXz62n/9Y0r59+8kH2HL+2afUFx5pzx5Gffkc/uAh7AtAc659j8gW3kk3fLZ94MD9dPMJ/tomi7x3IMs8qMWHrWYP/xzFtLtm4MC18qb82rY9oujtPpu7ffkspa8ce0FsXz759VTZvqdWDrvw7ih7+x76dp0TThzYF4DmtO+KS8p2/8tTa+ftp6eZVq1s7bvmJ3lvffseeumjfXSZnX1F0dt+Nr998JWQyafF1pWvf7r8vWzflSz33f4RO/vumXyULfPLL3/77lMvsxIv8wBMrsWZBPsC0IT2tV5800pHraCrf6XWc/vpocqp9NOBm+hrx8vplZUN7Ltnu5Wusl/7iqK3/2w+ufzoU85iY97rdBUXamP2XfXud/wq4nPfvR2ycfJDdN1mtvH69ziRYF8AmvSqW7tfti2/eITuuXRx72aWCT3yjwufXdhEre8vq3zu/YaZh8tzzm3+xN6+atHbfzZ3+7b9EtvGU7sp/fYLxb7W3w8+pLXvsWe5pFcee5A9HjhNv/i6lk5tPxUnEuwLAL5pfEuz+e2Dx/7L8gnsMtuzdMnBfZRWHFCuurV/d6N81e0Ie/oIs+/RyTw7PKy9zMe0dvIX9MRzOI9gXwBg31uazVe+PLn73cVszT516ih6UlHrKPmq2x6+yGX2tbCXUph9aw9w/Q6bbEtZHKid/F+cR7AvALDvLc3my//bzXm/ml6wLj+5kvG/dyt5X0rt7zh78OjXL9NV7Veoe5Yc3Pju4ziPYF8AYN9bmc2bDrJbF5YcU/5x7pGD5XKJb50btS+1rv56BX3qy01XRu1mtwLTdceexWkE+wIA+97KbC6fLH9rbyPPPVB6dJ28s6b9psbtS52/e/dHy/dfHruwjt9u9mL7VTiNYF8AYN8Wn813f4mzCPYFAPZt8dkcMvkUziLYFwDYt6Vn83dfb34QZxHsCwDsi9mM8QIA9sVsBhgvAGBfzGaMFwCwL2YzwHgB2Bf2BRgvAGBfzGaA8QKwL2YzwHgBAPtiNsO+AMC+mM0A4wUA7IvZjPECAPb9szDsEMb+T8ShYYgBgH3vEFI23g3+PAwrx1QFsC8AAADYFwAAYF8AAACwLwAAwL4AAABgX4XwYkp795qv50TLj7qs6AjfVvy1cs9G3xLj0cjOPpk0dIDdnm7Trte26+xrvKgTdTTsheck9tDJP7wklXbqzHcMCG2kAk/7+wPYUbl797Z1NzvCVftqz0A6rZvYWBBAaXGJta6t8KiS2MFqW9ZESl9I34cpAwDs2xT2ZU98HqDqY5Y3LcrsffP2tZjt9lh8r9f2zLjr2ZfX0aAXZlM/I+UudO1Xew379rba29eb0i55NerWuCT7wsy+vhbbVkCgNep+TVssSENi6+zbO70rZgwAsG+z2JcGjeX2zcz2DLbSlO5R7r1paKSvnxOt9YuKCfeggVFRC63UtPAM11677KjoucraVyka6POVexgdmhbR6UpwePRMXq/p1ZKomq9MH9HFEZR27kBDvX3LaFlOBH/RdenI6H1KlazFcNaiW4T7etm+vA61FzsionxS5C4P7+yXINuXpne12ffVYGe5hlQfdgBtlLWvWludfenwIKWL95vSM2i4r+dcSiPZOteH2Tc3zT1GBMUtvW1PqmmLBcktx2Zf1wK2bK7XGAAA9r1Z+/JkQwP7OmUWc/smmp2zH6ZB02i1ibrVOhcW0rAY5/v1HtW+7ZzXl1LTELmKoKHUqVyxr1I00LOIhj/O1625M6i1nWzfXJpUUtQn3arat6AbzRdr3+APaJFRqZK1SGc8TF1m0Q7jbWtfuRfWzB000E8ub6rKipHtu9jLtvYN6kmVGpwL2tHsB1T7KrVp7Js1Uu3ikOGULqb5pm42+8pr37hZSuEZ0Veopi1m31JvYd/knB20QWMAANi3Cda+en26kvfNpDSsB00Pj4hwzM//m3fJUurHXu/lMU4XEeE7gJqUzKrOYsv7KkUDmVVdirk5a8qGK0kBUwoNZe7sNVi1b1Bwjyph39IzhTuoUmU5e8+0HlR3hdbW2VfuxT7HiIhwk5xRmECddX1oJ70+ypb3LWBLVbVThbOKdM6qfZXaNPZ9YaTaRW7f0KAIrxp7+3YNkcs6lxQUU01b4frEWDebfcPjGjYGAIB9mybzQMVVtyGDaPrjfCMmt89Zb+o3n73F46OhilL7KPYtqrOvXDSQuXDSWTnv6zQ7Ypda9IFg9tbq6nBKB3WgdEMPU63I+4bkFuxQqlRbzLFS63ht3nfIILcy0eNX+Wp9rOpC1b49mTrVTuVnTptBVfsqtWnsG+andpHZd0f4YuuZYsrsedanXt53WtxZT+dik2mB2lZ4sdIW32VNdPIc1KAxAADs2/T23bLemXahpsdpkjcNW0gtaR6DI12pxVXYN4hdwXJS7KsUVexbm8OczC6tZdvZt9afOkd0oEzYmV3nyy/x5+vHKlWqLbo8QOfL9uV1KPucTYHUyiXoHMnWp1kB9vYNfaDESe0U9c6ptrdvTYqwr6t/jdpFZt+EodTiWMy6RIfL9u1lFmtfS3ofmn2fpi1hX/Wqm8VUWr8xAADs2/T2fTzIUzeJ5hbELvRmV92+isn0oKG9onRdhH3Zday8iYp9laKKfWkn706liQHZrnb2pT2jfLI7UF36pLa02yRvftXNb7xP8BWlSrVFN5+A7Ei5blaHcKh3ST+eD+lSwhXoVW5vX5rgXqt0iiZEUHv7+gSKO86+6kjVLjL7OpWE+wUU04kFsUNl+86MiVHzvtksn52vc6prq5592YsP12sMAAD7/uV5NfBObQwA2BfcxniXON+hjQEA+wIAAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAAGBfAAAAsC8AAMC+AAAAYF8AAIB9AQAAwL4AAAD7AgAAuAH7xlsRBgAAaFms8YS6OSEOAADQsji5EeoQgjgAAEDLMrgPYf+tqxyBAACAliQ/nxL+Y7oTcr8AANBCWJ0G51PZvrSPW/xdAAAAWoR4tyKq2hcAAEAL8/+/knyKWUhpPQAAAABJRU5ErkJggg==) ### API Keys (enable/disable)[​](#api-keys-enabledisable "Direct link to API Keys (enable/disable)") Enable or disable the API Keys feature. When disabled, the header is ignored on all requests. #### Header name[​](#header-name "Direct link to Header name") The HTTP header clients must send the API key in. Default: `X-API-Key`. Change this only if you need to avoid a header name collision with another system. ### Create API Key[​](#create-api-key "Direct link to Create API Key") ![Create API Key form](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAFdCAMAAABo0j7XAAADAFBMVEX4+fohJSn+/v5QV15sdX0eHh4dIyf////i5OeUlJR2f4bKzdCMk5n4+Pl4gIeprrPz9fV6goltdn6kqq+ZoKbj4+OAiI/u7/Dv8PKQl53b3uBiZWeusrdweID19faepKlxeoLq7O3x8fJGSU2DipHHy8/39/jV2Nve4eO+wsb19vd0fYTs7vB/goXp6uy1ur7y8/R8hIqOlZvl5ul9f4L7+/uTmqDn6OqNkJLk5uhpbG7a3d+jpabo6eunqKqEi5Jye4N/h4+XnaTFycxveIAqLzPMz9L29vdCQkIwNTiboqfs7e7O0dSHj5Xc3N0/Pz+qq6xsb3JyeoI1ODygoaO8wMW6v8Kxtru3vMCtr7HQ09bBxcne3t/U1tnd3+G0ub3N0NN+ho38/PywtbmmrLGhpqzx8vMtMDSFjJN9hYyJkJbh5OVNUFPGys3S1NeLjY/g4eF/f3/Cw8RYXGCamprb3NxBRUi7u7uGjZRDR0uKkZjQ0dLj5ebm6OmRmZ9ydXc4PD92eHsnLDC+v8GlpaUAAADDxsqRlJaUm6F4fH9KT1LX2NlRVFegpapAQECWlpaiqK3ExcY7QEP5+vqZm53HyMmHio7T1dfX19eLkpizt7utra7l5eZSUlKWnKLS09RwcnUuMzdfYmUzMzO8vL7Z29zMzM2Tlpido6i/w8eBiZCen6D5+fm0tbUtLS2wsrNkZmnr6+vY297X2dw5PkFcX2LDx8vg4uRUV1qPlpwkKS3i5OUlJSW/v7+kpqkmKi6orbKoqKiWmJqqr7U9QUVIS05WVlY/QkZaWlqEhokyNjk6OjoiJyussba5vcG2ubxmaWxVWVxpaWl4foOgo6WQmJ42Oj1XWl2Zn6XAwcKIiInQ09ZVVVW2t7dJTVBvb29wdXqFhYbMztBkZGQhISF8fHzKy8yNjY1tcHLAxMZdXV2QkJApKSl1d3pgYGDP0NC6vsJSVllFRUVMTEyCgoI1OT2HjJK6u7y/wsd1dXWRl52jo6NeZGtVWFsgJip4ensFLQ+dAAAACXBIWXMAAAsTAAALEwEAmpwYAAAgAElEQVR42u3dCXwTdd748WkJ8116EVpoC7SFFihXC20BaYHSchQo5YaK3BCEcgqCIEcrWJ8/N4qUG+US5UYQkMMLAR8UL9Tl0NeCisrqs+rK7vp3V57dfX4zk6QpVgS3jUA/79dr20kymXQzkw/jL5OMJoo9usnvAABe0SQ6SoVXU/8LG6kBALxmZJhZ37AongoA8CZ7mKpvVDhPBAB4ee83SpPoQJ4HAPCuwGhNmvA0AIC3NdHkdzwLAOBtv6O+AEB9AYD6AgCoLwBQXwAA9QUA6gsAoL4AQH0BANQXAKgvAFBfT+F19xX33ZMvzJqesbTFIz+7RH9dz/vptQ/regvjd7yu629N/+CgFq3rL1s3LdA3aFrrf+nHWBsAqK/21QfllA++uvb6lRt1vdb0f1W/ufqGZej6kTyzvkcmL9D1RbFF67tF11uzMgBQ39RK5ZwSGxW5IXaBvrS/pjX6UPu9PnXCyala+BvT819bFqjFTf+XfnbTh9qzumGHNvjL/RmH3HvIL+unTpg7t/H6frWjq+vri9S3qX5kl7G3bS0rdqmR4mX6IlYPgDJWX/snqrsrNO3/q1+9GhTZ9dX131tTv9ePbJw/y/6evii+lr5Fa5Rx+o0D+pFqK+fr+hvJlwdn6qebntLbOe92RZ//hj7dWd/Aprqe61nffD3f6LR7Wcf0c5r2nuuBAKDM1HdxucL6lgvxvOWCrl921ddo6yP6W1laOz1Hi4pT151UxbRGHlboVzQ1nrDHmnehrk8aquuPW+O+yoYi4766PtmueSwr6xW92gt6fhirB0DZqm+D//Ws7//Getw0SNefddV3vzmkYHk6Jv6KGtvVk5313WBdvdSaN14/G6hN1T+xxn0PzH82qkh9T+r6gRiPZan36Cb00WexdgCUsfoOKldu/gcfLNa0ER98ML9cubpakXHfqe5xX3V5kv7WD5MmTeoXt0Kf2nrSSVVftY+bq2nJ+mvq6klWqe0bray+EmaN+xqKjPu++4p+JatwWWp8Y/9kfRJrB0AZq2/9cuXcx5qFlyv31U+OeXjvrerO+jaYrF9JTv5yqqaGdX+YZez7pur6l8n1Dmaqn8lXHjbv00/X35s8ebIxZFx8fbU5GfqC5u5lGYO++klWDgDqqxU53jf/yOlHnPXVwifUyj85+Q0tZZye33SBqq82QTdGhOt9cuKVBZP7mXc5oB8yfu3Rx/1cfbUOmfr0FNeyzF7PZeUAYOTB2+xvvXWQlQOgjL/r1sDrf9Xc+fo3rBsAZfyIsxHe/6sycr5sxLoBULY/bfFJA54lAPDSJ42bf+L6pPEnzXmSAMBr37JjXzfZaO/ktnaeIwDw5jdMhr+zePHdMTxDAMC3qwMA9QUAeL++le++iZmD6hV/fZOaP70uu+1N/y1NepXmM1Sj8X92/wF3ef8xAdxx9bXbLM+XSH3D1/yW9a3U8pfmqG+E03/fLy8qt+bP31at3Y08FPUFqO8v8utfUvu+xbnl6nsjrlffG3so6gtQ3xus7/DDNR+K1rS4yg1Hb3M29nhAqJY9o+Zq9b0QiS21drZ62t/XuepbLeg+bfz2mnfFaY2NvN57r2vkYfzq4OAh5lzWVHbbJemj1O5m6pmatYd6LqjyiMOjjEc0DBoVGZCilhsR0CYk1qivx0Jd93TNPzggMjhbcz64ocHR0PS2zbW2ahfe+iekTlpw0HPWn19tdc1pz2la/3Xptetr9dQcfmYJG49O3zrS/XieWt6Vbpun+ak56znnGut3NOm8x8OpkQf3Q1lzux4lrnNDWw2tbht1Q1p/rfLiw6H1nE+nesyHvjOu9mcLBajvNfUd3b/5Xap2VZc039dmkNXYM+pTcfdUixsS1EDbeo+2ZFi2VuMeZ33vq/Scti+oS1zEai2r/UgtVtXOWd/ILna7tWdoTWW3rx8dMUprEDoirl1kNY8FVQ5K1d62+poSmR1WMTFBC6raoEGSv1Ffj4W67umcv1H68LAG7gc3R0/WpKRUXle4Qzo0fbw96wXzzx/plx1XJyhOq9M/vE7Dwda+ryphO7+VqUmq787H83QmIiywrrXv65xrrG245vlwxriv66GsuZ2PEjtmXa5Wt7C+lRq5n071mOPHaNrBhnzOEKC+19b3uKZ1maGNTVd9+K6G1dj+zhkSq2nb5mmhAyobe67mLUMqjVV3Ubu4gX55WtW/a12Gud51C+yV7fw8h3Mqe4wxumzfZyx461GPBVWO0LT7ZpizrjmjZk/soKn9aS3ibXPkoXChrns652+cZF7renDXYEV6YRLnDXf/+dkPqYm2A6z/+r/HXd8zanw6xTbS9Xie7hoR5hp5cM411mYv8nCe9bXmdj5Ky14JxnXu+qq/1/V0qse090rRji9hAwWo77X1/c7sRgfzPbikwtHd7BmRNlt/LaVX3LCRlaJ7BVq3JBoZmWbOO0h7Pknr3Nd9zEOd1cGjrDZZU+a4b3C0f231q29njwUZI81mqdQQg3GqucPZ5iP2XWLWt3Chrns65z9qnZbO9eBK7NHawTZbrDuJo+q4//yj5lzDtZVnGtpsEe76phlz2F5wPZ4yVs1m3mvs4YaVBlj1dc411q/ow3nW15rb+SiXamtF6qv+XtfTaYx2jBgemFiXDRSgvsW866a60TJRK/LeWm7DQdHaMDVD0PAR2pjhznetgvalqf3Lec7xYXt688hUjyPOskLSnEswppz13Zeuwl3jqMeCPOq7xlju6A6e9S1cqOuezvkbV7V2cLe5/876Y1qObK7qm+ja913j/vMbb3X+wfXzAhdHaH937fuqGObZEjzq6yGhfnBcirnva81l1tfj4Yz6Jrb0nNv5KC3Tzb3+lqON/1yw6ut6Oo361h22shLbJ0B9f6a+gauHB2rRLd35qpcYqNVV+75a54ZztOMNG7u6HBZ6j9Z/2FgtcKi6uLhrgPt435Fq/7DxGOOCc8pZ3wah2VoTNfRauCCP+qbUrKfVSbR71rdwoa57OudPbbhSU+O+7gfXtLtV/Iar+nYdb91haGJzLcvasW0UpGYZ3FzzS9Hi/CK0obUbWOO+oeFaSFutuPr2b6C1jAwfGazGbJ1zmfX1eDijvq6HsuZ2PkpsV/VPUl0tPLKJNsBm1df1dJrHPIzuGqE9fx+bKEB9i6uvFr44yC+gQ+HIw5I2Ve/dboyg2qK1obZ97r3iRqOztaHTIkcZbb3Pll1Y3ySbbXQ1s77WlLO+WmrVmrW7aB4L8qivVjctMiBXK1Jf90Jd93TNX211e+OYB9eDq93PaWPmGfWtE+w85mF8ms045sH483PP1BxWNUV7vlJA57YRWoOuzmMe3hmd3nlksfW9N9hWc476ZRzzYM1l1tfj4Yz6uh7KObfzUeIqp6tjHrQ6VUeN2G7V1/V0mvWNsKWot+nYRAHqW2IatQ+/TRb6m3p+DJsnQH1LVEiN22WhvyX7mAFsngD1LUEjba7PTNzqC/1NdYi85nMdAKgvAID6AgD1BQBQXwCgvgAA6gsA1BcAqC8AgPoCAPUFAFBfAKC+AADqCwDUFwBwvfoCALxO1VcAAF5GfQGA+gIA9QUAUF8AoL4AAOoLANQXAEB9AYD6AgCoLwBQXwCgvgAA6gsA1BcAQH0BgPrenhKuVgBuJVdjyBH1LROuDmTd45Yy8CrPAfUtEyqw6sE2CerLlg6wTVJftnSAbRLUly0dbJOgvmzpANskqC9bOtgmQX3Z0gG2SVBftnSwTYL6sqUDbJO48frWysgSeXYcWzrANgnv1nfjR9QXYJuE9+u7JX+vWd9WVzIOXRbpmTx5Y7y9Rc6ibiJZPTcubc2WLhI8yDnRsIO8YLOzKYH6ogTqe2FDU7O+O9ZnHetdID1PPD5w3PQeqbN6ihyYn3tp6vKytaW3s432Vb9W2toXV995zxVb37bBddm8QH1xs/WdmP+Ea+Rh6UrpOUFk2SGRmSelW06BSJ9ZZay+wUFGSc8nFltfpZj6JtQc0pnNC9QXN1nfXfLvb6yRh3wfn0nSs4+abCEyJVM2+xgm32lb+soxvUb3dTgvDBoV2bWDLcyjvpFvb1U9bT880rgwKjJtm1HfAUk1t9fxGHlImefXsEaU6z73bB3ZvqP6XXXEvIZBbzs8JgDqi+vU94lXtoyTgTnL98qJIvVdv/9O3NLr+o1PGHz4uHUhNXiNve60ovVNjewo7/w4QO37DrVlR82xzVH1Hdal4zbbPnd9R/qtSY2+d4yv8z6j+8uZu436Bt8TNSior8cEQH1xnfpK/MZxsnCpQy4X3fd1/DPZIakz77AtPWCI+jE40rrw9nb1Y0DR+krANgn1N+obME9d0bm2qm+EmphX2V3fvj+qy76R9ay77GvokPGhRn1nqB/vBHlMANQX16vv3nw18jB/6oH4WkXqKwnffH/q3A932JYeZDOFmxfOL1Y/Dhapb3tp17VlQ4dR3yBj1KFOsK8EX1ITa6a569vZWoa/dZca94rERg5W0Q0xWmzbWTgBUF/wWTdXfet7XCi2vgXpARXFrO8AdYV/sDjrO6qwvuc9ltEx0kzxEnd9owonAOoL6utUdZ7HhWJGHlR1Q2ypZn0DjIged488nHfXd0hQQeE9tgXtU95JD3QOOPhJ4QRAfUF9nVrahkf71l2jOqsynGrra98Xquo7NqBRYX0N5rtukXWi/HsZ77oFFX3XLSpo3ljflLc7mnOOOmr8dKTPkartXe+6uSYA6gvq67IvKd0vQO3MrmmoLgxKC0583hYrz9le+Gl9pY464swYfQjeNspW5Iiz6M6Vas5oa47rHrS1NO9QY7VUrVjZZh1x5poAqC+o78+qU1IHJ1SNuHYCoL6gvsV6p15sl6Ah1BfUF9TXu1v628HBbfo6qC+oL6gvWzrYJkF92dIBtklQX7Z0sE2C+rKlA2yToL5s6WCbBPVlSwfYJkF92dLBNgnqy5YOsE1SX7Z0gG0S1JctHWyToL5s6QDbJKhvSbg6kHWPW8rAqzwH1LdMiLlaAbiVXI0hR9QXAEB9AYD6AgCoLwBQXwAA9QUA6gsAoL4AQH0BgPoCAKgvAFBfAAD1BQDqCwCgvgBAfQEA1LdYCXy7Ot88DlBf4cxCEM66A+ornMEQrC+A+vJqBusL1JdXM1hfAPXl1cz6Aqgvr2awvgDqy6uZ9QVQX17NYH0B1JdXM+sLuO3qO2sZr2awvoDSrG8tH6X6tde++8wvLGv2TF7NYH0B/0l9+/2qZVFfsL6Akqhv0z0iKw75TsmMn3yytTny0OrA6St9mq3YvzHeIWGzzvqctRvzFbwxPadFrrRQO8x9eDXjP/DA08bPpx9gfaGM1zdwao9nMqrIFJ+5snf2crO+PstFtrw3s8qeZDm2p4rMDDTmi90ycWLP03f8vu+rna6dQAmb9PVHLykffT2J+qIsj/uuEFmYuVTt807x2SkyoalZ30Pq1lN/Flm1VJYt6uZxlyo5d2x9Uz9PLa6+X3zB1lPC+v0/t13UF2V73Nf34mz1c4oKq+w4bda3hYjdxyT2nidy4n2N2Zp9+tpbPj7N7tT6/teTxe37+r75EltPSa+Uwvo+Rn1Rtuu7rNaiPsa+b5YaA57vqq+8MtE5m2PS2XeN360XrY/Kva3rW+HJHd3f/KNj1x+eul/t5//Pp/946q/9HBU6dTe/VfZbVYIHuu/+7AEjuu6JZ3bv/Mf7xpPw5o4eTxWoiY/f9+2+w/jHqvwq1w1sXjfnsUdfcnqU+qJs1/fp/FUTc7rJlCMt9v6Qv9xd3wmbYiTwcbkUJntPPmLM12eDyFxV33HP3rb1fer1tRW+/vjbXX968VVV36f+feHh8i2+uPBxeTW4EvPiFFlb/tWwB55S0XVPyEcfy+XP1T9LL70YE7j7gjHbZqnwF+OGJ903FPfAa8tnsdX93Er5b9fUH6gvyvK478VmF4+JtHqtYErmjiNnncc8GPV1bDmZcWWurM308Yk3Z+84btEeo767jtyuxzxU2K3ePvzY2IX97GFV32/VwMIptf/q2L1W5FmV1CeNndnXO3lMyF/UPzWd1Hvz738scv9n6p+gNx2S9flMcTx1tfCGYkx6nZPkUF/gxj7rNiXzjj9+tIIxtPtH47X/t8+MkQc18d9/VD/+qir68UciT/2X8d/FnTwmphh7tjv+onZ5P1TvQap93b8a879/vzz4dVThDS6fli9fvsqD6sdaj8vmD/Pik+XLd5LCi9SX+oL6lq36vu6q70dGff9k1XfnbvURv6deNYZ8O3lMPKb2j1VhL+1409eMxSqznB/uDnx/g+cNTnunTJkidvUjxuOy+cNUZcqUiR4XqS/1BfWlvvKSUdEn71cXPu7kOWHsBMs/vviLMZv06P63182DRLrv+Hy55w2gvgDfcfbr6mse1rv26welx+5OhRPOY4Avv1j+CeN37O4XrTGFCi9ah6U5b1j1p47CuC/1BajvzdfXeVjvA93ffP2xToUTrmOAO31r/f5id6w1pFC+gucNa8uHCcc83LAHvr7f6esHqC+obxn/1hZ1WG9xV39r7Zt13O38TNb/OD/4dvnzPM8bPv2MLewmxPzNVd9PY6gvqG9Zr2+PYq9+rIrzOOEC8/fy8qvM345v3xfPG55czxbGtyIB1LekX80Dy//hsjnxZvdXzd+vfv7+3iI3gPoC1JdXM+sLoL68msH6AvWlvmB9AdSXVzNYX6C+vJrB+gKoL69m6gtQX17NYH0B1JdXM+sLoL68msH6Aqgvr2bWF0B9by1XB7LubyMDr/IcgPreIWKuVsDt4ypfigzqCwCgvgBAfQEA1BcAqC8AgPo6BQz+hRlCo4yfFf2LXOlf0TX1dpL/TT5ikUWtTPnJsgFQX+r7i/XNmnHTj9hopMeFeztccwUA6luG6usbkda1jjQKHRWQJxH1Rda8I/7Tph13mPWtGDAj16jv8Erbh4iEhBzu2tKob//VKsuOMQ2TUloGdK3RUUJG/LjG6PK6H1erJQwYM22NufyDSdPWjewYGi1bvypclDFvl6DaNWJzK21PaqSucC7CXDYA6ltm6ttucbPYMalRMbLvsBwMEGkT16h2gm/IHLO+ETI+wEhmnhTMe1qF0xHbVdXXPynQuDUvSRyVWsri4RKy1dfcKx7VUQLseUEJO2vXVRcd2w+Kfw0ZnDRILTb0K5VZs75q3ugC3yFrzH3fiv6uRZjLBkB9y0x9F9dOSkr0b5bdNilINTJmbIA8n5iUVDvErG+0+Pr5qmQePH64TX0JUblMFP9hq61zyKv6NkoTI9kh1tiE/70ilQcPOCryXV91MbpXUlJAqCpsULRaVJiIuShj3vA1D40576yvaxHmsgFQ37JT36HG5HdH43zTRfrerQYf2h11zWAkM0gl0zFscMGQeySki0gl8e8cWs9dX7W7mhtg3uAcEe7ccsBxkWyzvmnmtY5pQamFizLnXTc+quVDrvoWLqIS2yJAfctOff3HdJQUe8hQGdRevQk2JjFGsoJSJCHFrO9wuWQMF4TXFt8Z7vpWjA5NcY08JFaTJcOL1jdvdMLOacbIg2+ovzgGy5DKg7r6uhdlzhtql4iHJGKAOfJQuIhKEluPzRGgvmWgvjabLUDWjNqelpA77HCEsetZu6r60WXGtEpPm/U9Wtt6q2zJtHWLC+srKcOirfq63jLzrG/hu265d3UNym40uqMcXVO4KGPeOsPmHX9IUtoe9njXzVz22O1sjgD1RUmyDl4DAOpLfQFQXwCgvgAA6gsA1BcAQH0BgPoCAKgvAFBfAAD1BQDqCwDUl/oCAPUFAOoLAKC+AEB9AQDUFwCoLwCA+gIA9QUAlPn6Vnm0vIfuVdgSAFBfb+j+oOelBx9lSwBAfb2h/HUvAgD1vXXqO+4RthcA1LeU6tvUxyezRRXqC4D6erm+D0u3PRepLwDq6/X6yp99dkpWz41LW4t8eDqnlvolm6dmrqC+AKhvadbXN/mEyIH5uZemLpddHyZcyFklE1/pkfXvV6gvAOpbiuO+Pr0vS7ecApE+s8yrZu2QY6dFCnKoLwDqW4r7vhMPLZPNPobJsnxTpo/PBIn/VN1Ui/oC+C3r26P69S/f/uO+U/L3rt9vXfy+dRXfbybIsRYiDvZ9AZRyfWv5+CyN7/hzd1nZ7/qXb//6yp4Vjn8mOyR1pmROlKzMCTIwv5u09qG+AEq5vv18Hz8ZX3aPeZDlGfaEb74/de4H6Tf73IYWE0R+qHXxy9eoL4DSrq/IlkWy8lDGuD+L9PzmwPSFvVvXOttq4LiMnh2NkQZHci2fjOXy7KEjR46ZIw/LF+SfmyjSe8K5qU0dEjbrrM9ZO580BoCbrm/sgflRp17OutA7S3rOzlNd3TTl8ZzJjw8c18qo7Z/3r3TkTZT8RwJjZxqXJ+a3CntjdkfpfaCgYPK7cmxPFZkZeEv//3606LfsdGdLAHBrjPv6XHyi1SY12aKH9FT/4S29J6nRUDWx7GGjtjMzJ/mK+Ga8vFPMd92OqVkdszdL78dFkifIskXdbvX/31W6e37D5KN8wySAW2XkQeQN86CrudKzj1HfhWJOtGphjjSsWHCkepbseu/IAnPfN76pmuXAy+Zcc+eLveeJnHhfnlwA+DX1XbbBulRcfUVWvWe8Lbe36UVz39e4aulmV33VjvCks+/y5ALAr6lv87ObVWRzi6tvt4Gys8UK+3KV6EXmuG/GQrkwO9ZV30thsvfkI5zbAgB+TX1l4KaMEwcmFlff9VN9fM4l2Cer44LXm/vCly/mnxsorvquVZ8Pi+fcFgDAJ42FI84AUF/qC4D6Ul/qC4D63gL1rVL9+4xDxX91xeyZbDAAqG/p1PeJnPiBUc/Mor4AqK9X67uhp/W71YHTV/o0W7F/Y7xDuj3ce3Z8oLRQHz7pI8/WytiTxYYDgPqWbH1PbXbW10cdzbzlvZlV9iTLzLVhzyzYYe37PnP2kazkf7LhAKC+JVrfAh/n6EKrQ0aK1Ve8rVpqXu5x2qpvz2PqCy4y+XQGAOpbSvu+6mwWdvObLnwkt+dSH59DVn3HmVctZ8sBQH1LZ9xX1VdemWhOfzl/SsFaZ333tGajAUB9S+eYB9+Fs6z6TtgUI4GPS4vW4jig6jvuWZFJJ7uJ72Y2HADUt6SP9930vc9rTa36OraczLgyV1bNPnc6XtV31xF1zMPmcfkLWrDhAKC+wrktAFDf2wXntgBAfQGA+gIAqC8AUN87C2cWAkB9hTMLAaC+wrerAwD1vSXqa/cJZEsBQH1Ltb7V56ofM9/6ufq2rs42A4D6Ul8A1PdOq2/vj85NbeoQSc5c2kPV98PTObVay0L17ZKZ4jzlBQBQ31Ko76aCgk3J0qP35YmHVH13fZhwIWeVte/rPOUFAFDfUqjvJPV1krVkkzqj0CXnyMOsHVZ9PU55AQDUt0Tqe9rYp30mX9V3vcjKjXLxB5EsVd/lmzJ9fCaY9XWd8gIAqG+J1Td+g/rRo5aq7wX1hb5TZVMftSus6vt96yq+31j1dZ3yAgCob4nV93JON7EvUjvAvWutXDhVjftetPt+qeqbOVGyMifI5tcK3Ke8AADqW3KftpirBhWqJ6j6tsrMaapSm3yiVrKqb7/Z5za0mCAF49QxD85TXgAA9S35z7r1XsjWAYD6itfPLER9AVBf+Q3OLER9AVBfAKC+AADqK5zbAgD1Fc5tAQDUVzi3BQDqS30BgPreeH2rZLCRAKC+pV/fpj4+Gy++EVZcfTmvBQDqW3r1fVjCllc/sZP6AqC+Xq6vSLOpfVynDzLqm9Vz41LOKgSA+pZ6fWX+LNfpg4z6Hpife2nqcs4qBID6lnZ9kye7Th+k6tstR33RZJ9ZnFUIAPUt7fp+M8t1+iBV383m1GTOKgSA+pZyfWNPHXOdPkjVd/1+KXzXjbMKAaC+pXbMw6bZe12nD1L1dfwz2SGpMzmrEADqW9rH+2aJ6/RBxrtuCd98f+rcD5xVCAD1ldI/twUAUF/5Dc5tAQDUFwCoLwCA+gIA9QUAUF8AoL4AAOoLANQXAKgvAID6AgD1BQBQXwCgvgAA6gsA1BcAQH0BgPoCAKgvAFBfACjT9Y1pnGbzmrTG4awGANTXiG/AkDzv/QV5QwLILwDqqzQe4t2/wduPBwC3Zn3T8rz7N+SlsR4AUF8Rm7f/CBvrAQD1pb4AQH0BgPpSXwCgvgBAfakvAFBfALgj6lt3THrQXfWKu3OjmtdeU9DrLuNXbZstseJOqV3HvLLDMJFmd62Opb4AcOP17dJ+W7h9ZcSN1Xd8UHCMUd86vnXbVPSob0FAUgH7vgBw4/V1JG6zJjqPqLo9N6Fzw9FzRFKXBCVWLBA/9SU5ueK/veY8u3PuqmtmvGPWV31+eIarvkPbdJxxppnI2ICaXetJvSCHSvoo6guA+l6vvik2505r50rqy3DOhMQNDn1O6o23V5uWbe37VgtamdA3wJonzBZdf7tV34IfQ9z7vkFd56niBvoNsA8NssvoQSLn36G+AKjv9eo7qJdzovNwkebpqqLZI8zL7dpa9e18j4ivX5Z53ZAxEhV80Bz3tY0Kc9e3va2u+rXNGBI+304a15DY9iOpLwDqe/19353O+tYX6W9+I+9hies82mYLsOrb1bzuaXOe0dki8yqKK7vukYc5NQeLHDdnXCNhkQUDqjLuC4D6/sK471eF9T2YaE1vDclzjHfWd90c97zVzL6qcd1r6ytzeg2W7xY7Z6vqH9CO+gKgvr98zINv3Qizvr4Ba3wl5qCcnyO+VQMkNlgNBdcd1lx87zNnDVmnfjRr2P+a+hpHnG3rdTA8SM2VG6cOjOgaGUt9AVDfXz7eN3jGHLO+0nFEkF9Af8lNDGhbUb3TVtE45uG+rpHTzpu7yb3MCN97vpj6yraGuakP1Rx2ppFIbORWjjgDQH29/1m3NiupLwDq67kPRoAAAADYSURBVPX6dhntS30BUF9v17dr7Wp81g0A9eVbdgCA+gIA9aW+AEB9AYD6Ul8AKPn6puV592/IS2M9AKC+6pt5h3j3b/D24wHArVnfmIDGXtz7zWscEM56AEB9jfwOSbN5TdoQ4guA+gIAqC8AUF8AAPUFAOoLAKC+AEB9AQDUFwCoLwBQX54FAKC+AFBG6tvEwdMAAN7laKJJdCzPAwB4V2y0JlFxPA8A4F1ZUZpIGF/xCABeFR4uqr4SFhfL2C8AeIkjNkvt9Br1lajoJr8DAHhFk+gGIvJ/j00nQIzLq34AAAAASUVORK5CYII=) Use the form in the settings page to issue a new key. Fields: | Field | Description | | --------------- | -------------------------------------------------------------------------------------- | | **Name** | A human-readable label to identify the key (e.g., "Mobile App", "CI pipeline"). | | **Expires at** | Optional expiry date/time. Leave blank for a non-expiring key. | | **Permissions** | One or more of: `read`, `create`, `update`, `delete`. See the permissions table below. | After clicking **Create API Key**, a modal appears showing the raw key value. Copy it immediately - it is shown only once and cannot be recovered. ### Existing API Keys[​](#existing-api-keys "Direct link to Existing API Keys") ![Existing API Keys table](/assets/images/existing-api-keys-85db6c35193302a7e17153335a8e919b.png) A paginated table of all keys (admins see all keys; other users see only their own). Columns: Name, Prefix, Permissions, Expires, Last Used, Action (Revoke / Delete). The `User ID` column is visible to admins only. ## How authentication works[​](#how-authentication-works "Direct link to How authentication works") When API key authentication is enabled, Simple JWT Login intercepts every WordPress REST request and checks for the configured header. If the header is present, it looks up the key hash in the database, verifies the key is active (not revoked, not expired), and confirms the key has the required permission for the HTTP method being called. Permission → HTTP method mapping: | Permission | HTTP methods | | ---------- | -------------- | | `read` | `GET` | | `create` | `POST` | | `update` | `PUT`, `PATCH` | | `delete` | `DELETE` | The key itself is **never stored in plain text** - only its SHA-256 hash is saved. The full key is returned only once, at creation time. ## Key format[​](#key-format "Direct link to Key format") Keys follow the pattern `sjl_` + 32 hex characters, for example: ``` sjl_a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4 ``` The first 8 characters (`sjl_a1b2` in the example) serve as a non-secret prefix shown in the list view to help you identify keys without exposing the secret. ## Managing API keys - authentication[​](#managing-api-keys---authentication "Direct link to Managing API keys - authentication") All API key management endpoints require the caller to be authenticated as a WordPress user. Two methods are accepted: * **WordPress session** (cookie-based auth) - the traditional approach when calling from a browser or admin context. * **JWT** - pass a valid JWT via the `Authorization: Bearer ` header, the configured JWT header/cookie, or the `JWT` query parameter. The plugin resolves the JWT to a WordPress user before processing the request. Regular users can manage only their own keys. Administrators (`manage_options` capability) can manage all keys. ## Endpoints[​](#endpoints "Direct link to Endpoints") API Reference Explore and test all API key endpoints using the [interactive API reference →](/api/v4/list-api-keys.md) *** ### List API keys[​](#list-api-keys "Direct link to List API keys") **METHOD**: `GET` **ENDPOINT**: `/simple-jwt-login/v1/api-keys` Returns a paginated list of API keys. Only the key prefix (first 8 characters) is returned, never the full key. **Query parameters**: | Parameter | Type | Default | Description | | ---------- | --------- | ------- | ------------------------- | | `page` | `integer` | `1` | Page number (1-based). | | `per_page` | `integer` | `20` | Results per page (1–100). | **Response 200**: ``` { "success": true, "data": { "items": [ { "id": 7, "name": "My integration key", "key_prefix": "sjl_a1b2****", "permissions": ["read", "create"], "expires_at": null, "last_used_at": "2026-04-15 10:30:00", "created_at": "2026-01-01 12:00:00", "revoked_at": null } ], "total": 1, "page": 1, "per_page": 20 } } ``` **SHELL example** (WordPress session): ``` curl 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/api-keys' \ --cookie "wordpress_logged_in_xxx=..." ``` **SHELL example** (JWT): ``` curl 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/api-keys' \ -H "Authorization: Bearer " ``` *** ### Create an API key[​](#create-an-api-key "Direct link to Create an API key") **METHOD**: `POST` **ENDPOINT**: `/simple-jwt-login/v1/api-keys` Generates a new API key. The full plaintext key is returned **only in this response** - it cannot be retrieved later. Store it securely immediately (e.g., in a secrets manager or environment variable). **Request body**: ``` { "name": "My integration key", "permissions": ["read", "create"], "expires_at": "2027-01-01 00:00:00" } ``` | Field | Type | Description | | ------------- | ------------------- | ---------------------------------------------------------------------- | | `name` | `required` `string` | Human-readable label for the key. | | `permissions` | `required` `array` | One or more of: `read`, `create`, `update`, `delete`. | | `expires_at` | `optional` `string` | Expiry date/time in `Y-m-d H:i:s` format. Omit for a non-expiring key. | **Response 200**: ``` { "success": true, "data": { "id": 7, "key": "sjl_a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4", "name": "My integration key", "key_prefix": "sjl_a1b2", "permissions": ["read", "create"], "expires_at": "2027-01-01 00:00:00" } } ``` **SHELL example** (WordPress session): ``` curl -X POST 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/api-keys' \ --cookie "wordpress_logged_in_xxx=..." \ -H "Content-Type: application/json" \ -d '{"name":"CI pipeline","permissions":["read","create"]}' ``` **SHELL example** (JWT): ``` curl -X POST 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/api-keys' \ -H "Authorization: Bearer " \ -H "Content-Type: application/json" \ -d '{"name":"CI pipeline","permissions":["read","create"]}' ``` *** ### Update an API key[​](#update-an-api-key "Direct link to Update an API key") **METHOD**: `PUT` **ENDPOINT**: `/simple-jwt-login/v1/api-keys/{id}` Updates the name, permissions, and/or expiry of an existing key. The key secret itself is not changed. **Path parameter**: `id` - numeric ID of the key (returned when listing or creating). **Request body**: ``` { "name": "Updated key name", "permissions": ["read", "create", "update"], "expires_at": "2028-06-01 00:00:00" } ``` **Response 200**: ``` { "success": true, "message": "API key updated successfully." } ``` **SHELL example** (WordPress session): ``` curl -X PUT 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/api-keys/7' \ --cookie "wordpress_logged_in_xxx=..." \ -H "Content-Type: application/json" \ -d '{"name":"Readonly key","permissions":["read"]}' ``` **SHELL example** (JWT): ``` curl -X PUT 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/api-keys/7' \ -H "Authorization: Bearer " \ -H "Content-Type: application/json" \ -d '{"name":"Readonly key","permissions":["read"]}' ``` *** ### Revoke an API key[​](#revoke-an-api-key "Direct link to Revoke an API key") **METHOD**: `POST` **ENDPOINT**: `/simple-jwt-login/v1/api-keys/{id}/revoke` Soft-deletes the key by recording a `revoked_at` timestamp. The record is kept in the database (useful for auditing), but the middleware will reject the key immediately. To permanently remove the record, use the [permanent delete](#permanently-delete-an-api-key) endpoint. **Path parameter**: `id` - numeric ID of the key. **Response 200**: ``` { "success": true, "message": "API key revoked successfully." } ``` **SHELL example** (WordPress session): ``` curl -X POST 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/api-keys/7/revoke' \ --cookie "wordpress_logged_in_xxx=..." ``` **SHELL example** (JWT): ``` curl -X POST 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/api-keys/7/revoke' \ -H "Authorization: Bearer " ``` *** ### Permanently delete an API key[​](#permanently-delete-an-api-key "Direct link to Permanently delete an API key") **METHOD**: `DELETE` **ENDPOINT**: `/simple-jwt-login/v1/api-keys/{id}` Permanently removes the key record from the database. This action is irreversible. Prefer [revoke](#revoke-an-api-key) when you want to disable a key but retain the audit record. **Path parameter**: `id` - numeric ID of the key. **Response 200**: ``` { "success": true, "message": "API key deleted successfully." } ``` **SHELL example** (WordPress session): ``` curl -X DELETE 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/api-keys/7' \ --cookie "wordpress_logged_in_xxx=..." ``` **SHELL example** (JWT): ``` curl -X DELETE 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/api-keys/7' \ -H "Authorization: Bearer " ``` *** ## Using an API key in requests[​](#using-an-api-key-in-requests "Direct link to Using an API key in requests") Once you have a key, include it in the configured header on every request: ``` curl 'https://simplejwtlogin.com/wp-json/wp/v2/posts' \ -H "X-API-Key: sjl_a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4" ``` If you changed the header name in the plugin settings, use that name instead. ## Error responses[​](#error-responses "Direct link to Error responses") All error responses from the API key endpoints follow the standard envelope: ``` { "success": false, "data": { "message": "Human-readable error description", "errorCode": 84 } } ``` Common error codes: | Code | Meaning | | ---- | ---------------------------------------------------------------------------------- | | `84` | Unauthorized - no active WordPress session and no valid JWT, or permission denied. | | `85` | Bad request - key name is missing or no permissions were specified. | | `88` | Database insert failed when creating a key. | | `89` | No key found with the provided ID. | | `90` | Database update failed when updating a key. | | `91` | Database operation failed when revoking a key. | | `92` | Database operation failed when permanently deleting a key. | *** ## FAQ[​](#faq "Direct link to FAQ") ### Can I use a JWT to manage API keys?[​](#can-i-use-a-jwt-to-manage-api-keys "Direct link to Can I use a JWT to manage API keys?") Yes. All `/simple-jwt-login/v1/api-keys` endpoints accept a valid JWT in place of a WordPress session cookie. Pass it via `Authorization: Bearer ` or through whichever JWT transport is configured in the plugin settings. ### Can I use an API key instead of a JWT for Simple JWT Login's own endpoints?[​](#can-i-use-an-api-key-instead-of-a-jwt-for-simple-jwt-logins-own-endpoints "Direct link to Can I use an API key instead of a JWT for Simple JWT Login's own endpoints?") No. API keys authenticate requests to standard WordPress REST endpoints (e.g., `/wp/v2/posts`). Simple JWT Login's own endpoints (`/simple-jwt-login/v1/auth`, `/simple-jwt-login/v1/users`, etc.) use JWT-based authentication as documented on their respective pages. ### What happens if a key expires?[​](#what-happens-if-a-key-expires "Direct link to What happens if a key expires?") The middleware checks the `expires_at` timestamp on every request. Once the current time passes the expiry, the key is rejected as if it were revoked. Update the key with a new `expires_at` to extend its lifetime. ### Is the full key stored anywhere?[​](#is-the-full-key-stored-anywhere "Direct link to Is the full key stored anywhere?") No. Only the SHA-256 hash of the key is persisted. The plaintext key is returned once at creation and is not recoverable. If a key is lost, revoke or delete it and create a new one. ### Who can see other users' keys?[​](#who-can-see-other-users-keys "Direct link to Who can see other users' keys?") Regular users can only list, update, revoke, and delete their own keys. WordPress administrators (users with the `manage_options` capability) can manage all keys and will also see the `user_id` field in list responses to identify key ownership. --- # Exchange id\_token with a WordPress JWT ## Overview[​](#overview "Direct link to Overview") The Exchange OAuth Code with Google ID Token route in Simple JWT Login enables the exchange of the OAuth code obtained during the OAuth flow with a Google ID Token. This process facilitates secure user authentication and authorization with Google services. Below are the parameters and details required for this operation. This can be used when the OAuth process is happening in a different APP, and you need to obtain the `access_token` or the `id_token`. note To ensure a smooth process, it's crucial to use the identical `redirect_uri` in WordPress as the one utilized in the OAuth flow. ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `POST` **ENDPOINT**: `/simple-jwt-login/v1/oauth/token` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/oauth/token&provider=google&code={{code}}` | Parameter | Type | Description | | --------- | ------------------- | ---------------------------------------------------------------- | | provider | `required` `string` | Specifies the identity provider. Set this parameter to 'google'. | | id\_token | `required` `string` | The OAuth `id_token` obtained from the OAuth flow. | ## Request Example[​](#request-example "Direct link to Request Example") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST 'https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/oauth/token&provider=google&id_token={{id_token}}' ``` ## Example Response[​](#example-response "Direct link to Example Response") ### Success[​](#success "Direct link to Success") ``` { "success": true, "data" : { "jwt": "simplejwtlogin jwt here" } } ``` ### Error[​](#error "Direct link to Error") ``` { "success": false, "data": { "message": "The code or jwt parameter is missing from request.", "errorCode": 71 } } ``` --- # OAuth Login ## Enable OAuth on WordPress login[​](#enable-oauth-on-wordpress-login "Direct link to Enable OAuth on WordPress login") This ensures a seamless integration between your WordPress site and Google authentication, allowing for a secure and effective OAuth process. Once this option is enabled, on the WordPress login/register screens there will appear a new button: `Continue with Google`. To enable OAuth on WordPress, it's crucial to ensure that you have the correct `return_uri` configured in Google. note Please make sure to set the following `return_uri` for "Authorized redirect URIs" in : ``` {{your_site}}/?rest_route=/simple-jwt-login/v1/oauth/token&provider=google ``` To enable the `Continue with Google` button on your login screen, make sure you check the option `Enable OAuth on WordPress login` from WordPress. ## Create user if not exists[​](#create-user-if-not-exists "Direct link to Create user if not exists") If you will have google users that may not have an account on WordPress, you can select the `Create user if not exists` option from WordPress. If somebody uses the OAuth flow, and if there is no user with `user_email` equal with email from google, it will automatically create a random user, with this email and a random password. For example, a new user can have: ``` { "user_login": "user_23werowe", "user_email": "some_email@google.com", "password": "some-random-generated-password" } ``` ## Screenshot[​](#screenshot "Direct link to Screenshot") ![Google OAuth WordPress](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAWMAAAHZCAMAAABkTarAAAADAFBMVEXw8PGMj5Tp6erMzMzv7/Dt7e7DxMf///8icbEAc6r+//87kbwOeq7D2eS00eD6//////79/v1ZocT///mWwdfh6O3S4en//u94sc1oqcmlydvqQjY/Rk6IudTw8Oz8vQtDhvXw8PD29/dKmcAsirc2qVWvdVNFifp3ZJLj4uNeZ3Lr8fL83aUegrLZnmjswZPZ2NvM+/+admz5z5Xt/v8WFBf0Qzfc7/ErMjlXjsE3sFe9g1aSxeqUYVRHVXPZ/P5agLW45/H/+cR3uvQmdsr0+/9ipuHS7fHl7/Hv47jt69pEc7O+9f/k/f5aYWnD7PKc2vxusOyAYnzw7NJ8s+Lu2K3w7uRnU13//ed5S2w3LHhMispHYp/814dNU4ZLTVJlZGmmblRCTl+G2/qsf2ep2+/+6addndmx8v0dgrLOn3ZRWpSoqrCUl5qe0PBFSE+6i2itWBbJjlx0Y1/3wYeFsdfhuZDesYZ4sc9okL+BibNcea7+7bmq5vzMqYnmx6GJb3F1LipfTILo8v1qbnLG3u0ic7tXa4hWXGRNpOzrtXtys+fc6fjw7MPF+P+FwfBGbKhblfd5qNFec6RaocVGgcLt4MLu4c5ZUlJxqdrpnEn98OsweLZog7L/+9e/6Pszi9SzloA0qVEmcbH99N5alM+glbTZiTofUaHf9f5cb5v//N4iIDG3+O3hqHH85sJKfLl/VV3s7Oy8p7jJ6e9YtvVrxPfl0bEiPHbz3rOOzvj2/O45gLuw1uqEocPu0aj5yXj6+/g9grqFaWBnaH6miXmjpanEl3Pdv8Oz48E1oORkdZaIzJlpv33zkIjl7uMdZrr44NtfS3Pg8O/uVURPF1Xwal6jy+V3UUhyn80mcLZvfZ6/1vzQ4f7/+tH3rqnj5e3q3dbyfnYjP402GhWf1LFcRkvBcChXJCIxIGnW79n5xsNbMxu/vdPbvpqwckLH0N1Ls2bilkTNtcGDsTj80VUupWLwq1ne1Yd7wMW7viVIppKkrmjYjnO27dyszd2D0Qe6AAAACXBIWXMAAAsTAAALEwEAmpwYAAAZAElEQVR42u2dd1xUZ77GJwZymALThxkCZCkaaYoUXVTARgkIYgMTDShWLGB3sXvF2IVYMTYSS2wbhdiNGmNcY78aE9tuTE822Zhssnf37r33j/u+50w5ZwoMOBSH5/kkOHPOOzPwnd953t9bzvuKRBAEQRAEQa1FPgF6qTRKTBQlleoDfEDEtfLWS8WsZFIiGfdYqvcGGRdJZ6DRG2rQ8ELXR2MIpRGt14GPCyyCRLBM5ae1PaP1U5GIXg/TcAFhqUbr6LRWQ8/DMp5A2vWEoCVOvTV6vT5EatDr/XwE34JBC1YNlEYmDjXB9DYYaz2TQg1+JsqhYpkfaDUoiEPEsgAT4CixHclMXhwgE69HKDcgXYsSh+rMbuBIUi6AdaHiULhyvRHLxAbuQS2EWcpcLBvEMkCupxWLxRrWMAziOsXZhAamXF/EMjY8faLETshYVsZ9LZBzWbHxwteInZSesxfYRX28mIW13lnE4qIA/lcD1Z20RXEXvdOIzQ09jTgKKZxTCuEufacRqywv1YtDwM8J6cXSeiEu4oeuVBwAgnVKJ5NRaAFOe7EAqlYmQ29nnZKyZuztNGKxj1XWB7eoS36cU5Ce4VA65KHScyMgMgPpcDMNgdAzIXpT68Tb+jtCh3IdihJbX+taCtJgp6jBXhyTK0AKinU08FQ22bIjxiF2/JheAgjk2hUqDGONQWrsEgqVrtdreWOoIVJTMzuU/33QShOBXHsLzyqMhT1Clu4InYNKz8eHDWS09mqRSkz7znRCn7AMffDjndfM4w//sdWmASQdS1ZEwfJiuUgA2QI/wH58+7BBLZOBZC2Jm4HN27QOzEIvTDbMfZtaC2MV+yL0JDuUgXVSfj+w0CyibJIKqx4L0vPG/oRZOE6OZWww8x22yEGbTmPXRMhRGsKCXAMSdFWw7WCDwHgNDrrYtHaP67lMWipGp4XI0fCHnm3p8dsVQrOQOTALkyNLuWtAj2aIyGGvJkVjZbxFDlJkoVkYKznancHajR40HWXHOhrMwo4evYBlSK1m4W18qbdtixwyXenm+FTZb9LxnVpgFlJL1sxeC2hOO2IsM8etzH6Tju/UGtusLtSURIOxIxnrKyvjDXCQIgvNwhLyerT0nGQc4sgsHGQWFuvWm1wHcsRYZYSmtW8WKpFds5CKjFkfGDsfxzzjDbCTpJkzNV6+4S0G4/oxDrVrFjJhrifoLTJYHsrAuLa8wuwA3vbMQsWNdYiM3XSCjowoC2PkFbXmxz4mbAZ7ZkGsIlRrxyx4xJEf19nO87a1BR3fKrx5aZ2Kb8cqS/yjnedEf4VV9SblWYWBF6N+/JaJjB/S6K8Q1dbvJrVN0zQ87FH89rTM0sL242Vx6HcT1d5/bOkE0lo36WScleitzaKIZxUGtnWC/mNHCpUJsgWNdZNOxaGMsjYLA69ljXEQkVPjeTYpssbMTyYccpKZUgkNr6bEeJ6otnFpvWB4SSc0C5kpcFVCs5DxOi8MGJeuQ7IowfCSQWgWKpPrWgb7vY3HtfyWSxR63WrNkH347boooVn4mX1EIxiK8rM0U7h5QsiORXXNd/OzHevXcpagsRlyMnD5RyjvBZjvVldzWmc/RQ5hn4TYOLU3C1zHC2PM26yzGaLi91lYjJednaK1M+RURB8HCMIYDRBnJiCH2KTIWr5V8J3aQF8QaqkjdUiO6w5kKXt7ks28V5VBMLpktlzvUHMmwt5FJkXiJqr7Dkg/vluYjdfPWzBKyuvMENwZgvuanLo/j70fV28zHVY46CQT3qhj8mjcn+eUArhIVNlMhxUOnmqs7srhIhv3mTrrFgE8yN4OJgGEWN01osL90vWQtoirtlRWxhvgaFYWrSBVWtaMi3Dfv7PrV3DrUKiExhvq4D5pP9M34Y31K+oPOYBvvNa3UIfy+t40WIdF1ID1hFhc3kUW47VZvcnbfDMU1hNq2BKFMm5dLJXZeG2WbzL2fPrpTetiAXG91xTiUmOdNMCuVVilyFjfrSGQQ8VSLknQ2bcK/uQArFPYwBROJbj67az0Zs6FyXqbKiRtDZKfzLLklU4vlQkXwzL48NaNhRU3OJQNgnW6dWTZf72BLM2i9/EWrH+MIH4iV5aa14a1n39IBatQQw2Sj4q30LHVevTriX2EgLALpNMXsTtV+PEyBx8/di2nIuyr4Pr9QaSssD9IY+5zw97ZW4R9biAIgiAIgiAIgiAIgiAIgiAIgiAIgiCoXvKAHMpFhJ+DapFLKHs+x0AO9ZynK8IYjGtn7AHGYAzGYAzGYAzGYAzGYAyBMRiDMRiDMRiDMRiDMRhDYAzGYAzGYAzGYAzGYAzGYOzujHfpJNaHfBez/6gjJGD8xDowIlXZYajc6uiQEb0pXIXtGXdj7Nsulfyl04clu+AXjfzW398/aZ7tZzwebWa8PXFDHBg/AePboz09PVLsnTKRVEwvMH0JrZDxoZiSwnKJ7/y8wtJ9io7TSpJ6XqosKbwfx0TmlSR1l2yPqfRfOmlaydIdjHrBtIL9O1hiC8iB0ZLtoyr9dxNQkf8xjg1VS9HPEulb+Lbrb4pj33brR4wlj05eKEmq7C3ZNaogKW+o/NCFgsJy40efm1aSP+/A5ILC3XK3Yzz18L7cxYoV+Wc2JhL3zOzS5nS7sTUL8k4xWz4PHD9hTa+Xu+dOzj+T0W5Dypi8gIxRh+kVPybvDzfH5/cl5wLTJWbGvKK+YREL8nJ4jCNvz1sxoRNhX6o9fq+3b7eKJZtGDJXH5vfMXcx99IHEzcG5cdMn7Niilbgd4w7DdkjYZ4p3MuM6bJCTx/0l3Flm7svzer2cw8Tmr2GmVyST8wRnXxLG9NH2xN70HOfHBQUFQ+W8omyF19vCWNEhM2tudTk53Zd6Ra/qU6xXxBLsxo8+PSJhH8PEJhXL3dArdr1ZuW7HgURSa/lXZJkYq7uNVZ67UEA8lIKjYGnE0zJJJGTVU4fSYqlmxrdHt2mzWMIreiimsrCAx3h7Iv3eNsRR/yeMyXdnZmz66EMxxDF8Z+YtLXabOFZP3ZDCqDuQgGR2jco8zcWtgsd4e+LmFGMcG8F1OGzMDGzi2OQVlq/j8D5BHMd+W1hQUJI0zkEcc+96KJE88iUe5Db5cewyffTjvJWSL1adHl+RtSL/rucX+6wYLxYyjsybkZ6xSsL68QzOj3MseYVnioBxl10c43cq9tEvlPh8m5fu9d+e2EM3MLG3euqwM7mTOcYK7qN9oxfvajf2li64I/eFuQVj9WOSQ8yIU48v8CeXJ6nc/ZNy+IyVJHconLCDB05Nj2yWW/IKix/Ty70/3ysuFPgnnaLvdOgCSSd6VZdLWNLEEciJYoYYlH/SZpYxw330gRElhft3dCSHZ8jRzkN/BRiDMRiDMRiDMRgLpZzxgVcr0gczlE3OWJmwNmFr60G8lfy5yqZmPGNtwhJJ67EEyZKEtTOamvEHCUtal/EuSfigqRl7bZW0LsaSrV5NztirtWUQXs3F+PdgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZgDMZg7PaMGTDGnELmKZ5TiLmxmOPtDnO8ca8C7rlxh3tuIDAGYzAGYzAGYzAGYzAGYwiMwRiMwRiMwRiMwRiMwRgknyLGxo09wLjxGBs3RABj59fx9vcvXHpXDsaNyLjb7oiM+bdzwLgxGZP1tclS/NwuIOpZlf4V3FYhK4Yl0/Xm1WS5eLLodlKA3Hd8ZUlFsnFjDzCuJ2Oyi8EpbheQuS8XB3+ewm4VQhbwV3fLX0OCdntigvZxHlnxfGzE58aNPcC4foz9S8ja7yncLiBzqzfHkZ0O6FYh2xPLP7swPIccpJsgkG0qTpNV5U0be4Bx/RgnaCPkjILbBYT8Q9b/Z7cKUU/dHTnnUur0iiy6mQfdHYUyNm7sAcb19mO6OQq7Cwh5TrcPoluFxMVOeDM1dt3kVDni2GWM6S4gQ6KDX6o+xW0V8lliUg79nzH7cX/qIOzGHmDcAMYKbheQudX+haVZ3FYh6g4VyeqpFVkMQ/IMmldQxoxxYw8wRn8FGIMxGIMxGIMxBMbuuQdL9MRJz7QaTZoY3Qz3g0T/KUzZesJVGfan6KZnPDGsdZlC2MSmZzxJ2boYKyc1PeNnWlvt9gwYgzEYgzEYgzEYgzEYgzEYg3GjSSEH48aUOvrs4Z1e740tjgPjRtKtbQ+2er2Wenbrzqp5EjBuDJP44vDyXzK9qpKHbCufuHWkHIwbIYoPH5N/tNPrtZUTt16Rf7RhpASMXS3f2Uflit92smthXZErPqrqC8Yur+/eXR7HbOJWrjsqV/92JQuMXa4ts4/G+e6hiKs6qX+zhDEYuxRy1bzzP5UOXZkcdpaHGIxdahc/Ha76g8YvoHTryn3IjxtL538JuH9/RnEW2nnorwBjMAZjMAZjMAZjMAbjlsMYcwoxN5Zxg7mxmOONexXc4V4FCIzBGIzBGIzBGIzBGIzBGAJjMAZjMAZjMAZjMAbjptSq9xqy+fF7q8DYeb3XsB2m32vWcRCHgwRMi9zIoqHbeDfHeF50jSenmmgHg121ImZXkwXjWselo0XBJomijYO2Y+75+yedzXoCxnPzyslhxYr8vmDMTBKdV5p0XmScfBB5e3Tu8Qtj5Q1nHPltRTLDkCWqx4Ex80yw0mTCSmWwcRIN2VOBxOCwZPWCaQX7dzAnpxX4779YWdgjmfGdn1dYuk8xM6+kcFtMZeHaON922ZXkCGMseuhCQSGN4NgkEsiKFeFk45FdFyu5PQVaM2NL/cdjrBg4IjNrTF5AxqjDcbH5PTclVug2Vq+UrMg/szExVdkhM/34vd3ax7dzfNv10G1MHCu3FM2lleD0ivmZWQcS/514yndqxZEFeTlgbM3424IC/8JTdA8Wwrtv7IROincOx5GdFnzbpUro0Q4b5PQh2d+CeoWC7LZgKUrfQLEic2B1TuywH0aU96o+RRZkT5WAsRXj26M3koX96V5OpPIbRxmvyMwiW94cSKRHKrIIY7qQPdlhwZfbbWGNpSjL+J0N8g492vUf0q733Hv0zG45GNt6ReyEvooOh9llCSyMT7djA1IhZEyt21KUZUx2IJp7L78vOdurOqfx67w+f5xth+ZrI99t0YwZ3267UyLzZqRnrJJYGMtX5N/1/GKfgPHYmuPVqXJLUYbdzWy3XD1+LSmUSvx4SU10XGtmPEnAeJKFMTGMHDXd0WKznMeY5BX+STl8xpcq/ZPuxzGWorwdMVjWJK/wH7amSRhX7QgOm+31YHlacMS7O1nGrx1bHFyzp9nbILzcLXriU9RfYcu4T789D5bfnHPl5javox8ZGY/c43Xl5pzmbkuHmdsgYQ1oS7ckxlc2ZXr1mbfnGOHLZ9znj9ual/ET9wk9DYxnNy/jp1eOvSJj24NjYOxyxuPOp6TcyrzC1nmvHVsVsQqMG7cNstNB1gbGLmNc1S8i/blMMG5VbWkwBmMwBmMwBmMwZjCHBXOxMBeLwZxCCIzBGIzBGIzBGIzBGIzBGAJjMAZjMAZjMAZjMAZjMAZjMAZjMAZjMAZjCIzBGIzBGIzBGIzBGIzBGGo0xlAtcgVjkWdNG8ihajxdgJgEMlSLXBHGlDLkUCIIgiAIgiAIgiAIgiAIgiAIgiAIgiAIciMFzZyT5uBUYLeVTfQ7zL/rNjxzJy/LDp99RHhw0y8R7L8b96TZZbx6wGir47Yln1CBkwdtXDh8aXe3YDxqkChjVEK63ZOD2/dzkrFtySdnnPt50Kx1aW7CWNRxXdrAN8vC16YHLViYHV76ccceXY4vDL/ac/C08A+LuTOrY4aHdxcypoWvnhFZSopE59r3JP/32xiTvVQTQbl37PHxuYXZ+3uS18RkZz88I6LBqfHYdDH8w+7sj1k9Pqa/wmDTi9jP2XRxePhw8nsFkbPuEseTS9PH30/fuLD4pQHdIzrO6ULITN4c4clSCjSead8zyEPImBSumbX/iLkk0cCY7kGzEjJGrU0/PqDYyJi8H53qRN4gd/7+I0EeQQvWpRF2gZ7sD1LopQu7I8wvop9Tc6m0Swb5vYIeP1ziHl6Rnb2sNG1gTHhZ2fDymXO6iFjGXWZ+eFbHOoDxDPnbrb2CFh64sLu5JA3t8Qk3Jw86ScoGTt5sYtyjCz1F32DgwuKNF8vKJvQbPGC2twf7IyOme8eHD4+YX8QWi+lOvcKOJT21cRw4fg5hXE6fzexhYhy06c0PiznG5SZEdhkXm0tSnWx/uX3PWhh3n3w//SQ5njF/2iAP9sf40kuai98M6GmHccZP6SL3qfM211yacyQoLGLwgLskcaOM20Tkkj94wOjANtwZO4yNXmEuSYHkXiorTTde9qsXEuOxMCYlZrLOQhjnphOrbUN/pA8uu9pvluVF9HMCx/dIo4wHvpvmNoxF5z4cPfDN4dnb0gIfl4WXsX58KTz84ZLc+aQC4s4IGVcvW7ZsXRpb5wVaSrIJxnDyD1d9BT2eRirQdBPj6rLsq3dpDVm27sjM4eFL77I/yC+wO4J8W6YXsZ+TQT6SvB35tdyw9RHoSYKoNKKWAnW0QYIWbHMQe8YvCSIVXHitdXntjINmlpFkDowhCIIgCIIgCIIgCIIgCIIgCIIgCIIgqNlE5qssC58RYX9accao7GXLsrMH8covOBsBaPVTxqhtSzy+8BY5nFbcUTgfmMzRTAe1upU73xK3HfdzSMlcqPCzdAYVO63Y/IxjTKYdDydTsMisrW1dZi0L398PDOtEvM48L4jMbGVxB47flrYpZpAxji3POMYvtT8TOL8HmdMq8kQcO6XB05axyi43Me647QfCj06pFBknIJuecYxnZpeVlc1Ju3RV0wWMnVLg/KuWOCZzVwnHOXUw5m56Cjx+cf8RMHYS8gwPy5TCUh2d4212B3YCspVXnBwQEJGrDfxctHphccd1R2qQWdRP5GYXes/NQFMtx04rtq3zyORgOsOztMvAi9lLRwMbBEEQBEEQBEEQBEEQBEEQBEEQJHK3PSNbOGH7h4PCnm2RCguq15/RMmR/k9qg6LCWuTl0WHRQPf6MFhLGdn85j7Cw4JbJODgszD5jj6eNsehZqz9NQf679ejRjRuPftzCPW02PeumjBXMlkefPv98Z6Ln73z5Y7NCdk/GSoZ5dIfQNapz5y+3II5dzVh9wwyYo3znVvNFslsyVii+7GyKYC6aO396iwY3GLuKsZIxRnHnO1/euPHp850JYniFSxkrmB+52L3ziCV76wZFjDrPpXGs/pQyZus5hYKyJdmbEnHsUsZjXrhDHfg8oySAJRIl4auUUIGxyxj/1wsvvP08P5Fwwifef2WNM+fnPkyu440UKxLk7s94yAtUNzh7UKbwxAbyyXvx8V+tEVDZLWd2/ZRSKzpynhZ79ZVOxhfN/Ft8/DA7wBVv/GcrYHyIZTyXOrGE+cvrPK2ikbjog32+z8bxqbzdR+7EFc8WMzN+/+DmlF2/yFsr4zEs410Mx/hFnv5MEXyVRQvF/i3+xDz1d/Hxvz+leDs+/gGBt+Lr+INj5e9/lew75ai6w9fxmVnUIjptX3SM4CXn2WJfx7PHfadw38uQn+MP7k7h3o05RK6QvcmE8YGfvybv5P6MhxDALOPfmUUZq79j4fRalHr67b1ZU5arf90bZwxQAuf9v47jGL/6yo7PFh2j5UaO+bpqyJRjlDFbbM1cevyzRUe5oD2xJvL7Y6Z3e5DFvc0be7MiPxnXiuLYLuNX/7qGGfPJuCnLGTM8Cocg5Ri/EX/wYPxyCaOesvxfhXtXfzLOUowcMjJm30Ci/q6Ke7fLi0Zyb3N+Cnn1wZGtwI+VfK/gIFOv+JX1Cj7jNULGr3QijEl0c+76r70///vl/9sbJ2AsIV5RJa+F8RVJa8gr/ucal1fIF7P6M0uZ1nljvh+a5Ru92uQVlDG5tIPNjMd8MpJ6xcFTki0pbPETfb87uFxCz3PFWMakzhuUQhjzveLjKX3i3qfFUn49sUPtKXH3/Pgfbbve5LftuhPGL77OVkPnFsXHn+jL1Xkc47mL4vf+t4mxeiqp+sppnXeiL0MrN9alaYAai3GM1e98T9/mAK3z4hRcnRe5KP7giU6R3x8lR+N3xrl5O+8f/2zb9Tpp5xHKpJmnZFZRt3ixvLFHleTqN/bGtZL+iutd275FIJMBPgqYYVa9Tq3ixb80LmI1Se5O5LSOtrSSudy1LYX898sR9PnH3/zv72gY91dK0F/huv7jaySQ32pLKF+/du16165v/bOK5BarGDB23TiIUnmNjWRCmagtfSgliZsS/W6uHM87f41Dy4pGdFdvjDW5fFz68t+JR3CI3+ra9foPzdhL767zKyRM8DfXjV7R9frl883lxe7MmIat5IfL31y79s3lm9xTMHY14xYkMAZjzNtsQXH89M0/fvoYP3Xz6J9Gxk/ZrRVg3AQCYzAGYzAGYzAGYzAGYzB2zS9X08YNVNOiQ8XD0y3kgbUVWvfaChAEQRAEQRAEQc7p/wE2cPFlltJl+gAAAABJRU5ErkJggg==) --- # Exchange OAuth Code with Google ID Token ## Overview[​](#overview "Direct link to Overview") The Exchange OAuth Code with Google ID Token route in Simple JWT Login enables the exchange of the OAuth code obtained during the OAuth flow with a Google ID Token. This process facilitates secure user authentication and authorization with Google services. Below are the parameters and details required for this operation. This can be used when the OAuth process is happening in a different APP, and you need to obtain the `access_token` or the `id_token`. note For this, it is important to use the same `redirect_uri` in WordPress as the one that has been used in the OAuth flow. ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `POST` **ENDPOINT**: `/simple-jwt-login/v1/oauth/token` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/oauth/token&provider=google&code={{code}}` | Parameter | Type | Description | | --------- | ------------------- | ---------------------------------------------------------------------------------------------------- | | provider | `required` `string` | Specifies the identity provider. Set this parameter to 'google'. | | code | `required` `string` | The OAuth code obtained from the OAuth flow. This code is used to authenticate the user with Google. | ## Request Example[​](#request-example "Direct link to Request Example") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST 'https://simplejwtlogin.com/?rest_route=simple-jwt-login/v1/oauth/token&code=my-code' ``` ## Response Example[​](#response-example "Direct link to Response Example") ### Success[​](#success "Direct link to Success") ``` { "success": true, "data": { "access_token": "access token from google", "expires_in": 3599, "scope": "openid https://www.googleapis.com/auth/userinfo.email", "token_type": "Bearer", "id_token": "id token from google" } } ``` ### Error[​](#error "Direct link to Error") ``` { "success": false, "data": { "message": "The code you provided is invalid.Bad Request.Invalid_grant", "errorCode": 72 } } ``` ``` { "success": false, "data": { "message": "The code you provided is invalid.Bad Request.Redirect_uri_mismatch", "errorCode": 72 } } ``` Security Considerations Always ensure secure communication with the API endpoint using HTTPS. Protect the confidentiality of the OAuth code during the exchange process. --- # Setup ## Create an application[​](#create-an-application "Direct link to Create an application") To enable Google authentication in your application, follow these step-by-step instructions to create a new project and obtain the necessary credentials from the Google Developer Console. 1. Navigate to Google Developer Console 2. Create a new project 3. Once the project has been created, go to "Credentials" and click on "+Create Credentials" 4. Select "OAuth client ID" 5. Choose Application Type "Web application" 6. Configure Authorized Redirect URIs: In the "Authorized redirect URIs" section, add the URL where the OAuth flow will redirect users after successful authentication. This URL is crucial for the OAuth process. 7. Copy `client_id`, `client_secret`, and `redirect_uri` note If you want to use OAuth on WordPress, you need to add int the `Authorized redirect URIs` the following URL: ``` http://{{your-wordpressdomain}}/?rest_route=/simple-jwt-login/v1/oauth/token&provider=google ``` Important Notes * Keep your credentials secure. Do not expose them in publicly accessible locations or version control systems. * If your application has multiple environments (e.g., development, production), create separate OAuth client IDs and redirect URIs for each environment. ## Google Setup In WordPress[​](#google-setup-in-wordpress "Direct link to Google Setup In WordPress") 1. Go to Simple-JWT-Login plugin -> Applications 2. Fill `client_id`, `client_secret`, `redirect_uri` 3. Change `Allow Google` to `Yes`. ## Screenshot[​](#screenshot "Direct link to Screenshot") ![WordPress Google Settings](/assets/images/app_google_settings-488c81a6ad4ed2b01d0c36ad64f51936.png) --- # Shortcode ## Shortcode Configuration[​](#shortcode-configuration "Direct link to Shortcode Configuration") To configure the shortcode, utilize the options provided by this plugin for generating the "Continue with Google" button: ``` [simple-jwt-login-oauth provider="google"] ``` The shortcode includes the following customization options: * **provider**: `required` Specifies the provider name, e.g., for Google, use `google` * **background**: Defines the background color style (e.g. `#c8c8c8`) * **color**: Specifies the text color style (e.g., `#f2f2f2`) * **width**: Sets the button width (e.g., `250px`) * **height**: Determines the button height (e.g., `40px`). * **border**: Specifies the button border style (e.g., `1px solid #000`) Example of full shortcode: ``` [simple-jwt-login-oauth provider="google" background="#c8c8c8" color="#f2f2f2" width="250px" height="40px" border="1px dotted blue"] ``` --- # Audit Logs Audit Logs give you a detailed, searchable record of authentication events on your site. Every login attempt, registration, password reset, OAuth flow, 2FA challenge, API key action, and settings change can be captured and stored in your WordPress database. Audit logging is **disabled by default**. Enable it in **Settings → Simple JWT Login → Audit Logs → Config**. *** ## Configuration[​](#configuration "Direct link to Configuration") ![Audit Logging configuration](/assets/images/audit-logging-689ba38e8dab82ff771ea5a82ddd38f1.png) ### Enable Audit Logging[​](#enable-audit-logging "Direct link to Enable Audit Logging") Toggle the **Enable Audit Logging** switch at the top of the Audit Logs configuration page. ### Events to Log[​](#events-to-log "Direct link to Events to Log") Choose which events to capture. You can enable all events at once using the **Enable All** button, or pick individual events using the checkboxes. Use the search box to filter the list. The full list of trackable events: #### Authentication events[​](#authentication-events "Direct link to Authentication events") | Event key | Label | Description | | ----------------------------- | -------------------------- | --------------------------------------------------------- | | `auth.login.success` | Login Success | A JWT was successfully generated for a user | | `auth.login.failed` | Login Failed | Authentication failed (wrong credentials, disabled, etc.) | | `auth.logout.success` | Logout (Token Revoked) | A JWT was successfully revoked | | `auth.logout.failed` | Logout Failed | Token revocation failed | | `auth.register.success` | Register Success | A new WordPress user was created via the API | | `auth.register.failed` | Register Failed | User registration failed | | `auth.password_reset.request` | Password Reset Request | A password reset code was requested | | `auth.password_reset.success` | Password Reset Success | Password successfully changed | | `auth.password_reset.failed` | Password Reset Failed | Password change failed | | `auth.delete_user.success` | Delete User Success | A user account was deleted via the API | | `auth.delete_user.failed` | Delete User Failed | User deletion failed | | `auth.login_session.success` | Auto-Login Session Success | Auto-login via JWT completed successfully | | `auth.login_session.failed` | Auto-Login Session Failed | Auto-login via JWT failed | | `auth.refresh_token.success` | Refresh Token Success | A JWT was successfully refreshed | | `auth.refresh_token.failed` | Refresh Token Failed | Token refresh failed | | `auth.oauth.success` | OAuth Login Success | OAuth authentication completed successfully | | `auth.oauth.failed` | OAuth Login Failed | OAuth authentication failed | #### Two-Factor Authentication events[​](#two-factor-authentication-events "Direct link to Two-Factor Authentication events") | Event key | Label | Description | | --------------------------- | ------------------------ | ------------------------------------ | | `auth.2fa.challenge_issued` | 2FA Challenge Issued | A 2FA challenge was sent to the user | | `auth.2fa.verify_success` | 2FA Verification Success | 2FA code verified successfully | | `auth.2fa.verify_failed` | 2FA Verification Failed | 2FA code verification failed | #### Settings events[​](#settings-events "Direct link to Settings events") | Event key | Label | Description | | ----------------------- | -------------- | -------------------------------------- | | `settings.save.success` | Settings Saved | Plugin settings were saved by an admin | #### API Key events[​](#api-key-events "Direct link to API Key events") | Event key | Label | Description | | ------------------------ | --------------------- | -------------------------------------------- | | `api_key.create.success` | API Key Created | A new API key was created | | `api_key.create.failed` | API Key Create Failed | API key creation failed | | `api_key.update.success` | API Key Updated | An API key was updated | | `api_key.update.failed` | API Key Update Failed | API key update failed | | `api_key.revoke.success` | API Key Revoked | An API key was revoked | | `api_key.revoke.failed` | API Key Revoke Failed | API key revocation failed | | `api_key.delete.success` | API Key Deleted | An API key was deleted | | `api_key.delete.failed` | API Key Delete Failed | API key deletion failed | | `api_key.used` | API Key Used | A request was authenticated using an API key | *** ### Retention Period[​](#retention-period "Direct link to Retention Period") Set how many days to keep log entries. Entries older than this threshold are automatically purged by a scheduled WordPress cron job. The minimum value is **1 day**. Default: `90` days. tip For compliance use cases (GDPR, SOC 2, etc.), set the retention period to match your data-retention policy. For high-traffic sites, a shorter window keeps the database table from growing too large. *** ## Viewing Log Entries[​](#viewing-log-entries "Direct link to Viewing Log Entries") ![Audit Log entries](/assets/images/audit-logs-2a9144c55f664427be80cd5508f0791f.png) Go to **Settings → Simple JWT Login → Audit Logs → Logs** to view the stored entries. Each entry records: * **Event** - the event key (e.g. `auth.login.success`) * **User ID** - the WordPress user involved (where applicable) * **User Email** - the email of the user involved * **Status** - `success` or `failed` * **Details** - additional context (e.g. changed setting keys) * **IP Address** - the client IP that triggered the event * **Timestamp** - when the event occurred *** ## Logging Performance[​](#logging-performance "Direct link to Logging Performance") Audit log writes are dispatched **after the API response is sent to the client** - they never block or delay the response your app receives. The plugin uses PHP's `fastcgi_finish_request()` to flush the response first, then write the log entry in the same PHP process. If that function is unavailable (see table below), the log write happens synchronously before the response is returned. Database writes are fast, so this rarely causes noticeable latency. | Server environment | Async logging | | ------------------------------------------ | -------------------------------------------- | | **nginx + PHP-FPM** (standard nginx setup) | Yes - response flushed before log is written | | **Apache + PHP-FPM** (`mod_proxy_fcgi`) | Yes - response flushed before log is written | | **Apache + mod\_php** | No - log write blocks the response | | **LiteSpeed / OpenLiteSpeed** | Depends on version - generally no | *** ## Use Cases[​](#use-cases "Direct link to Use Cases") * **Security monitoring** - track failed login attempts and unusual activity patterns * **Compliance** - demonstrate an audit trail for authentication events * **Debugging** - reproduce exact event sequences when troubleshooting user-reported issues * **Change tracking** - see exactly which settings were modified and when via `settings.save.success` --- # Auth Codes Auth Codes are an optional security layer that adds a shared secret to your API requests. Think of them as API keys: a caller must include the correct code alongside their request, otherwise the plugin rejects it. You can require an Auth Code for any combination of the following operations: * Auto-login * Register User * Delete User * Reset Password and Change Password * Authenticate (JWT generation) caution Use long, random strings for Auth Code values. Short or predictable codes offer little protection. Treat them like passwords - store them securely and rotate them if they are compromised. ## Settings[​](#settings "Direct link to Settings") Go to **Settings → Simple JWT Login → Auth Codes** to configure. ![Auth Codes overview](/assets/images/auth-codes-2c1bbad70d68b7c62dc8a0b0a81c83bc.png) ### Auth Code URL Key[​](#auth-code-url-key "Direct link to Auth Code URL Key") The query parameter name (or body field name) clients must use to pass the code in requests. Default: `AUTH_KEY`. ``` ?AUTH_KEY=THISISMySpeCiaLAUthCode ``` Change this if you want to avoid exposing that your site uses Simple JWT Login, or if you need to avoid a name collision. ### Auth Codes list[​](#auth-codes-list "Direct link to Auth Codes list") Each code is a row with three fields - add as many codes as you need. You can have different codes for different purposes (e.g. one for mobile apps, one for server-to-server integrations). ![Authorization codes list](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAACoCAMAAACL+r3JAAADAFBMVEX29/dQV154gIf3+Pnc3N5sdX0dIyf4+fr////i5OeZoKbe4ON2foa6v8La3eCLkpiJkJbz9PX29/hzfIPl5un19vfV2NuCipHO0tSGjpRxeoLQ09bw8vPt7u/g4+Vud3+XnaT09faPlpx/h4+TmqDX2t3u8PG8wMSprK++wsbLztCxtruepKrN0dTl5ufq6+2QmJ6AiJDm6Orw8fKaoaamrLF6gol7g4pgZWp9hYxweIFwdnyhqK3x8vTd3+Hy9PSzub3j5OZ+ho3u7/COlZvJzdBdY2i1ur7CxsqipqprcXakqq95gYi9wcVobnPGyc3c3uCFjJNkanDo6utveIDr7O2Ei5JXXmSFiY41Oz6XnaOprrPs7vBuc3mssLbe4OJ9goaws7aMkJLEx8nh4uOgo6VyeoKWmp5ARUna3N2qr7Xi5OV1eoBUW2G2u797f4Tm6OmPl53V2NnN0NLp6uuwtbp8hIvGy87b3uFaYGfIzM/U1tnj5edzeX7Y2tuKkZhhZ23BxMjr7e9/g4igpquUmqHU1ti7vsBpbnShp6ycoqjIy83Z3N6+wcNITlOrrrGnrbKbn6OTm6Dg4OKMkZWwtLlcYmmmqaxGTE9aYGPBw8WAhYry9PV1foW4u76yuLyJjpIhJyttc3iMk5mTmJzo6uwlKy9XXF9YX2aZnaHDx8v8/Pxtcnb19vaRlZqHj5V4foKDi5JzeHxSWF/Q09W0t7mVnKKoq66usbSGjJEtMzedo6gkKS1BSE9NU1oqLzOlrLA8Q0ri5eatsrfDxcg9Qke6vL5ye4O3vMCKj5OZnZ/x8vLS1Nd1fYWVmZuytbeiqa45P0K/wsfLz9KDiY1mbHKChYmcoKRRVVhOU1YnLTGxtbrr7O6/w8cyNzuSlphkaGyFiIyus7iJjI+4vsGkqKuhpKiOk5ZUWVzKzc5na22+wMJrb3Jxdni2uryssLNESUyDhop3fH/EyMyfo6bP0dOqrrHf4eO8vsEeJCh5foMvNTieoaO1ubyBh4x7foLdcUFHAAAACXBIWXMAAAsTAAALEwEAmpwYAAAYSklEQVR42u2deUBVxR7H53I9Z+iqIJsmXlAk0ZTYXAApKDFUNFAWMRVFJFERF6BeuCDu9DTNyg1yBVNTsVwyzaVn2mKaLfraeJUtmr16bfYyq/fezDkzd5PM8r77fPj9/OE9956ZOTO/mfNh7pzjPcQdAACA6yH8H69w3xsAAAC4BN/wIGHfRDMFAADgMswhmn0TgxAKAABwJUEhzL5BmPkCAICrZ79BxD3ciDgAAIBrMYYTd1+EAQAAXI0vcb8BUQAAAFdzA+wLAACwLwAAwL4AAABgXwAAgH0BAADAvgAAAPsCAACAfQEAAPYFAAAA+wIAQIOx7z3q6Pp33K12+LU8l9n1K4xQH0enAQAasH0/rZqX8CtZtqvq53YfvKouv5x9P99w4dIPY9QJv7ZLcFvuwr0/rTgD+wIAriv7njIYsl4e6VfPnsSDqrpv4u+wb73o9r0MnZer6vvv7DsI+wIArif71p0yXKwpNZTW7Lxk1xn1/SPqq2xjrbqKDlfVuRNUzjFm3w9G793emdJGX7z+7tu7KZ2rqkcXrh3Olxc2aGmO0vy96r7lf62jy/nb9/WVh8oNe99fMV/T98d6AZwcVX2G0sd2WYujf194cEMut2/IN6PfXX6U/SzxzxsOqkc+RS8CABrO3Pf7uD6ltWf2FBrSzsfb73lb/fa0+rVm33mafVetUO/OzQ27R9239m1u2Pif1He+3Kd+wO27b8uHYVyxn+bmxqjqCZqzMOfbu9Vv6c+j1bdzP9Dsu0r98fMkde1IZl919KCDrACN99Uv9A1rcfvUt7ccZPb1+kx9Z9bX7JPv1ddzc7+dgF4EADQc+/p+lWYwGCreOjPOYIjrYPP0iyJVrSxW1cNW+1pWHtSObE34c/oxf/uzepDb9yyVl9aO/aTmUlrCtpapd8uVB77rM771hfohK2BtlFaANvlWmV01LMVpzudz3wvq2pk0Vd1L56tH/t7xNnQiAKDB2Dd96qz2Bh23NUy/Nrty1LuNdLT6JbfvC7SRrX1fp/Sv6gq6hZmUzlPVicy+ZdK+Y+5Wn2TbL3x45Ee25mBr39fVfEoHsSLuUY/oBVD9doh/6xuW4r5UYyjtwOzbR9UZQ79l/757FL0IAGgo9h1kyDkr7GuYZTB8Zd3jtVc33+OJ9KC6iJ7g9j2qLURoV924PD/mFn2VTU2ZfYcLxea9rn7BJtB1j6v/npfL7fuhJmN97rudy/hDawHC8o+P0NZ9LcWd5hunmX0r1bUvVFZWLgpgfyYqWWmJ6EYAQMOwb2Kh4clPC6V9F3cMse76SlU/27CBXUS7h2lzee4Rbt8T6tpvzlrlGb/Xuu4r7fuO+u7Hubmp6T+qZ/sc4fZlU+jcDo7rvrb27fw1uyy3Ye9Ba3HH1qpffPwus6/fBrZonPvFaDp/RW7ul+paPJMZANAw7DttfrbBsLS2pooLeFqF3SOPV6if8ZcP1XdoWdK+I0e5fb2YjB+3kWd/fpPCImpr3/fFPQ8/71MXnub2LXtdVZP0RYnD/J6Hc9TBvtr9vupnZ6zFsXsefnznG+2eh4+/fvfIhm/o8BVr2ZW6XehFAEDDsG9c4ZrD59kNv8ln/llVOK4CD5wHAACX2HeWYfuawjWf1iw1GHKOphlqESUAAHDJuu97F+PYmkPKslUvZ7HXfyFKAADgEvt21uxrMOxY02pR1Y67ECUAAHCJfV8S9jUYNpVG1XkhSgAA4Ar71hrWnRT2PWOIaY8gAQCAa+55YDf59tGpMBh2I0gAAOAq+9qAnxADAIBr9NkW7dtcbm/LG51ZYVPTy+4ubub8Mv+fcWv8BzL5+jspsL9/OPxafZ07iOh9C+r9eEk3fyeE1azgUgn4L9m3+rjNj65P9XeGfbstcLV95RFvvunSMv/c67dy/3aK343XqAj+0kJR7uuaQPvO/n25tWY4zb4hnS4b2F5t+b/+zf8H9v3Vdv7OKL20vr79ARlTKewLrmH7Riluf4J9nd4Rvd2UcG7fJ4zHgrv+j+37G4FtAPatn8bdKOwLrmX7dqoeywdx21RK7/SkTRRFadx+8Gs+A9rpu4d2Oa6EUjo+1udZ9su7xcErh/ETJzXS/+GhNDG0n9JP/02c9tP9PYso9X4+VmnRuQ0rRBPgHbPdort62aTzGxLp0yZKy2Fc0kIZNYWalrT1jwi37DCFto1sfL+nf0tmU7PJf8B4XRKihADT8di/yaNQt7HVkaIm8oiN2WsThzKbss+0PyeBTdp3G1h0Z/Dx9yzN1SthSSFrIRodX929dXsa9MDK6E72uU3P9twWUWdptWl22wHseL0GsyKee06PW9slzXpp9qV0dTNp3/ZtB09v6j0s+vhz3pS+GbwylMVS1ES2LdWzdevb9WZom9rKwSgjfWAl+yPxEnWb0cKnL8ssQuT2fHUwf+tY9kcrY1czZ4iy+cqDFqxLA2tnX3FAPaQO3RXY5KGeJvleHlYMh3oiZNGaXl8xEPRayEEku0tk1003WKta82C2PbCV/UATI4ZjEyWtSLbyIDqBBjYbNee1sTxRO61bpwzoXh0mjswRMRBdRycPVNwWWMJKLZ+kR/i3KOaLFytjZ7BIit4BwKn2jb35B2WmRUf63Dfj5rrnB2h7vZs9PZUW0e+azE3vOZiGZcwY+kDGjbR5v1sCPvKktz/sSxfo84KX+g+93c2PDolsbhze2TITXdA7sfmAT2zSPbZ6aphpsLavXfT9xvVTqSm2VdRNXS07TN3W09ua3DV0sttQGjo9am43XRKihEm3RrULniKP4hbhJ2viMPe1L1PObANbPxT+idvgwGM+gbK5ohIyhcghGr3+xXsT/RbQB1qGtYtuapfb1C2cvldtabWpXzod1pXOzDBTbze9IunK1KaRun0fa/uaxb7KXPbnztPDd84SPZatrfYVbet+i9djHnoz9E1OdH8a3COQdutP3SbF9w/uaAmR2yQ/v54dLyl7hlvzsOkO9mXBqiewdvbVDyhDat9dgcq91vfisHI41BMhi331+oqBoNVC5rJ0l8iufwsxRbXbZrWv3UATnUUtodFy8yI1++qd4Bfba+idPmN10bK579Tu7ROHRCfoyRgyBqLrbnkx1WvmHbKaHP0Tv8jZAd9l9Nci6alYRh4AzrRv89Zm+tRLDvZlZ2aQEsR3e4zSHoUcsZrSMOW21U+z+ZDPjdTEZkjGJhPHN7vDtqj77qf+RZesPMx4mtqn8/XRXjyatOK/92NiJ8rO6ZYdpufZ4fmK6eAZxoz7tXkjRy+h4EV2BjUNlUdxY3MjURMH+9qXabEvb9IolunhJ2RzRSVsVx5YDtHo8T21OXoG+xbwRku73KZhPEAzZat5pY+x4016g97SQ3yjaEZDlP7auq8yMN1iXy417ufhsVTGUtREtM046q4g0QyxyXl2fGLw2PZ8CuzGHsw3dpgMEXU7xua5wy4pO+IlPvOzt2+regNra19xQBlS++4KVIKs78VhRRPqi5DFvnp9xUDQaiEbLrtLZteDHaYNP2lfu4EmOotaQqPbt5V+1U10QvNoMQCEfVezNhuji/Vk1BID2XVz3nOspv5JOx/WHX8eIiMpRx4AzrTvbDaV6TXQwb58uqMtW9KOLbRUAyfzT+7o+hCfzt1IWyqcKWZTrE9Xo1h56K4orTorAXb2jTLFKoontabzfojrSP+KN2xA65sCtDVadq7JHfztEK30e0MU9kDOybok9BKKtR095VH4Yp2oyaXrvjZlWuzbRGRi++WMU6+ETCFyiEY/1Jf/G8KP1ryfXW4TOyfp8XjRank8+kRP2kV8hY5lH7Hpt7bywJD2bcNXETWojKWoiWgb/ZNn6wFiVqdvct54evIDN3bpzT50Y7/x2elWGSKtPuytY9kD2TQuwMG+jesNLOeTai601gvEAWVI7btLa758Lw4rmlBfhCz21esrBoK2V+Qq4BXl7ZTZ2ytKdYhi1qom7Ws/0PTOopbQ6PZtLOyrd8KdXON9rfbtyjux7V2WlV0ZOdF1AybbVpOjf3InHwKdushIyt4BwIn29RqljatA+nBvNjvxpGGWq266fT1e1KY8EUxPE5WE1WyHkU1b5sglMGOrfnfy10M+U+poj1by0k20cGGXWwP9envapLu5mcdtUcK+bF3Vs6s8aeQO/nb8s2IexE6YXs1sjuQRrW+Lo/ATStZEHvENG/vKMuuzr2iuqIRMIXKIRo+fpFeDFT2jpb192Sk9UwmXrZb29XoxKiNd/0ahRdXNux77UnEhXsZS1ES2jRXcd6DeDH2TM3VU3yfM3Wb3otJ7IkSO9pVlR7AKLWD2FWVL+9YbWGYafnHKV5vK8wPOsa5v2nSX1nz5XhxWNKG+CNlezmIp5UDgb2XDZXfJ7JaqsXVfj1iu1FaXDDTeWQ5RcrBv8ybsz/zDNnNfnia22GJfEQPZdXNWO8ZR/6SdDysmdIiMpLV3AHCafb9rwpfDJj1Ex4bSxIFsmqqst7Ov9za23MfWfSM7076D6aHuBfRm5UbaqkcBNRbTdiE0vId2Gv1wn5EWsanEkJu8KFuR3Zaql97mb9TY1tMmXVM29u/VT+c7ptKgNmPlSSN38Lfr+7HLHfFR9NlQGhKpS0Ivwei5xEjDPeRR+CkjamI5YnELP+pY5pBbL7WvaK6ohEwhcohGp/vMpXzd12RMaNbU3r7H36x7utrSamlfGrqtWi/ogTnsnyCfN+uz7/MRIdTrGD304h30Zrb8KWoi2maeotmHN0NsavTzWU+b+SywaEKGyNG+ouwZT5mNocy+omxpX8fAdtJdHXL8O2q8dbo8oAypfXdpzZfvxWHlcKgnQqnd7OwrBoL2VuaydJfIrq/7htLOLdmqTYYvncEiazfQRGfxr0LWKDna1y/2CfqDv9W+Yf6N6eToxyz2FTGQXVd8XxTl677WOOqf+EXeRX1XxmuR7KJ4yZEXNQSKAU6zb4Q2nCa7eYeY2j7VlZ0fXfk9D1b7sou9Pvzy/yexPl3Yl8I3WzzVhX1bpsUtMwa0ob3ZHRLiEv9rwZO6Rrai7Jo7vxthcmv9nofh0dVPs0Kt6RJaNpsjTmePYPZN0yxPGrlDmzYdivDvMSmMLTdEtnhO148ooXOoW5PqN+VRtBNKr4nliH7b+D0P9mUWuMl7Hqx2EM0VlZApZA7R6Ps9M/g9D6+xS/JGe/s+36I1v+dBtNpi32OK/gNyfqM0e/VtU599jat7jJreid8woAxhl/5l4PW2mXsqSmx/rRliU8PE5oJDMozWSZoIkaN9ZdlLjnfnV+pF2dK+joHNEGuhxT6KEvwDlQcUIbXvLq358r08rBgO9UTodpOdfcVA0GshB5HsLpFd3POQcV8v9ids8qQBs1lk7Qaa6CyeyholR/vSwG1Kz1uXWOxLiwZ2r55KrfeUiRiIrqOpT2n3PFjjKD5Jn+Sv1XFJj8iPWCTFyGunQDHgv/t/3QD9Yzcpr88IoU68Wfaq+N/epXrTVdyXfPVXt9r0xhgFsO/1Zd/nnqWw71URlk7DI+deTQkej9EFx0MwRgHsez3Z16xEhMO+V8cURelxdb/S8Z7SumURhiiAfQEAAPYFAAAA+wIAAOwLAAAA9gUAANgXAAAA7AsAALAvAAAA2BcAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQCgAdgXAACAy2H2dQcAAOBiYF8AAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAKBB2ndzQF4jAAAATiIvYPMV2XdzQYmZAAAAcBLmkoLNV2LfgBLECgAAnElJ5pXYNw8zXwAAcO7sN+9K7NsIgQIAAOfSCPYFAADYFwAAYF/YFwAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAAD2BQAAAPsCAADsCwAAsK+T7ftoh99KMWLQ5fZuWoweAgDAvhaSDYxZV2vf+CzYFwAA+/4u+65yxtwX9gUAwL5/yL41VYQsHrc1YVPFxkEFhMTsSi4/0T8ua08iGbM0f8KpXbp9547LijumpZcJJ8wjpHIcWcom0GUjTtZszN6pF5u+ptTwKCH/TNv4ciIhHtOyqmqYfS8kZ1WlE3L4QXQWAAD21V5eqfjl+6xA0nnZ8Pg9J5l9c8bM33jxXHzcCDLG0IeElZ/j9k1ceiL9wZh0nl4mFPbV576Fuyaez9aKC5r2r3hSTOYtPXdowkmScKom/UThYvJ9+cioM+MIqV2DzgIAYN2XwaalZUvTdumf/LCR2TeVkKrzhHQ4y+z7CiHna7h9T/D14ZO/yKw8oZ19pzGL89RskpyVyF9ylrFFCUPizqUJbHsx2bObkK1LA9FTAADY17LuuzW7nC8oHF23w2BIIDFlhOx5RlvKHcMcS776F7fvJm5qNhW2SWhnXzYXJjvC+O7KZK3QbL7EYPCo5BNitvIQp+XviJ4CAMC+Fvt2SJ7GbHti2tzEAgf7GqKYOmu5ff/5siWbTFj1D0J+GWdz1U2379wsbQqcw9aKA/ncdyshsxaTql3oJAAA7Gtn3zFZRfEbG5FnmF/7ONh3x8mwyqyO3L5h5YcJKSrg6WXCxWdJSfY4EsCla2PfoDg2Q2brvhWZpIat+6b9g5TtWExSTzUiWw/jqhsAAPYV677ZCdlshXbEuoTEuO1VjvZduqiw/IR+z0P/nKy0nHieTSbM3DNhXT67kJbP73mw2pdE7dnI73n4Km3jmgB+z8O6cYPY4vLhuMLsQbjqBgCAfa+AMUsRWQAAgH0BAAD2BQAAgN84AwAA2BcAAGBf2BcAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQAA9gUAAAD7AgDA/6t9wx9pdI3zSDj6FgDQ4OwbHma+1ttlDitB5wIAGpp9HzFf+w0zP4LOBQA0NPv+X6wDY7EaAAD7wr4AAHAt27d05BUkGpld/+eFebAvAOC6sO+ZlJjlKSljZi0iJKYjyU/5S9rLpG7NlnUvB5BVKQtLUwg5n71lwhiS9CQJWL5b5BUJ7CipSkpb5HCM+TH66/kD7ImcyeyRmtPYk5AvjrHa95JMsC8A4LqZ+3ZMYv8I+xKyn91m0IE9LfNT/hD4bPbc47IDZjK/liQtndihcHdRIft0S6VI8GrVlqy3CHmwouJiGDm63Su9fC5XNp/7TohJ62O1b3mHTRb7Prq/PGUXGRmXUzprq8z0YHn5uEOkIDltwo48Ura9Yl0x7AsAuA7tO6/0XIK2i9s3bOGFTLaZdPRM2qO7SXIqGV4oE+SfSggw5GWWmsnuHJImnxafzew7cRkJWpgp7Zt6ui7LOvct1ea+BwrM5edEpkw2NT4/iNTWkJ1/ySPJRaTMAPsCAK4T+/6FIe1LKifEPXlI2JfMfTQ57hxJGp705Fu7yYUJpGaZTJD/KvPpvI4LU1LKN5LCYhv7khFr8hfGS/vmpJKckQ72ZSsPJxeJTPPT2FFKSXYlIQfytu5PSUkZHQb7AgCuv7kvp89FaV/GzgNeSXW185l9t2ZNzAqQCYR9y7X3fBo7MVPYd+T2IHJA2rdkPzN7Dsm+QEjcKmnfOEIGLRKZuH2PWew7OgHrvgCA69O+tWzJ9qtvhX0vsI3+B4KS6ghh9iXLtjxqSZBfQRIMeXVs3WDkM2RZXEJmxYPCvjX5JHW/tO+yk+w63cKA07Vk4oGdbA2jo9W+eqbMA5nkzBpSu4mUsZWHLS+QiWdhXwDAdWVf/Z6HvPK4UzHx4p4Hr3FbKrIeJNK+AfvZ1FUkyD/9TQq76lY5rSKriGzNT0pjaxLJKQuTUs6VJVds+qaczGe3U6TMi5nPVx86lBkK9w9iW0cNFbXSviLT38dtz5lICrYnr9mYR8ZczC7cBfsCAHC/rx2HL1q389/C/7YAAMC+LrFvTmkB7AsAAPifxgAAAPvCvgAA2Pe3f2HylWu/Ya/gFyYBAA3v19ULrnn9vlKAh1sAAPBkITxZCAAA8FRNAACAfQEAAPaFfQEAAPYFAADYF3ECAADYFwAAYF8AAACwLwAANCj75pkRKAAAcCbmvCuxb0AJIgUAAM6kJPNK7Lu5oASzXwAAcN7Mt6Rg85XY131zXV4jAAAATiIv8xL51m9fAAAA/2VgXwAAgH0BAAD2BQAAAPsCAADsCwAAAPYFAADYFwAAAOwLAACwLwAAANgXAACuAfv6bkYYAADAtWz2Je7h3ogDAAC4Fu9w4h4UgDgAAIBrmRlE3N1DQhAIAABwJcy7hL8M9cbaLwAAuIjN3jPZpJfb1z0o3PcGAAAALsE3PMjd3f0/d7esjYMAUg4AAAAASUVORK5CYII=) ## Auth Code structure[​](#auth-code-structure "Direct link to Auth Code structure") Each Auth Code has three fields: | Field | Description | | ----------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Authentication Key** | The actual code value that must be included in requests using the **Auth Code URL Key** parameter name (default: `AUTH_KEY`). | | **WordPress User Role** | *(Optional)* When set, users registered using this code are assigned this role instead of the default role configured in Register Settings. Useful for creating multiple user tiers (e.g., "premium" vs "free") from a single endpoint. | | **Expiration Date** | *(Optional)* The date and time after which this code is no longer accepted. Format: `Y-M-D H:m:s` - e.g., `2025-12-31 23:59:59`. | note Leaving the expiration date blank means the code never expires. ![Auth code configuration](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAACdCAMAAADfTSvXAAADAFBMVEX4+fohJSl2foZ4gIcdIydsdX1QV17////i5OfO1NqZoKbg4+X3+PlxdXdxeoL19vfGx8iTmqDs7vD29/i+wsbW2Nu6v8LO0tQiJyu8wMSgpqt/h4+Lkpjx8vQ6P0Kjqq+XnaTQ09aPlpx+ho3p6+1ITFDe4OOGjpTu7/GfpKqRmJ7z9PVzfIN4e37n6Ori5OamrLHa3eDk5ucqLzPHy896goltdn6tsreeo6nZ3N/M0NItMjaJkJY1Oz5weIDn6u21ur6Um6J9hYwkKS17g4pobnWNlJqEi5Lv8fOiqK1obG7M0dPCxso7QESpq6z19fWjpafU1tn7/Px1fYXn6eslKi7Fyc0nLTG+wME+QkaTlpheYWS3urvk5ulbYGOwtLmXnaNFSk3u8PHx8vOusLL+/v5ARUlzd3n09fePl53g4eFye4OxtrvJzdCHiYz6+vqgo6Xy8/RZXWCBiZCorbOQk5VXWl2OlZtXW155gYiCipHX2t1scHJud391eXxhZmlTV1qxtbqzub2prK/l5unDx8rt7u7q7O5LUFONkJLW19iqr7QeJCjp6uxCR0pESEu5vsLAwcLs7e/S1NiFjJOKkZjh4uTW2+C2u7+Zn6Xd3+GSlpjJy8zDxsiAiI/b3N2/w8egoaNTWVxAREjb3uGDholkZ2u5urxQVFjr6+uHj5Xl5uZ1foV3e334+fk1OT3IzM/i5eZ8f4Pe4OKKjZDMzc6us7iyuLzd3t9MUVSIio3w8fHn6OkwNTiOkZNmam3Oz9DZ3N6boabFys3BxMjm5uelq7C3vMCDipGssbbU1tfS09WChYeZnZ7r7OxJTVG8vr97foFqbnC2ubo4PEBscHNeYmZrcXdvc3WwsrNyeoKsr7EyNzt+gYSmqatfY2eXnJ61triaoKbZ3eOLj5Rxd3y/wse7vL6FiIt4foHHycrP09Xk5eVwdHbBw8Scn6H29vaWmZuKj5OcoqixtLe9wcWbnZ/Y2tpXXmRgZm1nbXQxNjm1uLmIjZGkqaxVXGNwbDDFAAAACXBIWXMAAAsTAAALEwEAmpwYAAAR+klEQVR42u3dCVxVVeLA8QOc2zV5suqISioIYjwkFLdCMYHEVFwSJHOHXDNNk1zKtCKVXEjUXEZx1CydsdFKMzWtjLJtTJ1q2vemvZnGmfr/Z/ov59x73/OBVGDT+/OH3/fzCS7cdx+Xc4cfh8PFESYAwP+EfuGOG90IAOAXo+MmO/WN6CcAAH7Tr4NV34jJDAUA+JO7g6rvZGa+AODv2e9kYca5GAcA8C9XnDBHMwwA4G+jhdmIUQAAf2tEfQGA+gIA9QUAUF8AoL4AAOoLANQXAEB9AYD6AgCoLwDUp/o+8W6anC7lqBofcIu8lUsAgPrWyCVNVubn9L+6ul3vyon7rp479/MaPMtC+ZB6eXTuN1wCANS3Jp5Pk3J8acDC6vaVyvdq+jR2fQGA+lby8QU+PvLZEfmSzHlBiBWrhPh6VtpbYzYJcYPcvm/ikVsPiyhpGyUOdzwyYnq8/LXYLGUHcYfsJUQveWhu/h3vpcm88TuWiHj9uLfslYdHb2mdv/MOIe6S8r2Dqa9u4aIAaLj1Vc39D6u8/6n+u8J36ivlDfbW/XJ5/3dl1J2qvnL7oVT5rTh6RL5aUqLr+5pMfaA0067vTE99o+Z+dfXbS99+oJfsKLaulDtLrrHqu/GI3NkkTz1W1ffIQ/HycS4KgAZd3//6p67vw/+sXN/vpdxkb23Tawen5X2qvlHJ4lZdzYnyD0Ko+h6W8k1RkFqlvmPUQSvUf+/oN+2VB13fQ3K8EFtlqq7v9+qxR7goABp0ff92xQUXfPxZcvTHleqrEvm6vdVaL/IekvGqviOEeFHH1VPfLVaiJ9r1LbRz20sOUQd9ct/25WrNwbe+r6mAi5NSFqunflT8UUZxUQA0+Poue8L9/N8r1Vet+0601323yUk6onruO1GIHb71VXPfd8QKvfKwX8p7xNt2fdXS7pI8eerkUV3fx+VnTn33ye1CfCPTdNgfFqOoL4AGXt+PrtArD/f8qfLKg33Pw7aohb7rvlXrq9d9Pxup13KX5MuF0zO99U1eLouGjND1VUUuucNe9007u+5LfQFQ3x+or3W/b97j6n7fzfqeh/2iuvoWdExLHbJdL02cXLp82w5vfcXWTPnSp7q+3+VI+apzz8Npdc/Dm4L6AqC+4oL/Od5p9SPV1rcmlkwWYmOUPMn4AkAt576f/fdHH593fUe1/rSkVM51M74AcD6/dTvf+j4fL/PjSw4zvADwb/prCwDAL1jfK3z/0ricYQIA/n1fAKC+AADqCwANs76Nf1Uvx+iynud9aHBgjR4W1P5HdhYale7c63E5/6sFGmR9g8cNy2r5pPfNrpfar5uGV1/fkGbqxeWxoswwuj3bQm23afmLfj7Wefwy9W0UUrvD9ND8dH2tE65Nfa9vVmV/32GhelwNY3fbYtGlVS2vfwhfA8D/j/qGdm0ZnNt0wHnUN9c9MP166vuz61tVshHUxf6uFhyeTX2BelvfYE8KnroxJDxCtDUMQye3vXodKBqPjQ1JjBPi3uiQhCfPqa8Qicsq1fey8t09EpqL2OFqQhftParxxbHlw4Mi1fuy7Z/Kl/Vt1SZShM4uT2qbrN+MLhct1oZED1UPHTtn2DOF45J6XiJEWeNhGb9xzsPeFi1ix62921oRaRm7Rp2X5ynOPczSTZ15SncR0WOeMa/Qs6NwQ8ia9XZ9A9VztxfrM5LOXOSsKqTMaddUiC/6JM1XrzqFX2f08RytWEMTHNi0a1e1M/K5rGHPRFqHXdIyKCvFLZrpTGbH2CccVDE/qY29W3TJ7hb0pMhNDJmvv8eN3Z1RoYbc5zTVykOL2LZr19zsjOK0vsvCnZ8pmhmRTn2DA2fP2eBcI884T7tSiAIj0vNc9vlan5S9CaBO17cwsM8A/YNus3nNyx6Jrjr3zYhJDk8RFwX+I2JvUMQ59V0RdKdvfTunV0S0XOCtr+eoxl3VP8Ge0VyIcZfb9U0MDU0cK9wHOnf+YJz1phDH7424PShUNG63+sGE8oq4M42FmHJl8s2thtrn4Wy3MFbbH6nxvFzxXIr3Kao5zKe+t4cXi0vdnh091iav7uoz9x0euDp3zjjnG9FtIq7ratHli357kzaKxEc6uJp5jvbOfRe0yd37RpmYFt2puM9Y692XDoxotuZuT32due+Ujfe2ut7aPeC6p9xll4SWtywbnn6vqAhqVhxtuH1PU9dXfWIxa5xhzGga3K3MGldX93LP3Fefm+caecbZU1/nuezztT4pexNA3V73TU6Zn64K88HtQrgCi6vUV81tv1grWiSq7XEVVdd9DaNHpG99D6jpVmiSt76eoxp31/vOiML0JXZ9Y4SIudHaLE6y37Rk3Ws9dL36FtCpnQi+TkX57h7WeXi2W0Q7D9WPW73W+xTVHOZT3/V6SuzZ4VIFFAd86pt4QH3bMC7y/hjQvY2dxOMivKX+fmMffba++jE9Y4SazYqHM7yDWNGnSn2/EGLZc9au8Nv0y5uT1Ic/M1skHlfbhtv3NHV91clHdgu13my2oFBkH7fWfY2g1Wfrqz6uc4084+zU1/Nc9vlan5S9CaDO3/MQ3DdRJOiaGkOr1Ff9nK+qMtvaZ1VEDNPTz2mJ9rpvVoRvfVNmqxfzvfX1HGUtHuemu5vG2g8LUv3bOExEzn62m6FmbtYSaYu16YYRYz20RVtrdfUy6+g51nl4tvUu770Y6rw8T1HNYT71LdyQkZTicnYUGP3UWoBPfbP1GqthFTZYhVwc7yNWJ+42jO4iOHZY1wrn6LP13a02YocXWs9m2N++GmcYRnSV+j4srDgqa7pYv1qbr4ftmMhWE+Iyw+17mrq+bZ3TVVqqifjl2d5x9a48qBfONfKMs1Nfz3PZ52t9UvYmgLp/x1mXIBHurEJmOfX9c/jZyq0/c/ah2X/WwWhjr/t+UGnd94BqiEvNycIHqslgtPco+1d3scOjnR4E7bWa0rRnp4uSnfo+mDR0iWhXqb6dss6eh2e7an09T1HNYdobakn4jJ54u2LmXe/scKWrD3e5Xd/O1txXLYcUGzPt+aX+gf9KEdS02HWxPm5m024R9tHeobEqqL69pHf2fphjVwaHDowWnfRMOCvGHjj9STn1DT9gz31VwXuoua861UsNt+9pVq6v+w0rpsHV1de5Rp5xXn+xPvXIs8+lz7dziHeTLwagTte3uHtwaEzfYyKmXbBwqV8L/fYp+/0Dng31Vm7FPLVjY7L1/tsSCkTnpNV2fTemF/jU98HrLhFN05uLZReLiOxo71F2fQcmpBc69Z2/sX35WPErFefbnPq2z3KJoZXnvq7osS4R18k6D8921fp6nqKaw7SeA8XGN7qLmwtEXLvmnh09eoiCcru+/bqpBenh5f1EG2fdd8G4uMvSh4rAziIisLuICRWXpvezj7b266Hx1Ld7YoFw26vQbX8jXLHRoiC9WFSoz8EaOJ/6DshKFnrd9x+iePdGUZFd6DpmuH1Ps3J9hwfqBYgps6urr3ONPOPcvDzS1cOI9DyXfb7WJ2Vvimmd+XoA6m59l4QnhLRapsI4ICF9jYpAlwXWPQ8i9Lf6nge7cuLBxJB2U+wv5Yv6GPrHcru+ou8j1vqkYU+/BpQbs9Xv4gs2xGanRHuPsutbmH7M+YhBLQKvaxMqZib0DPfUV1zZakrKjZXqK/pdHBQYfZl9Hs521fp6nqKaw7T2iWvntO0uBqrbAJ7x7ijcUD7/GeevLVL0PQ93ZyQd6+cU7viCeep+hju79j2jjktZYIQM9BxthXCBvufBrq/rQLs31k6z3v1wVnQf/enunbKmpfocrBP2qa94KtvQ9zxMCZmvIz623Y2PqDVcn9OsXN9Evawg9gZFVlNfzzVyxlk81/dG/ek7z2Wfr/VJOZvpMXw9AA3nL40Tmv/AjlbNa/J3YP+Xavh3bHXDD44zAOpbyfUZLupLfQHq6+8qJMxvJqgv9QWoLwCA+gIA9QUAUF8AoL4AAOoLANQXAKgv9QUA6gsA1BcAQH0BgPoCAKgvAFBfAECN6wsA8DtVXxMA4GfUFwCoLwBQXwAA9QUA6gsAoL4AQH0BANQXAKgvAID6AgD1BQDqCwCgvgBAfQEA1BcAqC8AgPoCAPUFAPw76nuN7PgTj1gl4xlSADj/+uZIucXnTbeU7qr1PTFpe178iyd+vL5N9CHXytam2VrKqPGvTXXe5WgtrzUPx8uFggsBgPoqm6SU+368vrv2yOVLW8uTNa/v+IMB8r5z6kt8AVBfr1NyqcyZYJpLVV3vl4tWSG3/NfKrW9IO7rcf8orc/qhp3jXVPNHk5bQxL5jm4sdTdx7V9V3cpHXafV+eW99rzb/I8ZXrmyNviJdjVHxnlKzMX7TZHCJPm+Yg2Z/rAqBB1nfGERmWJj/X9f1a19e9T02Fi56+RmYeWenMbifky3esjb+WykWvyLwt5rtyxAOpau9fx8vTb+eN+H019X1AvlJ17psvR7rUxiS5aMfLAVsG52W6zf7yj1wXAA2yvqPkWxOsSDr19a485AwulLJQP+RpNRe2Hvu+ns92lC8ulnKq+Y2q7/fq8eYt8vVz132lnPVY1fpKeb96vVgun6kmvqdUhQeJ1NQZXBcADbK+p1UgR0kVwaVylcrr2fp+ZZpSPm3NffPk363Hfivf1Xv6fyeXm6rU8Wp5wVJi7e0oJ+mlhFJr3VfNdPdXre8ImbfZNF+wj5mrFpxHrvrJOysAoH7W151px/B9c5FK7FFV399LOdP5rZtTX7XuO95a9/1ejjDN1yrNfVeGhYWtesG0b1KLHzxhkg60WnmY8Jq8qeq675tNZP4mNfcNOKkOuto0S5e/opc8AKAB1neQTJ01a1aO+uXXKXnwaKpeSfiXvLXoqkr13fWWXH7woDzpXfcdI+cWHbHXfZsUlfQKsx71ZapMVXevnbTXfb8MkJtVfXupZ7/Bqe+1aokj9Qm14jC3qGhnkWn+QVq/7gOABljfWfJT9TJMZh4+8Xhe/HRd363LpXRVqq++3zdqj7rf98RX6p6H5/U9D3kTP7XueXggJ3Xnwqn2o7Ys3JO6bZVza68q7yz1n/ai937fCbfI1Bdm/Hp8fvwYNfddnCmnc1UA8LdufjdLfsdVAUB9/ezro/ljuCgAqK+/fRow8lEuCgDqCwCgvgBAfQEA1BcAqC8AgPoCAPUFAFBfAKhz/7p673UXos5a15t/ABmon/Wd8WGui5Gpu1y5H5JfoF7Wt3cu41K3cYWA+lnfdcx86/rsdx1jANTH+l7IsNR1XCKA+oL6AqC+1BcA9QX1BUB9qS8A6gvqC1Bf6kt9AVBfUF+A+no9n7lIv7o64Hf61YjpnwQ4Xh8UYD0gaoj3sU1uUi82pZ6a0MR6xHhz5NKr1Hs+j9rPWFNfALWr70OH0h71re/isLCwmw6qF7uqr+8neSVq4yX1gLAnzBNp+0yzw54dDDX1BVC7+rrSpp7a4Vtf/bL/SP2y2vq+HvUXzyRYG6WmvadX8s/CUF8AtazvmwfN/f+aUcP6Tpq7Neod07e+5qTWWzPvYqSpL4Ba1vemb03z5fd/oL42n7lvfsAge8PacavamrknoIiBpr4Aalnfe6J2mWbJqz9QX724G+a78rByxKLB1oa17rtFb36bOYGBpr4AalnfQ/b09jFzU4DV0iNFP77y8FjOwZmVVh7MrXmMM/UFUMv6TthzSE9iS4vM3wXcod6eGvD6j9fX3LU9/jD1pb4Afl5974/qoF9ds2eC2f/l78MqFuW4f+KeB3NxaeliZ+VhE/WlvgDOq773jbFefRmwypxRVJqXM2mX+VP1NQ/Hb99l/9YtlfpSXwD8pTH1BUB9QX0B6vuzv7SnOjf+TmVEqS8A5r7UFwD1BfUFQH2pLwDqC+oLUF++tKkvAOoL6gs0pPquczEudZtrHWMA1Mf69s5lXOo2rhBQP+s748PezH7r8sy394f8HzUB9bK+5ozcdReizlqXS3yBelpfAAD1BQDqCwCgvgBAfQEA1BcAqC8AgPoCAPUFAOoLAKC+AFD/6zv6KoYBAPzrqtHCjItkHADAvyLjhDm5jHEAAP8qGyxMs0MBAwEA/lRQYKr6mh0iIln7BQA/uSqyTE16dX3NwXGjGwEA/GJ03GTTqS8AwM/+F/hYyuJ7yk1+AAAAAElFTkSuQmCC) --- # Authentication Use this endpoint to exchange WordPress credentials for a signed JWT. The returned token can then be included in subsequent requests to protected endpoints or used to auto-login users. You can authenticate using any of the following combinations: * **email** + **password** - standard credential pair * **username** + **password** - use the WordPress username instead of email * **login** + **password** - mirrors the WordPress login page behaviour; accepts either email or username API Reference Explore and test this endpoint using the [interactive API reference →](/api/v4/get-jwt.md) ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `POST` **ENDPOINT**: `/simple-jwt-login/v1/auth` **URL Example**: `http://{{yoursite}}/?rest_route=/simple-jwt-login/v1/auth&email={{email}}&password={{password}}` **PARAMETERS**: | Parameter | Type | Description | | --------------- | ------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `email` | `required*` `string` | User email address. Required when `username` and `login` are absent. | | `username` | `required*` `string` | WordPress username. Required when `email` and `login` are absent. | | `login` | `required*` `string` | WordPress username or email. Simulates the WordPress login page flow. Required when `email` and `username` are absent. | | `password` | `required*` `string` | User plain-text password. Required when `password_hash` is absent. | | `password_hash` | `optional` `string` | The user's hashed password as stored in the database. Required when `password` is absent. | | `AUTH_KEY` | `optional` `string` | Auth Code value. Required only if "Require Authentication Code" is enabled. The parameter name matches the **Auth Code URL Key** configured in Auth Codes settings (default: `AUTH_KEY`). | | `payload` | `optional` `string` \| `object` | Extra claims merged into the JWT payload. Send a JSON-encoded string for form-encoded/query-string requests, or a native JSON object for JSON body requests. [Reserved claims](#custom-payload-claims) are always overridden by the authenticated user's data and cannot be set this way. | ## Request[​](#request "Direct link to Request") ``` { "email": "test@simplejwtlogin.com", "password": "SomeSuperSecretPassword" } ``` With username and password hash: ``` { "username": "myuser", "password_hash": "PasswordStoredInTheDB" } ``` With login (accepts email or username) and auth code: ``` { "login": "username or email", "password": "SomeSuperSecretPassword", "AUTH_KEY": "MySecretAuthCode" } ``` With extra payload claims (JSON body - native object): ``` { "email": "test@simplejwtlogin.com", "password": "SomeSuperSecretPassword", "payload": { "department": "engineering", "region": "eu" } } ``` With extra payload claims (form-encoded/query-string - JSON-encoded string): ``` email=test@simplejwtlogin.com&password=SomeSuperSecretPassword&payload={"department":"engineering","region":"eu"} ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "data": { "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c", "refresh_token": "a1b2c3d4e5f678901234567890123456789012345678901234567890123456789012" } } ``` `refresh_token` is only present when the refresh token feature is enabled in plugin settings. ### 400[​](#400 "Direct link to 400") Bad request - required parameters are missing. ``` { "success": false, "data": { "message": "Email or username is required.", "errorCode": 46 } } ``` ### 401[​](#401 "Direct link to 401") Unauthorized - credentials are incorrect or the auth code is invalid. ``` { "success": false, "data": { "message": "Wrong user credentials.", "errorCode": 48 } } ``` ### 403[​](#403 "Direct link to 403") Forbidden - authentication is disabled in plugin settings. ``` { "success": false, "data": { "message": "Authentication is not enabled.", "errorCode": 45 } } ``` ### 500[​](#500 "Direct link to 500") Internal server error. ``` { "success": false, "data": { "message": "An unexpected error occurred.", "errorCode": 16 } } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/auth \ -H "Content-type: application/json" \ -d '{"email":"test@simplejwtlogin.com","password":"mySecretPassword"}' ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->authenticate('email@simplejwtlogin.com', 'your password', 'AUTH CODE'); ``` ## Error responses[​](#error-responses "Direct link to Error responses") All error responses follow the standard envelope: ``` { "success": false, "data": { "message": "Human-readable error description", "errorCode": 48 } } ``` Common error codes: | Code | Meaning | | ---- | ------------------------------------------------- | | `45` | Authentication is not enabled in plugin settings. | | `46` | Email or username is missing from the request. | | `47` | Password is missing from the request. | | `48` | Credentials are incorrect. | *** ## Settings[​](#settings "Direct link to Settings") Configure the authentication feature under **Settings → Simple JWT Login → Authentication**. ### Allow JWT Authentication[​](#allow-jwt-authentication "Direct link to Allow JWT Authentication") ![Allow JWT Authentication](/assets/images/allow-jwt-authentication-d1026e3f9fdbe204be204310a0bc9911.png) Enable or disable the authentication endpoint. When disabled, `POST /auth` returns a 403 error. ### Require Authentication Code[​](#require-authentication-code "Direct link to Require Authentication Code") ![Require Authentication Code for JWT generation](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAB0CAMAAADuBmGdAAADAFBMVEX////3+PnZ3N+XnaQmNURsdX1QV174+fri5OcdIye8wMR4gIfz9PWZoKbBxcnV19hscHLx8vStsrdxeoJ2foYhJyvf4OKCipGLkpg1Oj729/jq6+2JkJb09fbDx8x6gomPlp1KT1K6v8J7g4rl5umhqK3m6Op1eXyMkJL19vfg4+Xw8fOepKkxQE7k5ejV2NvY296mrLElKy/e4ON/goWTm6Ds7u/u7u+yt7u/w8eQmJ6go6Xe4OJ/h4/M0NOVm6J8f4Pv8PHDxsmNlZvT1tnHy8/l5+hXXF8lNENtdn63vMDy8/RjaGuzuL3a3eCHj5Z9hYy5vsKAiJA7QUTO0tRzfIOvtLnBwsQ/REjc3+HZ2tuGjpSTmqByeoPR1NbFys3Mzs95goskKS3u7/CPk5VNUlWwtbpvc3Xp6upweICDi5KLk5lveICRmZ/i5OZ3e34nLTF1foWFjJOUnKN8hIuEh4paYGOprK9KV2PQ09Xr7e4rMDRxdnjo6eteYmZ+ho1hZmmgpqsyNzuJjI7AxMh0fYX9/f21ur6GiY7Lz9JFSk0eJChTV1qws7NCR0uJjI8wNTm+wMGVmJqChYi6vL48QUbJzdDc3t8qLzOssLakq7Cboac5P0Kqra55gYiorrNYXWBud3/o6uwtMzesr7HAwsRrcXdobG+qr7VGU2BmcXv5+fkoN0ZVWl2kpqmXnaOPkJK+wcbs7vC0tricoqdVYW08SldQVFhUWl2bnZ+8vr9ATVpHTE8zMzNeaXXU1tcuPEvj5eZfY2dzd3qZn6XHyctkZGT7+/vY2dllaW0qOUhJTlHJy82Slpi3urv29/eZnJ6Mj5GnrbKnqq2bm5u+vr4kJCROWmd4foNTWFuXm51TX2pSVllbZnGytLVmam16foE0QlBtcXOeoKNfX1+vr69ibXjFx8nh4+RWXGNobnWmqavO0NJPVFdDUF2NjY1qdH6FjZaYn6Y2PD+1uLlxe4WLj5E7SFYgICBeXl5dXV10eX9TWmE4RlQ+S1l1eoARCo7AAAAACXBIWXMAAAsTAAALEwEAmpwYAAAV80lEQVR42u2deUBV1dqH95F9XC0GQwYVEIUAARkUB66iqAhGiiCCIDiUgiNOSFcT0ExyHpCcB3I251LTNIcUy0yb/LK5bLBu2bXhNt3vjt3vXXs6+yCW8HUPmb/nDzp777XWXvvdnoeX96yzkyQAAAD1hKtf8B0AAAAcQrCfvybf/AgGAADAYUTkq/L1RygAAMCR+Av9+iPzBQAAR2e/VHzwsyAOAADgWCx+khSMMAAAgKMJlqQ7EAUAAHA0d8C+AAAA+wIAAOwLAAAA9gUAANgXAAAA7AsAALAvAAAA2BcAAGBfAAAAsC8AAPwu7evOQ2vZw4c/8PMN7uS8Se0P3Yge/MFqe/xGV/Kjjo5+7eMEALht7RvIOffZtP/nn4u2P3nZDY5cXcT5C3Z7HuI9ft6+wzinBwHlJiffXZtDOhOnlxdm7njkF+07gm9d/nhNAzzJ+SD/dmJ603mphaV483e5xnK1RcrLgRWFgR+9VJswqld94zgBAG5f+w745xePba/Jvj77tnK+rY7n+ytJq0Nd7FvbQxqnaK4Ly70f+kX7hvIdNY8g7MumiiR1Jedn2SOcD0tO3sd5eXJyF6VBxIucVxwpq10aq141AAD2vY7cfzX8c8OGZ2uw72iWsobvZyxheXnhiYuUBD8SuGZfGG/HmDd/hTXh/E7lL2qqBzwd6N3E0mVkYWaPWK23pZKP5BWujPXkPJ89wH3YCZFElpF9w6aWBlKKarR35zuu+GS+y5YoaeYnSnmhcdjCdt49WGy5N/d5cLvdIaXf6Im2fgq+gbyymLEx9Gtk4KatZVPF9bycWbFjurBvV/fKNe9oWXGyGGkSW+1eWXjkEtMnb9h3BM9hq3k5X8aW8kDa2ZjzLnpEOnB+iaLwwkDbiNT94sg1D7a1BUkb8N2tPG/h8hL9qpXKgz6xLjxnac7WUDzrHoDb3L5hDe9iSQ3/U6N9711EmnXdx79avpC/zE7l8cArhap9j9nZN+9K37vn88wOU41McwVfNChPJM5k3xTFvp+U8yNhy8i+eZUreVkKM9q7c36UxFZ8ahLnU8JeEooN38RLp18JZFtKz0+ZyvNWmw6x5XxN6Iu8Mtjop6a+hiXpzDvOcO/P2eP0YlMenaFrBe/bo4yrv2CuBfITYa/kVvCvpufRNWmTN+xL0514jV/yPsPeUVJ3s33LuLv2yhiRum/tcYJ/aAuSNmCHwA6hPmR57apFnIyJdeE8Z34pfxr/KAG4ve37WENfxnb8q8a6L29H5cpHuHcsO8tL2RS+kCqYNdl3BGnKm69g/mv4MLX3Dp7MzvOpJvsalYfz/l3Jmbb27iLJzCEZqeUFodjtnK+mz8eYv0ilV5L/bIcaL+JLWPj3/KKtn+AHzrVy7DviNO68LzvCP2JsE9n3Yf4+JcJcK0pMFw59WFzKJ3RN6uRtlQcq/F56lo85Wkrze9LeviWcMmJWTkGxjUjdf2CXeIUtSNqAY4TobVct4mRMrAv3bkUFkA/xjxKA29u+f26o/7iu7jtyET/qSjmkStvR/Axjj6r2XUF/n9vsO4ixQVor9QOt4DyS1ja+aLWwb2Ozh3yoRSznPW3t3fmzjI0kZ9kU+zgvVIaJ6LB4DbUJMx2ifiT4xTSW0Y+pyyGWqPOu5FSMmM9PsEwhy1Cy72j1TJkm+44mCbJjNKg6eZt9qfD77MqFVHYYwfmM63Jf0vknH1IAjBHvFL8mfuDetiBpA67om0MfO3KzfY2JdeErGaXwU/GPEgDYt2b7jmZnvck927n3ioEDB26LnS+sMUXYt5RqCk+a7Et1U39vvoxafaC6bJkmo4eFN69SxZTse17IS/nUTdjX1l6piQqLfsl5lZH7fknJJrkq59rAlWRf26EUKr4y1wol9w212Zfqvjlq3feokPJDZNf3xYsjZN+/8hN0pu1LTPZdSuVdmuRW8yI21b4jeAX5cjsvU8q+1eq+eVRKeYACYIyodH+F7GsESR2wpB3/6FiYsK961WKuxsS6iJPDvgDc5vad3eOLhm+//Tb9yK7BvuxZ7tM4PJm/HxbmniPqvkdGlwr77qPa6Up7+5LQMpeGdchTXVbOK5OTk1dyn/CSQv7Q/DxhX1Jw2AOGfW3tDYvO4PxKWBOt7lsZ5j6SFFW+YrrIfW2HzHVfk33VNQ9Hac2Dqe7rPYXqxQ+yJhXUOez9UJN9c7fa6r729qVcnbJoWm6mrlUw2zdiIa152LeQAmCMaNjXCJI64IxFfMTjK4V91auuVveFfQGAfec31HmsJvt29Sa7JSxdWJiTTGtet7+4aHEXYd9BD+blXKxmX8u1I2t89n1YIvqSwsQati9FVfRY4KKjy4V9B1UKFRr2NdrbLLqUzHfWWPPA32HRI3lhj0Cyr+mQ5fGR7TJHX2XV7Kus9837kNYh9NxUWjZVlJ+XZS7q6y4+12syfWW7wE3bTPZV1zxss/sCBy2syGWi8MvHKEsjPqhuX5YS9uJWXjn6km1Ew75GkLQBu+TxF6cI+6pXrcxVnxjsCwDsq9r3sdyWNdj3BiwR9v094hvK2/ni3wkAwIH2fY6tgH2LM8UyYAAAcKB9px58DPalYon7FvwzAQA40r5fsH/evH0BAAD8WvZ9+wzsCwAADrXvIWPNQxFiBAAAeLo6AADAvgAAABxq3+yWnj9z1KW98p/ZHe32dmt+k4NHWF31DsH6af7Y4AaNq53EjNtdNzwUXOP0Zw+5yRkOHlC7cDk71aa1dq16GKpFxdHUbu4AgP+ifZu2YLHjq5hD7JvQiSrQ8+h1ny21sm+V543t25LkJsa9fm9ui1/Zvi0b1MVg2rXWbN8qzzrf6ZYNqt9I37H0AOIWVvEjvrlVYZY4cmAI7AvAb9O+7Vsyx9hXoNj3htTNvje7t17sW3Oy+9+wLwug2IbMFD9CaIeTh3YE9gXgN2rftpQjqe/J+zI8Ox4k3Xokxq/zZRNnuQTFuIrNjKwQX0WMuc08B9ObPuI5z6J5NvtqDVt77UyMP6DuKu6e1VS8zJ6c3og8o3WgCsFdysnor3H/kMlBlLI6Bzg1L2prdNDsG74xI8upFWO9/RiL8WBe1Km9W3aA5wTajnWbk96ZZDwroIg2nejQXaLycHD9HGukPhVlr6g8zIjzbNrNaKyQmzh2s7N+etYtfvJasq/v2qA569QvIDs/MSur4xYPl3TqF3AfY6uasfzIDdYNEcqgSosJQ4YW0JxNndwiE/vF0bMvXHaOy2BJRWMTo1mqiGnMOqXyoIVBm7q+SShXxualZx1qrM5u1UzzfPSQGpuvJT6nxUadjXZDNPt2msBYhnBtfAuTfdtTSy8j3k7M4hbgr81Ei74lu6nVMwlvHgAcnvvmarlvmw0DYj2akUICwsMTV7EGPfPbFPWnzYzc9vHZQoyNvQ4c7OVykEU2b5XU0mZfrWFrqwcrcVEev8N6FSf0yurKGrm0ubsZeUbrICyp5L5kpJDB0W2D+jNn672suMjooNnXNTU62u0Jw75q7pte3GpIDBkxpFXb+CTmtmEGWxujpoA0rm/z7lWsjTFnsZfsG54xK7bF2DSjMbFl6Kj8cOP00eNnH5w1fgDrNC4tuKP6+DfnsY22HMqI8evvYtHtm9oxmDVwteW+vUflj5qTYO7k1tKPjUqkWMWFs+ixzvkbg1JmjHVlFpe24lr1MGhT1zf13LeFV9KMxCeUcVrPWXAw1TYfPaTG5ihbbMRs9Bui3cgkT0v+BtcsS751y3W5rx5vJ/+Obr76TLTotw3KtWyJxpsHgHqzr1sqPcLMK5i53MuYx1q1EtCdjNKL5JghxOhMuRV7opFlLD0kLNW+8kANW/f2Z2xcsbErsg+L68NYW6ur3sFkX4uoUXYezJzJ9r69w/UOpspDcFY1++6kDLkZaz2UGvePZG7klnubGfZN80wxTUW3b9ssanxoo9GYmJcofuqnT6W24VkDGFmSdU1X3Urt0qx0KZ4zdPvOaz7RrvLQlH5k3Gfu5Ebh8reWMBe6/NQ4Gj+oG2tGOgxSftNoYdCnrm0a9o2juEdbleQ39ZAo9Rjz0UOqb4pp6bERs9FuiH4jfTen9XJj/dJ6/ZFVt68R7wnNZlmMIGrRT/MqtuCtA0A92new8kFNklLo7RTCWrmlW60iFU6jP9fnCDFuVBqMSrAmkI9t9tUatvZi6t/qRFLcZCvlbQULqFJgddU7mOybYI0VybZahyTJah00+/q+1rS31eprb19KadvEs27KHBKVMjBt6vZd0NQ8Fd2+q8TeTuuNxsRr68RP/fQxr4kQDIhQP6MyKqPKpVAYNPtGPJeeFWOx2Vfkkt37mDu5kVDZnFwldDHiDAEHmHNHFuKh2FcLgz51bdOwbwH9emNWRfDV5qOF1G5Tj42YjXZD9BvJEvusc2Yb+6w7dJ19jXgHeVKSq89Ej/7aos1DYvHmAaDe7DukMzM+ZiP7rg9pHd5T2HcVKSheiHHeIfV/ZDyeGpjqvlpDs31dDgRbIj1YHFmvAeW+Wgdz7jue5NFosPH+1zpo9j3QPK1xKzKMJ9V+D3mwaP1TNzJoWpBtAZoQapCW+w71N01F2avkvpTTRW4023degHoJ6ulFcdZCue/4aLvPpXT7duxJw4ic2VK8YZUyqNKiQCjzPnMnNzJuidVPCV2qkDNVjfPHJsyJVnNfNQz61LVN8VK5sjgKSbBVyd070cl9bfPRQ2re1GMjZqPdEMO+Ht0LurJV3Qs629m38xDbBTs79QyaYQRRjz5l1uNi8OYBoN7sWzyzNbN0M+zr1JlZAoR9J4SHByh13y0b6GjXViwykiVkkH21z9i0hmb7ekWzg14k04IIy3pR91U7CPtuDNHqvm6WlOb9jfe/3kG1711klVFkmOY9Wa6nB4vovcXQraVZtoX5pRlCHXyfWvftRxlgG2POYq9S9z3Agifnmu07IyuJhRunr/JszQ5YBzCPCQnM9d7r7LszkuUXNGNtE5jfzAHKoEqLzUksaXK+uZPbnAUl3cepobvbsz1bFURynbC+SL1WLQz61PWoEMqVtchIYOu0uq/nRDZ7vDEfPaTmTT02Yjb6DdHtWzx0MmP5Q61Vdvbt1pTqDLZ4H0j302eiRX9iFfN32snadMb7B4D6sS/rNnhskZNh365B47rHCPs6ew1dF66IsSrOc2ZANP0lntF0XXNmGaquE9Yamu3bomXiIfHuz56Z4aGseVA6CPu2djGtebAY9tU6aPZNGdxviDBM+7hmiWKYGLHmQTNoQqSL17gFhlB7bVbXPMS6ZdGaB33OYq+y5iHAs+kAZrYvyx03Xl/zQInxgqYF66mFJXWmZ/NO19k34bmAAhquJy1NWKcOqq6KcLMWUCpp6uTm0XSzsuZBrM5rUzB2nIhMC6v2CaMeBm3q+qZSahBrHvqnZ62PUGe3Kt26sShJH1oPqXlTj40yG+2G6PZ17S3y7ozJzM6+4f30NQ9qvOfFl2gz0aKfFk9liAiW2gzvHwBujW8aN3gC8f7lL+LVHq9WdenlUozbAACe8wD71pU2FtY/sQ79fFts9sNtAAD2hX3rSqLVM25GHfpFxs/GXQAA9gUAANgXAAAA7AsAALAvAAAA2BcAAGBfAAAAsC8AAMC+AAAAYF8AAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQCA35V9AQAAOByyrwQAAMDBwL4AAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYF8AAACwLwAAwL4AAAD7AgAAgH0BAAD2BQAA4Aj7vjruvaiot/qx+ppX+Df/OHny799YcIcAALeVfUftvUdwYe/O+pnWn958/Y0xY954+s0/4RYBAG4j+zpFyRqn3epjVtee1189/yjuEQDgtrGvhyFfWY5KrYfM93nb6+eX4CYBAG4T+756gay7u1vjxt1204u9e36dM90vD69hr0WWY6vvC3/TvPXmzZ//0b7X75vyMG4yAOAWsW/AaVn+i/pyONUehpgOPSV/PVdKkqNse/rJ/W7uTNmX19+kfb953bz1+n7TRgfOK9yv3ugUp5bAvgCAW9i+l++R5WL1ZQtZvueynX3lnXW0b83UZN9/vGHeeuNTs30nSav7BtbmBLAvAOCWsW8U2TdFfVlC9o2ys+/e4+cU+5b8+L9RzyRJ6aI2/Jly7Bn528MXqmLnPBW1u0qS8v9y+r04eZrUX35Pkt6SZyuVh/vl8buj1krZb53eNUuS5n778dchNdj35Bjz1piT9vaVvuR7pNgrFTmXJMn1yprA+YslyZt6LP8fpfLg8/CmhdIHJ9b0/YMkrV5cer4H7AsA+B3Y9yd5uLxR2PfVXfLh8fKFNOfD8uEJ2Zp99362O22X3Dv+wnEmfSYfH35ase9hs333TnMZtVM+/u1b8mvSd3LU8OO1tu/c/TmS9GCPqmHln0uhR6s+/76afc8waVjlI7EjkqU95R3+cK0d7AsAuFXse9hWeXAm+x62s++qr38aIH8s9ZF3iapwkany8Iy8W6L9lOpuljvFyvIMKeR6+/47XJKmyZ2lBtR/GlUxBtRg37//TOWBc+7zkrS6lD6K6xI6t/CUJC2rZt+eknTlXUqsy64OKzsnSWdgXwDArWLfxHuMT92mkX3j7OzbbRSlvx9LkaLccD81M9t3o0T7FQLayrJE5tXsO82w748it1bb7PlYXiVF1PSp29PSDT91myQ12XdROsYFUxM4pehPVrPvC5L0lXL47CsjRQ/YFwBwq9iX7TWvOJPnSua674K50/ZS5aGPfFySfqTcd5z8rWHfbJH7ft2rV6/ZSZT7XpXcyL6NKMn1P23Yd7iidCdqk3pO5L7FNdjXYrfi7G/nqtV9GxSWFGcqW3PbkWovkn1LqdD8rM2+5y8ph4eV0dT7wr4AgFvm2xbZN/y2BdlXSpVNdV+qLhyf0MJmX9o/Z0LAv3spdd8osm+wLH9LEjfbd618PG6C52XJSX5qwls12Nfu2xaffiBVs690func5BFzpTHFUugkKSWQ7Lt4m3Sq1GbfgeWrpbnHpD0526RB3rAvAOAW+qaxId+9IVJ1+0q7jDUPbSQpdpcsj7PZV4od/tPp9z5rLeXvvrArhuwreXx9oWCanX2l/u+dPn75O7HmIeq7muwrPWr7prH9gx4U+35e6poy6fuyTSskV/d2K58m+77w0L6p7jb7SsdGFo50pzUP7wQmu8O+AIBb6Ck789Sn7HwsZ/9/Bp8t7FsnlqhP2Xn9bx/8YtNji3EXAQC/nydM7kk8HBV1+f65Uv3YV9qz/9OTJz/df06CfQEAeLq6A+1788C+AADYFwAAAOwLAACwLwAAANgXAABgXwAAgH0BAADAvgAAAPsCAACAfQEAAPYFAAAA+wIAAOwLAAAA9gUAgN+YfYPPIQwAAOBYzgVLkp8v4gAAAI7F10+S/GMRBwAAcCyx/vQjPwGBAAAAR5Kgejf/oC9qvwAA4CDO+cbqSa+/X/AdAAAAHEKwnz9+BQEAQD3xfzTcWrazLmg4AAAAAElFTkSuQmCC) When enabled, every authentication request must include a valid Auth Code. The parameter name is the **Auth Code URL Key** from the Auth Codes settings (default: `AUTH_KEY`). ### Authentication Options[​](#authentication-options "Direct link to Authentication Options") ![Authentication Options](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAACKCAMAAADBnhn0AAADAFBMVEX4+frAxMd2fob+/v5sdX1QV15xeoL////i5OcdIyfx8vNARUmboqfz9PU1Oz7q6+0hJyuQmJ57g4oqLzMeHh6kp6h4gIeTmqD39/h9hYyZoKaZn6WtsreQk5VweID6+vptdn7g4eOWmZtud3+go6Xn6OpucnSFjJPh4+WSmZ+6v8KMk5kkKS2mrLHZ3N/8/PyLkpgtMzeMkJLKzdB4e36Vm6FHTE+8wMTy8/SprrPb3N6eo6mAiI90fIRzfIOxtLV8hIs6P0J1eXyDipHj5ef19fZKT1Lg4uSKjY/V2Nvv8PKXnaSzuLyPlpzT1tmFiIvd3+Ho6evZ292WnKL4+Pi5vcHCxsnk5ej5+fn29veKkZjFyMzR1Nfs7vBZXWC+wsbGx8geJCiGjZSNlJp+ho11foU+Q0egpqvf4OPu7/BcYWS3u79na26xtruusLLBxMg8QUVOU1bQ09bj5Obs7e7b3eAvNTjw8fK+wsUnLTHu7u/Dx8r3+PmZn6RzdnlscHKqr7XFyc3BxcmChYhDR0taYGNobnV+gYRTV1r7+/vo6uy9wcXl5ufBw8Skqq+iqa3c3uDLz9HExse1ur6CipB0eHqTlpjHzM/V19iprK/N0NOJkJfX2t1RVVjS09Q9QkaHj5W+wMK0ub2wtbl/h498f4OvtLiEi5J5gYiBhIarsLVqbnCOlZtMUVTm5ueanZ/V19pFSk3j5OSgpavm5+nq6+1jaGslKy95fYC4vMBhZmlUWVzq6+s0OT309PX09vdXXF/O0dRlaW3X2dq5u71gZGfLzs/Jy8ylq7Cfpaq1t7lwdnleYmWYm53e4OKHiozNz9CssbaPk5WDh4m5uryoqqyqra6srrBWW17P0NK8vr8yNztxdXdAQEDHys2doKHk5umVmJpwdHY4PUHAwcLf4OCIi40sMTW7vL1vc3WssLKeoaOcn6GOkZOUm6CHjpWhp6wxNjpfY2drcXeRlJaipabIycqjpqeztrdWXWTMz9LY2960tre0ur7i5eabnaCKcuyqAAAACXBIWXMAAAsTAAALEwEAmpwYAAAatUlEQVR42u2dC1hVVdrHt7DnrF7kzohQgBIqKODhkgoJGKJ4QVR0shSlVNBQSVSEMUmtNM3wUqPWpGZmKqamNj5qeUEtu6dd7KqZ08VuU1N9NdP0zVffu/be65x9UMwaInX+v+eRw16Xd6+9Dv7O2u9ZBzTB7As4eQkAAIAm4WRATxavxv9KqzQAAABNRlWpYd/SnpgKAABoSvxK2b49sfIFAICmXv321ERANeYBAACaluoATZzENAAAQFNzUhOXYBYAAKCpuQT2BQAA2BcAAGBfAAAAsC8AAMC+AAAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAOCisW8bav4TLfzpzw1VzaTuv+CUZwkIAAAXnX27E03wKLicOv+EfUOoG3+dsH/16VWP01r++vn+vzbYuWLt7Gl7dz95rgEBAODitG9pCFHC9l9i3zNi2vcsFJQTda4kWnaOAQEA4AK27/O/s5HiUfVP+qqc5Eo1kI5qh4nuXUuS+9m+3zRP7s6/qv3wzOyQeaulj8f0liXbjQYTzETBU4f8qfwl7cVkSth2W4XWWVYdMzMPU2dmT1v5Z3c/tdQOeUrz606BT8iKAWOSj5d6BFxQlHxsztMyeTGh3d7yF2WY5iMDvy7AcwsAuADty879l2HeHfzvdo+qlbRrAM027Pu2Yd8nx9HelJSaNpQQOI9oi3a4knasPUb/YFnSmCMhtKVvSgJtTLnRkOXqkbRybu6n2tzcud396Qrts9m0MmWZYd+BlTTp+QRe46p+5vkquZWmtSV6UVY035VMB+0Bn6SRE76mwOkcgnbPJTqgHaRPUnrPG4TnFgBwYdq39+3Svodvr2ffJ4gWvEV0t9u+rswDPcUL1QnaKVqpacvocS4JbGuUWIkCKcs36Tj/TvcKTS5NXyN/lXmQ9j1F2zTtMwqx9ZOJB6LL5eNe2mVWPElUYAu4W/bfSDs4RK6mjaEfta+pd7PDeGYBABeqfVPYu8/vavvK8572nUv+1Vpz6dBA+libardvtqbdRnO0T4y8AJVzySqzxCbLbDLfXvt4x5iR3Mhu309YodrbRNvd/TQjxfsqf/UJpG84YLmm3SvXt/aAnGw4wiOYSTM0bTO9oj31PgeetBjPLQDgwrVv+kt+/dd52Ncv2XTrzlI24Bvad9K+W+Si1XzXTTozhTovYG50l2jJ9Kkly/10kL+rqNhJa9/+XNr3IK9pTfv2pjGa9ldKtvWTfE3JnPfdRTTEXPveSDTfFnA3LZUK32GmjiexfbW6yc/lGsoGAIAL1L6/+12v//HMPHzK2dX9+/cTtWHvdU4pl/b9jgJffcXtzOhKmpmSsrK7zaK5NC9liMr7Hj+S+2nBSHqlRbm0L6+lU/5s5n2TXXlfu33jss09D72l4BPm8Ckn2APa8r6WfWfMTeFGvfHcAgAuJvvOoXnyYQdt1ga9kDDmRWlfP5bxTpszDx8v35lb9Iat5LlpcseYuedhnD9xyuKzBModIO37BMv1BVOdizfynoc3tHr21Sp2qf2+XNEi5KP3KjwCDin66NicpzS3fbdwxMDn5+O5BQBciPb912NTh687g31/U37643QAAHChr313LUrpDvsCAMB5knmAfQEA4Lf5tAUAAIBfzb632z9pnIFpAgAA/H5fAACAfQEAAMC+AAAA+wIAAPi17Js+y3jw0f20rn8yi9Tj6YR3PFuoq85Wm7peP2N1nNc5DfPSDg1WTWx57qUAAPDb2nd0Zt3p9k3to10nncWPP8O+PRz8xej32Nk+GZwz8fSy2o7nYl8j9pnta5x7ceE5lQIAwG9v37Z66InT7atM1zBnt+9Z8erxa9n3HEsBAOC3t2/Z6FlSaVOWOzotYvuuKwm/1cg83KDrupeReRgfntXVR9NCI0Y/tDBMmzI2NDjRT9m3el2O7uivhb0cXPJMmObFfVKNfpx56JKfNyx2BTv1ASNyaddavdZH9omSDQqCHDn3sUmfzc+4gcvyuFeHOK/ramuv01Q0iTpb6wBNS4wwx3TpmnxHez5enOQYxYO4dGx+LB/Kc98gcwwDR0fFdFEdXaX9Y6NG17gaS7ps6pQU+7/WEKzqsIhwPadKRb4lKSbmQW1qyyy9E36yAACNbd/w63q1rtDqiheOuDNqlnZraJ+aJDPva6wz+bHQq3/Bpjy2b35d3aa7tI7TS/vEXq3suyJ4cfX8a7SypI4nO62zrX2lffXh2uRYrS78/0akZs7SHvzipNbRWFRrmT20uoyxIwqjFmuX1s63rX1jFhbc46hQ0STqbKZ9rbVv+OS2LRM1H687R9wTOoJDFGgvJ5rnZs/Oz1pTWtdRdVSl10R1KU0PTlONDfvq/bX+JaXGEFR1ekaf6sNVKnLUAT+/jlrQutLqPvjJAgA0sn37xPho6x/TVnjxWjNolhb0GBvV075B/TStRvfRQofzyvhlo9PETsq+Hb0mV/NDKK8hD4fXs28SryVb1/UJlsKcpY1fPkWdk+27IouTzb7p2qUR9syDTHksn6yiKeTZPOz7sKYdGKZ1aS/XzLcaIYYPc3l2/CZ7R1XaL4jX6cHfq8aGfeVD0gmjSFU7tho1ZuRqx53y1eKLL0vxcwUAaHT7juVV7f+t11Jj+fuFs7T1d2naCE/7rr+HH/UpWihnCMoWaW0vDdf1JFfe9+XYmJYjfHSDevblyGzN1FFmZJ/LwrMSq5V9U3Nk0sPXncM17FvC3+TfoqJJ1Nk87Mt9+jykpRut1qhD5dnEhfaOHqX5d6rGhmNlOmHw1UaRVV2lj5A1KvKJpJjYjlpcfkntrfjJAgA0rn39HIZp4lZ4sRhb8tqXVdSx3tqXU7/b9TRlX99FcXXTk2zvug1MStSirjG+rTmDffvIyF/M4u+rJ9emute+XNo13W3fYPWuW/4tKppEnc3Rlpt72nd8V821AY0Pa9TaN8jeUZX2kx3Dv/ewr3wByLnFKFLVDiPFoCLzb4JfuJ6/pl3XegR+tAAAjWrfQi+53Swova54unZDzCxt4nqfal/Tvvfl1Jl534wqbaHM+5r2zWumVee77Dulh+aXN0uLaN9X8xuuVbXmLK7Rz23fuvDpWi/HLG1FXy2g+IA773undrJkoNu+f7/FbV8rmkSdbfkQbaAjwoxtGXR+Lb9rN7CtOjTOzZ4tyOyvcd7X6qhKaxw3aPcE+3nYN6asdE1mX6NIVae399MOV1mRffqziJdrk+u0jlFVWtk1+OkCADSefYPS5dd7QsOmLF+flCf3PBQvWWfat+4Ba8/D1eFZvlUu+x4Ojh+c6LLv1Id0fXSVVt2v2DGsjO/geYeB0c9tX97zoG9atEYbwtsPntGUfbWCfEfOAdvusXti5J4H074qGqPOdkPQsE15EeaYlEF/CHIU59e4DhOt3Q2Lk+SeB9VRlW5dHxXfQ/Ow7+BL9fUdrSFY1bzbQu55MCP7bNL18MVaYozumM47NSbjpwsAcMF90jhv+vk3JuPVAQAALlr7TvXTOpb0hX0BALBv07JGjxm1VYN9AQCwLwAAANgXAABgXwAAALAvAADAvgAAAGBfAACAfQEAAMC+AAAA+wIAAOwLAAAA9gUAANgXAAAA7AsAALAvAACAn2FfAAAATQ7bVwAAAGhiYF8AAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAAD2BQAA0Dj2ffSd39t4JxqzBAAATWHfdz62H338DmYJAACawr6/P+shAACA882+Laj5T7TwpxsbqmpHV/x619mZLv/ZfRoc65VEj5zlon/VCznzxfySywMAXIj2vYJoo0fBFur8E/YNoef468aiBadX7aC5/PWbohebRFi5axvXvh8Xvffz7fv2ymTKNqZijz9RAewLAOx7TvbtGUKUUPFL7HtGTPs20XLxSvqgce37Sxbxr1PC47d1lkNyFiXAvgDAvudq39foq1UkV6qB9LZ4hOjKuSR5gu371+bJV4QJUdMuO2T33YaPU2RJhdFgo2m0+x/3p1X3ix+TKaHzgDRWB3PMlNaj7bKnrXzD3U/5bGO7vdnLhNg3O5D8D3HcRz+ZPTLw8ZvE3Tvep482iH/SSlE6kkrFPGoj9g2YPW1byrVSkp9tDnwkrHvlqlNuPV2erFkJgzGnmicv7dlgTB5r5LiQXK5QAxXfFoVQ+esycItJIYeibZkHq8Ya7XvmaJ/OppFj3vtQuCIO5ZF1ftdbVFWSugXoHfgt0R7r4Ok5yccORhvX+97e8h+Fa6q8W0yaVj6DJe2+GNW23uUBAC5q+86jtadotmHfBYZ9V79AeyMj97SghMB57DxRU0kHNxyjl1hN1Lx3CH02NDKBZkZ+Z9j37pG08rbcbuK2zRt2+dMu8e1sWhn5omHfRytp5dIEVonqp3xG+z8JpHdFVciEU+Mo4VExgY5Hfr77Q+dXgb0jBxSJD2nkvqNE/94XSINa7abyuf50yJslmfDewYrjFLJrdoJLT/PaKWlS87XJNKHBmDzWhOwxdExzDfReyo6M3LVB2jehcyV3ddlX1VijTdg/cySP9mj5jFdzaZtTRWz1Jq18dRuP5HoKvOKr8rl89/DByB9fcq19V/NIZ9DeNHm9b24gutc1VQO4JpeyK4TrYlxt610eAOBitu9iouvvJXrabV9X5oHu55zwRtGb5vEqk3ZwSeBNRomVeZD23U9LhfBOE6XGLbi/yjxI+/aWYb6lEFs/02ebhThCueKOfXw0hlqIxynlH3z37wwJ7PaUD5eV0+oNlcfmfkDZYgFRhRjEI2FJ8gI0jKibGBqi9NR2ZDclTT7DaqLSBmP604Q7aqQD1UBfolV333+tkXnYIt6gSrd9VY012jfN0fo4eUHNs6MiLqDANG76Ed87UGX3aXx12ysPCrd9d9MpIQ5x7HbcWTTn1x5rqv4wkifP6U9/c1+Malvv8gAAF7V9N5C/N8thqbTvB4ZfXPbNFrxOG8cLMoNyeX9vltjsm03m22sfHBwzkhvZ7XucDgpDn+5+ps9myOCVIuy2eZxypkhx//v8MOlR8fpOflyqiV10JHfCxs6neFCvsd7EtUTPsST5rj+a6C0hZis9tUhOU9IsNzx6b4Mx/ek1sU++yLgGuou/TntXGIHfpkBb5sGq8Rzt4hmbOalL16uIr5mzQtHPEa2WuV9nG5pUtJlot/mKkG1Wz+AI3YWYxK8d1lR9KF/V+I5jrvtiVNt6lwcAuJjt2yrZ/J+/sycrtZs4Ku37Lm1TIpLOfIU6X8/8210ikqmbZd8i4549LW0nzV3wjZTaBFpr2TdFSvdFSrb1c6195/KCsDc1f/36MWxK4Xziyc10hJe2b72RzCr7jrbRu21oNp/kbqJHxVvm2vcRY+37uqhy3Zofaidsa99/E1U1GFOOVdrXPVBx0z8iiXoagT3ta9V4jnYevXD0SWlfKyInHFbzrHTb96F0+nM0rVUby8dbjI5FdJyrF1xvpsClfa2p4teSN0SrSmPta12Malvv8gAAF7N9u3FWsqioiN96Em9SbuQqad+jFHhkmduZ2yvpk8jIeVfYLJpLuyOfVnnfpac2d7tpJC17bZWUGq+lI280877Jrryvp313du+dwG+oDaBtq5fKdWr3DZF84hQxqXdkSiDdLapYYfc+QfINLHveV25NeI/ej3yBLD2lJXRz2TdhDofY2HBMZV/XQN8a90rkUgr8w+n2VTVqtDJL3Yb9ufHom9K+VkRnEc2LjGxnXNm8yFx588C4Mw8LaNqrkZ/73+i2rzVV7ryv62JcbT0uDwBwUdt3Du2WDwdpkvjwUMKYv0n7tmIZ77Q585Glq3ZuLrrRVvLkNKkIc8/DC7zH9QPxzwTKPSXt+yHfRh+y9jzM5D0P3cRp9u0+NzB7mbfYM4mmbchlU77LXQKXVokZnDRIXsb51c1U6S0qZb5U7DvCex4+/4PaGBbWPTnEeK/LeOVISHN/SOL1kI9mpDUcU9nXNdCacYH8Vt1Rcbp9VY3naJ/eS/5bpH1VxKEp26aNKRrAbZ77OoG696xnX/HUuL0h8164321fNVXer03aWX68rf1iVFuPywMA4JPGjUrjfXqs3SFxzp/LAwCA//bfstN49t1yPewLADhf7Rt93v2GyV/jNyfAvgAA/HZ1AACAfQEAAMC+AAAA+wIAAIB9AQAA9gUAAAD7AgAA7AsAAOBXtm+zy8zHsVc3WHWV/ZMbhZ2EOBCrR9dv9J8SprdqvPlRwUJ7nKHS94/nGOUvp0/Jdq9GGJ3HfDbW/Ll4OOJshwCA38C+OTrT6dzsO99hq+rQ11YTl8qRCk9vdPHY17gsyYHFHuW10f+ZfYeoufeYz7PPX2pG69op8pu79PGwLwAXrH1PnPva9+xi9Zr/X2HfejSafc84/2ekf+3wof3lr1JrlTPsMdgXgAvcvs2CLksaNZD/Z+dl5dzKh18MzoodaNo3dYmjk5/pV14m92h28zNZsiXfKafGx8Q8pjIPUbrudVojP9+S8OmW3v6Sv7w9/0meZkmO+CuF1bdXpyx9sPhLB9FXv07scXiLDuFZz1azICNGZ4iykvBCS5il7R05w+Uo85LutAVzPrwk67IRwrssR3cMskLKcek1YnqesIJt93o439ceLLQwJzPRKQoWhQant1KdffsFOVpWGfXmoERcvOOBw3yqRUGjuMK4LCvzsN0rYtNDQ4y2l3HxH7d7DamtlcfuqTJG6lwXXJLOvzFzckbJ2Af6iyC+QTgQ7wpsDLeHbk2b53yq+bcmy3NEy9UL5svT21trX2ue1bPo17VEHyvEoFFRm/iPfBYMcwx+JsLVXR0CAM4P++p9xNZRfC/bf+h9mVNEs9b99vXL7Cntu7h2uF9ZvG1ZGzXEZ80owxZRw1u1inblfTPnn94oaOGIgRmDTPvWVol+m1iJcX6PhTqtvu3LenpPFYWDRWqxr/HgtaI0/2YWZHunKAydGhBvCtOZscgvNSqOR7lC2IO1Gh+wxzdPDAyO8+4bYIV8toNYWNxMGt0Ktl3vJ+zBRGhQXNxDB0T0iX2LR3VRnX3Dt97UKd2oNwdV7TXR775QPz5VqViX7l77SvvqZcInNM299o1JLL3PkWafKmOkf4qPrhhcJvZEFfotinHZVwU2h+ta+3rMp5p/a7I8RuTUnwkOTeSXqLZJQtnXmmfrWXQOy5svrhQBUc32vRx8rbM40W9iVISru3UIADgf8r4RohlLw9naafqlg2iWw48Zd0n7+vJqzNurwi3WYULcod/BtvB2TLxDiDPb12zUNosj3jnWFOY6WWQq66o4q2+nRfLPYAY4vJ8Z4iXPK22yR68WoVtZgh2EGGgKc6CM8+zDxijrB6vIEtFeW715kGbI6YNFRqGvuKqXCradB2sPJkL7CxGxzhx3ntVZ+LKP+icZheagJrbkLzcXCt81QvRJ8rRva44Yv9VtXxl42Fb7VBkjDeWV5g/hYjwvw51ZLvtaga3h2uxrm081/+ZkeY5ohJ5UE53Do4qfouyr5tl6Fns5jD8KOr49Dyd4+EAvrmwfobqrQwDAebL2lYnG1lViRfsSXV8jmvF9rsjrIu37gNSzPsgt1pvNlrxWuys+ZlQDa1+z0XCjb74pTPafyIwTE5M4R7HV6rs9qKSW36wLjVtSNawgPFrEfs+N9AIjNRs7mW+hTWEekDJ6sKs7HWoFc85a31rXnWLdqBi+4zdD7nH4FYfVVnEWwwpmZGVtwUToDxxsoRjhG67rrCuzsy9nNKZmGPXmoB42xt7PSAhzhYd9ZUTpUmXfEvPYNlVypGHGoS7SZ8l5dtlXBTaHa1/7uudTzb81WR4jGqofYBMvF6kLhbKvmmfrWZycY5SmJ8phTTzA9yAiMUJ1V4cAgPPLvqFDKry/ZPvGSmOlSvsOnu5qu8dha2nskEpLjK1vX3ujXsHuE/myC9L0qoLMQT6ieKur77VDWvuJrmXFIuJBFmZ7zjNX6Nca9m3P2otWa19eno592GZfM9itw3pV36TLFfuU+HQVMrRskVhexgOyghmutAUzgrN9uy7c7jxhLKZlZ0uyJnJQHZ51vx3HFXsasG+weteNj21TZYw0KsD4fjx/781r30481YXxQgU2hzu9k33HmZpPa/7dk2UfkZdpX1/Dpu2NTHWwsD+LvbKMNfR4GTqc1748eZ0i1HnVIQDg/LKvV4Dw82L7xqwQK0r2SftuLW4rvIcbjcJa97XbN4xXeR2G1bevvZF3fD9vUWUu53wzJ/vkjRY1V3mLK/WtVt+tThEdNVTcmvmlGJ75hdxLNVQk3mwKsjA2zLurlfddMlFUlMTZ7GsG+yMLpZ/uLJgv7rgsQg2na+YJEZF5tSuY4UZbMGXfy6YL76B4YXa229ccVN9avugpN6kK47LOYN8HUt32tU2VMdI1LYeKVn1EQVaBGBLVX0R8KfbFxgsrsDXc4eudyr62+bTm35qseiPqsOmOsNgyM0Vtrn3VPFvT7lzOmW7O+zp6iPuCWzmLT4iamAh1XnUoHgzAfxkAfvO8b6zLqSdqN3W9jO2b56vHHjb3PAz/e9Qoy3rpcjuD2775uh4eV9++Ho2GfhnqNXqyKcw162PknodnMoLSl2y1+qbH6A7Wf1u9kPUm3+7vEp7VNczaFFZWvKRM7XkIcvCtu82+ZrBrH1g+mO3bK0PXN4Wp4UzUq/hWfKArmLkfzBbMsu8PwaPz0uOF2dluX2tQBe0dxUF7XBXp9j0Pbvt+HyP3PFjH7qkyRuo9vtiR9CAXZ+gv856Hnr5BsXxCK7A1XOdy154H23yq+Tcnq96IxPQlcrOGzb5qntW0+/lm6ZxtvzI2avR8uckhNp5fX1R3dRi1Ff9lAPiv+KTxOX+YrMmDNQlsXwAA7Av7wr4AANgX9gUAwL4AAABgXwAAgH0BAADAvgAAAPsCAADsi1kAAADYFwAAYF8AAACwLwAAwL4AAABgXwAAgH0BAADAvgAAcN7a96QT0wAAAE2L86QmAsIwDwAA0LSEBWii5wjMAwAANC0VPTX+A2h9MREAANCU9O0rNPn3J0eEIfcLAABNhDOsghe90r6iZ8DJSwAAADQJJwPqhGVfAAAATcz/Axr2PTSZQ5bTAAAAAElFTkSuQmCC) #### Base64-encoded password[​](#base64-encoded-password "Direct link to Base64-encoded password") Enable when the `password` or `password_hash` value is Base64-encoded before sending. Useful when passwords contain special characters that would be mangled in query string parameters. *** ### JWT Header Configuration[​](#jwt-header-configuration "Direct link to JWT Header Configuration") ![JWT Header Configuration](/assets/images/jwt-header-configuration-880dc5df81fa65fa1ec2f622f4547455.png) The JWT header always includes the standard `alg` and `typ` fields. You can add extra static key-value pairs to the header using **Custom Header Claims**. The following header fields are reserved and cannot be overwritten by custom claims: `typ`, `alg`, `kid`. **Example JWT header with a custom claim:** ``` { "alg": "HS256", "typ": "JWT", "x-app-id": "my-app" } ``` *** ### JWT Payload Configuration[​](#jwt-payload-configuration "Direct link to JWT Payload Configuration") ![JWT Payload Configuration](/assets/images/jwt-payload-configuration--5bb5fddf2f1d85c268f4f39ecf9b918b.png) Choose which user data fields are included in the JWT payload. At minimum, `iat` (issued-at timestamp) is always present. | Claim | Description | | ---------- | --------------------------------------------------------------------------- | | `iat` | Unix timestamp when the JWT was issued. Always included, cannot be removed. | | `exp` | Unix timestamp when the JWT expires. If omitted, the token never expires. | | `email` | The authenticated user's email address. | | `id` | The WordPress user ID. | | `site` | The site URL where the token was generated. | | `username` | The WordPress `user_login` value. | | `iss` | Issuer claim. The value is taken from the **Issuer value** field below. | #### Issuer (iss)[​](#issuer-iss "Direct link to Issuer (iss)") When `iss` is enabled in the payload, this field sets its value. Defaults to the site URL if left blank. Used to identify the token's origin, especially in multi-provider setups. #### Custom Payload Claims[​](#custom-payload-claims "Direct link to Custom Payload Claims") Add static key-value pairs to the JWT payload. These are injected into every token generated by the plugin. To add claims on a per-request basis instead, use the [`payload` parameter](#endpoint) on `POST /auth`. The following payload keys are reserved and cannot be overwritten - either from these settings or from the `payload` request parameter: `iat`, `exp`, `email`, `id`, `site`, `username`, `iss`. **Example:** ``` { "iat": 1718000000, "exp": 1718003600, "email": "user@example.com", "id": 42, "department": "engineering", "app_version": "2.1.0" } ``` *** ### JWT Expiration[​](#jwt-expiration "Direct link to JWT Expiration") ![JWT Expiration setting](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAACiCAMAAAAqYZ6vAAADAFBMVEX4+fr09PV4gIf3+PkdIydsdX12fob////i5OeUlJS6v8L29/iLkpjx8vRQV14gJyvBxcm8wMRXXF+Tm6CusLJZXWB4e36RmJ709vfZ3N+Tlph9hYyXnaSZoKZyeoLh4+VBRknv8fI1Oz57g4rp6+2Qk5W3vMCeo6nO0tSJkJZKT1Ll5unf4OOFiYytsre+wsbt7u9scHJveICGjpTV2NvJy821t7lcYWSVm6KPlpx+ho11eXzHzM8pLzOxtrvV19nDx8tzfIONlJrx8vKhqK1GS061ur7Gx8gkKS28vr9tdn6DipE6P0J/h4+ssLbX2t2zuLycoqfk5uiCiZHAwcLM0NOws7Rvc3VPVFeNkJLm5uft7vCkpKTd3+L5+fl+gYOmrLHFyc3z8/RweYHc3t+5u7zR1Nf29veFjJMiKCyYm52vtbrZ2ttNUlVTV1onLTHi5OVna27KztAxNjo4PUHQ09VucnRhZWjv8PGfpapeY2lzd3qoqqzn6Op5gYje4OJ6fYDg4eHa3d/r7O1aYGMlKy8+Q0guNDf8/Pw8QUUpKSnt7/C/w8fT1tmcnZ6kqq+ztrfo6uvIyszj5edITVCJjI6go6WytLbp6urS09Tr7e5UWVyprK9LS0uhp6wrMDQsMTVRVViboaaPk5Xg4uOEi5GKjpHU1dbDxsjMztCyt7tpbXB7f4K/wcL6+vp/goW8wMMhISGIi41kaW7R1NaAiI+goqSorbOlqKkzOTyChYdydXhiZ2yrrq/e3t5DSExxd3xYX2XX2Nn+/v7Aw8WEiIrCw8Pn5+m9wcWDh4nDx8qurq5SUlJmbHOqr7V8hItpaWkeHh69v8FZXmEeJChFRUUxMTF1eoCVmqGgoKCKioqusrVUWmGOk5fVi4w/Pz/ir6/FxcV2fIHNdHV0dHSprrS4vsGVmJpCQkKcn6GgpquGhobFXl/qw8TamZmzLi+3OTpfX180NDSSkpLw1dV5eXnRgIDltrbeo6T25OTCVlfLb3Dz399wdXuZn6U3NzffesyhAAAACXBIWXMAAAsTAAALEwEAmpwYAAAQHElEQVR42u3dB3xUVb7A8TOZ/+QqiQmJCQECISEJEKIQCCglUZIQCBBaBDSCBGkC0iMQepHeqywgQlRAFxSBB9IEC9h2FxW3uM3VddfV7buv133n3DszTAo8pMxjk9/383GYmXvn3sy97M+zZ+5EZQEAgk+ZG1dK+m0AgKBIT3F567sqSQEAgiapzK7vKheHAgCCyVWm6+ti5AsAwR79upSV4uY4AEBwuVOUlc5hAIBgS1fWbRwFAAi226gvAFBfAKC+AADqCwDUFwBAfQGA+gIAqC8AUF8AAPUFgFpU3zbS+TJLmsrTnAoA1PdKWsqDarHJ6HGRjUrtkINHxCvDLF/v3O9RzUuLo39T5blsGaRvp0Rf5FQAoL5G/TrJR372vT0bq6vvc5Ko1CmRhuqOsbJ+S3T0CimIjo5O8ta3XN9vf5X7d+oLANTX8Q/fi4iY9fobERE/ml+1vi+IPK9WLI2coV4SmaufvFua+pbr+o43f7paSj3VfuzY9vfrSrfM/niRM/PwlCRuWZqo2hRI9sRj6h17nLzfmXk4F7usdPFGs9qU6SdWjOPcAKiF9W0REdFxkQpTAztFvPF8lfq6lsickbJg4i73YWmpqtS33B4Hj9wtxwvlN0rXd9mCpVKY4a1vwbIFp9SEj8/rAL9WVlwg+4tj7PqOku9PmSWR7+vVZEeJyDRODoBaV9+y0xHn9B919D8zI16vUl8z8TtHBm2R9hOlpGp9vXPA5t5it6nvPWp7gaz31tfMFqsN+p/Z0sY382Dqu0MOKLVfTuvVdNGXylpODoBaV9+fRvxc385N1jfu1yM2Vqnvc7L0lGx4SZ7T076q+pkH7SGRFsrUd7zp61pvfZ8wi8YtbqrbHB1Y30LRkw2HJV+vNlupCfIcJwdAravvjyLMbO+5N8x/8e2cXeKK9dUTv6X5Ki+y1Jn2rb6+cyRbosOcse+mSP/YN1Ev6iFLxr00xdR3mcT4x746ujPssW9n6gugdtZ31ixz+0lEO32bEvHLKvXVE79mniBaZLOqft53vdq3pKDFRLnb1De/OFpWJAXU9x6ZNGhvtqlvS5lY/ELleV/qC6BW1/eVnx3Rn7g9WbG++WaIqid+zYxBsTjTvtXM+36dkag/cZufLT3M2HdFwcfjVUB93Q+KnJ5u6nvPJHPhmn3Nwwuxu0sXT1XUF0Btn3lQGT89ML/SzMP4Ah3Lb0TXdz7HGQCu7lO3vd57o+v/d+CnbiWRMnYk9QWAm3bF2VPOvfp7KlxxtlhOrFfUFwBu3rct9upvp6mBByp/2wIAEIxvGv+SgSsABPO37LwyT/+Wnbs3ujlGAMBvVwcA6gsAoL4AUBvrO7xxwp1RHf7P1ULuuvyyunfenLeY53F9g7WbhN6IfcY3UM27XcPeAVDfy5qWlhMS16Dys1mZSarBo7dEfVvfWX19H+gS1ravUl085qb3BY+tU+VX3LD6Tm1HfQHcwPpObfvKhlUD+1R+uk7/q3r1/299VUc9Hu3aydw8Y37m8GpeccPqe00jbwDU9zLCkqOcO65nQpPvM7G6kNu7tepnDyT1zMPUTqF9Mluo+7rqL8x5wlTIhfCjamR4Qqa3RiGre+WsC1OqW3xO8zvs3h5tpJ8d6avvmjEjcouUavzbjmPiUvxbM5IaJYzplqZ8G/Ot4Xs4s+PRu6Z1yOnVWt2lf5BQFdYnOXSY3tHjofF1L9X3PrND09reXQLq67zC/4b0TxI/1/v6qI6N0sbosfKj4T179nOG/vZO9IIOaXV8O9HX5yXof62Utd0++bchycNc/pmHgL0DwHXV93nPcOfOM5lFfZPrqCaeVmp7yHbVTI999bxvk5yBg/u1DahvXH11R+i7g7NCBjv17fjIyN5TVZfQNRtyG6miHHfKByEqPcftrW/RiKhVv04erhrP26D6DPNvzejfeG7fzDT/xrxrBD5UWdOSsnIecUay3w5flP7J46puSLui8Ev1XZPgXjXPleNe5dlQZezre0Ohql+v7b7XR3lGq2ljlBrRwjV8kTPF4uwkyrPGvxNjZiv9/uNUg/dXtRvzpa++gXsHgOuqb4sE50+3mUJdnama9NRxCZ/mq2+/5iaxAfWdZkdJqUZ1nfrqxxf6qDg9jizy3KFCFmV1TWtS9xPfzEM/vao7eaBqrFs2Oty/NXt/ekgclebfmHeNwIe25s2cloboH29+vIprplTfS/UN67koq7HKXJT1gapcX98bmhy6Li3J//oovUpYz/ruhHcDG6p3Yhb4VjJG91Yq933nfXTw1Tdw7wBwQ8a+ZR79X25rN8+ZJu34qK++w17VD3sF1Ff/H/JX7VkJZ4gYor+3rJftydL3PZNV/2brulxoPbObr77D1pmtvasa6/+iXLve/q3Z+9NJzErzb8y7RuBDtSYu1KOH4qalec5namqP/n3BGZfqq3KbrXtFvdpsXfMq9fW/oRGhWZdeH6XnRVTPFJUV3nOMM/b17sQs8K1k/9shZGTKiDw1t3G8xxPuq2/g3gHg+uZ9P4jyjn31bGvdzMr1/baOUlhOC9VtphncOvXt1lxV+NRN1zdO9/Yd3fHWHXqltOjfqYF/7GuGrfEDfW31bc3en9lSmn9j3jUCH6qQ1u+49QzAarMRM1TW4vTzDQLq26rDnvlqaoc9qyvUd/Wdl97Q5NBHQkb7X++rr1Lb1+1x3oGzE3uBdyXbsAtf/o9Sz3ZtUv99f30D9w4A13/Ng3taH/VMY/fwtDqV69tkxGS1Ws/Utjga5m7ure+GeQOVemRuYH27HE1S63S/NuXEq7zQhDBffYv0h1dZZt7Xaatva0b/mSpJz/v6NuZdI/ChCi1Sg0NbqYG96uvMxiUp12hVd0+e+9mA+k7L0T/vqhzPpgr1tV/hfUOTQ9Wi0Ha+13vrm7fGTr+6tBN7gXclW4PkND3SbbRauTv66+vbe7vV/EUDcN3X+45Oy+mZtlq5uupLBNyV66umxnt+PUa3qk/uA/d566s2xSV06lgUWF/1ZXzOs0mmZXrsmhmn/Fec3b9nRPgm/8jWvzVlrnlo+0G3XP/GfGsEPFRd5uX2b9RK1c/UVzC4+3VKSNOXMDze6YFWAfV19TRzzEedq8r89bVfEfCG1oT29b7eV99cjyfe+a3y3p3YC3w7sSUn6ITPTw7vMCz80jUPzt77hfMXDUAQvmkcOvcmba3OzOvZkPnEDwBqaH3buVWd3JuxtaINKuXommvfVFgXe/oWAGpmfXM9I+I23IytrdHfCq5zHZtqfrQuZxsAv+MMAKgvRwEAqC8AUF8AAPUFAOoLAKC+AEB9AQDUFwCoLwCA+gIA9QUA6gsAoL4AUHPrCwAIOl1fCwAQZNQXAKgvAFBfAAD1BQDqCwCgvgBAfQEA1BcAqC8AgPoCAPUFAOoLAKC+AEB9AQDUFwCoLwCA+gIA9QUA3JD6NpR63+h5r3sl5gpLt8nJik9EysNX+fOclG2cQQA1qL6FYuyr8nxM7LhKz7hEXNU979VDHtK352PPXbHNCys+sTj2yaprnZfzVZ9cKEd8dz/7gnMJoAbUNz82NnbhVbzcqe9lOfW9oskSezU/Z7X1tWIjnVB/+i9//M9/+z1nE8DffX3tqYKFkyYtVPkySM8FNMxftkDZMwztJfF84exRy2TSQ8etb9mD5BftmYeYCZMSi1/Wy5ceLiw8bm9nq1m6xJ55iJX3yndNnxy9a4ru5bZ7lxWWPObs65g0tKxUaTMju3zh7N3l25yZh3vlZHT2jLnWKCm3rJYy4IDZ0gwr41Th7tOTLWvUx7tl84tmymOOvZGhn/7pT7//d84mgJow9r3XlDH6vEwxPSxdUKoHn059x544cPh4/sHOu+Wia6/I3tSHzfNzZFe9FTJbL5ez70nkXLOdNx+UJ1Ibeus7NjFSdj2RLYet8UuyD8yQB519zZb1pr5j9ZJd2YUmtk59IzuXS4mu70S7vj12yI7UmMfOyv6SJUuHuiedSE2d/prJ+wJ7I//1xZ///B9/4GwCqAnzvkss661okdIM08OLehKhqbe+5qOuMr3WXv1xmTPzYJ7fLFutd0TK2ktkhjVBRgXMPDj1PWUtkPyhT0u0dVAX2DohdqCtI3rbur5nhw4Seb6JRCpvfd/T5Z3gr68z83CPiXMbGfRYQeHn+5bb299vb+Szf/3si3/6lLMJoGbMPFhWd5FUy9R3of6ES95y6luon9m2f6kO9PSA+u6WF82K+9rLCj0f691AYH3nWIf1SLWHtLSm2PMV8oK9yildbV3f2dZLctZsrsxb36f1zhOd+m721fdr54XF1trvizTtrmc7/Bdb/OGPnEsANaa+y3dI9rK5JqoDrIv+sW+iXpIvJefq6foOFRnuG/s+bZ0RybOX++o7QA9fffWNsbbIQbu+B2V69+7dt2bYq4wzfU/VGxggmwPrG2PX923Jt1yT9O636MGwHvsm6hcO0GPv4RtLzKd1xXKMUwigpl3z0F5HsfMciX1L97Bl6ln/vK+pb6KkPlWq62uVSufUlyvO+wbU900p2DunSn3HL5l0PvXkWMt7ue+MK9T34Uh577To+h6TpamfP5Yvp1KLm3Z3lxen7pdZpuuLOIUAatr1vqO2RTbNs6JlnO7h1hO7L13zoNe4uEvKzdjXOqbnANz2NQ9bzTUPqmJ9zSTDxCr1td6cUVq6Y7p3Z/kFwy9fX+u1xIKTZuYh46zIFiuj3ors8hkLX55SoLc73iob+xBnEEAN/q7b1X/77BrEyNfX+tK15noJAKC+12J59/uv9aX3d+cEAqC+AAB+xxkAUF8AAPUFAOoLANQXAEB9AYD6AgCoLwDU0PoOH3I7bmlD8vibC9TE+g45w3G5tZ0ZwjEAamJ9b+ew3Oo4RQD1BfUFQH2pLwDqC+oLgPpSXwDUF9QXoL7Ul/oCoL6gvgD1BfUFQH3BKQKoL6gvAOpLfQHUzPp+68O/ffSLbfrOd36wcucADhn1BRCU+j75153HPh/1pmV9fug7eT8+tI9jRn0BBKO+JV8Nde785UN9891fccyoL4Bg1Hfngr+s/GqtvvPDH+ubn+zkmFFfAMGo78pDv1r/k5XjrJc/itGP1v6QY0Z9AQSlvt/VN7/7BfWlvgCCWt+vzEzv8Y8s66/MPFBfAMGr7z97x77Wh/anbiUcM+oLIBj13XboHzO2rlzrXHG29tB4jhn1BRCUb1u8vXPlD45Z3m9bvM0ho74A+KYx9QVAfUF9AVBf6guA+oL6AqC+1BcA9QX1Bagv/9OmvgCoL6gvQH1BfQFQX3CKAOoL6guA+lJfANQX1BcA9aW+AP4O6jvkDMfl1nZmCMcAqIn1zRtyO25pQ/L4mwvUxPoCAKgvAFBfAAD1BQDqCwCgvgBAfQEA1BcAqC8AUF8AAPUFgFpQ3/TlHAYACK7l6cpKCeM4AEBwhaUoy5XBcQCA4NruUpZVlsSBAIBgKiuzlPljcBhzvwAQJMvDtpdZdn0tV0r6bQCAoEhPqW9Z1v8CX2SLZDXpZyUAAAAASUVORK5CYII=) How long (in minutes) the generated JWT is valid. After this period the token is rejected by the plugin's validation and auto-login endpoints. Default: **60 minutes**. Set to `0` to disable expiry (not recommended for production). *** ### Access Control[​](#access-control "Direct link to Access Control") ![Access Control settings](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAC4CAMAAACILL9SAAADAFBMVEX4+fp2foacoqdud39sdX0dIydQV17////i5OeUlJRweYH+/v7AxMdxeoLZ3N9yeoKVnKG3vMB4gIfu7/F8hIv3+PmLkph9hYz09PXl5+mTmqDIy8/s7u97g4rg4+WCiZHQ09aiqK3T1tjn6eu8wMSMk5nm6Or29veZn6XDx8u6v8J5gYjr7e6rsLWepKn29/j09faXnaTw8fODipG1ur6OlZtBRknFyMuprrOGjpR+ho3Y2tx1foV6gono6uy+wsb6+vrz9PWRmZ+kqq/g4ePN0NNzfIOHj5WFjJOAiI/Fys2ZoKbk5ej8/PygpqvW2dzV2Nrq7O7d3+F/h49/ho3s7vDa3d+xtrv9/f3O0tTMz9Lc3uHw8fF1fYV5fH/j5ea8wcW+wcazuLzU1tnKzdCwtbry8/XR1NePlpyaoKaorbN0fISKkZh3f4fh4+WNlJre4ePBxcghJyvg4uTi5OZ/goXx8vNxdXitsrf3+Pido6igpaqhqK2NkJKXnqMqLzNtdn6BiZDt7u+yt7vV19qlq7C0ub0nLTGQk5W/w8ckKi7Cxcnk5ufq6+yho6bp6+2Tlpi7v8OmrLH09veJkJbX2t2Um6HHy87Gx8hNUlWus7ijqa5ZXWD7+/stMzf5+fk8QUWWnKJdYmQ0Oj3e4OKBiY+Di5EyNzvV19mQl51ye4MwNTmvsbKJjI46P0KIj5bc3t9aX2OEi5JXXF9PVFessba4vcHLztHo6OmEjJNhZWmWmZuYnqTY2964urvY2duvtLmPl521t7lITVBUWVxtcXTa293g4OG5vcHDxsqvs7ju8PGoqq1+gYRFSk319fZ2enxvc3bQ09VscHKQmJ7FycykpKRjZ2rBw8S2ur7Jy81zd3t8f4Pi5ebS09SKjpCSlpi/wcO8vb8sMTXNzs96foA+Q0eGio2ytLVpbW+foaPJysujpqqChYeFiItSVllma27e3t6qra45PkJrb3JfZGhLT1OssLKlqatcYWQeJChkaGyLj5KZnJ6Dh4mcn6G7o8pKAAAACXBIWXMAAAsTAAALEwEAmpwYAAAbaklEQVR42u2deUDUZf7HH5jn2Wd3BkTBAUGmEBg0FdBI5ZYRuTwQULwWkxBERDzQ8ETwvkhSFG+TtLy28kjNq8y0DanMUlPb7bL7Pnbb2nZ/+3u+1xyopR0o8n798Z15zu/zfcZ5+eEz3wHCAQAANDxEOrSq9P4jAACABsG7spNq38y7CQAAgAbjbg/ZvpmdsBUAANCQdPIQ9u2EyBcAABo6+u1EeKUR+wAAAA2LsZJwb2wDAAA0NN6E/xG7AAAADc0fYV8AAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYN+rspR1xYsDAGiq9o29au0bjH18w+cpKX1u487dS6/WdIj9DfYFAMC+GsZLiX9Izriy3qOMscU3+nvRsp5jbOuaxWWwLwAA/JR9P/ts+6E/SPzzw+nd6jWxnZvYYTmcfXlxsRDn2Dc+KL78PSET1m/c+uPzhLxz6Ft2WdR/sreMbfpeGfQSY38hZORxQnb94/EFT75IyDbG/rum7OHnifCyMDN5jZ38eOcr1mbYFwDQJO279w82PnNs+pLd+4Wkxqr1rGzyye9Iz61s0992v0/eZWX3nmGbfat2Fn9Y+n97yRD2eGnpK2pYu5W9pjzJ2MmenLyYvS3Zd+PfnmNfkU+6sidLHxT2Le76/oPWZtgXANAk7XvIzr45Di3PMHYhgbEJ5B3GdhGSTt5iXUdKjyfYh4Q8zA5XlRX/a3U6IZ+yTe/kliiDOjL2oPLsMfayiIpZmWTf4+RFtlPLPLzGtqbbNcO+AIAmad837Oxb69DyEttsJF3ZZJGBWCBXnGGH5MfHmcwZ8v1i8TB5JLlXPCz4rzJqs5bbPcNeJyJMZt7bJHkfZ8U2+560b4Z9AQBN0r6edvbdZt9g2ahIdrHHBcYSRFRL/sM2l0iPe9mZCxcuvHtBfMR26cWN7GlCAlxKGfNQnb34Iznv+xj7gJDDbKMU+24hT0v2/ZG9L9v3FTk0VpthXwBAk7TvKZt8d1fZN/yLsRN79+5lbKnI+z5e+toaKe+7962H3yfL2ILPS9/a/A1Z82HpY8XsnUu7/1M6mRUruYesl8Una3s3lpGMjba8r2pfEU2XfqPa19oM+wIAmqR9vW32fduhYTc7IT28ztbI9zxIpYlnPiiWcr7ddm8u+/KH98gZcUvaxoWhW3YXM/bBcWK735edWKre8/AvYmffZ0TO4mHVvtZm2BcA0DTv93W32ncINgkAABrMvrmafN/AHgEAQAN+1+0/qn3TsEcAANCA9i05Kct3PrYIAAAa9Pc8TPxKyDcPOwQAAA38O84C3tr7AjYIAAAa/jdMVmJ/AAAAf9sCAABg32vRstmvG3+H043O/WvPSLxdxReoe7v6BNZcX//RwcpjxO90J7S2BSH31G8J7PxzYyf4EG+3a7RZeif64B88AI3XvndS2nL5yHqV3a1v6xbWv4cRo1qxdSTJOSse+8uHJVThrqtMLY24hn2d73GY+ydrHc5+HdTNEYuMqCPNetnXht1FfCktDwv87ex7512/nX2d77lh+7ZOrvtl/0YyaQCJpzS6szfeLwDcTPveZczvv/ya9r3Sf8K+/XYYSWXMMHGgUirZye/qU/+cfa+z9kbtK9HeuX6NbN+ATkt0ubeLfa+8xhuxbyoZ22MP3i8A3FT7EjJ/BSF/9nSNEIbr5anTzR8vglkn4h5sTpHzAK33lBcd7Szq2qv2DdU3I72meYpDJLG3b+AYV8+5hAyaIQJQGiqPuMOpe0xMd0JC95mGzQsVJgoe1787aS+aOktzh07xomFZ6kBrbacZ0aZBROssoZx9RLJ+XIVcNh4Lo24jSO+QLkln062LV2YTmYccOR4XmYeMcXpdtp19Cdkuu7ZqdErikSBCJq1wq14naoamRO8T9u09fVTKeN/ew7wWqTtBBvrsoNWOu1Pfvr1mufpkahe/0t1IyIEwa61s3+AOHe6T7Tsp1d203CK+9z1lXP/4UMm+xoLtnSSTypcecNY1LEGZ+9WaxLD7rPZVN6TlQHKOjieL5JSKdI3tA0fVjGmvDgusSS30iV3r7pXg8Gr0Th2V3KOS9JBevD25dvYl/Wgo3jAA3FT7WrankhKn7MzWRZlEP8RiGajEvu5nq+QsbMKOXpaOk+xjX9LlHrKu+z5xmO5g3xa7Mue7V2n2VWJfXXxAa7eOZI7nQO/qY+QOupaku3dUQj0xd3hKP+OWLG2gVjsjomKlqb21sxb79tEHZoab5CzJStOfjbF9SO+YSpI3zrp4ZTYp79vCWbIRid2Rl1nVzN6+AUWrpJIlp09FQQ2piozPzNYFkwqdS2aqTtg3RqQ9nm0TtLL/CHUnzq71MKbV2x1H+/brMMR3raf14k35hBTkWGsl+5bXVA7Vj5Ds26w2s1/yfrG1z1ZVdTkg7NvJpyDUGvtWpaT6ntPvksurXs1qXZih2VfdkGktyIzIQBLSQtlt6Rqpv3VYoH5J7LSU5ZX7pf8AbK9G7w4BZN9y0kv8DzuxsMrOvsYpKXi/AHBz8770iViS3UM8n7nE6JbdScs8uPspLqzOq595IMd8yJ13JIjDBFI/89Dyz472pSLUW+FHio4SssVLmEhM7+ln9azrXPuBaq1Rv5KQRRHWztrZpXSz0TRUKg508pMU03ufiAtpR3Xx6mx29r3YpV7el9ICo1bjnUhWOgn3nQ0mOSKarEoU9p0i/qzdDqGo9iHqTvikSgGs4+442rdABMNGJ2/tGqakEos+wL72Dir+A4lfp2UeJohzuQtFr90npvVMNdoyDysTxZmdR1vnF5ZV7KttyKJqkrKkQAqBrfb1tA2Tng+kYoFuAfabKl1T/hhicetDwmfY531pUT7eLwDc1Ng3dGXMXDJa/lk9j6zy1CVrse94xZDJra+wr7+bbzS5O9GXejvYN3uMnlI/R/tGi/pRvUqUz+aUHOioXppns6iv/UC1tk6qTetg7aydfXm8VFYSCfuSdT6+pLcUBRZmqItXZ7Oz7+j4enlfrRQ6Oqyc0tDcZPE8Ppgsl5R3p7Cv+PF8qDxZF3Un7hg1LGZJvd1xtG+E3DZCu4aKYaG9PG21kn13SKqskewb1NuLUk9la8UuBZpc+9jlfXPvFE8GFchl/7PRlE5R7attSIWbb2RJTKWb0WbfzrZh0nN5y+QXzrqp0jWl9SckNc9oSrPP+wIAbn7eNzuCXJymVXSM30MW2du3WvlDcCY7+1p0x8RbPflYB2Jv378XjkgnkX7koshH9BH2NWmfugmD6vrYPoGy2Ze49rMfqMW+OjFwSYSDfaW5cqRVeQ1V15nhuZz0FnbtSCu1xSuz2ce+269h3/tWDCwJoqErnYTIfETsK67GmKjYd6DJfifEH/DoXp7puDuO9q1e5HDxJPnVmkBrrRL7ir8HsnyGZF/nNndU1drsm32k1hRgH/uK1YQosa97d2/jdM2+2oYQ92Op5Ilj6keimn21YfXsqy1Is29apH8MgX0BuLXs2yn61dgO4rOajKASEa1dXEESwqps9k1oGURE3jepl82+xLNQZC/nFTo72Hd8SyOZK6KtISmhxhBhX2mEZtApPeqIJd9aDG+j5n17WMiWLG2gVjujwDhyRXsH+0pz9XEdT1qbLFJx0nDS6Ugw6V04NL3GTNTFq7PZ2TegUKRFm13Fvu2FTvNoaFVkLRkv8r5/148l91HFvkbPY+JmjoHqTvhVkWb6LMfdCQq3t69f5FhiTLBePLmns97DWivbV3eMVLrLed/Oi4hxlL19yX1eyhcQpUuvSskm3tEZyp72IZlOU6x5X2VDiHNhLQkvvMfRvtqwevbVFqTZl3glra1v30F98I4B4KbalxzzJH8/6xr5bEVJF0q9dpGqJOmeB9W+pNceKtK2rXXqPQ/SOzmYih/AV9FsB/uSdf2fXT5LFPaNmyXUJo/QDGrMiXQbM8gq1LFF6j0P+0zSPQ/qQK220zrxEb/Rwb7y2efu0ZuHy8WB/Skdd7fIaYbppHselMWrs9nZV9yroNNlX8W+IyOeqJaWOGnFHs/O0j0Pd+4pCFPsS7KmuzuZh6o7sVxH9bXEcXdWUlvKnIaQhAh9cmfbxQdQKUms1crxfgudes/DFpO5Zrld5kF0uKe//LGifOkBz7qGqbe93RUzzrmz1b7qhpBscYdfAl3paF9tWP3Mg7ogq33X0j717av3wzsGgMbzTePsMbfO1cq2BNfHXU9gDwBozPYNMM+DfRsjlhUTsAkANGL7ervWVMK+jZCh+nh8twIA/I4zAACAfQEAAMC+AAAA+wIAAIB9AQAA9gUAAAD7AgAA7AsAALAvAAAA2BcAAGBfAAAAsC8AAMC+AAAAYF8AAGhM9gUAANDgCPtyAAAADQzsCwAAsC8AAMC+AAAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAAD2BQAAAPsCAADsCwAAsC8AAADYFwAAYF8AAACwLwAAwL4AAABgXwAAgH0BAAD8Mvs+zP7CH2T3/uwsj7H7r+dkUxmbfSP9AQCgqdn3ccae/wX2/StjT/HJjLGNP1zQ2t5gbCnsCwAA12PfT4VA3/rl9t28fitbvEs1bhljJ2BfAAC4Hvu+z75jmwx29v3LmgVdS+P46+w4/4q9w3ezd/mbP2z89qW2nL+5puyfrzja915ueJkdVqb6iL28mPXkvO8XO7t+ItlX63+Jdf3i2zfkmT/h/PQrXVnZS9oDnz3528s/TuL8wScX//uH2XiZAABNw75xO9nqy+xTm31fZGX3bmJv8P+yz/lW9tbgBcWtnllc9v7r7AwfuZmd+Li4vn2fusw+U+Z6nb39OlvI+WF2WUzBZlv7X2LFm9//8Bu26fM17Hv+Nju58K3d2kPbl9nHLy3+4KFP2ZcLF+79K14mAEDTsO/TbKtBcqjVvs+xj/hTjGW9yb58nn2w/k32JL+fPcaFiZ86zh438H/Wz/sytlmJWLOK2bYXWVcupniRvyfsa+1/ibE3pep3+DPsZV7KPvw0i2sPx9mXnP+DfbSaPby6J14kAEBTse/HQrhPs7I4q30vs/c4L2b+g8uKlxYvXfA/9oVIQMisXsp2c/55/bzvVw/GKlN9wjbx2f8Ww7eKWDpL2Nfa/xL7VrRvVKYhT3UVx8lx6sP/lNrSwT+K45oKvEwAgCZh31aLFfkdt4t9v+FfM1Yi8ghd9z7Duoq07/3s5OrVqz+SYlnOD9XPPFj5UpnqfvvYV+l/SYqIRfVhaZoN3LDt6U1stfpwnHUVte+I2Hj4hd1S3gIAAJqAfUWWd/369ZvYx1fkfUX2ViQcLrPiVvyZxQu+WPh5sZT3nfx/7Fr2FRUn1q//ju3ccJg9vnCNkvdV+iv2FXnf0oUn1/MH7124cCd7T30Qed/JC0s3r77w1UIx6DBeJgBAk7DvepFY4Hw1W5xlvefhI+meB8Kl6PVdEQCvEe3bDm3deeKkdM/Dv9efvJZ9F7LvxHHkAvZu3893bjys3POg9Ffsy59+smzT+sP8aZFyWLDQoD7w2a9sKnvyUM9dJ0TcfKYELxMAAN80BgAAAPsCAADsCwAAAPYFAADYFwAAAOwLAACwLwAAwL4AAABgXwAAgH0BAADAvgAAcJvat+T8n8Atzfks/MsF4Ha07/mvsS+3Nl+fxx4AcDva90/YllsdvEQAwL4A9gUAwL6wLwAA9gWwLwAA9oV9AQCwL4B9AYB9YV/YFwAA+wLYFwDYF8C+AADYF+AlAgD2BbAvAAD2hX0BALAvgH0BAA1jX5cuO6iH9KSinfuw6pGcP7TfrPeap/0KxH7N3ekq+VndTHfqNZ7zkfO8XM/2U5tnT0uhbaxzjU7SDXCY3NY8aYXe66JW3XZmYVFInFZalaLf468VHPrBvgCA29e+OYNyZPu2dU+aFGs+aOBBT+T4DSoyq80HgnMV+1qKDnbv51fBuTmin0ewbrjS7N1m0UGbfUP2T3O0r7XZkhh+eq5+kVo9xtzR+9ECtZBWvqptYPkkpeDYD/YFADRi+w7eP0ufnKAWQlOjO4SHtHHoECXb158KAaZTP6XuVZpubVfsuzyyr1zqS7uJo84myC72s80ZUH8xSvPF6MGcr/VSqnZR4e4R2hnOtpN8nKoUHPrBvgCAxmzfvKQRbf1a5iuF6Sm7LOFOV7evOJ6mg5S6fGqpZ9+w+B76/svEk6TqOJ7rGnBj9m0nKXaEOml2tDhsoOr/CNHdxWHto0rBoR/sCwBoxPbdoBsoji18lNCXDuXcYLqafdsWhQw2zKMz5KrTyam8nn1ddakJa/UviPg4mVJ9Ar8x+45ZJw4TqZJfWJsiHXcEKqE5bS2O7YepOQn7frAvAKAR29ebysjC48NppTjWXM2+fGxzqgs5GC89zZq1fWp9++qfEIdgkRMI8dp/4Ihb7I3Z11OxqpItPqXYN1vNZMj2jVZ6O/SDfQEAjdi+QbTCVvgp+4q7GloZhrUXj1MPVsfx+vYdECIOSygfS8V9Dzwi/sbsW6BkFE7LVd0l1cbRIUoHJznzkKwUHPrBvgCARmzfwboXbIWfyDzIuFAR0z5kdjbwK+zbRo59W/LxdKx4sqLNjdk320lMOSVMqQqQMgv+OjW52+6IlHEIVwoO/WBfAEBj/tRtfmK3VnGta4UHhXmn9xefuumEELs1V5vTo5bRA1Hi9t7uI/z3UZHubRXxSFpUVNRpZcDpqCh6Kkp8xja2PMdyQL+M9/XyEZ+60bmch+cJk0dFJVdHZajzjY1KjYmK2sB5YL4yubX5tLiTLM1tguhiFn4f5+nrPWsaV87Qr7xX22Xl3sp81n6wLwCgsdvX4JKk9+qSK2JYccdC6PRh5fNmBosgtVBtzpPTwiK8vajTpQwS93tlKIniKGVAmlyQ4tdtB/UpUpIg1tnkapZytV1mSp+ZSQxQ5zPLJRFJe6mhrLWZD1e/RXFUintP1xQWTXuIK2eQv22xTZ3P2g/2BQDcdt+2MKS4/M6LmipnJwDsCwDsq7Gl28iA1GFtf+dF5fvghYF9AYB97fFOoYWjJmHbYF8AAH7HGewLAIB9AewLAIB9YV8AAOwLYF8AAOwL+wIAYF8A+wIA++KtDfsCAGBfAPsCAPsC2BcAAPvCvgCA29C+57/GvtzafH0eewDA7WjfkvN/Arc057PwLxeA29G+AAAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAAD2BQAAcAvaN8n/Rke4tFMevcZfq+XadGvO091+dRfrqqfSOPwTAgD8hvZNW7GjyGfL73G+WNdr2zds1W9n35AXfr19LdSDD6VUP+4o7AsAaBD7vqpbVNcq/xTsK+w7gFum6OpgXwBAA9h3sGmR8mTDumjTfM6DnFxikpsN6V+YIwR3ZF1h87pB7l754rmnq7mZ0rNVagfaYSq3OA/zqhUNo2aaI7ZYOzinbn+kYtvMxEeXcO5EKa0YfMo0LHww5/kp0aeutG/uLNfmFt43eFZigS/PcDeI/w32cG2I5Njqmh0HM2T7BrRxN4XHiQVO6dJ/iWxfg3OPDaJPd3Gadtyjh+uj+aqYlaWoalUbWvbkrWkFr515lS42+3JePkIqqiezrnpOtNc5YV/3KeMe4WPNrklbuGHOo9TtKM8163QttOtQ6wAA4Oft661FdOuSHsgwZfMgXXhWYNGRoLTCIO6iP1c3/RFRFlZcNtbSwr2v3LNF83Q+Po6fjffNSDnKXehRfjS6ldbBOUbEjge2tU0onKTEvhfNPdNr5vAHdN0s63T17burg79lkJnHXax8wPkI56Z+Qt8ttCGyJctzWuUUnpbsO35Vq10RgTyIDuIl7iOFfTc0dx5sjX37PtLG0lo/Vi6rS1HUqjVMX8bjB7jw1GVXdrG3b5rOQyqqJ9NWfc59YLpZsm+PvtzoNMGSUGTJMI011FVyvX9cXE/tOtQ6AAD4efv6qz+bG/QiwqxNEnIT4aRbGufNV3EXM+c95bJsJN5SkVv7MQFSdLhDuDg7VUSRomA+oHVwzlMnFpqT7Vsk4uLhXryFiDn7Jta3r1AtNzh1lJ6mJ3Ket47H6T20IbJ9w8ThkQNa5qHbTB5ULhZknstdfMzrDLbMQ0aiWE5IsHV+sRRFrVpDbQ1/5Jwzbznxyi52eV+qW2ZLS8y0rrqHqM2Q7Cs2xsVHtLU719MpTZze4DZhg+06lDoAALiu2Pch+fE0tXA+sIP4wV4U3CuEULrLqVWt7OKppzSNu1N6dGqBV2K4IZ9KjOIuNaLDzECtgxjGeZRPNKV5sn2nyt0oDw+XlFvfvkly4/ODw/eUUzqYPzBscK7ZOkS2rzq7sK+vsxelZmVB23O5i8m10i7vO0TS9PxpalpBXoqiVq3hATfLgKkxWW6GK7s4ZB4U1JNpq05+VeoRJ29MsLy6HH4qQldt4QfMuoie2nWodQAAcB1535YuSuyrE9HluaRr2Te28PkSHpmmDjKkdRgy0cRt0WlYrtZBtq/7ko6GGXn8ASn21SmObCHmMlwR+9bUyoUlYyYaZwv78ogRMxdZh8izJ4tDcq5k32nxQX1X2dm3YJXJwz72FVpNlWNfbSla7Ks2uM9pw1fMqeZXdrmKfdWTaavuIa5qvGrf9tO1TpPMkpxHLk/WrsNaBwAA13XPg2HuKb7O2fDQmOxr2beipYE3o4p9M07zrAH+BvMcA8/qyV1086XMrNZBtq9TJbc45fHQcpEDzvNpy+P68Vh9AF9C/fnAWnv7zh0QwA35vLsQWo5k3/3t9KetQ2T76qJ4lMgqC/u2q+WG7fb25Uu8lF99uy9e5AdmTeDp0ZOkorYUNe+rNUwrXMWnFO7nV3a5in3Vk2mr7nZwqmGaat+6DvlCsrMDYvmGgilTn5cyMdp1KHXWawQAgJ+637ffih3lY2r5hnningfDNTMP81LOhs9S7NtL3MswmvO2M9ydxvmJGyOcabJI1KodZPuuiukS0k4kgMPFPQ+GiwPcPMXNFH5hB6ft8ectzKp9pR/VU3l+kj6iHX8oaUWNbF8PKsWm2hDJvurswr7DTeNmhtvZVyzuhf4jpU4BRdI9D2ddH1VDa3Up2j0PaoMLzeL5NONqXa60r3oybdV8TuSsQap9eWwP18izD0xMobRL6NRRlHqJdLhyHUqd9RoBAOB3/K7bz3/nDAAAYF/YFwAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAAD2BQAAAPsCAADsCwAAAPYFAADYFwAAYF8AAACwLwAAwL4AAABgXwAAaOz29e6LbQAAgIalrzfhlaHYBwAAaFhCKwnv5It9AACAhsX3NBF/5awOGwEAAA1JXR0X9uUemaHI/QIAQAPRN9RXBL0EGwEAADcB2BcAAG4G/w+o7dTvmvilGgAAAABJRU5ErkJggg==) Restrict authentication requests to a comma-separated list of trusted IP addresses. Leave blank to allow requests from any IP. ``` 192.0.1.1, 192.2.2.2 ``` The wildcard `*` is supported in any octet, which is useful for allowing an entire subnet: ``` 85.*.*.*, 86.*.*.* ``` --- # Autologin The Autologin endpoint lets you log a user into WordPress by passing a valid JWT - no username or password form needed. This is ideal for: * **Magic-link emails** - generate a signed link and email it to the user * **SSO flows** - redirect users from an external system directly into WordPress * **Mobile apps** - open a webview session without re-prompting for credentials * **Cross-domain redirects** - seamlessly land users on a specific page after authentication The plugin validates the JWT, identifies the WordPress user from the token payload, creates the authenticated session, and redirects the user to the configured destination. API Reference Explore and test this endpoint using the [interactive API reference →](/api/v4/autologin.md) ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `GET` **ENDPOINT**: `/simple-jwt-login/v1/autologin` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/autologin&JWT={{JWT}}&AUTH_KEY={{AUTH_KEY_VALUE}}` | Parameter | Type | Description | | ------------- | ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | `JWT` | `required` `string` | Your JWT. Can alternatively be passed as `Authorization: Bearer `. | | `AUTH_KEY` | `optional` `string` | Auth Code value. Required only if "Require Authentication Code" is enabled. The parameter name matches the **Auth Code URL Key** in Auth Codes settings (default: `AUTH_KEY`). | | `redirectUrl` | `optional` `string` | If provided and "Honor the redirectUrl parameter" is enabled in settings, the user is redirected here after a successful login instead of the configured destination. | Parameters can be sent as query params. ## Request[​](#request "Direct link to Request") ``` https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/autologin&JWT={{JWT}}&AUTH_KEY={{AUTH_KEY_VALUE}} ``` Or via Authorization header: ``` GET /wp-json/simple-jwt-login/v1/autologin Authorization: Bearer YOUR_JWT_HERE ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") The browser is redirected (HTTP 302) to the WordPress site or the custom `redirectUrl`. The response body is empty HTML; the redirect is handled via HTTP headers. ### 400[​](#400 "Direct link to 400") Bad request - unclassified error (e.g. malformed JWT encoding). ``` { "success": false, "data": { "message": "Invalid JWT.", "errorCode": 25 } } ``` ### 401[​](#401 "Direct link to 401") Unauthorized - JWT is invalid, has a bad signature, is expired, is revoked, or the auth code is wrong. ``` { "success": false, "data": { "message": "JWT has expired.", "errorCode": 14 } } ``` ### 403[​](#403 "Direct link to 403") Forbidden - auto-login is disabled in plugin settings, or the client IP is not on the allow-list. ``` { "success": false, "data": { "message": "Auto-login is not enabled.", "errorCode": 26 } } ``` ### 404[​](#404 "Direct link to 404") The WordPress user identified by the JWT payload could not be found. ``` { "success": false, "data": { "message": "User not found.", "errorCode": 24 } } ``` ### 500[​](#500 "Direct link to 500") Internal server error. ``` { "success": false, "data": { "message": "An unexpected error occurred.", "errorCode": 22 } } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl 'https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/autologin&JWT=mysecretjwt&AUTH_KEY=mysecretauthcode' ``` ### PHP[​](#php "Direct link to PHP") Using the simple-jwt-login PHP Client: ``` $simpleJWT = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $url = $simpleJWT->login('Your JWT'); header('Location: ' . $url); ``` ### JavaScript[​](#javascript "Direct link to JavaScript") ``` var JWT = 'myJWT'; var AUTH_KEY = 'MY_SECRET_AUTH_CODE'; window.location.href = 'https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/autologin&JWT=' + JWT + '&AUTH_KEY=' + AUTH_KEY; ``` ## Error responses[​](#error-responses "Direct link to Error responses") All error responses follow the standard envelope: ``` { "success": false, "data": { "message": "Human-readable error description", "errorCode": 26 } } ``` Common error codes: | Code | Meaning | | ---- | ------------------------------------------------------------------------------- | | `23` | JWT is missing from the auto-login request. | | `24` | User not found - no WordPress user matches the JWT claims. | | `26` | Auto-login is not enabled in plugin settings. | | `27` | Invalid Auth Code provided. | | `28` | Client IP is not on the allowed IP list. | | `29` | The configured JWT payload property (sub-key) could not be found in the token. | | `30` | The configured JWT payload property (user key) could not be found in the token. | | `68` | The JWT issuer (`iss`) is not on the allowed list. | JWT decoding errors (`1`-`22`) may also appear when the supplied token cannot be parsed or its signature is invalid. *** ## Settings[​](#settings "Direct link to Settings") Configure under **Settings → Simple JWT Login → Autologin**. ### Auto-Login[​](#auto-login "Direct link to Auto-Login") ![Auto-Login settings](/assets/images/auto-login-c5a9c5ce922a61a2816b14e54923c9b5.png) Enable or disable the autologin endpoint. When disabled, all GET requests to `/autologin` return a 403 error. When enabled, users can log in by passing a valid JWT via URL parameter or `Authorization: Bearer` header. ### Require Authentication Code[​](#require-authentication-code "Direct link to Require Authentication Code") ![Require Authentication Code](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAB0CAMAAADuBmGdAAADAFBMVEX////3+PlxeoJ4gIdsdX0mNUR2fob4+fri5OcdIye8wMSJkJZQV17Z3N+ZoKbg4+Xe4OPu8PGxtruLkpi6v8KXnaTl5um/wsd7g4rw8vPBxMhtdn7z9PWiqK3s7u/M0NPy8/Tp6+2GjpShp6xyeoL29vfX2t2Tm6Dj5ef29/iQmJ6VnKOCipGtsreqr7V/h4+TmqB9hYycoqemrLHc3+GvtLl+ho2NlJu1ur7IzM9zfIPR09aorrM1Oz6Plpx5gYiMkJJveIDf4OL19vd5gorV19jQ09bw8fLV2Nuwtbri5Obt7vDBxcmFjJO2u7/EyMzk5ujz9faepKnu7u9scHJ8hItKT1IhJyuAiJCkqq+Pl50lNEO3vMDm6Orn6etweIA7QUTO0tTFyc1/goXm5+kyQE+zuL1eYmbU1dh1eXyXnaPr7e53f4dKV2PJzdDp6uyHj5cqLzPExsrAxMhTV1olKy/Mzs/l5unDxsnBwsSPk5V0fYWssbZXXF9ud3/p6ura3eC+wcZjaGt8f4P9/f0nLTFye4OKkZefpapFUl+RmZ+JjI6Eh4qdo6jLztLU1tkoN0ZOU1Z3e34kKS1UWl2Ei5IxP02boafb3uCUm6FlcHrS1Njd3+JxeYHO0dOUmJqprK+8vb9rcXeDi5N2f4YeJChga3ZhZmmorbJVYW35+flNUlWYnqVtcXRATVpeXl67wMO+wMHY2toyNztlaW08SVdvc3bc3t/IysszMzOws7RYXWBCR0vd4OKqra4uPEugo6V4foJxdnhobG5ARUguNDhaX2JITVCbnZ+JjI9FSk1kZGSFiY/7+/usr7Hq7O3a2tw9Qkc5PkKYm53Gy87g4uRbZ3KMk5m+vr6bm5skJCS/wcNVW2K5u72GiYw0OT1RVViChYeztbWwsLB0eHqkpqnW2dwrOUhobnX29/emqaxrbnE9S1hSXmqQkJCtra2NjY2mqKk3RVJpc3709PW2ubpueIJOWmZPW2edoKIsMTUgICBYZG9YX2XV19qWnaVZusnZAAAACXBIWXMAAAsTAAALEwEAmpwYAAAWfklEQVR42u2deVxU5f7Hz8Acnh5QCEFkEhCQS4ICIgJCLtAQLriAV9lSw6u4a+H20hBzQUUzNLfUMqublbl0XVJLzTK37Kempa2Wrbbfbrf6dZff/d3vc7Y5M4yGVKPU5/0Hcuac5zzLec6b73zPM6MkAQAAuEp8FxVyHQAAAI8QElWgyTfPxgAAAHgMW6Aq3wIMBQAAeJICod8CRL4AAODp6JeSD1EWjAMAAHgWS5QkhWAYAADA04RI0nUYBQAA8DTXwb4AAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYF8AAACwLwAA/CbtO4CPvsISXfhDlz/gFs5vvvJdl2IuH4lrDwBoVPYt5Jy/tzfr8t+LllW1/hJ7zm7gfLvTK4/zuZe371TOhzPWsaoq/0p26fQ6uG9e2YvbYF8AQGOx79DR7+xq4c6+71Ud5vxkA+vLInkPa4h9r3SXxihq6/F9RY/DvgCARmLfju80+bRJkz1u7LuLRVbwLMYCF++bd/QYBcHbCiuqsvgUxor4eXYz57comQfKBxwrLLrZ8vymeWVzI7TSljP8Xn44jLFpnOexh3gXdpR0zHeQfbOOVBRSiGocP4C/uOW9slfZs+IA/g8lvWDLOj6laC6L2FfEu4x822mXUm5XL0c5hbhCXnYTY3e9zdj0vYd3HBH9WV+248WDwr77B5ypmLwNcwAAcE3Zd0GTYDaqyTK39r1pA/+eha3g975/nK9no5bzwi3zVPs+7GTf5Vvm5L/Ly4YdMSLNh/mGV5aLwJnsG6nY9x/7+IWs9WTf5WdO8x2RzDh+AOcrhnE+dNQyzhdn7RGKte/lFQe3FLLbK3YuPsKX7zbtYot5xeij/Mxwo5wa+nL+vFrzeb7hxZG8aBr7mH7Zu5xq2H+Yz5m7g+/BJAAAXEv23dUkjrFP33Gb9+VTKK27jRdFsD38n+S94yKj4Ma+d9J/niFeK6jgU9XSL/IqtpMfMdnXyDzsLNhPznQcP4AXMnaIH9PSC0Kxb3O+m7FTrECE0qfJq45dtg38WWbvwl91lBN8z3W7rhDVfMHnsAv8Bcb2kn3v5hcoEOaPYxIAAK4l+37aRP9RJ++7aQNfEUYxpMoru4TAntPtu9tkX3q89op21MdK4eHLSZkn+Ybdwr429rnZvh+zCM6nOY4fwA8ytokM7lDsx3yecpruwyZX0DFZpl3buRD8ZDqXUY6pyyGeVdt9hsRMgfVRVkbhOhtN9t2l1lSGSQAAaBz23cX2FJFEp/Oi89OnTz8Z8S4/zSgAJvtWUE7hA5N9aR1YQRFfT0d98IpSeL3m1ruFN8+yYcK+O0Usqjx1E/Z1HK+sWruXLPog521UxU7n/EHGxpJED30+/TTZ17ErkvPPWdhhJfbVyjE173tIzfuu4B8J04vYl+x8geybxY9STdOfxSQAAFw79r1h7jtNXnjhBfqR6sa+7CPexWavooRt1oBDIu97YVeFsO8KfjTrtLN92Uu87KWsYcvVBbn7+JmqqqrT/D372Hn88XeXC/uSgrMeMuzrON6w6BDOt2TdrOV9y7IGbGLv833nD4rY17HLnPc12Vdd87CC1jyY8r5FiylfPJKdPUyFsy6MxiQAAFw79v2fJjqPuLPv/iKyW+BLx+edrlrM2NtHN0x+Xth3+8jlp191sa/l8wsVXVbsHCvKUrqBFh+wWk4P7R4u3LBisbDv9jKhQsO+xvEOi75E0fIeY80Dn8zyN/F5cwvFugvHLsvHm6aU7TrLXOyrrPddvpNWNkzb+88dR6Yqax42zBkgnuvdfPD0lMK9JzEJAADXln0f6Rjqxr6X4FlhXwAAAD/fvv7sPOwLAAAet+//5T0C+wIAgOfty5bV374AAAB+Ifu+88JI2BcAADxq33uMNQ99MEYAAIBvVwcAANgXAACAR+2bmuN1mb3e1yv/3HCj06ut/Op5cps1TC8QolczsOklDnapxAn/4MvWU+8G1fN8zuhN75zo9LLzZkjMT5xF67e7pmqj/LOg0btkE5LrDPkN7et73jB/r/a+axrUJN/m9Zocbse6AcPTkOrMBPhAIcBz9m03kUVkt2EesW9gM8Y6dKLfB93+U/YNi4k3vTy7vYstI1snZ69MjWtIg9p4NcS+ouk/375av12aqgxJXb1EWIfExtDXLdcoP2qsKhONEj/Xvqv71T0q12/+uEV1jsyIDmRN/1SPUUqvtLsMtJMO+xbfllwz9id1qI+1+eK7te8vU10bL9gXXDX7Xp/DPGPfy4jD1b7TvFtGXdq+luigppEde8Z6zr7udXul9nXf1EvbN24dmTApTfwQqvTJNZf4ufZ1Q232X27Pe3CG68vBHerXr8HWca9dRodP5Dxoy+/te0XB6OXs+wtVB/uCq2ffWIqo1En7p2KvG/NopiekJ5XEsV413qEpYWKzODM8ThHj6iCvaLqLbZu9+vR1GEQ7MMAnMT1pthZDrclsJ35NrUzuTTNeK0BvKYOVyugdeEHrylCKcXy7bl7QJ9YoYNi3a6qfMIxQcErC9VTIh/mndvVapCq5Rah2Fw2J92rXytGgCP/KZO1/T/JPTa8ssY3J9OvFeiTR9spcNqv9fOsa5kMnU25l/3A/r/gIo1PKH5rOSs8DfJ5I36w1MF44uk+GeDfcyy9mTXiiUUDfdIyAUJ9Lv2xjlJbl9e9m7WYT/a7bVHVIvCe1y6Sq9Wug2pd17cTyuiXQD+vtJvuqJbS+K2+4F3gF/cewr7Zj4CzWj3raYo1h377JmffYGJuQVjkjeqjIPJgvGREXqrlK64S2e4QSdK8xCjYLp/jUGse8E18vNo8ea5aeKEzZlcLkCUHqQPuOCc/so/6VDJj5gNPZ9ckRNyO0MiVOuzp65kGbg4R68fXhcVOdOkcaXp1SUJt/1ONu3WZDI8Bjse9qLfb9pNvQiIQgmvmldnt6LWs6Me+TPuQe7+KO1yelilvb9ujsvIxxeaz/gsGjchz21Q4MsCawU97qO73XcrtnZD7Aenv3yA+iGa8VELeVEraRhVpH58eGBjNf6/0st49RQLfvEGt+cLHjzlJj3+Tcwe1TlN2bO6uH2YtrIvrdttpoUGn44NikJap90+7vFV3cO+oef8O+8QmBlh6m2Hd+7am2rxudUuwbb7fHp1JPejK9gRNpQNrE2Knp9rSSvNnZiXoBfdM0AkJ9Lv3q4D84NtqPjbgxhDUNE/1201Q19i3tuDqp1rgGmn17tmevdcilH8nMNfbV+65kNFbnjfC2a/bVd9wziIWn+bL+g3T79vMZNSR9DAuorM0bka3a13TJiLN6aKh1Qt89iGJfyvvqBQ37xtudRo8lzz7bcqxhXzUYzZ59KkFd5fiXaOZ0dn1yNAuaFbImVbs6hn3VOeiIfdXhcVedNkcaXJ1SUJt/AS3bRtWuWwKPAE/b138Evaf3Gc686Rt0E9S3nzdQeOCdQZm/YnFr+y6il8b0toh7foTzu2c6MKBlAWNBucZLdNvH050faw3TC5jsa7mNIpQW0cyXTBPX0q4X0O3bjJLELVe72JdMN3SBstuvr3pYbCaV7NBZP3/AfNoM7q92JoFiPTr5rDTDvje2znPKPJTQdwtbT2mdUu1Lrc8tJusUML2BtnVRLLVGND3Wh2Kv+ER9FPRN0wiQ+lz6Zcmm/53Z14/1pRBc63fdpqr2pf86KXGGcQ00+46KsZT42jItJf3r2Ffru1H/wNWaffUdFPQW9/YXIbBm33g6d77VNuIetTphX+dLNlRLW+id0Hdr9tULGvalgubR6zHTxlYOcrEvTZMCGk4i8Ubns2uTg42jzf3J2tUx7OuYg6p91eFxV52TfRtQnTEhaP4FWEnnJeHwCPC0faOVd5hLlBwb3WGD/ZOtVhEK0+27ulLc2p2VA3oGWruTjx321Q5UcmZd1Yczo+IrrRQ4rawVEgnTC5jsG2il9/w9uqmJOrp/tAK6fZMp5l6U4mJfek0RqSP2ndBOmPo+/fytlPalG1ldcXJqlW7fgK6VOb1N9hUKz+yodUq1L6mxY6XSE72BbPMglpQrmj5BxFQlifoo6JumESD1ufQr0GpTWmbbnJyZYlH6Xbepqn33K4OuXwPNvmEzV7c7y6JXt5tUx75a37XMwzqrNVezr74jPyYizZYTJZ7ZqfZdSX9GmbVXyhPismuZB8clU2LfSOVfvRP6bs2+ekHDvjRPzKNXM4axTitd7DtGewfjCEb1s2uTw6Y+TdSujmFfdQ467KsOj7vqnOzbgOqUgtr8C5gv3km0hUeAp+27poXjMRvN9PvCA+zifbf3BLqZksSt3fceNZrIpgM6OeyrHWi+lb1nD7fUJChJ06YU+2oFzLFvNmXvekcb9tUKaPb9RLlDxsWxmMH0Ob0E1sLFvi0GFmixL6mlf2f9/LNCmdN6Ms2+s8Tb9oHCXJGzW+blG/ZNEbdmlNYptdkizE9SeqI3kNX6dRxnUWNfqqx9oj4K+qZpBETs69wvpWVKityS222C0u+6TTWeutGg69dAsy8LSqgUbrHmu4l9lb4raefMJadYWq4R+2o7vClm90ttbzx1i6dSw62RzahpcZnu7Bs30Fe7wGonXOyrF+xbI2Jo1b6m0QuLUa5aALtxGmOTgli+8RhM1WGvmfudzq5NDpadr51AXB039m3R3jE87qrT5kiDq1MKavMvwBpIw43YF3jcvrlpAczSypjpzVswS1dh30V2e1cl73t7N9r7wGDWvz8LLCalaA9stAPNt7JPPsvzIZmutFnuE3lftYC4rTqHa3lff0ukX7Bxu+gFVPu2Fs9DCjJrmd801jEmgbVqZ3eyL615mGW/vWesvXg2C6nsqJ/fEpRqYVGzXO0beFsI602hYa6dNb2tu62lttzNP5RyCulGpxT7tlNS3EpPtAYye0yHJxQj2NNoecjMRL2AvmkaASXv69yvDjWsO+V9YwNZVNpQJe9bt6nKkGiDrl8D3b4JmRSIZWSqV8iwryih9108mBpoYf8xYl9jx32ZE1liZifDvv2Ku7MSyvuu68UmZTvZt0cLx5oHS+4MvRMu9tULDk2Ks/TX7GsavX6PigRS6RMssYblrQxiykCbdKgsQrBN89XPrk+OhEWBLOx+7eq4sa9y8bVtd9Vpc6TB1SkFtfkXMDOVRXkvMQYEAA/Zl7WKvq1Pc2Om7w99vW2KsK+vz/wS5ZEO6xXvlVaaT++ji9uVkEHmK8lM/UCzfSfmpHdoTpnX1LTiBGXNg1JA3FYB47Q1D+H0JNpi3C5aAdW+9hjFPyXN2fXxC9LpZXu0WPPgsC+ztU5uGbomjw0p9aK3wvr5Wfca70dfr3W1L8so7VNTnMtSZlrX0XLZFH3NQ0K7mfGnjE4p9lW7qvREayC9w7U2VY3Qy29lUPNEo4C+6RgBZc2Dc79sY7IHdkpn0+jBeglT1zzUaaoyJLputGug23eolfIjeVZ/Z/sqJbS+C8KTSlOKc401D9oOX2sUZThiHSvOgpMz7xNrHpKtnfssMdt3RJB24vv95rf0a6F3wsW+ekE2I724p2Zf0+jFK3F4xri4wM1dV4qJIwbarENagJsdk25cen1yWEakxSxopl+duvZVLr6+7aY6bY40uDqloDb/AnwGzRRrHowBAeDa/KRx0zG/tdH7JT5wVpfgmgYVC1CfHv06PDrY0wUBgH2BJ+2bP4RFFY9qSElbSrtfqZc9LCw43aMFAYB9gaftu8RqTQtuUMk0v9hfqZfp1nXxQzxaEADYFwAAAOwLAACwLwAAANgXAABgXwAAALAvAADAvgAAAGBfAACAfQEAAPYFAAAA+wIAAOwLAAAA9gUAANgXAADAldsXAACAxyH7SgAAADwM7AsAALAvAADAvgAAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQAA9gUAAAD7AgAA7AsAALAvAAAA2BcAAGBfAAAAnrDvZ0Eby1f9eAe7Wu36wzdPPfPMU99YcIUAAL8r+zZbeqvg4tLEq9Osv7715ht33fXGsbc+xCUCAPyO7Nu8XNZY5X81WvW3l/XfXv4rrhEA4Hdj34RVssGqEVch8n3Z8fvLiH4BAL8X+352kay7tpXN1mot/bL0yV+mprZyjptXLbIc4fraH94yb71V//qfm1P3tcV34yIDABqJfUsPyPLf1V9zZPlAe9Oup+WF1dL9crnjlTvkO+pXU+q5++pp32/eNG+9+bVpYxjnO744e6kqRj0L+wIAGrF9/32rLOeqv06U5VvPOdlXTmygfd3jzr5PvWHeeuMps32XSbvnFF5JBbAvAKDR2Lec7Bup/jqW7FvuZN+lW08o9h1b+XT5ufulZJEbfkzZ95h8x8aLbSIqn161to0k5f39wFfx8ngpWP5Kkv5XnqRkHtrKP6xdNUNK/fHAwtaSVH1H+cLWbuz7zF3mrbuecbavNJU/KUVsOXz6OUn6bktF4buTJamISryfpWQeuty997j0wdGKOX+UpN2TK3bOhX0BAL8B+34p58idhX0/Wyhv/EG+OMt3o7xxUapm36Vr185aKLdMuriV0dbWnFWKfTea7bt0/LhmifLW6B/lzpK/vCp06xXbtzrrkCSNnNtm6r490ugVbSZ2cbHvSCZNPbMt4s4q6clDw/74tymwLwCgsdh3oyPz4Ev2/beTfSds/XIo2bevvFCSQuU/mzIPj8lrJXqdQt0f5GYRsjxEal3Xvt/aJWk8bTWl8uMpizH0CjMPnPP39ki7/0mP4p4fXT1vlCStd7HvDZK05VUKrHf0mrrjBHka9gUANBb7pt9qPHUbT/YtdbJvq54U/pZL/UW6oS0dZrZvZ0mqUdeplcbKskTm1ew73rDvfBFbq8c8+a08Qeru7qnbMemST92WSTdXvSo9zAVHunMK0b93se92SbpX2b3n/CZRAvYFADQW+7Kl5hVncrVkzvvWVo9fqsS+WyXJi2LfIDnasG+qiH0XZmRkTFpCse9ZSi2Ml3pTkFtwwLBvjqL0zXTMiBMi9s11Y1+L04qzf51wyfu+Mm/sTWXKVvUUUu0xsm8FJZo/cth353PK7qk7qOlzYF8AQKP5tEWq6dMW5U6ftiD7SiNkU95XCpe3LurnsC+9Xrmo9NsMJe9bTvYdLsvRJHGzfWfIW+MXeZ2TNstPL/rRjX2lD02ftnjqA8nFvtLOl6qr7qyW7rpJGr1Miiwk+04+Kd1S4bDv9EO7peptlPc9KW0vgn0BAI3nk8b/b8h3aWvJ1b7SQmXNw3xa89BDkiIWynKQw75SRM6XB75aGyDlrb24MIXsKyUsvPjn8U72lQZ9dWDrOX+pOrq83N+dfU0fdnP5qJti34kV30Uu67Jj78PSdwOmnBax7/bHVxz5wmFfadu98zZ9IdY8FFZ9AfsCABrRt+x0Ur9l51s59eecfJKwb4P4UP2WnTf/9cFPHvrwZFxFAMBv5xsmn0zfWF5+rm21dHXsKz35tfiGya9PSLAvAADfru5B+9Yf2BcAAPsCAACAfQEAAPYFAAAA+wIAAOwLAACwLwAAANgXAABgXwAAALAvAADAvgAAAGBfAACAfQEAAMC+AABwjdk35ASGAQAAPMuJEEmKisM4AACAZ4mLkqSCCIwDAAB4lgg7/QgMxEAAAIAn0bwbmBeH3C8AAHiIE3ERetBrjwq5DgAAgEcIibLjTxAAAFwl/gvqDp5m4AKI2QAAAABJRU5ErkJggg==) When enabled, an additional Auth Code must be provided alongside the JWT to allow login. The parameter name is the **Auth Code URL Key** from Auth Codes settings (default: `AUTH_KEY`). Configure the codes themselves in the **Auth Codes** tab. ### Redirect Behavior[​](#redirect-behavior "Direct link to Redirect Behavior") ![Redirect Behavior settings](/assets/images/redirect-behavior-81997edf080673a63e25cbb110384414.png) Controls where users are sent after login succeeds or fails. **After successful login, redirect to:** | Option | Description | | ----------- | --------------------------------------------------------------------- | | Dashboard | Redirects to the WordPress admin panel (`/wp-admin/`). | | Homepage | Redirects to the site's front page. | | No redirect | No HTTP redirect is performed; the response is returned directly. | | Custom URL | Redirects to the URL you specify in the text field below the options. | **On login failure, redirect to:** Enter a URL to redirect the user when login fails (e.g. expired token, invalid auth code). Leave blank to return an error JSON response without redirecting. On the failure redirect page you can display the error message returned by the plugin using the `simple-jwt-login:request` shortcode: ``` [simple-jwt-login:request key="error_message"] ``` ### Advanced Options[​](#advanced-options "Direct link to Advanced Options") ![Advanced Options](/assets/images/advanced-options-1020cee187c277b23d967a0efc3461e3.png) #### Pass login request parameters to the redirect URL[​](#pass-login-request-parameters-to-the-redirect-url "Direct link to Pass login request parameters to the redirect URL") When enabled, the original JWT and any other login request parameters are appended to the redirect URL as query string arguments. #### Strip these parameters from the redirect URL[​](#strip-these-parameters-from-the-redirect-url "Direct link to Strip these parameters from the redirect URL") Comma-separated list of query parameters to remove after redirect (e.g. `jwt, auth_code`). Useful for cleaning sensitive values out of the browser address bar. Leave blank to keep all parameters. #### Honor the `redirectUrl` query parameter as a redirect override[​](#honor-the-redirecturl-query-parameter-as-a-redirect-override "Direct link to honor-the-redirecturl-query-parameter-as-a-redirect-override") When enabled, including `redirectUrl` in the autologin request overrides the configured redirect destination. This allows per-request redirect targets, useful for magic-link emails that need to land users on a specific page. **Available URL template variables:** Use these placeholders in your custom redirect URL or in the `redirectUrl` parameter. They are replaced with actual values at redirect time. | Variable | Description | | --------------------- | ---------------------------------- | | `{{site_url}}` | The site URL | | `{{user_id}}` | The logged-in user's ID | | `{{user_email}}` | The logged-in user's email address | | `{{user_login}}` | The logged-in user's username | | `{{user_first_name}}` | The user's first name | | `{{user_last_name}}` | The user's last name | | `{{user_nicename}}` | The user's URL-friendly name | Example: ``` https://yourdomain.com/profile?uid={{user_id}}&site={{site_url}} ``` ### Access Control[​](#access-control "Direct link to Access Control") ![Access Control settings](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAC4CAMAAACILL9SAAADAFBMVEX4+fpQV17+/v7a3N8dIydsdX19hYz////i5OeUlJRyeoLAxMeVnKFxeoJ2foZ1fYVveIBzfIOAiI+coqfV2Nv3+Pjm6OmZn6WLkpiOlZuDipFtdn6Mk5l4gIeFjJOiqK39/f3z9PV8hIvh4+WxtbqepKnk5ed5gYj19vff4ePr7O7d3+Lv7/C+wsb8/PyprrNud397g4qXnqTT1tiQl520ub1+ho2ZoKbFyMv3+Pm5vcGCiZB/goVweYHb3eDq7O3O0dTw8fLBxMh/ho3o6uu3vMCTmqDQ09b09PTw8fLe4OOGjpS8wcXm5+j6+vp5fH9ZXWDHy86Qk5W7v8OmrLHY2tzg4uSPlpzl5ul3f4fU19n09veRmJ61ur66v8KTlpj5+fmEi5Ly8vTs7u8gJiqKkZe3u7/M0NLl5ufKztB6gonJzdD7+/vy8/Slq7Cyt7vc3uFBRknZ292/w8cnLTHW2dyvsbLHy89xdXddYmT19fXDxsrw8vNbYGOkqq+XnaOrsLWgpqvP0tXR1NcjKCydo6hMUVSHj5WWnaLp6uzN0NPn6eoqLzNgZWjj5ObFys329veho6bT1diIkJbg4eKhp6zX2t00Oj3V19qMkJKJjI6tsrfGx8izuLykqa7Cxck8QUWvs7iqr7XDx8vo6Ons7e8tMzefparJysySmZ98gIK1t7gwNTnt7/C9wcVjZ2rLz9GorbPi5OVPVFcyNzukpKRtcXSgpatSVlmUm6FITVDr7OxpbW+KjpC4urtmam2oqqzt7e6EiIqChYfu8PE5PkLHys0sMTVXXF/s7vCwtLmBiY+2ur6boabNzs9scHJ2f4Z4e36JkJeHio3Gy860uLytsrZFSk2HjpXBw8Te3t46P0K8vr+kp6pUWl2VmJqprK7f4ODT1NXZ2tslKy/ExsdCR0uanZ8+Q0d1eXyus7fX2Nm/wcMeJChzd3qsr7GWmZvFx8lvc3WytLbEyMzi5ebc3d4kKi6OkZScn6GxtLWeoaPR09O6vL5VW2Jyd33nLjqWAAAACXBIWXMAAAsTAAALEwEAmpwYAAAgAElEQVR42u2deVwUR9rHa8dqaheFmQEFZIZLVFBWDkURERCNx0eQGBUUQkwMqETEm0TxwngrKtGomHi/iUcUj2hU8moSjVFDNvfmMNkcu7mP3eTNJjG7Sd73faqPYWbAO2Ex/L5/zEx3VVfXVD/zneqne4AJAAAADQ+TD2GpI34PAACgQRiRWqrbt2oWAwAA0GDMOq3at6oUQwEAAA1J2GmybylmvgAA0NCz31ImUhMxDgAA0LAkpjIxAsMAAAANzQgmfo9RAACAhub3sC8AAMC+AAAA+wIAAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsG+93Mcn4+AAAJqqfZfWu/Yzzo9f9X6KNzy+Y+/s++orWsEfgX0BALCvQeIZ6++Co+quryrn/ILfVe4m7XHODx+6UA77AgDApez7ztH4Fb+TrEja2d2tiO/dyt+jF7N+eOPDAhJn+D8+LTj7DmMfDd5xeP8Uxr5c8Qw/S+t/PFfOt76jbdST87tpAryHse9ffHvaofcZy+X8k0XlM6Yw8jKZmb3Ijxzf+5mjGPYFADRJ+/7v72p5x7XoGL/5FP+YscjBvHz6kUWsw2G+9ZHZN7OfefnL0/n6hyP3Fry64elzrBd/e8OGz/Rp7WH+ovZi0l5+aPoFfru0745HHudPsh8/5oc23E72XTD55tsdxbAvAKBJ2neFk31fcyn5gvPzyzj/iH3J+feMpbITfHKxfH6Xv8rYDP51ZHnBV/+TytguvvXLu4q1jTpyEqrKA/wNmhXzcmnfPex9vtfIPLzID6c6FcO+AIAmad//c7Lv/7iU9OTrE9lkPp0yENPUFd/wFerz21yFCj6UT8XsZXqa9om21Xojt/sN38/YXzj3y5XyfoIX1Nr3iHMx7AsAaJL2/cHJvrnOBWE7NMl+WHWe82U0q6W57/pZ8vkc/+b8+fN/OU+X2HY9tYP/zNjy5hs4r9Kd/eG/1bzvA/xTxt7jO+Tc937Nvk/ym1X7fqZOjfVi2BcA0CTt+3mtfGff6lzwFefvnjt3jvP7KO/79oYX1bzvuRMzbqYZ67SnN5xY/z479OqGBwr4l7tmn9gwnS/Q/mFy2ht0Ze3cjnI2aUdt3le3L82mN7yv29dRDPsCAJqkfUfU2ne4S8Fsfkw+7eeL1Hse5FL29E8LZM63++z15cdmv8Cm0y1pO4ZU/HV2Aeef7mG19/vyd+l+3++P000NXzEn+35AOYsZun0dxbAvAKBp3u8b5LBvLwwSAAA0mH3vMuT7fxgjAABowN+6bdDt2xJjBAAADWjfWUfqudkXAADAr/13HrKPk3zbYoQAAKCB/8bZ8hP/2wMDBAAADf8XJlMxPgAAgP9tAQAAsO/FaNPsarfwqLNFu9uude8jvOi30Ale/TKqr6z+we3ac3qvX2d0r340rpBsu+22hL7uYzhLCXOqEzRQGxPPOlvrJZc+KJc7CldQBQDwS9o3SVHaDCt2W9mpn/Gqr+P/YYyr3zy1VS9q36ISl8VxV66w0xNp6/TTrNkq57Vz5rF8RbEFZvw69r2nG9uUR8/d1IcyRWO562hceVtXxISQSHbPuuu3b3sv2BeAG8a+/5W42mfY5ZR6Xfa9soYuxkhf9zWqfZeHbYkt+rXsW2JNZKnjzPSgUK58oFJxHW1dEZ071TeGsC8Av237MtZ1Df09nACvdPrMrwqIje06kOZ63ixou91HPde+Z5QtZ0pnWjdSbrByXlDcsDDW0odej+qvVQ1ba46b6GSOMR7WhXfStLWbuYxESB/qcO/t9m6aYbSGugQn2wvV5cSaQMWzC0to13pxXkdHPyoe9FAC0yjzsEmdeVLmYZI9OTbDyb6MxZfJpVsP+lg7039GWrnGszqE7DvWR91pws7hPgPzE8weU/U3xVL6WdV2nN6o2pze+XDvg639dWNWWJqxVQsD6EHas9a+NBrObeljQI0lefV7Vmuhql2EEjHLzb56P/ShyxtKq4KLjLVEnvom+zo6J8ewxuyxRQnTR0d17DYfa0iFat+M0V4BlYwlzBsevDtVtW9KxGpZx5uaGWgMf+3BMtSqFfSmL0yfzrTZpHqqAAAa0L5h8fPYnS/te/aenGdZcq+wsGbahDYo71bVN8usq8IeXumYsjabWVUS3MNhHrXq2vTCdXEjHfb91nv18tZzWbj5wLObLJp9lW2sY9DDjrlv++SMqpg4NeGxLm5S4tL2LGFcKmtrd/QjxqckMUral/WluS/lfZda21bd2szZvstz/qzKc1P7woS5LLLbnGf3WbazQkvvZ9fSThPGUZYgPsRvnU8X/U3lbTud2NLtjbLazocrbWuN2fo2trlT2W0sZKe7fZ3bMsagJKJX/rYArYWu/UawZmFu9tX7oQ/dzAAaAM9IY62kmr6ZKO9rdI7GcEtQy8IAJUwfHdW+PpMG+tSo9u2b8mzXoFtZQsRyVjZM2nf1uCm1c199+J0Olq5WvaDQmpjaJoiNoAl+nSoAgIbM+yprlrKM3fR67pZEz31hRjohqL/mm+q2dRIGvatd7JtooZTl1HSHffM2MVao3LlpoWxFs6+Nmg3o72hIJlYT48aqn37v/tICCa+TSJWH9X4wr0rjqptu3zGt3fK+ipKQaKwZYWXrvEmRedvZJpre3mol+z7I2KPWSMpctNPfVL+18m8Tu75RVtv5cOM0Xxqzph9LCl9GD73d7OvSljEGCTSJTvT2U1sYs2ZlncyD3g9j6GYlp7KanS5rdfsa716OIc2E1ylh+uio9r2H2vNxZB7aTFLf4/zRVNJ1XLhT5kEffqeDpavVKAhK+XPImnC5vk4VAEADzn0r1o2rZAfVc9+27M8BscHG3HegZt/ge1zs65fgoSgBLvY9reSTiiJYgqLUyE/xKLmFsnLYQXoK1DMP9HL4KkdDw+bI5X3qcllwbL98pl7xN0/S+5EmW3Sx78E5bnlfY6niYKBNUSqKgmXJdqbuNInsS1PxsWpjrfU3FT7cPG6L2xtltZ1Xu2gYc7VnvpnNsuYrI9znvs5tGWOQrraZq7Ywy9/DOizR1b5GP/ShY/59Wbf+jrVO9jU6J8fwACUsSOfa6Kj2TaHMhFnPPCQrSn/1Pco+BLUJcc776sPvdLB0tRoFvn3nfLu9087bWN0qAIAGzftmpLMxC40VD88ZxaY627d6k7o+Trfv8yHhkXTu3MxDlvZXqyZSmpRtcZr70qfYTymeSLnFCmsd+8qGNskdeIzVdxkVMIwlkF0fVlKNfniVuM994y9i305rUu70UyrWeZPy+tHcl3aaaNXsmxLn/KbojxJ3sj3r+kZZbedd7BsWW0PtBNdEMHf7OrdljEG1lr3VW0jsH1Hkal+jH/rQsbtemZST6NQ7h32NzskxpP43U6fjcnRU+1KrRerc9ztrbkfpb4d9S0bpWZNCde6rDb/zHvW5r17QqUVgai/fbs1Y3SoAgAa1b5j53qUR9G+Fovxm5cpzZ7Ys8NZa+y5r48co7/umftdX56kscXgAO20ZwbbQ/EutujYhsXiNU97XJ43Nobxv8krW21LHvrKhQq+BrChOPdVf2Z6Fdd7OEswHOrawM70fLGZ3GHPJ+y63rmaueV+dkWSstkpFZLeZrEPsdvZd8qOsk6LZNzGghm5baKa/qf6RrJklzfWNqnlfrfMu9mUBVkqFTrD6utvXpS1jDPp3e5QlLtNaWHeapXbrxf5rvpN99X4YQ8ciPX0P1q51sq/x7mkMe4+alfi8EqaPjmrf3ZGRw9W8b4c2iazSee7bocpHu1l4lo2y3frwOx0sI++rF3xn9WCzzJ4V9VTxi8FnCIAGtC+rCWDf5Xl1iy+c1VpRPFLYrYvlPQ+6fdmqUUrOFHZPrHbPQ1ScvcUw+rQWxQfPS+qvVQ0LodsGEmvveejhYX2ervsXeSgxwV3c7as2VDkq2a5dTErxURT7LMphBsbKex60frCKsjjtngfDvnQ7gMXtngeN4vQ11WRftvKVUQHSUweSRj0fqNmXpe0Mesl+QH9Tw2KV5JnM9Y1K9M672rdMocI/Kxl17OvSlj4GbFm6Jbiz1sJMuu1gAs0/H9TaUlMJI7R+OIaOzVOaOXrnbF/j3av3PHRL2qaE6aOj2jfD2zonUs08hPjED0tysu9AttRjqFppmLznQR9+p4OlT2yNAjNlm9/MY/VUWafgMwTAb+SXxi/5XVm9hJGNpccZoxFGAIAb274tE9lIO7vB7LvcPgFhBAC4se3bWknOW36D2XeEVzX+FBwAAH/jDAAAYF8AAACwLwAAwL4AAAD7wr4AAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYF8AAACwLwAA/OftCwAAoMEh+woAAAANDOwLAACwLwAAwL4AAABgXwAAgH0BAADAvgAAAPsCAACAfQEAAPYFAAAA+wIAAOwLAACwLwAAANgXAABgXwAAALAvAADAvgAAAGBfAACAfQEAAFybfWfwu8Xt/ObLtvIA73klO2vF+cmrqQ/AtfALh+01Ubp3kRAFvNBt9dP8bzg+4NL2fZvzKdcQxn/lfJCYzjnfMeO8UfYPzu+DfUFDcO1hW3iebxViD+fF4i2+4BOu8Q9HUF81t/OnhJg9+KTb6r/yJ3GYwCXtu4si78S123f94MP8wve6ccs5fxf2BQ3AdYRtYXEBf4hmpvwv4n1+bs/gwVv53sGDv752+06eVlrv+sEF/40DBS5l30f4Ir7V5BTGdy+aNnlDptjP94gn+ZdiNgXp32bseKZnhRA/LSpf8bKrfV8Wpo/511pT/+ZvXOD3CxF9au/kH6V9jfq7+ORTz/xDtvzxj3Si9tnHvLyn8SROTn/m7P5HaQZx6MLfZ/wRhwlcCdcRtoViEf+3ODSZ7P0yf0A18wrHdJWC+onBZ/njL4gvnnyGP/MUWfqUSOO8lSNOZ/BTxy6E65UkX/AZQss86CFslKlzYgAuat/MvXzjWb6rNoyf4uU3b6XzsE/40+IwPxE6rWDABx+WP7KffyOK1/N3jy9wt+9DZ/k7Wlv7+e37+RAhvuZnqQl+0lF/F1+w/pFX3+dbn15EdW/nR4acmG08VbzBjz/y4ad37OLHhvxw7q84TOAKuJ6wLRQ9ec9WBU+/cU68wX+uY99W09YPGXLkK/L3q0Me6Un2PaHa14hT2uOCFfun6JUk7/NHNPvqIWw0IP55BXNy0JTt+wQ/bJouo8QI48f5P8UgztN+4se+558O/okfomB9VVBIP7SHv20SK9zzvpyv12asfyzgXzzFJwtq4inxAtnXUZ9OE3+Sq78UH/CPxQb+6i7aQn/aw48J8SL/90d8xsZsHCRwRVxP2BbSSdqijXzPzQuWaukxV/tWXHjmo79FC3GO3/1ChXDY14hT2uN+IYxKkk/kfqR99RB2lP2FH8eRApew73GavT7ByzMdYXyWvyBD6W+h5QX3Lbhv2r/oxOtJ7brER/fx2TIa3fK+T95+k9bUj3Qx449/p80P06SEAvako/4u/gyV79CaYQ99TI/TM/Wnf2lrN4TKvSwqxGECV8D1hG2hKOQFD/CHvuIn+Buibubhk7/ThGKj2EjxeuFftOED4iTZ14hT2qPMJ+iVJE8Zc18jhI2yuzH3BZey74ALWlDtcZpEvE+Xgnka5REmn/uAT6b8WU9+ZOPGjf+Uc1nhPvd9ubatY1pTPZ3nvkKf+9KMmFa/J5sZL0xfPLGVb9Sf9vCPae2XNDdeeX62zFsAcDmuK2wL5Q0TOz4V9/Md/LN67CuKd/Xkg4VgL7xTUDD+BLn1I3Xuq8ep3KNwVCKWqc/qHWd6COtlG/iPOFTg4valdNlgedH3eJ0EGmVv6YzqLC8YID74cNqpIU8vkAm06af4xexLK94dPPhxvnf8e/ztIYu0vK9WX7Mv5X1/GHJksLj95iFD9vIX9CfKp00fsmH9xvNPDqGN3sNhApfnusKWLHmEzrqE2Mu1y2Jued9jG4YcpwtpR04NOcWnRd/Ndwx5XMv7qnGq2deoJBm/92y0al89hB1lM/j3OFTg4vYdTGdoQmzkF9IcF4//SRePf2BCzl5/ppnEInlVd8Xhve8ekReP/z74yMXs+4NatXga/zn66b07vtbuedDqa/YVTxwq30p39jwxmfNpQ0z6kzj58tbyQ/vv//5dmst8k4bDBC7PtYft95wvlUkyeaX4Re2WYTf7jn+SJtbHPhA0NeBbnxCmUzvWf6Le86DFqWZfo5JKT35eta8ewkbZHxccwpEC+KUxAEK/OFH+i7dZWFDvzyo+ocQIALAvANqk+de4EvbTxvrWfrER4w1gXwA0DvMZ+P0ZgH0BAAD2BQAAAPsCAADsCwAAAPYFAADYFwAAAOwLAACwLwAAgMvYt/ixPwDQeHnszvpCGWELbrCwrc++j72FbyXQiHnrsfrWImzBDRa29dn3Dxgo0Kj5wxWvBKDxhi3sC2BfAGBfAGBfAPsCAPsCAPsCAPsC2BcA2BcA2BcgjBG2APYFAPYFAPYFsC8AsC8AsC9A2MK+APYFAPYFAPYFsC/CGDQN+9q6/EJdiX/wOjaeOwzHEva9jjBu3tqqVMkX7f2DzNXFQtzRw57sMSFNLy5pEaTcor46PTdI8ehAfwhwgodXXolenL/QRwlxtHXwzdg+Lo3XFj+6JtnjT8bqirnmnHaZxtItPpZRjs+SSz0A+17Ovl696KFH8MVrnradFqLIp25BByUS9gX/Uftuavuaat+KoDdXLrUHm4Tfmk392+bY9eIDZUWafQfkBHcq6V8ohD29pKos9juteFDI1OBa+7brsdDVvo7iMGtMaWXyVH31aPvJQYEJ+kJL25mKDNtKbcG1HoB9r9u+zUfTg++DsC/4D9g3tEeSJXisvtBqrTkipl2IS4Us1b5dFBJgR6W/tu5eJdVRrtl3WLdodSla6U6PllpBtnZubWIf985oxX8yhwrxuYe2apJC7s419pDnL308T1twqQeasH0vE7a27vFeSWeEaKMoSlB3elCaC9vEgOSkW2RtH8XS16i5ewwFrTVKzPcN8vYdIEQvL1rpp1R1lBv5iviykJyI10P1yvNf8fRoGyqm2FoKMdVrqWOjFGV1sLVdcfYSazV9WLqOntDG6j9As69LR01D0y2LM4RI880x++fLmkM9ImpCDwSYJ0TjsDdB+9Yszq3o32a+trDTZ9KAGO/67UuPkUpbPQqVMDf7Bs7JS+4zlF68WZ0piryWX519/aVic/VG95npYbyiR6y5Ez18HqgtuNQDTdi+lwlbW7fPe/nLL3Cnua/tpV4VU5USsc3ePrGkSIgQGVQVFj8K7giTWHVvafbR0SaHfY25b87RZa/bzujnYS+tGhA1vEyIti8NKLT0Fo6NUpSAod3b5AVkbBnXjpwa65+/8hW7Zl+XjtbkHKjo0FeYRgUOSl1D85Wu5uFnulqe331gYuwWHPamZ9/xsSn02LefNoeQyjPF1Wffipx2oaYJylp1VWTwUeFmX6/Yo2M/T+5B8+NgRUleJq7OvqM300O2ouUXPleTcNYMbY6j0OdEjDTrOQnneqDp2vdyYWujiwOhnkWu9pVJhOoEsVOv2EOeUKkZ3zlztDXRtkF17Jsn58ebtXJ7V3qISqad2eN9qkXtRinKJCF6K+EUqd3IvpYKmbgYJO3r0tHQ2Jnqc6WSLfcxVnS1jqe0hzfNe1usxWFvevYdpKhoVx2+U0/3l9RnXxHeQoltF6yGaVpSfCt3+1rW0EMZ5QTaefQ40Nnzpquzb4BmVS1bvE2z7z49k+FsX5d6oOna93Jha5OTzaQMV/sekBGYLnJteZvuNekVZcbXFEFZ4vy1HtTg/Dr2pZmumDBXq5yj7ZUu0+XbzPLCs7FRitJKOpUSFL08yb5J6rThXmlfl44OUvzU56k58rHPn0TXxTLe5UWUmBY47E3Pvn5KYe3CpexLV4dLTeaRcqoRXJ0p3O3bh864xBZFhCt034NIn3NNmYdIdVUnqdpMpZdW4SU18xDsknmIxJFu4va9XNiqV90Ch9ZjX3oZPmahVz994koZXxFljRYmj21+402xvcS90r7ta+0rJ8zDdPsGdTLa3+JpJgc7NkpRMqV9hZY21uxLq8m+Lh0dpGgZuakR8tGH7Csv+dW0lvatxmFvevYNtfSoXbhE5kGluUJz2jvsviZRx74h6ty3DcUsnX6JNSFXZ9993tTkg3py9yaZWegSqyd3/TvLjEOMtuBSDzRd+14ubB329ZZJsE6jajMP/mp5rlKhPsuMr3jQV4gqafBH6Ss/Soq0iGK+vVLqbt94Q5GpXncdtZtqN3Kzr5Z5aC/t69LR2swDqXtA7FjYt6lfdetq7V6aWURR0ZpCeGcfunxhoTDubpwIpWYNVQ5k0VlWp9wuZTLtW5r+XMusrKxIbYPSrCxlWxZ9o4fbNoUdSB4qoj36ZYq7lEqKpxr6SGRlBVdnRenthWcdHZeVRZmuDP0ihKM4Ut5J5kmXMcLtSym9FpA/KGmh0PZQYltVMZRSa2p7jnqgiV91u0zYOuw7Wl4nzrXKaawtSLvqNnJ+aGhZjknN+6oZXx9KboXSvLZ9uq2XaGUdKkrtZN9WsSXO9pXhl6LUpJpaThSmN+eKiojXajdyt6/TVTeXjhpX3YLz/FKXyKtusG/Ttq+p95sWj9Z30RyWYrXVTrNtwlxKdU00G9eW1bQVTW/HWGJ96GYbmhuoZGkbVKoLctaRG5zsI0/MbvKN87LLXG3ruTL5Jemjt2dXl2gm7aFPZR3F4jv9VxRTlEfJsUvMOQvvENoe1F9b5OrtOeqBJm7fy4Stw773JitBdJFMveOsd7Ai7zjra1YUjyz1ngc14+snp6oi2+4zbr7MU3RZY/MZK6O0Rr3jzLCvGn5Zra3e9gfFphyaFmfZohwbudl39BiLZ+c0zb4uHaXbz2JtFPyn/XPMc08K2Be/tnDD5NP8V+5lKzU7AcAv+GuLy4dtPb8+lhlfMWb3L9x91akAYXuV9r2/e/FNR80Vv3Iv5+/GkQK/oH2vLGzrs6/8aVBRFuwLGoF9B/ko1uGPYhzBDWXfKwvbX+wv78C+AH/jDMC+AMC+AMC+AGEL+wLYFwDYFwDYF8C+CGMA+wIA+wIA+wLYFwDYFwDYFyCMEbYA9gUA9gUA9gWwLwA3rH0fewsDBRoxbz1W31qELbjBwrY++9752B8AaLw8llZfcCNswQ0WtvXZFwAAwK8N7AsAALAvAADAvgAAAGBfAACAfQEAAMC+AAAA+14Di6/6n2k199eePTpcrOTidG8hOnpedxXQ5Gl0YVsPbTrgON2I9q18xZrT7/5fY39LvS4exoG3/HJh3K7H9ds3TKkSYxUl2T4FcXJD0JTDth6GnkZI3ID2vdcy9XTp/G2wL9m3jxjwugVhfCPQpMMW/EbsGxo3VXsxfrM5rqsQft69xwU369XH/BpFSufN1han2wZ5zKfXAV72ZlrN0nkRSkQrMcDX7DGTCobPtacPdFTwXRv/XPvcudbALUJ4K4rSPnRbnDkmVIj5PuZtdcP4riSvFmEiuizJ6p8vooJM9LEaJYxNZLBWL7EGR6lhfFNIUFxMJnXwwdZ9tqhhbPLNG091OtFu/EXVbq/A+XqEa13Rw1gvaJMtipRCMXNuPVVq7Uv/ajw3u9qqLEG0NGqadtg2j/cPSI8SPaTJY2KMzMNd9tjYvkKL3hQfWhdcafTJz7ts+POImkZn30FKpvZi8+KlUXH7hF/s9rSMnM5+La1+ornl29M7n4tJy6DwGhoe1jcoWq3Zt0VH0SFT5M3Jj/KZIporU8QUc6lRwXcczR0P5FaMta7UJhF/smd3XDJRLLV0D9tscQ/jSRGrB7S1i8wxqUt9OwsRV0KfgzHGJmq42V4rfc0cKcO4w5nSSekZwk9pK2YFFVMYj2/hG+qYREQ/FzKgyBKunYVpXdHC2CjYOVTM6dNcHB1at4qzfStjq3a3LTWlIFoaNU07bJsrJaIyXRRbWonQnPsN+yavzszMFlr0GvbV++SnbELMNEL7dtFPckwW+qqeuZiOE30ve1YK0eIW0dwuRLa6XKUdYS1KRo6+iR6XWymo982jr2NasB8wKvjW6A1TvKhhnEMTjO88xBj68o62uoexb1/as/dJ+bKjVYiazSIzucrYRA3jQHp47oBxCtd9rvCzUYfslaJ3P/tmU+0pXJTsTrsyR/vUFS2MjYKZS8Rz3/rKuUSdKk55X8UyVLTYXIpYaeQ07bCV7zDUFi3yZorV3YyrbibP3nJKrUWvYV+9T+rwgEY4971DfY5UBtAxi6BzFFoIak8R1knNURnLvQOSFaVSBCnKlFbPe1hjTPMVyXDRXJ6kz80wKtBmQmTtNitKjRrGrdRqiojZLmPXPYwXq4VTQrePsilKqFhqDr3L7thEDWO9dQrjfF8PRbFrHYovEs3jvFKdEmi9ZLx3Xagu613RwtgoWOo5oE+rcWmeprpVXDIP9JbjzeO+RbQ08rlvUw5bNXlsSxO3DBcLuzrueThgj03P1qNXt6/RJ3XvoPHlfds01ycR9DX97eKLhfFN1imzRLdKfSNTZUSv7DhR+zUfWGRUUMM4aMtJ01otjIVFC7Yx1JapziRiyUx1Ycvo7MR8CmORnjt3qmMTtfVgGUVFMowXzvGLPlMbxr39z8RVOU8iKD7nqZMIoyvGJEIvCJoYIl6ZWC3qVnGzrxB3bLGFIVwadd63SYetYd9Ma76lyumOs+JhwXr0Zss5eJtKo0+wbyO+58FUuU1s9jXdMXrfxcK4sI1JNFO0MI6KFGl9upjsE00iLVs0j+0qU1xGBTWMvVNFmHeNaGWjZFpNvwqRWSJuSl4utihdRMpM5zCu7LNcmOaLTjuF2CTDuIe/pdSxiRrGsVkii9JzFMb+M4Up3jmMxRYP7Y9ols2h08Ok3hSiI2cAAAHVSURBVKKj+VG5aHRFT6AZBQutZ8TrVu06s2sVN/tWRosOlgrRNRURIxr1PQ9NNmwN+4q1a+yO+31bTZHZFT16Iy0dxbdUU++T3Ht+GaKm8d3vW/KK1TZ6phg/gS4emy56CjfBJy8mSQvjVXRR+KAQFWuDXrL3pyvMvkowZf71CmoY3zKudTt/yqTF0MVj05g+ngF0etQ/MHjhqC5ijB4ugfKM6KiY/6Yl3V/csfiVJWoYVynyS97YRIax3jqF8Xdx9rkxTqdw1LkefYplpeU58uJxnpdxhqh3xbh4rBf0VtLEfCWqviqu9o2JVZLP0FSmEhHTiGnKYeuwb4nSu9a+wxXFI9yI3mV56SFUU++T3HuUgqD5zf3W7fI/3gGg0fHbCNvTlkgcStgXANi3wTl4FEcS9gUA9m1oWin90nAk8Vd2AAAAwL4AAAD7AgAAgH0BAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYF8AAACwLwAAwL4AAABgXwAAaAT2HRGNYQAAgIYlegQTqRUYBwAAaFgqUpkozcc4AABAw/JwKaP/RXIaAwEAAA0JeZfJp2crkPsFAIAGIrriYZr0SvuK0tQRvwcAANAgjEi9Vej2BQAA0MD8P0woWWcOqd0DAAAAAElFTkSuQmCC) Restrict autologin to requests from specific sources. Leave fields blank to allow all. #### Allowed IP Addresses[​](#allowed-ip-addresses "Direct link to Allowed IP Addresses") Comma-separated list of IP addresses allowed to use the autologin endpoint. Leave blank to allow all IPs. #### Allowed JWT Issuers (iss)[​](#allowed-jwt-issuers-iss "Direct link to Allowed JWT Issuers (iss)") Comma-separated list of accepted `iss` (issuer) claim values. When set, a JWT whose `iss` does not match any value in this list is rejected with error code `68`. Leave blank to accept any issuer. *** ## FAQ[​](#faq "Direct link to FAQ") ### How do I tell the plugin which field in the JWT contains the WordPress user ID or email?[​](#how-do-i-tell-the-plugin-which-field-in-the-jwt-contains-the-wordpress-user-id-or-email "Direct link to How do I tell the plugin which field in the JWT contains the WordPress user ID or email?") In the plugin settings, set the **"JWT Parameter Key"** field to the name of the JWT payload property that holds the user identifier. For example, if your JWT payload looks like this: ``` { "sub": "1234567890", "name": "John Doe", "UserID": 123456 } ``` Set **JWT Parameter Key** to `UserID`. The plugin will use that value to look up the WordPress user. --- # WP-CLI Add-on **Simple-JWT-Login CLI** is a [WP-CLI](https://wp-cli.org/) add-on that brings the full power of Simple JWT Login to your terminal. Generate tokens, inspect payloads, revoke sessions, and manage every plugin setting - all without opening the WordPress admin UI. It is the go-to companion for DevOps pipelines, staging-to-production migrations, automated testing, and any workflow where speed and scriptability matter. ## Requirements[​](#requirements "Direct link to Requirements") | Requirement | Minimum version | | ------------------------------------------------------------------- | ----------------------- | | WordPress | 4.4+ | | PHP | 5.5+ | | [Simple JWT Login](https://wordpress.org/plugins/simple-jwt-login/) | active on the same site | | [WP-CLI](https://wp-cli.org/) | any recent stable | > The add-on automatically deactivates itself if Simple JWT Login is not installed and active. ## Installation[​](#installation "Direct link to Installation") **From WordPress.org (recommended)** 1. In your WordPress admin go to **Plugins → Add New**. 2. Search for `Simple JWT Login CLI` and click **Install Now**. 3. Activate the plugin. **From zip** 1. Download the latest release zip from GitHub. 2. Go to **Plugins → Add New → Upload Plugin** and upload the zip. 3. Activate the plugin. Verify the commands are registered: ``` wp jwt --help wp jwt config --help ``` *** ## Commands[​](#commands "Direct link to Commands") ### `wp jwt login`[​](#wp-jwt-login "Direct link to wp-jwt-login") Authenticate a WordPress user and print a JWT token. > Authentication must be enabled in **Admin → Simple JWT Login → Authentication → Allow Authentication**. ``` wp jwt login [--username=] [--email=] [--login=] --password= [--format=] ``` | Option | Required | Description | | ------------ | ------------ | ---------------------------------------- | | `--username` | One of three | WordPress username | | `--email` | One of three | WordPress user email | | `--login` | One of three | Username or email (username tried first) | | `--password` | Yes | WordPress user password | | `--format` | No | `text` (default) or `json` | Priority when multiple identifiers are supplied: `--username` > `--email` > `--login`. **Examples** ``` # Authenticate by username wp jwt login --username=admin --password=secret # JSON output wp jwt login --username=admin --password=secret --format=json # {"jwt":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..."} # Capture token for use in curl TOKEN=$(wp jwt login --username=admin --password=secret) curl -H "Authorization: Bearer $TOKEN" https://example.com/wp-json/wp/v2/posts ``` *** ### `wp jwt decode`[​](#wp-jwt-decode "Direct link to wp-jwt-decode") Decode a JWT payload and display its claims. The signature is **not** verified - use `wp jwt validate` for that. ``` wp jwt decode [--format=] ``` | Argument / Option | Required | Description | | ----------------- | -------- | -------------------------- | | `` | Yes | The JWT token to decode | | `--format` | No | `text` (default) or `json` | ``` wp jwt decode eyJhbGciOiJIUzI1NiJ9.eyJpZCI6MSwiZXhwIjoxOTk5OTk5fQ.sig # id 1 # exp 1999999 # Extract a single claim with jq TOKEN=$(wp jwt login --username=admin --password=secret) wp jwt decode "$TOKEN" --format=json | jq '.exp' ``` *** ### `wp jwt validate`[​](#wp-jwt-validate "Direct link to wp-jwt-validate") Verify a JWT signature against the plugin's decryption key and check that the token has not expired. ``` wp jwt validate [--format=] ``` | Argument / Option | Required | Description | | ----------------- | -------- | -------------------------- | | `` | Yes | The JWT token to validate | | `--format` | No | `text` (default) or `json` | The command always exits `0` - check the `valid` field to determine the result. ``` wp jwt validate "$TOKEN" --format=json # {"valid":true,"message":"Token is valid."} # Use in a shell script RESULT=$(wp jwt validate "$TOKEN" --format=json) if [ "$(echo "$RESULT" | jq -r '.valid')" = "true" ]; then echo "Token OK" else echo "Invalid: $(echo "$RESULT" | jq -r '.message')" fi ``` *** ### `wp jwt revoke`[​](#wp-jwt-revoke "Direct link to wp-jwt-revoke") Revoke a JWT token so it can no longer be used. The token signature is verified before revocation. ``` wp jwt revoke [--format=] ``` | Argument / Option | Required | Description | | ----------------- | -------- | -------------------------- | | `` | Yes | The JWT token to revoke | | `--format` | No | `text` (default) or `json` | ``` wp jwt revoke "$TOKEN" --format=json # {"success":true,"message":"Token has been revoked."} # Log in then immediately revoke TOKEN=$(wp jwt login --username=admin --password=secret) wp jwt revoke "$TOKEN" ``` *** ### `wp jwt config get`[​](#wp-jwt-config-get "Direct link to wp-jwt-config-get") Print the current value of a plugin setting. Use dot notation for nested keys. ``` wp jwt config get [--format=] ``` | Argument / Option | Required | Description | | ----------------- | -------- | ------------------------------------------------------------------- | | `` | Yes | Setting key; use dot notation for nested keys (e.g. `cors.enabled`) | | `--format` | No | `text` (default) or `json` | ``` wp jwt config get allow_authentication # 1 wp jwt config get jwt_algorithm # HS256 wp jwt config get cors.enabled # 1 wp jwt config get jwt_payload --format=json # ["iat","exp","id"] ``` *** ### `wp jwt config set`[​](#wp-jwt-config-set "Direct link to wp-jwt-config-set") Update a plugin setting and save it to the database. ``` wp jwt config set [--type=] [--force] ``` | Argument / Option | Required | Description | | ----------------- | -------- | ----------------------------------------------------------------------------------------------------------------------- | | `` | Yes | Setting key; use dot notation for nested keys (e.g. `cors.enabled`) | | `` | Yes | New value to store | | `--type` | No | `auto` (default), `string`, `int`, `bool`, or `json`. With `auto`, the type is inferred from the currently stored value | | `--force` | No | Skip plugin validation and save regardless of validation errors | ``` # Enable authentication wp jwt config set allow_authentication 1 # Change the JWT algorithm wp jwt config set jwt_algorithm RS256 # Set a 2-hour TTL wp jwt config set jwt_auth_ttl 7200 --type=int # Set the decryption key wp jwt config set decryption_key "my-super-secret" # Replace payload fields with a JSON array wp jwt config set jwt_payload '["iat","exp","id","email"]' --type=json ``` *** ### `wp jwt config list`[​](#wp-jwt-config-list "Direct link to wp-jwt-config-list") Show all stored settings as a flat key/value table or raw JSON. ``` wp jwt config list [--format=] ``` | Option | Required | Description | | ---------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | | `--format` | No | `text` (default) - one `key value` line per setting, nested objects expanded with dot notation; `json` - full settings object as pretty-printed JSON | ``` wp jwt config list # allow_authentication 1 # jwt_algorithm HS256 # cors.enabled 1 # ... wp jwt config list --format=json ``` *** ### `wp jwt config export`[​](#wp-jwt-config-export "Direct link to wp-jwt-config-export") Export the full plugin configuration as JSON to a file or stdout. ``` wp jwt config export [--file=] ``` | Option | Required | Description | | -------- | -------- | ------------------------------------------------------------------------- | | `--file` | No | Path to write the JSON output to. If omitted, output is printed to stdout | ``` # Print to stdout wp jwt config export # Save to a file wp jwt config export --file=jwt-config.json # Filter with jq wp jwt config export | jq '.jwt_algorithm' ``` *** ### `wp jwt config import`[​](#wp-jwt-config-import "Direct link to wp-jwt-config-import") Import plugin configuration from a JSON file produced by `wp jwt config export`. By default the entire settings object is replaced. Use `--merge` to update only the keys present in the file. The command shows a diff of every change and asks for confirmation unless `--yes` is passed. ``` wp jwt config import [--merge] [--dry-run] [--yes] [--force] ``` | Argument / Option | Required | Description | | ----------------- | -------- | ------------------------------------------------------------------- | | `` | Yes | Path to the JSON file to import | | `--merge` | No | Merge into existing settings instead of replacing the entire config | | `--dry-run` | No | Show what would change without saving anything | | `--yes` | No | Skip the confirmation prompt - useful in CI/CD pipelines | | `--force` | No | Skip plugin validation and save regardless of validation errors | ``` # Preview changes without saving wp jwt config import jwt-config.json --dry-run # Full import with confirmation wp jwt config import jwt-config.json # Non-interactive (CI pipelines) wp jwt config import jwt-config.json --yes ``` **Backup / restore workflow:** ``` # On the source site wp jwt config export --file=jwt-config.json # On the target site wp jwt config import jwt-config.json --yes ``` *** ## Common Workflows[​](#common-workflows "Direct link to Common Workflows") ### CI / CD token generation[​](#ci--cd-token-generation "Direct link to CI / CD token generation") ``` # Generate a token in your pipeline and use it to seed test data TOKEN=$(wp jwt login --username=admin --password="$WP_ADMIN_PASSWORD") curl -s -X POST https://my-site.com/wp-json/wp/v2/posts \ -H "Authorization: Bearer $TOKEN" \ -H "Content-Type: application/json" \ -d '{"title":"Hello World","status":"publish"}' ``` ### Staging-to-production config migration[​](#staging-to-production-config-migration "Direct link to Staging-to-production config migration") ``` # 1. Export from staging wp jwt config export --file=jwt-staging.json --url=https://staging.example.com # 2. Review the diff on production wp jwt config import jwt-staging.json --dry-run --url=https://example.com # 3. Apply wp jwt config import jwt-staging.json --yes --url=https://example.com ``` ### Automated token health check[​](#automated-token-health-check "Direct link to Automated token health check") ``` TOKEN=$(wp jwt login --username=healthcheck --password="$HC_PASSWORD") STATUS=$(wp jwt validate "$TOKEN" --format=json | jq -r '.valid') [ "$STATUS" = "true" ] && echo "JWT OK" || echo "JWT FAILED" ``` *** ## Troubleshooting[​](#troubleshooting "Direct link to Troubleshooting") | Error | Cause | Fix | | --------------------------------- | ---------------------------------------- | ------------------------------------------------------------------------ | | `Authentication is not enabled.` | Authentication section disabled | `wp jwt config set allow_authentication 1` | | `Wrong user credentials.` | Incorrect username/email or password | Verify your credentials | | `Could not decode token…` | Token is not a valid JWT | Check you are passing the full three-part token | | `Token is valid. / valid: false` | `wp jwt validate` reports invalid | The `message` field explains why (expired, bad signature, etc.) | | `Token has already been revoked.` | Revoking an already-revoked token | No action needed - it was already blocked | | `Setting "" not found.` | No stored value for that key | Setting uses plugin default; use `config set` to store an explicit value | | `Invalid JSON value: …` | Malformed JSON passed with `--type=json` | Validate with `jq . <<< "$VALUE"` before passing | | `Cannot read file: ` | File does not exist or is unreadable | Check the path and file permissions | | Plugin auto-deactivated | Simple JWT Login is not active | Install and activate Simple JWT Login first | *** ## Contributing[​](#contributing "Direct link to Contributing") Contributions are welcome! Open an issue on [GitHub](https://github.com/simple-jwt-login/simple-jwt-login-cli) before submitting a pull request. ``` # Clone the repository git clone https://github.com/simple-jwt-login/simple-jwt-login-cli.git cd simple-jwt-login-cli # Install dependencies composer install # Run unit tests (no Docker required) composer tests # Run the full quality suite composer run check-plugin ``` See the [README](https://github.com/simple-jwt-login/simple-jwt-login-cli) for more information. --- # Code Examples Welcome to our Code Examples page, dedicated to unraveling the simplicity and power of Simple-JWT-Login. As we delve into the intricacies of this authentication solution, our goal is to provide you with clear and concise code snippets. Whether you're a seasoned developer or just starting your journey, these examples will guide you through the seamless integration of WordPress into your applications. Prefer to see them running first? Try the live, interactive demos right in your browser. [](/demos) [Open interactive demos →](/demos) Let's start this journey! --- # Register a User in PHP and Get a JWT ## Introduction[​](#introduction "Direct link to Introduction") This example walks through a complete PHP integration with Simple-JWT-Login: registering a new WordPress user, obtaining a JWT for that user, and using the token to create a WordPress post via the REST API. It covers the three most common steps in a headless WordPress workflow: 1. **Register** - create a new user account 2. **Authenticate** - exchange credentials for a JWT 3. **Use the JWT** - call a protected endpoint For this example, we can create a helper function, that will do the actual call: ``` "test". random_int(0, 10000). "@localhost.com", "password" => "my secret password", "first_name" => "my firstname", "last_name" => "my last name", ); try{ // Step 1: Register User $result = call("POST", $domain . "?rest_route=/simple-jwt-login/v1/users", $data, $headers); $responseJSON = json_decode($result, true); if ($responseJSON === false) { throw new \Exception("Response is not a JSON:", $result); } // In case of error, success will be false if (!$responseJSON['success']) { throw new \Exception($responseJSON['data']['message']); } $userID = $responseJSON['id']; echo "Your new user ID is: " . $userID . PHP_EOL; } catch (\Exception $exception) { // Unable to do the call echo "Error while registering the user: ". $exception->getMessage() . PHP_EOL; } ``` ## Step 2: Obtain a JWT[​](#step-2-obtain-a-jwt "Direct link to Step 2: Obtain a JWT") note Please note that, in order to use the Authentication endpoint, you need have "Allow Authentication: yes" in the plugin settings. ``` "test@localhost.com", "password" => "my secret password", ); try{ $result = call("POST", $domain . "?rest_route=/simple-jwt-login/v1/auth", $data, $headers); $responseJSON = json_decode($result, true); if ($responseJSON === false) { throw new \Exception("Auth response is not a JSON:", $result); } // In case of error, success will be false if (!isset($responseJSON['success']) || !$responseJSON['success']) { $error = isset($responseJSON['data']['message']) ? $responseJSON['data']['message'] : "Error while getting the JWT"; throw new \Exception($error); } if (!isset($responseJSON['data']['jwt'])) { throw new \Exception("The JWT is missing from API Response."); } // Your new JWT that you can use in other endpoints $jwt = $responseJSON['data']['jwt']; echo "Your new token is: ". $jwt; }catch (\Exception $exception) { echo "Error while trying to get the token: ". $exception->getMessage(). PHP_EOL; } ``` ## Step 3: Use the JWT to create a WordPress post[​](#step-3-use-the-jwt-to-create-a-wordpress-post "Direct link to Step 3: Use the JWT to create a WordPress post") note In order to use the JWT on all endpoint, you need to enable "All WordPress endpoints checks for JWT authentication" from the plugin General Settings. In this example, we will create a new WordPress post: ``` "Post Title", "excerpt" => "test", ); try { $result = call("POST", $domain . "?rest_route=/wp/v2/posts", $data, $headers); $responseJSON = json_decode($result, true); // Final Step: Post create response echo "Post create Response: " . print_r($responseJSON, true) . PHP_EOL; } catch (\Exception $exception){ echo "Unable to create post:" . $exception->getMessage(); } ``` ## Full example[​](#full-example "Direct link to Full example") The script below combines all three steps: register, authenticate, and create a post. ``` "test". random_int(0, 10000). "@localhost.com", "password" => "my secret password", "first_name" => "my firstname", "last_name" => "my last name", ); try { // Step 1: Register User $result = call("POST", $domain . "?rest_route=/simple-jwt-login/v1/users", $data, $headers); $responseJSON = json_decode($result, true); if ($responseJSON === false) { throw new \Exception("Response is not a JSON:", $result); } // In case of error, success will be false if (!$responseJSON['success']) { throw new \Exception($responseJSON['data']['message']); } $userID = $responseJSON['id']; // Step 2: Get a JWT $result = call("POST", $domain . "?rest_route=/simple-jwt-login/v1/auth", $data, $headers); $responseJSON = json_decode($result, true); if ($responseJSON === false) { throw new \Exception("Auth response is not a JSON:", $result); } // In case of error, success will be false if (!isset($responseJSON['success']) || !$responseJSON['success']) { $error = isset($responseJSON['data']['message']) ? $responseJSON['data']['message'] : "Error while getting the JWT"; throw new \Exception($error); } if (!isset($responseJSON['data']['jwt'])) { throw new \Exception("The JWT is missing from API Response."); } // Your new JWT that you can use in other endpoints $jwt = $responseJSON['data']['jwt']; // Step 3: Create a new WordPress post $headers = array( "Content-type: application/json", "Authorization: " . $jwt ); $data = array( "title" => "Post Title", "excerpt" => "test", ); $result = call("POST", $domain . "?rest_route=/wp/v2/posts", $data, $headers); $responseJSON = json_decode($result, true); // Final Step: Post have been created echo "Post have been created: " . print_r($responseJSON, true) . PHP_EOL; } catch (\Exception $exception) { echo "There was an error: " . $exception->getMessage() . PHP_EOL; } ``` --- # Todo App with Vanilla JS ## Introduction[​](#introduction "Direct link to Introduction") This example builds a minimal todo app using plain JavaScript and WordPress as the backend. Each todo is stored as a **private WordPress post**, so they are only visible to the authenticated user. Authentication is handled by Simple JWT Login. [](/demos/todo) [▶ Try it now](/demos/todo) The app covers four operations: 1. **Login** - exchange credentials for a JWT 2. **List todos** - fetch the user's private posts 3. **Add a todo** - create a new private post 4. **Delete a todo** - permanently remove a post ![Login screen](/assets/examples/todo/js-example-todo-login.png)![Todos screen](/assets/examples/todo/js-example-todo-1.png) ## Prerequisites[​](#prerequisites "Direct link to Prerequisites") Before running this example, make sure the following plugin settings are enabled: | Setting | Value | | ------------------------------------- | ------- | | Allow Authentication | Yes | | All WordPress endpoints check for JWT | Yes | | CORS | Enabled | The "All WordPress endpoints check for JWT" option (under **General Settings**) is required so that the WordPress REST API (`/wp/v2/posts`) accepts the JWT issued by Simple JWT Login. CORS must be enabled so that the browser can make requests to your WordPress domain from a different origin. Configure the allowed origins in the plugin's CORS settings to match the domain where your app is hosted. ## Step 1: Login and obtain a JWT[​](#step-1-login-and-obtain-a-jwt "Direct link to Step 1: Login and obtain a JWT") Send the user's credentials to the Simple JWT Login auth endpoint. Store the returned JWT so it can be attached to every subsequent request. ``` const DOMAIN = 'https://your-wordpress-site.com'; async function login(email, password) { const response = await fetch(`${DOMAIN}?rest_route=/simple-jwt-login/v1/auth`, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ email, password }), }); const json = await response.json(); if (!json.success) { throw new Error(json.data?.message ?? 'Login failed'); } return json.data.jwt; } ``` ## Step 2: Fetch todos[​](#step-2-fetch-todos "Direct link to Step 2: Fetch todos") Private posts are only returned when the request is authenticated. Pass the JWT in the `Authorization` header. ``` async function fetchTodos(jwt) { const response = await fetch( `${DOMAIN}?rest_route=/wp/v2/posts&status=private&per_page=100`, { headers: { Authorization: jwt }, } ); if (!response.ok) { throw new Error('Failed to fetch todos'); } return response.json(); // Array of post objects } ``` ## Step 3: Add a todo[​](#step-3-add-a-todo "Direct link to Step 3: Add a todo") Create a new private post. The post `title` holds the todo text; `status: "private"` keeps it visible only to the owner. ``` async function addTodo(jwt, title) { const response = await fetch(`${DOMAIN}?rest_route=/wp/v2/posts`, { method: 'POST', headers: { 'Content-Type': 'application/json', Authorization: jwt, }, body: JSON.stringify({ title, status: 'private' }), }); if (!response.ok) { throw new Error('Failed to create todo'); } return response.json(); // The newly created post } ``` ## Step 4: Delete a todo[​](#step-4-delete-a-todo "Direct link to Step 4: Delete a todo") Delete a post by its ID. Add `?force=true` to bypass the WordPress trash and permanently remove it. ``` async function deleteTodo(jwt, postId) { const response = await fetch( `${DOMAIN}?rest_route=/wp/v2/posts/${postId}&force=true`, { method: 'DELETE', headers: { Authorization: jwt }, } ); if (!response.ok) { throw new Error('Failed to delete todo'); } } ``` ## Full example[​](#full-example "Direct link to Full example") The complete single-file app below wires everything together. Save it as `index.html`, update `DOMAIN` at the top, and open it in a browser. ``` Todo App - Simple JWT Login
``` ## How it works[​](#how-it-works "Direct link to How it works") ``` ┌─────────────┐ POST /simple-jwt-login/v1/auth ┌───────────────┐ │ Browser │ ──────────────────────────────────────> │ WordPress │ │ │ <─────────────── { jwt } ──────────── │ + Simple JWT │ │ (stores │ │ Login │ │ JWT in │ GET /wp/v2/posts?status=private │ │ │ localStorage│ ──── Authorization: {jwt} ────────────> │ │ │ │ <────────── [ private posts ] ───────── │ │ │ │ │ │ │ │ POST /wp/v2/posts │ │ │ │ ──── Authorization: {jwt} ────────────> │ │ │ │ <──────────── { new post } ──────────── │ │ └─────────────┘ └───────────────┘ ``` * The JWT is kept in `localStorage` so the user stays logged in across page reloads. * Todos are stored as **private** WordPress posts - only the authenticated user can read or modify them. * When a request returns an error (e.g. expired JWT), the app clears the stored token and redirects to the login screen. --- # Headless WooCommerce with Vanilla JS ## Introduction[​](#introduction "Direct link to Introduction") This example drives a **WooCommerce** store from the browser using **only a JWT** in the `Authorization` header - no consumer key/secret, no cart cookie, no nonce. The whole app is gated behind a **login screen**: nothing is shown until a token is obtained and validated. [](/demos/woocommerce) [▶ Try it now](/demos/woocommerce) It covers the full storefront lifecycle: 1. **Login** - exchange credentials for a JWT (or paste an existing token) 2. **Manage products** - list / create / delete via the CRUD API 3. **Cart** - add / remove / view via the Store API 4. **Checkout & pay** - place an order via the Store API | Step | Endpoint | | --------------- | -------------------------------------------------------------------------- | | Login | `POST /simple-jwt-login/v1/auth`, `GET /simple-jwt-login/v1/auth/validate` | | Manage products | `/wc/v3/products` | | Cart | `/wc/store/v1/cart`, `.../cart/add-item`, `.../cart/remove-item` | | Checkout | `/wc/store/v1/checkout` | ## Prerequisites[​](#prerequisites "Direct link to Prerequisites") Before running this example, make sure the following are configured: | Setting | Value | | ---------------------------------------------------------- | -------------------------------------------------------------------------------------- | | WooCommerce | Installed & active, with a payment method (e.g. **Cash on Delivery**) enabled | | Simple JWT Login → Allow Authentication | Yes (so `/auth` issues tokens) | | Integrations → WooCommerce → **Enable** | Yes | | Integrations → WooCommerce → **Store API cart & checkout** | Yes (lets header-JWT requests skip the Store API nonce) | | CORS | Enabled for your app's origin, allowing the `Authorization` header and GET/POST/DELETE | To **manage products** the token must belong to an **Administrator** or **Shop Manager**. A customer token can still do cart & checkout - it just cannot edit the catalog. See the [WooCommerce integration](/docs/integrations/third-party/woocommerce.md) page for details on the toggles and the security implications of skipping the Store API nonce. warning Always serve the API over **HTTPS** in production - a bearer token must never travel over plain HTTP. ## How authentication works[​](#how-authentication-works "Direct link to How authentication works") Every request goes through one small wrapper that attaches the bearer token. That is the only "integration" code you need - WooCommerce treats the JWT user as the current user: ``` async function api(path, { method = 'GET', body } = {}) { const base = state.baseUrl.replace(/\/+$/, ''); const url = `${base}/wp-json${path}`; const headers = { 'Content-Type': 'application/json' }; if (state.jwt) headers['Authorization'] = `Bearer ${state.jwt}`; const res = await fetch(url, { method, headers, body: body ? JSON.stringify(body) : undefined }); const data = await res.json(); if (!res.ok) throw Object.assign(new Error(`HTTP ${res.status}`), { data }); return data; } ``` * **Products** - `POST /wc/v3/products`, `GET /wc/v3/products`, `DELETE /wc/v3/products/{id}?force=true` * **Cart** - `POST /wc/store/v1/cart/add-item` with `{ id, quantity }` * **Checkout** - `POST /wc/store/v1/checkout` with `billing_address` + `payment_method` The Store API cart/checkout writes succeed **without a nonce** because the request carries the token in the `Authorization` header and the **Store API cart & checkout** toggle is on. ## The files[​](#the-files "Direct link to The files") Create a folder with the three files below and serve it over HTTP (don't open it via `file://`, or `fetch`/CORS won't behave): ``` # from the folder containing the files python3 -m http.server 8080 # then open http://localhost:8080 ``` ### index.html[​](#indexhtml "Direct link to index.html") ``` WooCommerce + Simple-JWT-Login - Vanilla JS demo ``` ### app.js[​](#appjs "Direct link to app.js") ``` /* WooCommerce + Simple-JWT-Login - vanilla JS demo. * Everything is authenticated with a JWT in the Authorization header: * - Products : /wc/v3/products (CRUD, needs an admin/shop-manager token) * - Cart : /wc/store/v1/cart (Store API) * - Checkout : /wc/store/v1/checkout (Store API - needs the "Store API cart & * checkout" toggle enabled in the plugin so the nonce is skipped) */ 'use strict'; const STORE_KEY = 'sjl_wc_demo'; const NS = '/simple-jwt-login/v1'; const state = { baseUrl: '', jwt: '', user: null }; /* ----------------------------- persistence ----------------------------- */ function loadState() { try { const saved = JSON.parse(localStorage.getItem(STORE_KEY) || '{}'); state.baseUrl = saved.baseUrl || ''; state.jwt = saved.jwt || ''; } catch (_) { /* ignore */ } } function saveState() { localStorage.setItem(STORE_KEY, JSON.stringify({ baseUrl: state.baseUrl, jwt: state.jwt })); } /* ----------------------------- tiny helpers ---------------------------- */ const $ = (id) => document.getElementById(id); let toastTimer = null; function toast(message, kind = 'ok') { const el = $('toast'); el.textContent = message; el.className = `toast ${kind}`; clearTimeout(toastTimer); toastTimer = setTimeout(() => el.classList.add('hidden'), 4500); } /* Pull the most human-readable message out of a WP/WooCommerce error body. */ function apiErrorMessage(err) { const d = err && err.data; if (!d) return err && err.message ? err.message : 'Request failed'; return (d.data && d.data.message) || d.message || err.message || 'Request failed'; } function log(label, payload, kind = '') { const el = $('log'); const time = new Date().toLocaleTimeString(); const body = typeof payload === 'string' ? payload : JSON.stringify(payload, null, 2); el.innerHTML += `[${time}] ${label}\n${body}\n\n`; el.scrollTop = el.scrollHeight; } /* Core fetch wrapper - attaches the bearer token to every request. */ async function api(path, { method = 'GET', body } = {}) { const base = state.baseUrl.replace(/\/+$/, ''); const url = `${base}/wp-json${path}`; const headers = { 'Content-Type': 'application/json' }; if (state.jwt) headers['Authorization'] = `Bearer ${state.jwt}`; log(`${method} ${path}`, body || '(no body)', 'dim'); const res = await fetch(url, { method, headers, body: body ? JSON.stringify(body) : undefined }); const text = await res.text(); let data; try { data = JSON.parse(text); } catch (_) { data = text; } if (!res.ok) { log(`<- ${res.status} ${method} ${path}`, data, 'err'); const err = new Error(`HTTP ${res.status}`); err.data = data; throw err; } log(`<- ${res.status} ${method} ${path}`, data, 'ok'); return data; } /* Store API prices come back as integer minor units (e.g. "1299"). */ function money(minor, totals) { const unit = totals && typeof totals.currency_minor_unit === 'number' ? totals.currency_minor_unit : 2; const code = (totals && totals.currency_code) || ''; const value = (parseInt(minor, 10) / Math.pow(10, unit)).toFixed(unit); return `${value} ${code}`.trim(); } /* ------------------------------ auth flow ------------------------------ */ async function authenticateWithPassword(email, password) { const data = await api(`${NS}/auth`, { method: 'POST', body: { email, password } }); const jwt = (data && data.data && data.data.jwt) || data.jwt; if (!jwt) throw new Error('No JWT in response'); return jwt; } async function validateToken() { // Confirms the token works and returns the WP user behind it. return api(`${NS}/auth/validate`, { method: 'GET' }); } function describeUser(validateResponse) { const u = validateResponse && validateResponse.data && validateResponse.data.user; if (!u) return 'authenticated'; return u.user_email || u.display_name || u.user_login || `user #${u.ID || ''}`; } /* --------------------------- screen switching -------------------------- */ function showApp() { $('loginScreen').classList.add('hidden'); $('app').classList.remove('hidden'); $('whoami').textContent = state.user ? `Signed in as ${state.user}` : ''; } function showLogin(message) { $('app').classList.add('hidden'); $('loginScreen').classList.remove('hidden'); $('loginError').textContent = message || ''; } async function tryResumeSession() { $('baseUrl').value = state.baseUrl; if (!state.baseUrl || !state.jwt) { showLogin(''); return; } try { const me = await validateToken(); state.user = describeUser(me); showApp(); } catch (_) { state.jwt = ''; saveState(); showLogin('Saved session expired - please log in again.'); } } /* ------------------------------ login UI ------------------------------- */ let tokenMode = false; function wireLogin() { $('toggleMode').addEventListener('click', () => { tokenMode = !tokenMode; $('credsFields').classList.toggle('hidden', tokenMode); $('tokenField').classList.toggle('hidden', !tokenMode); $('toggleMode').textContent = tokenMode ? 'Use email & password instead' : 'Use an existing token instead'; }); $('loginForm').addEventListener('submit', async (e) => { e.preventDefault(); $('loginError').textContent = ''; const btn = $('loginBtn'); btn.disabled = true; try { state.baseUrl = $('baseUrl').value.trim(); if (!state.baseUrl) throw new Error('Enter the site URL'); if (tokenMode) { state.jwt = $('jwt').value.trim(); if (!state.jwt) throw new Error('Paste a JWT'); } else { state.jwt = await authenticateWithPassword( $('loginEmail').value.trim(), $('loginPassword').value ); } const me = await validateToken(); state.user = describeUser(me); saveState(); showApp(); } catch (err) { const detail = err.data && err.data.data && err.data.data.message ? err.data.data.message : (err.data && err.data.message) || err.message; showLogin(''); $('loginError').textContent = `Login failed: ${detail}`; } finally { btn.disabled = false; } }); } function logout() { state.jwt = ''; state.user = null; saveState(); showLogin('You have been logged out.'); } /* ------------------------------ products ------------------------------- */ async function loadProducts() { const products = await api('/wc/v3/products?per_page=20&status=publish'); const rows = $('productRows'); if (!Array.isArray(products) || products.length === 0) { rows.innerHTML = 'No products.'; return; } rows.innerHTML = products.map((p) => ` ${p.id} ${escapeHtml(p.name)} ${escapeHtml(p.price || p.regular_price || '')} `).join(''); } async function createProduct(name, price) { await api('/wc/v3/products', { method: 'POST', body: { name, type: 'simple', regular_price: String(price) } }); await loadProducts(); } async function deleteProduct(id) { await api(`/wc/v3/products/${id}?force=true`, { method: 'DELETE' }); await loadProducts(); } /* -------------------------------- cart --------------------------------- */ async function loadCart() { renderCart(await api('/wc/store/v1/cart')); } async function addToCart(productId) { const cart = await api('/wc/store/v1/cart/add-item', { method: 'POST', body: { id: Number(productId), quantity: 1 } }); renderCart(cart); const count = (cart.items || []).reduce((n, it) => n + it.quantity, 0); toast(`Added to cart (${count} item${count === 1 ? '' : 's'} total)`, 'ok'); } async function removeFromCart(key) { renderCart(await api('/wc/store/v1/cart/remove-item', { method: 'POST', body: { key } })); } function renderCart(cart) { const rows = $('cartRows'); const items = (cart && cart.items) || []; if (items.length === 0) { rows.innerHTML = 'Cart is empty.'; } else { rows.innerHTML = items.map((it) => ` ${escapeHtml(it.name)} ${it.quantity} ${money(it.totals.line_total, cart.totals)} `).join(''); } $('cartTotal').textContent = cart && cart.totals ? `Total: ${money(cart.totals.total_price, cart.totals)}` : ''; } /* ------------------------------ checkout ------------------------------- */ async function placeOrder() { const address = { first_name: $('b_first').value, last_name: $('b_last').value, address_1: $('b_addr').value, city: $('b_city').value, state: $('b_state').value, postcode: $('b_post').value, country: $('b_country').value.toUpperCase(), email: $('b_email').value, phone: $('b_phone').value }; const order = await api('/wc/store/v1/checkout', { method: 'POST', body: { billing_address: address, shipping_address: address, payment_method: $('payment').value, customer_note: 'Placed from the vanilla JS JWT demo' } }); const num = order.order_number || order.order_id || '?'; $('orderState').textContent = `Order #${num} created - status: ${order.status || 'ok'}`; await loadCart(); } /* ------------------------------ app wiring ----------------------------- */ function escapeHtml(s) { return String(s).replace(/[&<>"']/g, (c) => ( { '&': '&', '<': '<', '>': '>', '"': '"', "'": ''' }[c] )); } function guard(fn) { return async (...args) => { try { await fn(...args); } catch (err) { toast(apiErrorMessage(err), 'err'); } }; } function wireApp() { $('logoutBtn').addEventListener('click', logout); $('clearLog').addEventListener('click', () => { $('log').innerHTML = ''; }); $('loadProducts').addEventListener('click', guard(loadProducts)); $('createProductForm').addEventListener('submit', guard(async (e) => { e.preventDefault(); await createProduct($('newName').value.trim(), $('newPrice').value); e.target.reset(); })); $('productRows').addEventListener('click', guard(async (e) => { const add = e.target.getAttribute('data-add'); const del = e.target.getAttribute('data-del'); if (add) await addToCart(add); if (del && confirm(`Delete product #${del}?`)) await deleteProduct(del); })); $('loadCart').addEventListener('click', guard(loadCart)); $('cartRows').addEventListener('click', guard(async (e) => { const key = e.target.getAttribute('data-rm'); if (key) await removeFromCart(key); })); $('placeOrder').addEventListener('click', guard(placeOrder)); } /* -------------------------------- boot --------------------------------- */ loadState(); wireLogin(); wireApp(); tryResumeSession(); ``` styles.css (presentation only) ``` :root { --bg: #f3f4f6; --card: #ffffff; --line: #e5e7eb; --ink: #111827; --muted: #6b7280; --brand: #7f54b3; /* WooCommerce purple */ --brand-ink: #ffffff; --danger: #b91c1c; --ok: #15803d; } * { box-sizing: border-box; } body { margin: 0; font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Helvetica, Arial, sans-serif; background: var(--bg); color: var(--ink); } .hidden { display: none !important; } .muted { color: var(--muted); font-weight: 400; font-size: 13px; } /* Login gate */ .login-screen { position: fixed; inset: 0; display: flex; align-items: center; justify-content: center; background: linear-gradient(135deg, #7f54b3 0%, #4c2f73 100%); padding: 20px; } .login-card { width: 100%; max-width: 380px; background: var(--card); border-radius: 14px; padding: 28px; box-shadow: 0 20px 60px rgba(0,0,0,.25); } .login-card h1 { margin: 0 0 4px; font-size: 22px; } .login-card label { display: block; margin: 14px 0 0; font-size: 13px; color: var(--muted); } .login-card input { width: 100%; margin-top: 4px; padding: 10px 12px; border: 1px solid var(--line); border-radius: 8px; font-size: 14px; } .login-card button[type="submit"] { width: 100%; margin-top: 18px; } .login-error { color: var(--danger); font-size: 13px; min-height: 18px; margin: 10px 0 0; } .link { background: none; border: none; color: var(--brand); cursor: pointer; padding: 0; font-size: 13px; text-decoration: underline; } /* Top bar */ .topbar { display: flex; align-items: center; justify-content: space-between; padding: 14px 20px; background: var(--brand); color: var(--brand-ink); } .topbar strong { margin-right: 10px; } .topbar .muted, .topbar-right .muted { color: #e9ddf7; } .topbar-right { display: flex; align-items: center; gap: 12px; } /* Layout */ main { max-width: 920px; margin: 0 auto; padding: 20px; display: flex; flex-direction: column; gap: 16px; } .card { background: var(--card); border: 1px solid var(--line); border-radius: 12px; padding: 18px 20px; } .card h2 { margin: 0 0 12px; font-size: 16px; } .row { display: flex; align-items: center; gap: 12px; margin: 8px 0; } .grid { display: grid; grid-template-columns: repeat(2, 1fr); gap: 12px; } .grid label, .inline-form { font-size: 13px; color: var(--muted); } .grid input, .grid select { width: 100%; margin-top: 4px; padding: 9px 11px; border: 1px solid var(--line); border-radius: 8px; font-size: 14px; color: var(--ink); } .inline-form { display: flex; gap: 8px; margin: 12px 0; flex-wrap: wrap; } .inline-form input { padding: 9px 11px; border: 1px solid var(--line); border-radius: 8px; font-size: 14px; } /* Buttons */ button { background: var(--brand); color: var(--brand-ink); border: none; border-radius: 8px; padding: 9px 16px; font-size: 14px; cursor: pointer; } button:hover { filter: brightness(1.05); } button:disabled { opacity: .55; cursor: not-allowed; } button.secondary { background: #eef2ff; color: #3730a3; } button.danger { background: #fee2e2; color: var(--danger); padding: 5px 10px; font-size: 13px; } button.small { padding: 5px 10px; font-size: 13px; } /* Tables */ table.data { width: 100%; border-collapse: collapse; margin-top: 10px; } table.data th, table.data td { text-align: left; padding: 8px 10px; border-bottom: 1px solid var(--line); font-size: 14px; } table.data th { color: var(--muted); font-weight: 600; font-size: 12px; text-transform: uppercase; } /* Log */ .log { background: #0f172a; color: #d1d5db; padding: 14px; border-radius: 8px; font-size: 12.5px; line-height: 1.5; max-height: 320px; overflow: auto; white-space: pre-wrap; word-break: break-word; } .log .ok { color: #4ade80; } .log .err { color: #f87171; } .log .dim { color: #64748b; } /* Toast */ .toast { position: fixed; left: 50%; bottom: 24px; transform: translateX(-50%); max-width: 90vw; padding: 12px 18px; border-radius: 10px; font-size: 14px; color: #fff; box-shadow: 0 12px 30px rgba(0,0,0,.25); z-index: 50; } .toast.ok { background: var(--ok); } .toast.err { background: var(--danger); } .toast.hidden { display: none; } ``` ## Run it[​](#run-it "Direct link to Run it") 1. Save the three files in one folder and serve them (`python3 -m http.server 8080`). 2. Open `http://localhost:8080`, enter your **Site URL**, and log in. 3. **Load products**, create one, then **Add to cart**. 4. **Refresh cart** to see totals, fill the checkout form, and **Place order & pay**. The **Request log** panel shows every JWT-authenticated request and response, and a toast surfaces success/errors - handy when verifying the cart & checkout flow. Still getting a nonce error on add-to-cart? That means the request reached the Store API without being recognised as a header-token request. Double-check the **Store API cart & checkout** toggle is on, the token is sent in the `Authorization` header, and CORS allows that header. See the [WooCommerce integration](/docs/integrations/third-party/woocommerce.md) page. --- # Configuration The **General** settings page is the foundation of Simple JWT Login. It controls the API route prefix, how JWTs are signed and verified, where the plugin looks for tokens in incoming requests, and global security options. Go to **Settings → Simple JWT Login → General** to configure these options. *** ## Server[​](#server "Direct link to Server") The Simple-JWT-Login REST API is accessible via two URL formats. Both are equivalent - choose the one that fits your WordPress permalink configuration: * **Pretty permalinks** (recommended): ``` https://{domain}/wp-json/simple-jwt-login/v1/{endpoint} ``` * **Query-string format** (works even without pretty permalinks): ``` https://{domain}/?rest_route=/simple-jwt-login/v1/{endpoint} ``` ## Request Parameters[​](#request-parameters "Direct link to Request Parameters") Parameters can be sent in any of the following ways: * **JSON request body** (recommended for POST/PUT/DELETE requests) * **Query string** (convenient for GET requests and quick testing) * **Form data** (`application/x-www-form-urlencoded`) The `JWT` parameter name is case-insensitive - `jwt`, `JWT`, and `Jwt` are all accepted. ## Initial Configuration[​](#initial-configuration "Direct link to Initial Configuration") 1. Go to **Settings → Simple JWT Login → General**. 2. Set a **JWT secret key** and choose a **signing algorithm** in the **JWT Verification Rules** ELSE row (the required default rule). See [JWT Verification Rules](#jwt-verification-rules) below. 3. Click **Save Changes**. caution Use a long, random string for the JWT secret key. This key is equivalent to a master password - anyone who knows it can forge valid tokens. *** ## Route Namespace[​](#route-namespace "Direct link to Route Namespace") ![Route Namespace setting](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAACKCAMAAADBnhn0AAADAFBMVEX4+fq8wMRxeoL3+PlsdX0dIydQV17////i5OeUlJQeHh729/jq7O7l5uns7u+XnaR2foZtdn61ur7g4+WTm6B9hYyepKmPlpytsreZoKbQ09Z4gIfe4OPn6eujqq/09faJkJaLkpmgpqtveICxtrvl5ujM0NP19vfZ3N/v8PKenp6+wsZ7g4pweYGGjpTW2dx6gonu7/G6v8KVm6LX2t3c3+FzfIORmJ6mrLF0fITBxMhyeoK3vMCeo6kiIiLEyMyhqK11foXj5efO0tSFjJN5gYicoqe1tbWaoabw8fOrr7V/h4/y9PWzuLzJzdDIzM9+ho2CipGCiZHT1tnV19qprrPx8vPZ3N5KSkrs7vBJSUne3t+AiI94eHjBwsSKkZi+wMKkpKTa3eDm5+j5+fmNlJqXnaOMkJK2u7/w8PDGxsbn6Oqus7iwtbpaWlrGys1vb29TU1MjKS2ZnZ6Zn6VARUk8QUbj5eaPl52Ei5LR1NdKT1Lt7e4wMDC8wMWxsrLy8/TU1tlWXF+Um6Hy8vKgo6VDSEy/w8f8/PxdYWXAwMAlJSXo6uzDxsorMDSQkJCxtbqhp6wgJipERESBhYr+/v6JiYnGy84rKyvS1dcuLi4nLTEzOTx4foOiqa7Lz9KWmZvU1NS0ur65vsLa2trq6+xwdXhkZGTh5OWCgoI7QUS7vL86Ojqlq7Ccoqh6fH01Oz6FiIx/g4ZUWl3Nzc3Bxcnd4OLR0dGdn6KJjI/MztA2NjaBiZB+f4G5urszMzNvc3WNjY2do6hgYGBVVVWHj5VHTE+ztrhOTk5SV1rc3Nzp6ek/Pz9eY2koKCjJysqHh4dqampPVFfX2Nnh4eFYX2OtsLJlZWWlp6moqal9ho1zc3NlaW2PkpRqbnBNUlWIj5Zxd3zOfX2Wlpaamprb29x5eXlYWFhHR0eurq44PkKTl5ktMzfcpafXmJnEYGGtra3i4uL39/deXl5iZmrTiovkvr/u3d2zLS63ODnKb3G2traanZ/S0tLhtbXpzc6oJo1vAAAACXBIWXMAAAsTAAALEwEAmpwYAAAVcklEQVR42u2dd0BUV77HfzD3OhEEQXodijoSiqBIEUUBS1RQMDDKEwsYRIolJEQlL4qaKETBGkt0jW2M0diTvFWjJkZjSWKapm163WSzKbvZvq+cc8vMnaKSrMtT+H7+uDJ3zpx7ypwPv/ndw0h6AAAAbQ/xg8HscRsAAIA2wcNsUOxbPIIAAAC0GSOSJPsWGzAUAADQlhiSmH0NiHwBAKCto18D6c06jAMAALQtOjPpPTAMAADQ1niQ/jaMAgAAtDW3wb4AAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYF8AAACwLwAAwL4AAAD7Xp/7RVHcvOgDp9+LtlV80f6UmZWOIbpPvOeGN/3T32P6AADt0L5RnRgDndh386JvRfGt1ttXrPh32Pf77/7+3ad/wgQCANqdfddy+8Y5se9z1NAifkDkubZu05KjDUSrxZMUKooLT4icbdT/yreb3//CYt/aTbsl+/b/RhTrnttJ9Gux7ug3m49ue6Ol6U2imLVLNr14j45yD39UK74xix4S6w7VfbsriTyXrBYPNk1hlRx75aB43zHSPfTRpj0nPOWK//L9X//66YOYQABAR7LvNpH5NveCuOdXB8UmHbPvXsm+J5vEzRUV2XvFlgO7xM2yJbuI4gnxgGTfc3t2HX5RXGJk9q2trRPFlj2bxFco94j4xuEl4u/on+KRioqf9jH7inUHvhXfJ3PL+4eaxNoymiKyIve/RYfEPYeviE1yO/78/d/+9ve/YAIBAO3OvvO4fQ85zfuKtVuJO3EqbRTFYxb7KpmHIyJ7VZO4VbXvlCOrd3L7dnEnmsCL/VoUN9Jm8YrxLXGTboq42pNeFVvod+JPk95kRR4Sa6vppCguN3B/3yc+RIvEXex74LuY+HUMLeyCnD/976e//x9kfgEA7c++hVFXrkQtdJb3/UgUj+TSO8yY1CCKCyT7llntu0dKQHBjKvY9Jv7E7fvmrvtr2flJzL57iHi4ywRueEcuLX5hvsCO30xh9mXPvimKOSMOX2iRssbfyCb/Qin5jtKS7/6M6QMAtMs9D6+8QuQ08/BqLYtImTon0Bge+7awe3DnuH3vEZewEovE5yZNmrR3Eil53yn0oVjL7HtBbDp3TrZvHbfvPZJ9J4m1e1nxt1igW7b3Q/ENOfZdIIrmQ2LdO5PuY/ZdxNIQzOOG1eJWVvLcF5g1AEB7tW/z2l8xFnXix7WzHOxLn4gHTda87xHxxYr7uH3PiasPfcCcuulwxdGDaVb7lq0WmWs/Ej88d8TBvsZF4oWKig/r6J/PVVQsEo9w+15h1X1Ia8Ule3fx2JcV23WI5X2PinuOVhyuDcWsAQDaqX3ndLJhjoN9n1nNNj14HuJ7HkxEO5tq6+7h9s1dxFLCRIOaNrdcaDpmtS8d5vZt3iwe3OpgX4o5umRT3aK1NIVnlBdt43se3mlp2eVJ2R+Jm07cz/erHWs6KLLshu7dNzYdPPJ+F8waAKCd2ndhpwBr5mFrp4Vt2qKHuJsBAKAD2rd/QKdPirqMW3XlyqpxXYo+6RTQH/YFAIB/v32ldMPKEn5cmyc9gH0BAKCN7Fsj/7XFyja3LwAAwL6wLwAAtJ19d3HhBg/kx9PB/PgJxgkAAPD9vgAAAPsCAAC4Je2bG+Tq69LX5tToeUKvq5Tu70seGfZnnOHf7V9plIfrDehZz4hfVq1L1194QT+bURvIRmBG4i/vSELOzygc1+sqXbaZ6RRB6NuaQRioTF5QH6dP+3hd++WOc39D5hOA/2/7jhWElK5h1yjgWsgO3QLIUxC8C1zYz+FR16pvTEIM9bL9Y+aCq+8v1tjXZ1p6XNQ46jeoFSvQUwhLzmD/HUeUdBgcIUhI7XLauqTutm0UhPjIO3k1nG6km14QH5mXK9ciNLfavppqs534wMM3xDVy0I2y7+je5BmdTf+qfYe16tfYgOXXt++YITHEfs9aByH7ak5kTY/1dW7fxF6/xL528wnALWrfZspeHNkq+4YZmqNHX8++fYY5nPLKboV9jYlRPmGxPVu3Allb3OPHEY3K5wfu666BylPXbp3ijXzyHBm9nFcjR6dD1ycVjpSaGvxzYl8NTswTlrJvjqn36RtlX0ZoIrWRfVvTZT7TNp9ysq8Rkd5Y+wLQXuxLyd5EwX1TCmLZ95L5pgiLifpFuiaMc7AvUepIrd98vNLK89mLgvwDSkI9g7L8llKeFD72pTFxJsrJkr7CIVoQvCgs1bWgp1JSEt5k18hCrX19BIMl8xCy9NnE+XPOZgQ1kEt538gh4+QVOOtZV99i1b4UsJ2Kh9Z0o2JhuRP73jkkvpxJ3+fjjMVbRkqfVEMCy0eFu6v2Zc3Ksdg3aKTlF4VqX/eRcVn73MkloOvkIclEpntdh0yPsHTYsCorrjtpq/VivQ6dFentvd0ysvvvVTIP07ak8DqUEVarHDFNqlI71OogRQUMSTVz+44LceeJG+XjezK7Bje5Mf0ZFv5Fd1E76c3Kpsn9VyuXJ8MyZD1LskbK9u0j1aFcyDoRxoxQucrpfimnTVLmQemyRL/yeO/5aq+Va/CZ7uMiZx6Kh2UJ/vIYKG8gnr0oo0FCKC3ty5oeKvA3QdCMAFfeMesEdeWV+HjFJibGWlrr41VULg2dZu67D2bNE9ydzGex/1BhqAkLH9yq9p3BYt/1wTFj2KpOrUnSFZLJa37xmJBiB/suD2m2sa+wksyJGykokQlw7uDq5FF30gAlIoryTwoZLRdLzyZjSZTnoOgyuaT00basOC/EqLGvyWtxT6Nq31Sf+vTy+uwEF3IR7qQ7s4r5Cuw9NMezJtJi3xm+tH5YMDv4kaN9e8S7FBfFNRj9thePTldW61yjsXy0xb71QrXFvnleeR529u0eWeaxuIZdvp6ChzABTK7emBhh6fCqhOzkuB3aaqW4Lz4nN7fMMrIhqt+iY7sEDrGMsFrl/qDq5LMR2qG2DNLQMBqZJsW+fkyZ07arydN+Suw7mP222OGrdtLGvkrlymQoQ5Yd3b94VbQ19lUvpJkI/xqi+ak0yGtjWPk0yb5KlznLU2YUG8epvVavocw0GwT3iL7ZVCiPgfwG4pweQIPzXWjgAN50Ofb1C672lb8rT227FPt6h4eNyfBUW+sjzFAGzjr3in2dzGeerwf1ysXCB7do3ldIV5TBForvKi4Ctg7Zqn/aPu8rCP7utvZl8WrgFgpiS393CnPnDn+LfRtK5qk5CGbfZP7s/iKppIW4ftq8b3VaQbzvVNm+zIG+rOT0KBaasaci1/MVGMQspPOaqtp3Y4Yu3GVEii58oBP75rEO6OJ69o6TI1tptdYT1QSqeV+BxXJK3jeHdP194/P72Ng3hMVcz/iRC7O9u7dRF92P1RmhdlgXzcLLpQnaarl5dBnzDdbeGQVlVF2YwgxKZM9G2FJlDzbOEdqh1g5S/WTJvnn7yRTdxd6+veN09PEstZM29pUrVydDGbI8Nh/GFKt91QtpJqJ+FFF5M6XmsQSCYGL2VbvMmV7Oj2qvlWto7FuW0WDJPMhvIM7SxVTydBAPgS32Zb81ciaTZoJk+wrMnhHBamvVT0HauVfs62Q+p0dgjw+4hWPfhhyvJNqYmiUIgeQTkJX4NBVJWpJDkKx6HgqmcuPlNscV29g3hQdPfaV8Xk/pJeUW+9I+oYfVvqPH8krusGb+5k+OF4Rguz0PPuWpsn1D5Rwhy5i68E+xfQfwFZggXWGhat9c77ICH0ook+/p2dk3LZwdAuaPTuBnlNXKKuWLWI59i8NTyRL7MnL7C+M09jXJN+DknK23OUmIYa+KUDucJLDvji8cqq1WMs/6SO8hTmLfaVId6ghbqhwhVakZau0gFY6S7BsWnxsbQPb2Jb+FPTJy1U7a2FeuXJ0MZcjSeLw51mpf9UKaidCFlJnjTTRvDDsl3Mbsq3bZMpqk9lq5hsa+x8Za877yG0h6mOGZb0o0sxujFvvukDtmnSDZvln851lqay1pYM3cK/Z1Mp+me/1S0nRY+OBWzTzQ0PUUEjtV58+XcEOsd/H009YC83j+cOAWWVVBRbaxL1uP4YMlXZQp/2Gnat/k+GHTtLEvWyD+RRb7zklf2IXes7cvrQ9xsC9f2GNn8RW4eClp7rqxqKiGrdq0Glny9rEvX+x+PXt7scv6OrMvGVngpbEv0bPztbFvdA+tzXTR7MXdItQO66KZM55OcLAva1j4PGveN4i0dagjrK2S5VU1Q60dJMW+FDAo8mlH+3ZfVeNv6SRlVLOP+Tb2VSdDGbI8dlanxL77u1kvpJkIShs5gCVbU9mzU4UGKfaVuyzFvnPl2FfutaN9y1IMmrtu/A0k//qpiaKPa3ylpi9V77op9lXbHqfedWP2VVprta917qez7vZgsa+z+dQFDx2NhQ9u3btuyeTVg4q9AinYSL2iY5YPZXHbM9VSgZVsC1l2er2sqn7xSVr7ek8zPxa/UFpVusgZOjKXqWsyN9/FWLJUk/edTx5Z/Sz2DWWfnQttYl+PwN3G4PI7HOzr3b14ZXoSX4HB+btJ19Nq38B0pvcx6bKR7PO+rqHsxl+u0a+ZfFyd2pemJ1jsO2C9oXq7a6jWvoGpMZRbbzHNQH+KKYmwdHhVkK4hYoe22hHey8m0UPJpdZF1z4Mu9LSlDmWE1Yf7WZUJEaQZau0gqfZtTog3Odp3alZ+vaWTFNFM/TJs7KtOhjJkc+J3U6wg27dosPVCmomgcXGT2ffnDyqJoXA576t0WepJ+kbieV+51472dT/LYvdCaQyUN5AcZqc308j07VLTexYYbeyrtv3sLKt9ldZa7Wud+5wSd50/z/s6zGdyEpnzc6i5Hmsf3JJ532h2J7s5sXwYU1iatxDPfDwn1fW9ufJGMVNfgX9gVlRVXkPh/PNhnBylDPAeGqvsJIrxD/GKfExdk/tYqvCZ9B6qfSlsrmtBjmbP0ZZRc9Oe1dq3i29C/Kgik4N9pwUJ85Q9Dz0Tood0tdo3R5jO7rYLQXb2lVtXOC8+ku95OCuUD57h1L4j4uvlvG8azY9MTJ9bb5P31eXlZ0zubjGN6d6Sgn0Rlg4btrC7/zqbatMEIblcEPzKKFlQ6vBIDREKwi11KCOsPhwxLTquW7nNUGsGSbWvKfoOcrQvRYbwD9tKJ0NTJ5d3tbGvOhnqkD02dt4dBbJ9d4fwPQ/yhTQTwYSbwW967vBLGTZC2fMgdVmiX2Q03/Mg99rRvmyLRQrb88DHIFR5A0lJDcHMElLJUtONZ/meB6t91baP8eZ7HmT7Kq212lcz94Hlz67kex4c5rOZ7bTYx4L2QKx90KH+1u16GzVvAM43y+4WDK2vomvzTdvhPv7XLTLK6Z+oRY3sAO/lq2yUvoHzCQDs+zNXoCmtoJUvL8ulXlkxN2WHe4SRuWTj9UqN9nN2R6k6PZs6pH1v8HwCAPv+TPvmRyS38uUrBe+EwpuzwwsF4b0d1yuUMLa3k7NFIbHUMe17g+cTAHzHGQAAwL4AAABgXwAAgH0BAADAvgAAAPsCAADsC/sCAADsCwAAsC8AAADYFwAAYF8AAACwLwAAwL4AAABgXwAAuJntCwAAoM1h9tUDAABoY2BfAACAfQEAAPYFAAAA+wIAAOwLAAAA9gUAANgXAAAA7AsAALAvAAAA2BcAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQCgPdq3obQzuKkpfRDvXADao31LJ2Bcbm4mlGIMAGiP9u2MYbnZwRQBAPsC2BcAAPvCvgAA2BfAvgAA2Bf2BQDAvgD2BQD2hX1hXwAA7AtgXwBgXwD7AgBgX4ApAgD2BbAvAAD2hX0BAO3Zvrf/x1XreGB4q8vePt7JyW1u/4mJgH0BgH2dL+3hE1tvX7uy/+VWeU37TphZqX24YI3lxzmz17hNdDgLYF8AkHlwal87rmdfO2avs/y488vS8RMdzgLYF4COYN9/zNzgNn6qlE3ofPftLz/5fOPwMw+cuEuvz1xxZsNvv1bsu/PtUw/MrrRmHhoyn9Lrj7N4terSBDfGbKt971r38oYzr7IHD4+/dH64Ww8p88CrfnT2S+zsXY8+9c7xRu7bt/krZsr2ZWcxWbAvAB3Jvg2ZX1deLn1Jtu+pmT90vjT7heErlr3L7HvqZGWpW5VkX/OpFRcvn7i70Zr3vfsz/eUNmS/pV/zRPvY9sWFS5YHMi/qLmSsqq86r9l322uVt57lpH37ykcplD+v1ukvDNfZlZzFZsC8AHcm+l92mWoza+VEdC0lPsbj3bebETJ4LeHy2ZF/mWL3+kUvHrPZd94L+3Re+WqD/qrOdff+Q+ble3/jkCf1rv2Un3lXte5w9KOW53QMH9PrXf8MSvRt0GvvyswD2BaAjZR7OHH/i9h8V+55nj5//ih2eYFmBTB6brjgv2Xe2m8SCSnaYKJV9eFnjbz5b8aUu81XZvifZMz9w++5028leN/GPkmL1/23JPLAHwx9gCn+Sxb3/YOZ9XNaubF/pLIB9AehI9tX98Nr5ZVVK3pfbdya37+OqfcfL9n1dKX3x4kU5S8ESv8efqlpTdalRtm8De+ZB2b4XeSzr1L6P6vVPPcpC67s2LKjMrNLYVzoLYF8AOtqehzNPOLOvlHl4XbJv51N/0Nvt97174oZHdJlfspTEm3aZhwXsh/P2mQfVvuuk+3Nfvl2qJHpl+66bjamCfQHoWPbd2XmO/vKpUmf2PW6961Z56u1tjTtfq9TYd90yVmbmMlZZw7Iqm7tuL79auSJzgv6iG7vrtsbevmu4m/VVy8Zztz9SVTX+8aqn1LMA9gWg49j3x6/c3DInNjqzb+l4N8uOsx9nP7nh7teNGvs+7Mburq1w41vLnr/ajrPMl991a7Cx7xfLHtRLeV63beyfRimbvEY9C2BfAPDXFsy+V70R9vmZVl//6+O2jz97wVkp52dhXwAA7KvlpZlPtKqCz481nDxud7EFVc5KOj8L+wIAYF8tyx5/qVUVvJaZuWZFI+YA9gUA9sXShn0BALAvgH0BgH0B7AsAgH1hXwwBALAvgH0BALAv7AsAgH0B7AsAgH1hXwAA7AtgXwBgX9gX9gUA3Bz2LZ2Acbm5mVCKMQCgPdr3wdLO4KamtBLvXADao30BAADAvgAAAPsCAACAfQEAAPYFAAAA+wIAAOwLAAAA9gUAANgXAABgXwAAALAvAAB0APt6NGIYAACgbWn0IL3ZHeMAAABti7uZ9AZPjAMAALQtngbS65NiMBAAANCWJCXpif9T7I7cLwAAtBGN7p5Jesm+eoPZ4zYAAABtgofZoFfsCwAAoI35P2mmBuVQpUF1AAAAAElFTkSuQmCC) The **Route Namespace** is the URL prefix for all Simple JWT Login REST endpoints. The default is `simple-jwt-login/v1/`. Change this only if you need to avoid a conflict with another plugin. The value is trimmed of leading and trailing slashes automatically. ``` https://example.com/wp-json/simple-jwt-login/v1/auth ^^^^^^^^^^^^^^^^^^^ route namespace ``` caution If you change the route namespace after you have already issued JWTs, any existing links that embed the old endpoint URL (e.g. autologin links in emails) will stop working. *** ## JWT Verification Rules[​](#jwt-verification-rules "Direct link to JWT Verification Rules") ![JWT Verification Rules](/assets/images/jwt-verification-rules-45f49cd24c059beebb1127d24dd66806.png) JWT Verification Rules let you use **different signing algorithms and keys** for different tokens - chosen dynamically based on a claim inside the token itself. This is useful when: * You accept JWTs from multiple identity providers (Auth0, Google, your own service) * Different clients were issued tokens under different algorithms * You want to migrate keys without forcing all users to re-authenticate at once The rules are evaluated in order. The first rule whose condition matches is used; if none matches, the **ELSE** (default) rule is used. ### How a rule works[​](#how-a-rule-works "Direct link to How a rule works") Each rule has three parts: **IF** - a condition that inspects a claim in the incoming JWT | Field | Options | Description | | -------------- | -------------------------------- | ---------------------------------------------------- | | JWT Part | `Payload claim` / `Header claim` | Which part of the JWT to inspect | | Claim Key | text | The key to look up (e.g. `iss`, `alg`, `x-provider`) | | Operator | `equals` / `contains` | Comparison to apply | | Expected Value | text | The value the claim must match | **THEN USE** - the algorithm and key to apply when the condition matches | Field | Description | | --------------------------- | ---------------------------------------------------- | | Algorithm | `HS256`, `HS384`, `HS512`, `RS256`, `RS384`, `RS512` | | Secret Key (HS\*) | Symmetric secret; optionally Base64-encoded | | Public / Private Key (RS\*) | PEM-encoded RSA key pair | **IDENTIFY** - how to look up the WordPress user from the token payload | Field | Options | | ---------------- | ---------------------------------------------------------------------------- | | Identify user by | `Email address` / `WordPress User ID` / `WordPress Username` | | JWT payload key | The payload field that holds the identifier (e.g. `email`, `sub`, `user.id`) | Use dot notation for nested values - e.g. `user.id` to read `{ "user": { "id": 42 } }`. ### The ELSE rule (required default)[​](#the-else-rule-required-default "Direct link to The ELSE rule (required default)") The **ELSE** row is always present and cannot be removed. It is used when no IF rule matches, or when no IF rules have been added. The ELSE row has four steps: **Step 1 - Key source:** | Option | Description | | --------------------------------------- | -------------------------------------------------------------------------------------------------- | | Plugin Settings *(recommended)* | The secret is entered directly in the settings form | | Code (`wp-config.php` or custom plugin) | Define `SIMPLE_JWT_PRIVATE_KEY` (and `SIMPLE_JWT_PUBLIC_KEY` for RS\* algorithms) as PHP constants | Storing the key in code keeps it out of the database. Example for `wp-config.php`: ``` define('SIMPLE_JWT_PRIVATE_KEY', 'my-super-secret-key'); define('SIMPLE_JWT_PUBLIC_KEY', '-----BEGIN PUBLIC KEY-----\n...'); ``` **Step 2 - Algorithm:** Select the signing algorithm (`HS256`, `HS384`, `HS512`, `RS256`, `RS384`, `RS512`). **Step 3 - Verification Key:** Enter the secret key (HS\*) or public/private key pair (RS\*). For HS\* algorithms, check "JWT key is Base64 encoded" if your key is Base64-encoded. **Step 4 - User Identification:** Which JWT payload field identifies the WordPress user. | Field | Options | | ---------------- | --------------------------------------------------------------------------------- | | Identify user by | `Email address` / `WordPress User ID` / `WordPress Username` | | JWT payload key | The payload field name that holds the identifier (e.g. `email`, `sub`, `user.id`) | Use dot notation for nested values, e.g. `user.id` to read `{ "user": { "id": 42 } }`. ### Example: multi-provider setup[​](#example-multi-provider-setup "Direct link to Example: multi-provider setup") | Rule | Condition | Algorithm | Key | | ---- | ------------------------------------------ | --------- | ----------------- | | IF | `iss` equals `https://auth0.example.com/` | RS256 | Auth0 public key | | IF | `iss` equals `https://accounts.google.com` | RS256 | Google public key | | ELSE | *(fallback)* | HS256 | Your site secret | *** ## JWT Input Sources[​](#jwt-input-sources "Direct link to JWT Input Sources") ![JWT Input Sources](/assets/images/jwt-input-sources-37e5715034848b8e1f1bb6c0ddff142f.png) The plugin must know where to look for the JWT in each incoming request. Enable at least one source. When the JWT is present in multiple locations, the higher-priority source wins. | Source | Default parameter name | Default status | Example | | --------- | ------------------------ | -------------- | --------------------------------------- | | `REQUEST` | `JWT` | Enabled | `?JWT=your.token.here` | | `SESSION` | `simple-jwt-login-token` | Disabled | `$_SESSION['simple-jwt-login-token']` | | `COOKIE` | `simple-jwt-login-token` | Disabled | `$_COOKIE['simple-jwt-login-token']` | | `HEADER` | `Authorization` | Enabled | `Authorization: Bearer your.token.here` | You can rename the parameter for each source. For example, changing the REQUEST name from `JWT` to `token` means clients send `?token=...` instead of `?JWT=...`. note The recommended approach is to keep **HEADER** enabled and send tokens as `Authorization: Bearer `. This is the most widely adopted pattern and avoids tokens appearing in access logs. *** ## Integration Options[​](#integration-options "Direct link to Integration Options") ![Integration Options](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAACKCAMAAADBnhn0AAADAFBMVEX4+fptdn6Zn6Xh4+VsdX12fobAxMf////i5OcdIyf+/v54gId9hYxyeoLg4uNxeoK5vcGTmqB0fITw8fI1Oz6ZoKbt7/BQV166v8L29/j09fWepKmMk5m8wMTq6+3m6OnV2Nr9/f3Z3N/r7O6LkpgeHh6gpqvBxciQl52mrLGFjJNARUn3+Pmkqq96gol7g4rx8vSAiI91foWwtbnKzdDk5eissbb3+PiVm6H09PTo6eutsrfU1tm1ur58hIvHy8+PlpyJkJb8/PyWmZv6+vrFyc3Cxsl/h47S1diVnKLg4eKDipGCipGXnaScoqfu8PF3f4fe4OOXnaPc3uF5gYjd3+FveID29vZCR0qNlJq+wsWboqeorbJLUFOiqK2prrPc3t+usbLj5edweYGlq7CQk5X5+fkjKCyRmJ4nLTG+wsa3u7/R09aGjpQgJiqHj5VZXWCEi5K0ub3l5ufO0tSGjZS0uLzN0NPFyMvy8/R+ho3l5una3d/M0NI7QUTO0dTV19mSmZ+OlZv09fbLztCyt7uKkZcpLzKMkJLOz9BweICvs7i4vMCkp6jt7e+BiZDZ2tyqra/19vd8gIO6vL2JjI6go6VcYWSoqqzo6uzV2Nt/ho3Dx8vLz9JFSk1ucnRITVCgpav7+/tvc3bGys0uNDcrMDTJzM+EiIrGx8jj5OTq6+yxtrvJy8y9wcVPVFfW2dy5ury1t7jZ291xdXfi5OVgZGehp6y7v8OHiozm5+lSV1rm6OqKkZhzd3lUWVx1enxWW182PD9eYmZhZmmQmJ6qr7Xy9PXX2t15fYB4e35JTlE+Q0c8QkY5PkFna26lp6l/goXj5ObCxMUkKi6epKqTlpixtLUzODy/wMLT1NXr7e+eoKK/w8fo6OnBwsOanZ+YnqRscHKipqvw8PCDi5EwNTnExseBhIaChoiOkZNqbnBjaG3Hycvb3N1bX2KKjpDR0tPq7O63urwlKy+ztrqPk5UeJCjY2dpBQUE/Pz+Ag4XIycqnq66kpqh/g4a4oWJaAAAACXBIWXMAAAsTAAALEwEAmpwYAAAgAElEQVR42u2dCVxVZd7Hz4WDzzwsIhdFUERNRgUREBoXXCFEUBMxQc0FEs2NWCRNXFNUTB13Uyu1xaW01CkdM80yDSpN07A0bLLeycmpt32qWd/3/5znOfeee3EjjRr7fT8fL9xznu08z7nf+7//c7hqjOgUNu03AAAAaoVpYaUkXo3+BQVqAAAAao3AdMO+QaWYCgAAqE1K08m+pYh8AQCgtqPfUo2FRWEeAACgdokK09g0TAMAANQ20zT2G8wCAADUNr+BfQEAAPYFAADYFwAAAOwLAACwLwAAANgXAABgXwAAALAvAADAvgAAAGBfAAD4Fdn3fs5717zWg7wNlgkAAPsO509Ynh3hK6+l0q2cv6BpmYcOFV+2yHOfzayc+dkP1k238Ufp8dlDG7FMAIBfl32XffbvG2nfK5FSySuHf8sr365mXwAA+LXZ9/PDDY9c0r6UQjg/vOzwc9qjnDijRT04vGzmyiqKbteUHX2Q8/8V6YLVx9osGZzP6x8+q70rivFzRuaByo6buXuPpn3ET2w8M/M22WppG360WCveyY9VaPX5ycItj67SVhq13jMyD0suthk3eHWJRjsvfrHl6FlNO3vkON+yEgsIALjZ7JunZR5ueKjV5ey7eeWj/IR2bjDfueAdbR+fefILfliLPcZnvv6KtG/l5td3b9/y2ZNf8Mqc997g/MkFzxj2vcjLXj7Kj79A9uUvneT8K9kb58vpB2l6Lgk2/6OXeP7cVWv4mQULioV9K/ZTw/X54Shj5xF+pmLFhfx9Cy4ewgICAG4y+05uGJ/dsHCrdjn7Pqv9m19QmYfYfL5KKy3jc1dxvkd7W9qXHrTSJVThGH9QZR6EfWO/5+9qK17h58m+R8XO80arzwrtaloXzu8iwX6iaTv5SZV5EPY9y3mx9h7nDxg7M8nZK8ry73oqDOsHALjZ7Hu4YcPJf0ulX+Ye+dul7JujfcPzlX2Xcclbb/EyTasr7Xucygb+3/4y2r7AYt9lhmb3U7WP+EHR2ndGq3M5/4Z+kGWnkGDfMvISFvv+h2/RtBJO4q7P12pVnKdob31LLe+uwAoCAG4q+05vSEygXx451PDlS9m3t7TvZ/x1CnHz+W0ffPDBu8tWCSuvUnlfKruPt3nrg2Nk3/s4PyXtSwpdq1VcMGLfl0WIK+0bdIHvpLzvfr65Ssa+Gyj2Pc83OGPfHG2rjH2Xa0uEfbXAZ9ZuppgbAABuJvveKezbsJ4W3LDhid9dwb4nef0Fy7XVfObqBScre4u875NHnfa9yAev2i1i3wTOP1rQ2z3va7Gvdlbd87BKXFjbvHo3z3+A0hH5T36nued9lX137luwOp+fxQoCAG4q+04w7Ntwx+KGn9XVrmDfH2ZyutoWtXZnWf2XTrTQctZUHn9XhKjSvsXD+biVR8m+5Gdysrzn4T/Dv535hKfmZl+6u43u9z1yvybse/4QP0oarjjE+beyqSVP0j0PX8ZqTvvuppzG5u9CsIIAgJvKvt80VPr9W43+Ok38McVynh97XUOqb9z+AAAAv2b7NmxVo9YuDv9y9Wa+T4N9AQDgR9l3hGnfhvfXpLV3X+EX9v87CvYFAIAfZd9Npns/uxVTBAAAtWbfJxo2HPI/RD3cTwsAALVo37999g2mBgAA8O3qAAAA+wIAAIB9AQAA9rXie4vxo0HwVco1uf1qTVhoFeDytHHXGzbcbqov9/FedfwuzEis/RW8517Hr55e1acpVr+uK6duMw4A+Bntm5fo1392NS/261pz+470r6l975ji8vTWXZfv343oW668f/E6bXyA63jdnysmj6WHXsZDz0vZt6+ud4souWJnbXU97vZpmlalC7pq6W1j4gZsuleXJMhCQ+wrnEW797qafcUEmPa1TtOV7Ds+4KqTBPsC8Iux79ys59cF3df+57Hv5ble+17Ctpex7y6/KC0sOo4e9LBL2veRqLxeEVe2b0ttT0CRsK807Yfhqenrn6dfMnTHF1cc0Pt3V0VnF9XQvlZgXwBuEvuGxDSRv5TujYt5Wrzgy4f0Gq8FU8x2u+ZTHtpO6xKZO6TYad/4Hv6zyVJyq3gt9/pQ03zuEPu8qFJGkwEj7JGvkYkaxPm+rz7tN55T8OrXRhM9KLy8NVzTtk6Na0+aofqqQzPz0KTHh/Opuuz/jnD/e6jbwAH+kRMSqeSwOR4rhrWzf3hAu532B5v7N4XbbBNF/Wkk0r1xZK7FlHnIoCJejvEKE1qfq6piBhbeom3qF36L1nOqOQlNegyYHxzrYfRK9tW0eYlyLjYt9Q8I0qLi++p+XZzdCqVqr+mlDvv6zFKza7Hv00PKA1TRXXqIsq86Gq1Byx6RYlQzehnTQhgT4Ok1Pjp6vCaniQ5ei4/zbaXs22ROWnjkc/Rzvn94MznkcnGEXQfQzlGjRBE5SWr9El7173uf0VRQ44H6wFi8VAD4me1b1wyl9t5T/FpMsOapL9K+9qmSsafPqyu03+U2CcqOKXHY1zfvQECEubXYHhXWzUebZo9yxr5Z47/uHKlprUcceK1XF1knOkyLH2K1r6d9fdC8LGlf1aFpXz1Py4uUoV+s146grf2DtH4NDrxWQPbV4+l70ub9rrjBABnWmftzZ1VUTDcaiMnRek311KJzRN5XxrpyvM7YVz43qwrmdNVGjG9PD6fNSWii0/fQN55/IDVa2reixwhjLnYNnFW1KFx7LeaOqHW/s3RLSo1aNNUZ+77ap1W6u319x9e1VcminduZsa95NA0GJmjtI7TirDpBe7Mssa+tbcJWvyo5TXTwrXweKg437at30brEBWmLc4Im+qyQQxZHWJUVq4X0v8UR+6qVWtGuZdWUhTmiqYkB07Rb8Gc3APzc9r3XT/6MWkjx6vv30Au+VNPC85R98ygt+irtjJnhsG851XnRsdVnevcRiZ6tOloyDySsUr10jx9lOYMbyzrtxaYqi33n9ROtS/uqDk37UmAcYlth9N9kNm0b0Coqq9ho1pOiS4NpdikWc7/fjlIzXzEhqFd5ExECO+wrx+u0r3yuqhrb4wO0vp730UMrcxLEIKIWUjw/WeZ99aIEYy4aUKgb5fXCdK88erexdEvJXL3/Q2be914t9ulwW0Gqi30fssVqRYtV0Txr5kEcTYPOlH+nWU2jcNhusa8wbWKetC919upiEWMr+4qDCu9u/N7tDmPI8ghbv6/NmurMPKiVek1knfsNE01NSDyF1wkAv4TYV15QSic7ag8NlKlGcqS0b4amRbQVG3ZY874P9XJs7be47ZTy8ae7WuwrPvnawmYYIpoj65A0NHumxb4Rw2hLX5V5kB2a9r3dqG70P8xoIz5dD6RURaIsGTKsj00npwmxqP1a93BbpAxC30/buvfeoSkBmtO+crwueV96blYVpPpVxWmB9ip9mjkJYhBGr91V5kHNxT1GrS5a+0hbQJWlWwpoi8O7OmNfomqUvcJq35Y0LV2LZOaBUPY1j8acVTUtDvvGybkxp6loruijYg8NQmsi3vHS6pGFc3X6vGDMm3GEj8zRhj7ttK9aqVv7iuzHUNFUrIevPSIKLxUAfu68bzeZ943Koldqq3uq23eyeEX7znCzr7l1fFrfsFn9psp9xY6rbraw6THOPhq0FdIIE00E0H8hVIdiXyoUYr+afSf0U0OjYUxQ9h2fOD32APkq5hbHfuG6tkXS/35tH4mNbtnVsO/7bva1PndWpY//tnjqNDJ+oGMSxCCMXru62rfj+2adzPAIS7dCqZ65VVb70u97LPat8DPE7elmX/NozFkV/drdrrpZ7PsqFbvFjH2FTvv2PGXv8rU2VdnXOMIKvwML1TDEJKmVek0khxoPk1fdovIG4tuWAPhF3PMQldde29sgqiQx2PGCzx6hjFPsn6Ftjalws6+59ZSfrxYb5ycdE2hb57BvVHg83UUgQ8MG9vVfp4Uaed/y01pQEeV9c09pdbKuZF/R/7qBdJko84DW77QWOEnZN5i0GU++Ktjk2B/bxZCzwUD7Oi3Rfoth3/v6rHCxr/W52bRBuL0eXaiyU8tqEoxBNG6spbdztW/e1D1a1H3aqZFa6Yfllm4NpXYsd9g3u0vU9L0xIRb7TvESt5u1HuZmX/No1KhO5e7RxuvSvmIC3O3bqig2aqhpX9vTQfH29IxuUVozM/Y1jlA7XRCq1lZMklqpFe12aNPiMkVTr6VrYVPv1R7Jw6sFgJ/9fl9b4vta6Qi63B/leMHv6S/ueSDjaM2KckNHam72NbdqcZTaLRirmooQ9zwofQae9vEKXS/rdO5jGyvveUj36FEUIe558NWzI7tcwb5G/6de9Z/aupjuecjq1nWILFlyT2JH4avuNrqcL/fHztF13xwVZvuStxZGGfZdUSDucXDa1+W5atqgXKd3iU06fQhQk2AMItajXd9RrvbV7pu0MPJ2bXovXR8SaOnWUGqqX6zM+0Zoe1+0R/crtuZ9X80Wj1v7h7ja1zwac1Tr+xYN7SPtKybA3b5a/NSli0z7DmigF9GajOjVOmKpsq9xhFqevkOthzFJaqUSWvuLnAY1lUL3ptA9EWM749UCwM3+l8aXuUfY60AN2nj+NNZWu7a/KVyXlY7pAQD2vYx9H4rSgodca/3iBC2sXSrW9hrtO6oxZgcA2Pdy9p2j545NuNb6XXR9ajCW9trsG6vPDsPsAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYF8AAACwLwAAwL4AAAD7AgAAgH0BAAD2BQAAAPsCAMBNYF8AAAC1DtmXAQAAqGVgXwAAgH0BAAD2BQAAAPsCAADsCwAAAPYFAADYFwAAAOwLAACwLwAAANgXAABgXwAAgH0BAADAvgAAAPsCAACAfQEAAPYFAABwY+y77e+/tfCP3pglAACoDfv+4w/WZ3/4O2YJAABqw76/veJTAAAA/w32/T1vI39ZwvkD8rdH+W3sLT74x7T25VHOH79SgRzOX2Cv8LuutUExlhvBSf7HS22uf+0jAQDAvlez73C+m63hbzC23BDqIX7xBFd0Evv/wHnZnxn70xjOn2GrCp+4cfZ9hvM3Rje/Zvu+I8y/jQvBLuDDL2vfQDHyM4Xv/gT2/bTwbcuzMv4sTjkAwPXZ1xDbQSG2u8fwPywoLJzJKwsLC0OUffk7jO3jwr4OboR97+JnrlLCxb4k6wTxFnHEeIu4kn03FF7gfNWNt68rsC8A4Lrt+4yw3Jtt8o+wtzmnQJet5vXN/WTfzfW1ki2bhX2NzMO2NWVHfy/sG/LyhTdXO+w7aN/gcY+e82Yb+T6q9CjrNIb/0GlDPq//x78YKYsFx9o4yghGiyB1A+v05OBxGxbcLT7Xf1lYJkW7sZKX7f+Pm32Ty+iXg3zDFu9B9BbhXs8xFrLvWtb8GP+UBvLEpxfeYM98sfnMCbrXY9sTg7/PP/Jn9mDhFv7mv834W+3cyD994szM87TltjcvfHqQ7Ps5vRkNL/uiLrP2dJdxIG02vxGyxPh08KlrawAA2Ldm9n38W758G1/50hbvL+Vneot9V3G+mq89Tw/Kvh3a8DdXviLsu5tveX1DpbJv8iG+8+IGerKW72SfkMTPUhuBW07sW8Mrt1HFys0rDzrKCJ46wctGP5j8Ep+5sj7/oze5bUzhQfnRfucX+0jAd7nlfdfwl9mxDV/yBz6g1t3rOcZi2HdbGV9JRh3TZuVtZ3nZ6wd5/RJ2gu8e/deXMrvw46NHv/5P2aRj50bOD9Gg76fRf//pF5XSvhdWtuHHO1l7Evblbb7cws8NGl3JPxr9rktrAADYt4b2FYnf5fzZBfyBl/gnrFrsW1y54fiW3qZ9z3K+nf2L7BvC+btsUJmy79s8v4Q9wLdQaja/ZPhg/uxqoXWROj7Gf8+MWNlZxmC56ISC7RZsGefvkdsOm32K8PtlvtHNvpQf2cZPvs1v+5Ifda/nHEugzFmPyyGjnglk7CW+mrE/8vPsCF/wr2JG3b/59ld3q44cOzeKd502/BzbT9pmX0j7rmIllfwba0/CvmOWsDco6JWZB5fWAACwb03t+w4/dpD/+S/8nTH8m+qxb9IbnD+5xLTvWl7G2Atk096GUQcr+65Vl+p605a7+LkLJ/fz5Szk4v4y2jaaKh6ntpxlHPZdK1x8NyeT1aeYVXFuTX0qVehmX8qP3MafvXvMkf30FuFWzzkWI+/76ehtIpsgLhHOlF0eZF8dpx87t7HXhZvPySYdOzdSXM12UoJ7pojMX5f2pWG+ws9ZexL2PcbYk3yNmfe1tgYAgH1ral8S24VHWYf8MzLt6xb7Pp7z/Zg/LbHEvtvEg4h9l7NAM/PwFB9z9qmnnnq3E1vJN/D3Pm2Tz//EvuRtlj91zLCvuFXNWcYa+25jX5mRpeQD/u35v5yoZl9K/F7gS1jhFvEW4VbPORYj82CwUdzJwQr5buryg6cYS/ph1XDKSbM//4tSzo2MIo6dRllh3/1Cw/vN2Hd7vhH7WnoyDsSw72aKtplLawAA2Lem9qXELz8pZESf6S9hX/bAV8xh35A2/KXRg0Ws+QQlPQ9zZd+kQr5/9OiN5KZvSOXeD4oraqSpDWcPcod9nWUc9nXNqprh9rhnvyurZl/Kj9DFPPYdF28R7vUcY3G379u87OLov75yF3v5k9Gj3+QLHljz3eiDfEwHo4hjp8O+a3n+PopnDftuGF3IZ4a4531N+w6naXjGpTUAAOxbA/s+KoI9IbZnjdsQ/nlJ+zLmtC/d81B5/Ly852FzmXERTd7zsGDDuGOFFFsGfs9PsB+4yCBv38nH/XO4w77OMg77sk50G8SGv3aw/i2D927OP3uiun3fMd4inpJvEW71HGNxty+bu6Z+2f7DX7FzlGbIPxhYvCafLpyZf39t7nTYl+55+P7ERhX7vln5RaZbT077rhpHsndtDQAA+16zfXtX3qC/D7vZIPsWYxYAAD/avn93/Zadf7jt/iSfj9mGmYN9AQA32r69/2H9hsm/u3/D5Bp+5htMHOwLAMC3qwMAAOwLAAAA9gUAANgXAAAA7AsAALAvAADAvgAAAGBfAACAfS9JU68aVqjjIX+2rOeyubzz9R1H3vzanLUWfoz5Zjif+4y8ZLEpHd23WCsRBanXPxbqRAzHbT5rQLcMtw3UlGjx2tbxUrPj/5OeOSbzov1vzGpWmwAnQ++EIsAvyr4TZtNDL+Ph1tq0r7XfS9m3j653y77y15ZH6HqcRwv6FhxdUI8NioiJ85ibqkuCZKE59iRn0fW9rmzfxvWq2XedaQXPrddp3z7d2ezFjKXrxkOEHOXDrmWok8vbt/GVnWzsfj69hvY1ju8y9hUtDup6tWFEZ1y/fTtlrbtBr4FqE2CQ0vE67RudAb2AG27fHD9vFhgdRw96YG3a19rvJe3b3XtXr+wr23cEO9AxUthXmrZB6LLSvPH0y0jd8T8lV+n916uiAZHXZd/q1Ny+EwIYu/Vh8dCONtwZerlQ/MfbtxrXa9+rb70R9h0Z/dO+MmBf8Eu0b/OFvdnc06G9yQr0GkqJjk6hjXP7+nesoKed5/RKUcUWxcQNa+7YdP8A+8f0o05Aml9kprSFrMMS5vuljXLa1yzY2iN8Uibr3Z+0OCvSvd/H28bFTBSFPgzf0WGo/6Rgw74UH7/IfDoPWaqa9p73se73HJsbarMtNu3LMvXHHfb1MfVnse/EOZ07qqI5enPTvnvm5NrqmGNz2vdOCkY9mM+Uj+0RzVnCCJ+Y7GTmRdtGqqSAefTN4331ohBRqTXF7bNIonnt4hYJ+8qRNmo5UB8ov/K3Trh/6OcO+06nt5y279vpYYTVvo8FUzA8nm3383bNPKgBTheqjmwmRxc02//jPDLJvB72YR087C8mmH3I3fTBW41O9SztW0/Ibtgw65DU0I3jq+Mxyk7LY66yWi2jRZF5kC0mlS+1e1SpfjxD/Qvkd4Z40PM7zTNHNWDMfFsKnGkh1HqZp1R5j6HGINSZIytkGm0+Nyl3znYml9zZPvNpP6ddRHN5dqgzha2PtPXPMHur29FPTzMnnSZADZ81TTRPxZHUvhfNWWv/AHqrt7Zt6evAfL8ejTubs202Lps1DhKCATc679ujHhuVsoge9rKmtoigGX4lLGdgaqenQ1lT/WkW61NilOoaWrdF2jzHpvX3h8ywn2J1bJMbTbYPEi9xVSfp4YiKVllO+5oF9V2s2SSyHBnKo557v20LtmfG7KBCy8gW4VXLoqV9k1uPYj6zk8ymM2M8vdPDWG5qcnJd077eT091xr6zi3qucLevb0qxrUQWjV9qxr7pfpMbJfU2x1Yt9h27x7PXvSxjU6OcSU2csa+wrzr69ktzvE9Z7bs9a0rFiKxUc6SLO7ZgGcnyg7BnxWKfJNO+zRdmsL7rwjPY0k1W+05Jo/egoeKHq33VAE0fiNElLR3RaetCTzZ06q6EgqU9A08PdfRhDJ7ko0antkr7lmR1YM3797YOSQ1dxr5ZKbHxkxyrbK6WaFHYV7aYPCFse78P5dYor1YVM/pXOGNfdeaoBqz2levlOKUmq9hXnTmqgifFvmG5dRq1j7nbWHJr+/Q8afY8eXaoMyXVb25ySYJZefbTpd7TzUkX9pXDT/KtVzHL3tkS+/o2W9Ix271t87lx5tqc9lWNq2YR+4Kfwr7zOrI+TVPpYQq9NkgZLzZj/ShW8fZq0dRGX6se2swoRZEGO+XLrJsee57V6UM/l84VL3FVJ9OLxDfbNfMgCpJomtuS2ITTrENWrFu/3gspUEkpMAp5k1nYBJn31SODmA/1pZqu69WM/it6b79Wjzvzvnr/6WbeN5VFTQy1JS5zse90WwcW+bwqusu0b3AP69iq2bcLY50XSS0OcLWvOnr/z83Mg1LYhAHkRXuqOdLg+QnW4+/madqXzQluFMfaBzfSW1jtG+bnPSrFS4TA1a+60QCt9s0UaezT5WxoPB0G1a/7sKMP075qdGqryjyMTWGpU12G5GLfF+m/N6FPEWqVzdUy7etssYVdTlKdABH19nTaV505qgGLfdV6maeUrhbPPHNUBWFfcSXAOybPWHJr++J5s77q7JBnStpk60nZcYT4j53UpAv7yuHnxIh+rfal37uEV2tbPTfPXHO2VeOqWdgX/BT2XebXKY6F2DuREJrGMeMTaYGhs+eMZF5r45pYB3mNiJmbls2O0/V4VieNng5oIl7iqs6sSUKLTvuaBcUnX1sgC8pNTmnt3u8gnf6ft+kDjUKD9BCK+VTmQSVhVdNs0SRbx05sfahtkiP23R5azxn7iqs3w+zJVvuOoCbrRcrMgwgmpX3LI6xjq2bfU4Y6qob66nqoq33l0Yfondzsm10u7JpqjrTDUF97trf6mJ+r680c9p2XNqMBy0ubMZC55H19PPsGzk+g9lztqwZote8sYa2J/YwcppgvMSTVh7KvOTq1Vdm3ew/WeCKz7nCxr1wec5XN1VL2VS02Ly+y6TSzYmu5UXCy077yzDEbsMa+cr2sp5QxCHnmmBWEfbPFqrRuZSy5tX0fevPaY1dnhzxTJq13OSlbx0X3ZGrShX3l8GcVOE9Fad8dRhbHpW1nX+aZq2bbbFw1C/uCn8K+ybZ5dLZOmjeQOdya9ghz3EYk7cuywlw2+aS08N5LUhUp3MhbxUtc1cn0Iut0dNrXLKhez6z11iE93fv1zqJTu2eBUcg7i14P9Vztq5omToWK63AlEZGOvG/T3BKrfVmJfsBi32Q/4yXU1M2+wWOtY7PY97R51Y3U0bht06RNlFSobl/mn2PatyNlEKZQ7CtGTrGvY6TezQbOEj8T7M/FsqlO++7yG3YnC/EbdtrVvo0pgdJ5IiWFXe2rBlhXBJPdmhmjy6SkMWtZbrWv2cdpM/bNsfas7JvsV7VQzpK5Qw19u8W+5iqbT0+bsa/RYsr8ulFLaGbF1uDTzhMoJsN5XqgGjEneS5WNhRDrZT2ljC7UmaMqGLGvMKRvnjH/1vZ9ZtDCtVNnhzxT0iZYT0r6H6dTbBVq0p32zbGcio6rbuRWl7adfZlnrjnbjsaNZmNgX/BT3O8bam9CV2TsjZ2voWYPH2DeeS72jQ9YwZJ3OTZ5hbEKL5KqbRlbFtdIvMRVnaSpm1gxZc8CdXkLkVnQtO+mgtwO1fpt28/77vk7ZKHHWrIVS13tq5pOWMce9+jc4TnxIdNhX5bW2WHf9s951x0R09xi361eIuU6ttzNvkH2ZYzyvmpsFvu2b+u0r8cjzLt1KAuxpVezb/uAZCbzvp33skaRoSwh9wBLodyHGmnmIBb4sHEJsLibN/vcEvvebaM8Liuyp7jaN8W+l6XaA9zv91UDHLSwBetJjYjRJS1txVrE7bHa1+zDGLzI+xqjM7ea9zzsTRwi+zJ3qKEbx2cuj1pl86lo0cj7Gi3eSZaaTDMrtqYPpCt/p5YYDSbOdZ45qgFBarvm3i315mq9rKeUzPvKM0dVEPZt4T+S3ReTbMy/tX2fj/eMbDdPDkqdKXndljDK+6rKzZJYxsIQNelO+yb5dmfF/tK+eUVJDvu6tO3sK+lhWdycbdW4alYcZFV7KAbcYPt21umD/Fy9jiXYzStYOMnDxb7eEx72C5/o2NQ9ek5jD5Lqh/30yN7SFrIOS3gxMtSjM8uMlgI0C5r27bCwX/V+Hx9FV7K9ZaEOQ5d+PMzVvqrpuu10fU5Ihx667uvptO8yvw4y75vN2obbo09vt+Z9Zxuvlxn9m7val65yZ9E9D2psFvse6C/ueZD2PRUzZEA2+THbes+DPHq6HK7ueRg0tHWkKJTXJ7JfUao50k10I4G8v4CNajc2u6/TvuxFCnDZKBGgW+17QKdPzuLOAFf7qgGy+8ZOGkGNGKMLGuv/cSpzyTyoPozd3TLM0amtpn136a2Yy5DMoWcb9zzI5VGrbAb8/T8AAAGCSURBVD4VLRr3PBgt3l2QmCbsa/STMNt/6tjtclJt4p4HOTOqAYNFc/pScXO9LKeUYV915qgKwr7s88jcIevUklva96nj5ReRJAelzhQ2N1KnvKyqnG3TczeZk+60L93zoPdoKy8BJiWKex6kfV3atvS17kW9h7hFQs22alw1Kw4yU4diwH/DXxrX23GZHb1Sf62r43P/z9l7etag/9Z5G3kdlT021aj49f6VJoB9f8HM8vX+da5N8622wJ+z/2GPsV+bfesms4y4FbAvgH0NCvrk/ErX5rF2U37G3jvoAYHs12bfybqt4HMG+wLYFwAAYF8AAACwLwAAwL4AAABgXwAAgH0BAADAvgAAAPsCAADsC/sCAADsCwAAsC8AAADYFwAAYF8AAADXa99pSZgGAACoXZKmaSwsBPMAAAC1S0iYxkqrMA8AAFC7VJVq9D/IpGMiAACgNiHvauJHUAhyvwAAUEskhVRR0Cvsy0rDpv0GAABArTAtrJQp+wIAAKhl/h9joZnlXQyDjAAAAABJRU5ErkJggg==) ### JWT Middleware for all WordPress endpoints[​](#jwt-middleware-for-all-wordpress-endpoints "Direct link to JWT Middleware for all WordPress endpoints") When enabled, **any** WordPress REST API request that includes a valid JWT will be automatically authenticated as the identified user before WordPress processes the request. This lets you do things like creating posts or accessing user-specific data through the standard WordPress REST API (`/wp/v2/*`) using a Simple JWT Login token - without any extra plugin. ``` curl -X POST "https://example.com/wp-json/wp/v2/posts" \ -H "Authorization: Bearer YOUR_JWT" \ --form title="Hello World" \ --form content="Post body here" \ --form status="publish" ``` *** ## Security Options[​](#security-options "Direct link to Security Options") ![Security Options](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAACKCAMAAADBnhn0AAADAFBMVEX4+fpQV159hYweHh5sdX14gId2fob////i5OcdIyePlpyVm6H+/v7s7e/AxMdxeoK2ur78/PyZn6Xz9PXg4+WrsLW5vcGWnKLf4ePw8vOMk5mtsrf19veLkpjDxsk1Oz7k5eecoqdzfIPm6Ori4+XZ3N96gonW2NtyeoJ8hIv3+PnFyMvy8/SQk5XR1Nd1fYXt7u+gpquXnaT09PTp6uz09fZ7g4pZXWCTmqCRmJ6/wsaeo6lud3/KzdC7v8O+wsX6+vqSmZ+kqq+8wMRtdn7d3+GDi5GAiI+zuLxweIDq6+2Ql51ucnSEi5KCipD9/f3Bxcjo6evu7/GHj5XFyc3Z292mrLHGx8jj5OagpauGjZR3f4e0ub35+fnb3d+NlJqvtLmkp6iepKn39/jT1dhBRkmFjJOprrMhJyvr7O3X2t23vMCyt7uusLJ5gYg/RUjh4uP39/d+ho2wtbnLztB/ho3Z2twqLzPg4uTv8fGKkZfM0NLQ09aMj5GboaZweYGxtrpLUFPb3N0lKy/Dx8t5fH9RVVjl5ulhZWjO0dShqK1ye4Pa3N58gIP7+/vU1tne4OOorbIgJirHys2jqq/O0NKgo6Wqra/f4OInLTHm5ueIkJbEyMzc3uHV19rHy8/k5ueYnqTv8fNxdXdAQEAkKS1rcXfk5ulobG/Bw8R/goWKjZA7QUSGiYs9Qkduc3YoLjJlaWxOU1aJkJemq7DOz9A5PkLQ09V1eXvn5+lXXF+Ii415foCiqK3R09OssbZUWVyFiY/AwcNscHJVW2Kdo6i2uLmChYdXW16pq60xNjpzdnnDxcaDh4lTV1qcn6G8vr94foNobnW4vMCan6SXnqOlqKrk5eiVmJpDSEuxs7RcYWSYm5wkKi5KT1JFSk1ITVC7u7uAg4W5u70uNDeeoaJGS04zODy+wMLd4OIwNTl0en/y9PXIzM+NkZTExscsMTWjpqdaX2K0trfj5edYX2VeYmamqazy8/W8vsCSlZddY2pSWF/Iycqqr7NzeYCrSJHyAAAACXBIWXMAAAsTAAALEwEAmpwYAAATu0lEQVR42u3dCVyU5aLH8cc578zTw74MIDBgjAREDgzpgCguqIiAqKDizqggoqCVG4yo2MnM3URLzZNLZu5rHbcyux07mpWdztVstU6rVtbJ7r1nuff6uc/zLrOACWmXg/r/fj4xwzPvO/O+L/Dr5ZlxIJQLzt16FwAANIutuTYeXsL/sz5DAACg2TxTKNfXasOhAABoTrZCXl8bznwBAJr77NdGaG4ijgMAQPNKzCV0Kw4DAEBz20roXTgKAADN7S7UFwAA9QUAQH0BAAD1BQBAfQEAAPUFAEB9AQAA9QUAQH0BAAD1BQC4bev7JBuHwwsA8GvVt+Dk+2vff2NM4wv+8WhfQhawpTjGAAC/pL4Lvz2xt1vD4TRWfuHoV/ObePeoLwDAL6tv1olWf27VamX9YVsdu8gvYvmbUz55YN+upb78k9Xzq9gZazRjhWQ1a0PIH1jfbd8cFjMPXzHu9LtsTyIxnWaf43ADADRW3+9bdSWl//Ntg/Gv2dF/viqau5vt2nGF/RchO1ndgpfaxPL6ttPqWz7upfdEfb8cx+bPfq/dafYqucgOluBwAwA0Vt+9rXgst51oMH7oqDiffZSE1/FzWVsVm9aunL1LiOPv7vX9eoL6rJsy87Cb7SUvsRdxtAEAGq3vn1tpH+pb/o/NjG2fwRRj+JXLYpjXN5z8TZ15IB71zapbaz3NinG0AQBuuL6rj/APW9gkWzl7b/v27T/N4Fc+IiT879MYqyY7lPoe1uq7n70kVtrP9rI0HGwAgMbqO+CdE63eeUd8mFrvlnJ24Ggbti+LT/fu2jl7x8dr+JWP39pxMNZ3LVuwe0u9+vIaz15N+KQvY6/jYAMANFbff2ulea7eLe9u+4Lt+cMT/DUPf5u/r80r+/kTcJP4ax72FZB/XGCvvFWvvjN2MfHEHBnHqsJxsAEAmlLf57LirlHfG7NTmYEAAIBG63uWfP4r1XfI7HFbZuBYAwA0qb7/aX3uV6rve+zCJBxqAIAm1pd8+6vNPAAAQFPre+Kd/0Z9AQCatb6vOV/zUIZjBACAd1cHAEB9AQAA9QUAuGPquyJEvgiXgknnAGVIu2xId0+T7vMx/wZDRsO1FxWPW8+99zR125u+JABAy6ivPdnUsL5d4kmnjvw6v7y5+hZWEhITcKP1rejQhIeQN7RJSwIAtJz6tpVGbGhYXy1qP0/X9JPNG69vkzSyoQAALbK+c+0hol5D1yV4H+P1HZ2sGyDPPDwuSZJBnnkI0Jlf4++po4+0Z/coIUNT9KlFwVp9E0f3kxKWk5Ljqckv8Ldvz7LXZvQkXoP4SXMUXyMkIpvPPHTl93R/ZihfOv+yUt9OcXGd+Bu7e5v7dRKfrrAHaY9rDUrW+RHS02vTzLKJ8nyCdtWobqCgbJHRUGSf0okoGypmHrThEDFMBkVlZIzEdwQAtNT66jpV9/IlpimrrN1yQsgAffxjUcq8r3xKyS9/ZygtsJ/jLc0zmezTyD3R1viyUK2+E1OfTuxwnlRGFT/mPZp0WDzValriqm+6SZ73Fee+g9YRUq3McRgzVhVcTvAlGw45LpsvEaPE3/VSe9y8Y20nZi8nPaUkMqtMqa9y1aQbae1iVuqrbpFRmkty40qVDeVLOocjyQS9L6ldGPwd3gEeAFpqfeMzwkl+BZlo4Geu6SEkvYIX1bO+6X0I2SiFE30SIZHH5ZUGeGv1LTbMSuQXIwYTcklHAuzyzc76ziLO+gYnnCdXFykzD9J3hDw/S77euYJ/aiPa4xoX8z6HjiU9+dolvUxyfZWr8al86TlKfdUtkleMXOWsrzbciw9HzUpM6GbD9wMAtNj6pvCz2pH5pIv4N3CrQkj+NEKsnvXNF9PC0lCif5xPUywibYN0khTlnPc9XpbR0RouyciKVZ71fdxVX5IyNTFVeQrPmKwsU5qeLPHzVHkaWH3cGvl+7KTn/XysV65cX+Vql+H8oodSX3WLjGZ+ERrmrK82bFDufkNURhnOfQGghdY3OEHunXGigZ/CduTnvl0JuafeuS9v5xGpnVbfOceMpugot2fdLkUVkZzz8tWAPPmiYzQhfvXrGz+lNI64nnXjedR3OpI4TK2v+rjFqcoiDesbr26gfO6rbJFRsvL/Yyxynfuqw+rdE+K7Kh/fEQDQMuv7O4OYis1bYZoSTVpn8Hnf/PDEOUp9a3qblHnfbAfpcY5o9b3fjyR6Oes79D+IbVMIicx0kOAkUmAuJXzeN2Qssea71Xf8MbGobmCkZ30N54nVoNZXfdzEqNGJJLf4GvU16eaRan913lfZImPGudya2uXKhop5X3VYufvw5fz/ButI2/H4pgCAFljfdDlOl0eUDH0+P+p+8ZqHKf0ilfqaBqqveQjVmec846zvpdSIsCJnfYuz+UTBMySxz5SEmXMJeToqh7/moTDIK7/Irb7GERJPaKR03rO+8+LsMfer9dUe1zFMb4iouUZ9iXGgZF80WrkHZYuMhoqMyfzFDfKGitc8aMNKfe2SpHuaTybjmwIA7ux/aTxv3U3fxaZo0oTXDQMAoL4uwesG3NT6xd+Re5IdqC8AoL6/SE0O/5caN2OulDF8PUF9AQD1BQAA1BcAAPUFAEB9AQAA9QUAQH0BAAD1BQBAfQEAAPUFAEB9AQAA9QUAQH0BAFBfAABAfQEA7oz6AgBAs+P1pQAA0MxQXwAA1BcAAPUFAADUFwAA9QUAANQXAAD1BQAA1BcAAPUFAADUFwAA9QUAQH0BAAD1BQBAfQEAAPUFAEB9AQDg16nvg8/+xs2zD+IoAQA0R32f/Yv7Z395FkcJAKA56vub634KAAAtr75t2CTlSl/2aGPLfvDKFvZmo/f4E3vE7W4BAO7g+j7MhDM3Wd9lj7ArljVNq++2tO0/d/vLjPni6wgAd0h926SlpS29yfo+xdiMJmyhXN/rQH0B4A6q72b58reMvX2gagE/f+37Mas686Nc351Xqj69qNZ3Y9+DVa9okws/plWxXa/T9u/XsTYLfqBD5BPoAp8xB/bt2tFOWWQMGzf7gXHUtPv9tZ++7UPpmw9XHbVoMw/1byw4vKfur6t/ku/mye4nD2xh83+PLygA3P7nvj+K+n6x41O2jdIDV3bzAH8gMrlv73xW97Jc343fsP2fnWZKE5ezgxbLo59RR9W2Fz9kW2JjTzK2w9L+Rbbr5BW2QKvvli+WvtH9FJv/1lfsIzqDB3XzPld9PW488jXbtePDpTNeYmy35Ykv2SmLZf9qfEEB4Paf990t6vs5ncS+odTBRw+zviKTs3mL2WdyfXeKueH32H55pd+zPW++PIpP97bnn+xhY2gsY7+lJXXsVbqsir2s1lekejsrb8cX/yt9kX1C6T9d9fW48Xs2jlAars48fMT2Dynuj68nANwpMw+x9E+snNK3P2zDe5wmMvm6mHXYJtd3s1xptktZi5+ksrVv04dOnqni1yxKfdcoi4i15Poe5B9fV8fWvCHOiSe56utx42b1hFmpr+MMHzv4A76gAHCH1Pcpub6vskfe/mGbUt+3KP1EPfe1sE+HcD+pq1n/18KYbScbt3rIHq2+y8rZR3yRP67R5n35xyGs/CIf+4DPSuyh/ATYNe/rfqOFtSmhtB0tZayDWDd2e182H19QALj95333u+r7J7b2J0uVUt+qvadYXalc3yPfsL0WyxnlxQ9PfGixHGblJW+xTy4edp770tls12zLyY+fcqtvYBo7Y7H0HUdnlLO9s/d51td5I5/3Pfr9gqXUyviDPPXlZosljZ3CFxQAbv9539Ou+vrwOYb9m5X6fpnGLryqvubhqTf2PPLwlQ/klTZ+WMfYA5/TCQfY2s8edtbXZ/X8fW1ObWvnVl9qmv3J2gfSdvPXPFxgB3Z71td145E39tSxnaLffEL4TbFNR+PxBQUA/EtjAADAu+wAAOAdJgEAUF+8uzoAAOoLAID6AgAA6gsAgPoCAADqCwCA+gIAAOoLAID6uukeY/a+/hIhkfS+6yxyyYvSgY+pn1TG+f/ccrrWP3c3JVJ3Oiy0hX5NGtn7BiYkXPfmmG7K5b2taUoonaAerQn++OYHuPXq61/MP4Tm3ehj1gw3Nd4f4+Vr3RAtVym9lNKVMcpI+5wO9Mbqu/Dpa90y1rPJca1vcCejvelN1Pd6e3+j9e3qEPU1BSg7JS4B4A6rb7exTejPdZq2MZX/VbfuZoc8cnccvcH6XlvLqO8vus8m1pdLCb25nQKAFlJfW8pkaXIJbR+TrJundsCHrkrmCetK9cft2UXan/pRF/SL8o9YQiskSepGp/Xz9w5Wb25rCPGao40UzEwIe0H+3dtjOLhzspRyN1/VQAOGiZW8O4mPWXwkiIbqzMMSKdVH2rPFYGBIP3OQ1b2+fnmborr1H52avIJvUmWybpAy8+AxXFPWa8SlbuL+fCp7SwmDxXpB8rYOHl5rz1W3dLzX9Gj1/pT9DkzYyHcwJ1zbUP1UsePKlgqFmf69k/gaXucihl+i2sHyywuKGp6l7L682Q323mPYbe+5iiD+4eoKmteF0oURcn2VR6XUGOE/cI26rnK4aUyPmf6Z7d1mHuSdEjMP6rZUey+WwvCjAHAr1bfCewJt3Z2m97BmZcuxoqnVNHt6WxpXTfWZgYGZleoK6oJdq4Mr9IG0Kz/3fXpyafu5EVp9pT7OkcDpRcEDcpT6ug33n3muA12inP11HilWuvqCvK6Rn/teNswo9DpLxWPKY90DcnNjNnnUV+J/vD4g4sEJYZV0kL54QoRaX7fhpMXTurcrkM99s1KNPo5c52libq2f7XjqKG1LHXEzlBXV/V40l99/pnOP9OmBgV6HnOepgdnH2l/OqeZrDKaDk23aSn5SPF0/XK0v3+yGe+8+7L73Iui13amPPsujvsqjJhoGBNeMCFaOhHq4YxbPCj9nd5/3FTslLtVtyZxr8ynGjwLArVTf0JkFokiL+U96txT5lmGhtuxIP3EKrF9P6fp+6grKgrJ7jXJ9Y/6dv7G6wVer7zLnSJaBn8FlqvV1DVcnjHL+7h3WU1ytHOasb2YFT6SUKD+m89dxs0d9RehH8FPPoTqa2VWcMiv1dRsO6+OceXjQsN7HbeahIpNvQmqSc0unviCvqO13/HRK7Sude6SPp3TuaGcps8x8qbEh/ESUfxIxTVtJ3EH/Xsr/LMRmN9x792H3vRciLtPBqdSjvsqj+nXkt54d5DoS/HDHFPE/wCSFN6yvti3eq2z4QQC4NeqbPJF/COhIS+bozON9kiTBS5mZPFezqrTzStGOav6n1pLVFZQFeYFqJWm9XN+B8kqDtZkH6hxZKE4Ii9SZB9fwod6umc8U+QmjkKvO+pbV8CtSAdXfrdxf/6v5vSSpv3t9g8Rcr4yWHeK/c6v1dRseXuOa9x09PMO7vbO+43m+aN4AeUt502nPc/KK2n77jKh21JY490hsxMgezlIuFBs+8jXqJ363P9dTW0ncAe2lTF2LNRruvfuw+94LncJoj6me9VUeNURevo9yJNTDHSP2yBzbsL7atrTNS44bhB8FgFuhvmXR4jRX/Obvs37ywupU1y0dEoo2lMQd4z/veh6zmmznDWLBAvPgcDpFqW/YPLf7kzOrjmQZ+Gmnt6u+6nD14mXO/oQq8773uc59+eP5SqOc9Y2eWZ1obVBfmqNMJmTyZ6Fau+qrDYcFuD/rNjRivDKVIs59xX3o1HNfHuWiHvKKzv2+GtlzjmuP6tU3y8z3J4Wf+4qA9u6irVS/vg333n3Yfe/lefQcUzLfau+VlN7nUV/l0Cifaoc7hu+JTXK41TdVqa/rCzcqulcwfhYAboH69hloornmeJploo7ppT4RlT7Uob4H+2T+UoTnzeJ5n96xd2dr877Kghvv9aFL1HPf9Xx22CfJvb7qSOCUlXRjhqu+6nD/dXxiYAlNyue/LA+N44laZvZ1zftmP0SLzlJnfbvxBvVpWN+pHU20ezy9r6zE5zW3+qrDSfdaKZ/3Pd6Dd6sDXRakvPBg3TQRqrtpTar8Iom2GWcds2oHyys693tNatQh1x6pHZS3VMz79htAJyTHUr+MkbY+ySZtpfr1bbj37sPuey/r2FmcJEemUFuZR30dk/kWDLXKn2qHOybVQSs95n2VnXLuwPpA2jrnIToyFz8OAC29vonn+G+s/DfflQZJWkHpQ4v0Bvss5aYYHaXHc3gd9X6GxUVaLNQFX8hOH99PqS9NGpgzPMi9vtpIwcyyiCBXfbXh9jFmKYUGrhPP+vfmr/fdYKfO+tKeOnPnEld9Rw18Puwa9fUJmJ4QxZ+xq5zSb65bfbXhaWUSnwJuO0IKqs6WJHuJvGJNBn/Nw5KyWnsHdUu7ZkyOVu/Pud+pCYGuDVU7qGwpV5juL7bXb1OMVLbGuVL9+jbce49h970XNkjiFN00J69svEd9aUGm/5T0XGVd9XDHTM3PyAx3r6/YKXGpbsv4DKmWn0XnrMePA8Dt8G/dtBL+f5jIJ5nL/iV/8Kit4UbX9AvCNxsA3Or1/ddBfQHg1qhvjU6I+LmFGrkZ9QUA1BcAAFBfAADUFwAAUF8AANQXAABQXwAA1BcAAPVFfQEAUF8AANQXAABQXwAA1BcAAFBfAIBbsb5bA3EYAACaV+BWQnNLcBwAAJpXSS6hNiuOAwBA8/K1Ef6Xxxw4EAAAzamwkBJxYS3B3C8AQDMJLPEtpHJ9qS13610AANAstubaqFpfAABoZv8H0iA66W6aYLsAAAAASUVORK5CYII=) ### Enable safe redirects[​](#enable-safe-redirects "Direct link to Enable safe redirects") When enabled, the plugin uses WordPress's `wp_safe_redirect()` for all redirects instead of `wp_redirect()`. This restricts redirect destinations to the same host and a configured allow-list, preventing open redirect vulnerabilities. Enable this option unless you have a specific reason to redirect to external domains. --- # CORS Simple JWT Login includes built-in Cross-Origin Resource Sharing (CORS) support, implemented in compliance with the [W3C CORS specification](https://www.w3.org/TR/cors/). CORS controls which external origins (domains, ports, protocols) are permitted to call the plugin's REST endpoints from a browser. Without the appropriate CORS headers, browsers block cross-origin requests for security reasons. Configure CORS under **Settings → Simple JWT Login → CORS**. ## When you need CORS[​](#when-you-need-cors "Direct link to When you need CORS") Enable CORS if your front-end application lives on a different domain than your WordPress site. Common scenarios: * **Headless WordPress** - front-end on `app.example.com`, WordPress on `api.example.com` * **Single-page applications** built with React, Vue, Angular, or similar frameworks * **Mobile apps** that enforce CORS in their HTTP client ## Settings[​](#settings "Direct link to Settings") ### Allow CORS Support[​](#allow-cors-support "Direct link to Allow CORS Support") ![Allow CORS Support](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAB0CAMAAADuBmGdAAADAFBMVEX4+fpxeoLl5+mLkpgmNURsdX33+Pn////i5OcdIyfz9fZQV17x8vS8wMR4gIfDx8s1Oz7n6erk5ujh4+WPlp1weID29/d2foaQmJ7v8fK6v8L19vclNEO1ur5KT1Lf4ePb3uAkKi7Z3N+ho6YnNkWepKqZoKaqra/y9PXU1tns7vCCipGgo6Xd3+HW2NuIkJaTmqCxt7uXnaTFyc3n6et9hYw+Q0ducnT4+PlBRknr7O1ud3+Tm6B/h4/p6upDSEyqr7V5gYlXXF8hJyvBxMivtLrt7/BfanWEi5KprrO+wsfv8PGzuLycoqfs7e88Sld1fYXt7e47QUR7g4qkqq9KV2Ous7j8/P3m5+nP0tYyQE/V19h4foOChYiNlJru7vDHy8/w8fPJzdDR0tPR09a2u79ARUmmrLGCiZGxtbmNlZuAiI/Lzs+4vcGUm6KKjZApLzIpOEcwNTmNkJLk5unM0NMtMzeYnaOdo6iRmKDN0NJ1en4zMzNTWVx8hIsnLTFZXmGKkZczOT36+vrDxcfo6uxzfIOhqK3X2t20ur5SVlnO0NK9wsZ+ho1mcXuusbPJy8x4fH9wdHg8QUZna27g4uQxP00eJCiZm5t0fIRSXmptdn6FjJOkpql7f4Kcn6FPVFdXYm7BxclMUVTe4OJPW2eurq4kJCS+vr7AwsS7vb9vc3WcnZ3X2dovPUwrMDTS1dbm5ueys7NiZ2zp6+2gp6xye4PIzND09PXDxsqztreQk5VbYGM4PkLAxMissLbGy87LztFWW16+wMJfX18sO0lIVGFscHOHj5Wjqq9qdH6Hio2mqKqEh4pHTE/HyctbZ3Pa29zp6+zi5OWQkJCNjY1dXV1jY2P+/v6sr7FobXJaZXBxdnmgpquVnKN+gYSlq7JgZGdhZmm4u721uLqSlpheaXSVmJpmZmacn6Tj5eZeYmY4RlNATVsgICC/v79WXGNzeHpTWmFdZGqfoqRsdoFDUF1ibXjCxsskM0J+hInEx8mnqq2ytbZrdoCBh4s/ebliAAAACXBIWXMAAAsTAAALEwEAmpwYAAAPaUlEQVR42u3dC1xUdd7H8d/ImTn9ucodnEIgQFBRMcELcg+E0IlFEsVwwUALSrmJkrqpqXnB8lbe75hteWkLNdfsolmuZdnaZdtuT9pl163dZ+/Ps/s8+9rf/5wzwwzRq9yV2V38vl8vYc6Zw5wzM7w+/v3PmZFUAABwP5Jfnmlvug4AANyiqd3TqG9eJQEAgNtUFmr1zfPEQwEA4E6ehVxfT4x8AQDcPfr1JLV9BB4HAAD3GtFOahMeBgAAd2si9To8CgAA7nYd6gsAgPoCAKC+AACA+gIAoL4AAID6AgCgvgAAgPoCAKC+AACA+gIA/OfWt7foRzeKkXgMAQDcUt/fCrH+u9b3vRWL6nbOtBG9ub44qvjpA7wqQgixKLvRQuRfnnFfxgfbjE1dl76bu4WYiOcQAHpifVcu6bwmr06IqInfrb5zhajbeUjcTX+NElER/OeHsr6LTjYL8RBRtsiJyH59hbGt6xLqCwDXdn3venpQpzXbRMM68YVzfW3lI+/LmOlNfxA7KX2DSKcVYoe26Y+FKI8nWhzoOVJE9KJeO0VKPNf3CfKuE43kmSNO8UYX9JvtWHpWlBNNEwNpoEg5l9K8No8mC/FZRN2CaCLLjXvuK157Qe781ey67ULagWcRAHpIfRNvv30O0cTb2c+9/rvV9coVYs05keFU3/j5onh7b/ErywGxwcbBfciWIyZrm74iTli1C1WCtyX6f8HDYFnfJzeIS0SLRPZnp2z223UsPStetddXTFvTzNMcXN+GNSnihI3KRd3cCHFiIu885+TaG9cIca5xNZ5FAOgh9U3w8vKKJA8v3VyX//btgBA/XCnE4o76nhKiFz0pxL1ULC593LBo++PihL7tHvEJ2QfBd/O3yXLCQc77iig5eK7KlhfXGDfsWHKqb44/XRIinX/uU7JFiR97bxBPkbW32Mg7fxYzDwDQ82YeIr3uSfD6i5x58JptdbnmY9Hbwm1c21HfbeIQkbfgLs4V5yLWr3/9VfEBGWPfDLLPz/JYV3b6DTnvu2eDmB8v109+fC3H3H7TxpJW33VafYu1Yt/Bf96U+9vxplbxFWI7L2xDfQGgB877jrOs/V1f/t7nZtf18c3aXKuIynMe+0bSajn2fUhkiP07xEjxnmPIO1Ob981rEDt53neFaLZpMw9v5Ig/EPWT5YySr79JjqWLPADulWMf+z4kxE+1se/lHB77CvF/FN+gjX3lVAYPwi/jOQSAHvWq2yWv2V2tfk+I+dnZPEkw8OvzvvRTzvJKnuMVAdRxzsP8FB6vnjLOebhEWn35rLXe3pQjdmb3FnWJ+raOpZniUKO2g4EiakHjOn3eN4NXFYc7z/vK+voL8UpjG55FAOg59a38/e8Lu1q/QMyX354We5zOeTinn/MgJ3obLNQgIpzP9xUjtfN9n+bzfS9OJqO+bTniOL328+YNKa+sNDZ1LOXNbWiemaLVd9prhw6ttcn6frouagHPPli27YkqfiKQjPpyqeVkBgBAj6nvL70+HSQnZPv8C9vG9dUvcH0xwAWAa6K+fX/3gcV3LmmvuoWgvgAAbjvjrIqHv12dcYb6AgB047stfknUvl1/t4UPHiUAgH/9O40BAMANn7KDdzMAAODT1QEAUF8AAHB/fWNvoJtHX51jaDJ1dfHfzb2Dv7bqB9H4BQIA99V3yibr1a1vYVJXF69I6xCXxXE3uF59p19I8DIiP7P8kpZp1qzSr0swj+WvNrN5ywA+u2OA3xXUt9rx0fOXTfhVAoBurq+/2feFq1vfq+Bb60tBy4keWCW/HOYVfTw6BvG+tVp9h3nuTp16ZfXtgPoCQLfXN2lK5pCO+iZsDZ4SwBMGFjpcxNWr1jZJnBKc6kM+QR8t7DMszDRgFn9i5ZAj5hmUF5tlzqo0xo3JS+d4U2BoQU2cnG4IHGwa8kCmNvPgO2FKWon+BjvtJkKeH180nZcnFCWPNcdT0E1EUzmekR6mM/wv/5s8UlOXt/FQNtSSO8BsSpA/1ocXhxqHZq9vEh90rYx0mp9LfeNNs1KjtfoSBWXa62vsMzA0c0oaf7p8ZZxpazXX17dAPzT94OXMQ9yHQVtb2imU99im30kAgO6pb3Lrw1ts9voGBPvkFYz3pvGRlLYqkLIi5RZLjuTmWaPJx5xA1toPbX7BkRQ2odAyiMaObqJo7YN9yS80YVjNbAo052qTvdbk5f2nbjLqG2S11ryo15dvgpI8optm5NJu30EBCzvq6x3a2v+ob38KnhUfH62NfZeNj7QsCXCMfe2HZtQ3wWTJy4pfaskzL3Gpr994y9ASvb7DeFBv1NfYZ6B5Ao3ytVHsQv+ELFnfMKs1LNd+8Fp9s4bR89P1sa9+JwEAuqW+g1IrKb/aXt+xYfy5Y+PvpTnVebWZPnIILIe1NXo6uXDLlvIc8bgCGn04T14x+IL9ZsJ4sjXA7B1o9tTqO2g8r4sz6lvF49znHTdBvjxZ25ZMYbzTZR319Wnhq2bvtphaPY2Zh+jQKovTzIP90Iz6hqRGV8TRmeiKH5BLfXm8O5Unsm1yJjjOYq+vsc/ALXzjHpMs/PcHjZX1ncT/B8ed9oPX6juB1yzU66vfSQCAbqnvhzzmW55vr+/0n8iAtdItM44enjTumD77qq3kdA7lTN4pB5LjKDCoKGs3/wM+eel0i4/ZPIXyK/gK84XAUNLqO3Urfy8x6suf6ZD0gOMmKvXXyCj/RTlCddS3QFubSy94pG7Vx770/NbUITZHfe2HZtSXplSX+FBBdckcl/oOM7eR1TRVn3kg+6tu9n1qhxd0U6E5nKhC1pcrnLjJfvBaffvwX0hpen31OwkA0B31jTdpXQq0j31l9ZLv5fqU+FVmfai/2FUd5EjnsqU8HI0t4CXv1i39eTBalTVVH/vyphN57GvUd1Aobze6y/pSsD6bEMadi+b6jj5G9JwHVc+xH5LtJ/l0i979RI/pHWNf49Ds9Z0wI7+NXpyRf4tLfZO0u/NRp/ra92nU1xLMh3SDrO9RrnCa/eCd6hugv+qm30kAgKtfX79QebpZUIF93tfURkfH81Ru1qYlNHiTfv7rsE084RutpdNa20pNRYk0yUrRweHLCql91ST9dmrDqWQ22etrTfajh01d13dCSzjFV9Hu/EpLLNc3M5by8j1oSRa/mJfoX5kgJzRo1gArXbhMnkMztZ8r4B93HJpR36oj/LJg3hHzZZf6JldrsymFnepr7NOoL82JpfBaWd8BiW21d9kP3qm+lVt4Nlm/k5QUgF8rALjq9Q2T41g66htiP+chP9hD9iwumZsXbMy7Rnpo5zzIdA4LMg3g3k5PNZuO0TE+NaDEuKF7kpeOq3TUlwLPmGseuKvL+lrGrjIt5POAc4tMN3N9C+OC8qdzPC+HmVYFBVTWmM3JkWQ9Yw6NTOMpDf2Migu+8pwH49CM+sZvkYPh2iJyru8yrqVsbp9O9TX2aa9vZVztgBJZX5/QIyVW+8E71Zem8zkP+p2k4Cr8WgHAf9Q7jYce+7YtKs3x/9At+066Okfoi48ZBoAeVt/IeIouCu+e+ob4pbajvgCA+nblLnPqmQTqnvrOqb2ZUF8AQH0BAAD1BQBAfQEAUF8AAEB9AQBQXwAAQH0BAFBfAABAfQEAUF8AAEB9AQBQXwAA1BcAAFBfAICeXV8AAHA7rq8KAABuhvoCAKC+AACoLwAAoL4AAKgvAACgvgAAqC8AAKC+AACoLwAAoL4AAKgvAADqCwAAqC8AAOoLAADuqG+Ix+ayR/YOpm7dufXtd+bNe+ftEXgaAAD11SXVXy/Vx2R2474f3bf/N+npj+3f9yieBwBAfaWhZYrhYFy37fq1X9gvvYv8AgDqyyY8ojg8Mra7Rr6/6Lj87lN4JgAA9Q2p5+o+OMvbe9aDfKH+/i5/MEaZ2HnVGCVXv6Ao/i5XPKfc9rWft+5zXtr37XO/wwfq31PucF77jMCsMQD0lPoGnVaUs/rFLJ57GOJ01a2K8uVtf4vmS5+ft/1T9X17v/PSxrc6Ln9PSPtRXwC41ur7/vWKMkm/+D+Kcv37LvV9eW+MUt/a5W1dUX3f+Y3z0mMvOdf3Rxj7AsC1WN8yrq+3fnEU17fMpb656qjzylel2szDR5vrlTGFas1ppezzClnfhbsOjvHX62sruvWRBy+rat7Zg5vDuqjvvHTnpfR5X6/v8DXP7rnIW22bX3dyNS9un1/3yfe0+t4/s7ihvFRVjzek9EN9AeBaqa/aVw6Nub4vKptbwt7vq5reH3xWOT2K63s69GVl889kfUNeVv6WdvorUv+sfJV18B+r74mJ6sxyVd3x5Pc39iZ1+KHHR61foNX3i+w7AtcfV/v1Xv3wSdQXAHpMfXd1zDz4cH13da4v19VH1vcmZUzFBV4Mlz+j3MP1bVGtp5VEWd9qZbOq/lFJsilKXzWuq5mHx7555kE6pQ5vVNXFJ/V1655Uh3/MfxmIUbK+i1aq6oEU9ZMdqno36gsAPaa+Ndc7XnW7jesb9k1j31J5SsTeXurYMV/yhf/i+mbKLV6Q9Y3Vz1cLWqYoqtrnCl91+5Fjond1Bs88nKwTYrE6nFurNk/m+j6j5XmDGnFJboz6AkBPqS/FOJ9xFlPaqb7Dziu36vO+asDuz5UW/5j62Bf2avX1UMNj7GPfP1VUVDyXwGPfh7sc+47Y57z069JvrG9i8xuj1GlcX56EKBTpcuwb1Vfb4BPe4A7UFwB6zrstcp3ebVHm8m6LjnMeuL5+Z1ta9ipDeyn1NwyO0ep7UM77qsa8b1FL0JcV6ufKrpayLurr8m6Ll5zfbdGpvgfWlaqr5di3OF09rs/7Nl6sVEcsVvtFPPOzJ1BfAOhJ7zR2xDfmsOpaX37329lo/d0Wibt4yeSthikxpvNafWP31jvOeci69eDmPweqtgfr/zS4q/qqj76rdvlOY33et9wx8/Bxxq/KX+f6NkZEXRyl1bf0i5GH5n/G5zxMe/046gsAPelTdpbH/K/8lJ2ymAnduO+n9m18jD9lZ+Ov8T5jAEB9DffX7CorOz+jtFt3PuKtl+bNe+mtUjwNAID6AgAA6gsAgPoCAADqCwCA+gIAAOoLAID6AgAA6gsAgPoCAKC+AACA+gIAoL4AAID6AgCgvgAA8M/Vtwmf8AgA4GalTaS2h+BxAABwr5B2Uj1teBwAANzLZiX+n4LD8UAAALhTYaFK8lv/EMz9AgC4SWmIrVDV6qta25uuAwAAt2hqt6pGfQEAwM3+Dqre5hP74JKZAAAAAElFTkSuQmCC) Enable or disable CORS header injection on all plugin responses. When disabled, no CORS headers are added. *** ### CORS Headers Configuration[​](#cors-headers-configuration "Direct link to CORS Headers Configuration") ![CORS Headers Configuration](/assets/images/cors-headers-configuration-e3f9c48ee871494d4e1f8d564f4adce9.png) Enable each header individually and configure its value: #### `Access-Control-Allow-Origin`[​](#access-control-allow-origin "Direct link to access-control-allow-origin") Specifies which origins are permitted to access the resource. | Value | Behaviour | | ------------------------------------ | ------------------------------------------------------------- | | `*` | Any origin is allowed (permissive - suitable for public APIs) | | `https://app.example.com` | Only that specific origin is allowed | | `https://app1.com, https://app2.com` | Multiple specific origins (comma-separated) | Default example value: `*` [MDN Reference](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Access-Control-Allow-Origin) *** #### `Access-Control-Allow-Methods`[​](#access-control-allow-methods "Direct link to access-control-allow-methods") Lists the HTTP methods permitted when accessing the resource in response to a browser preflight (`OPTIONS`) request. Example value: `GET, POST, OPTIONS` [MDN Reference](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Access-Control-Allow-Methods) *** #### `Access-Control-Allow-Headers`[​](#access-control-allow-headers "Direct link to access-control-allow-headers") Lists which HTTP request headers can be used during the actual cross-origin request. Example value: `Content-Type, Authorization` Include `Authorization` if you send JWT tokens via the `Authorization: Bearer` header. [MDN Reference](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Access-Control-Allow-Headers) *** ## Recommended configuration for headless WordPress[​](#recommended-configuration-for-headless-wordpress "Direct link to Recommended configuration for headless WordPress") ``` Access-Control-Allow-Origin: https://your-frontend-domain.com Access-Control-Allow-Methods: GET, POST, PUT, DELETE, OPTIONS Access-Control-Allow-Headers: Content-Type, Authorization ``` A wildcard `Access-Control-Allow-Origin: *` is simpler to configure and generally safe for JWT-protected APIs (tokens cannot be forged), but restricting to your specific front-end origin is a good defence-in-depth measure. --- # Dashboard The Dashboard is the first page you see when you open Simple JWT Login (**Settings → Simple JWT Login → Dashboard**). It gives you an at-a-glance status view of every feature in the plugin, organized into four groups. Each card links directly to the corresponding settings page. ![Simple JWT Login Dashboard](/assets/images/dashboard-63f724b74b43917d69c34903009ef0cb.png) *** ## Routes[​](#routes "Direct link to Routes") REST API endpoints exposed by the plugin and whether each one is currently enabled. | Card | What it shows | | ------------------ | ---------------------------------------------------------- | | **Login** | Whether auto-login via JWT is enabled | | **Register User** | Whether the user registration endpoint is open | | **Delete User** | Whether users can delete their own account via the API | | **Reset Password** | Whether the password reset endpoint is enabled | | **Authentication** | Whether JWT generation (POST /auth) is enabled | | **Refresh Token** | Whether clients can exchange a refresh token for a new JWT | | **Validate Token** | Whether the token validation endpoint is enabled | | **Revoke Token** | Whether clients can invalidate a JWT before it expires | *** ## Security[​](#security "Direct link to Security") Access control, CORS policy, and authentication codes. | Card | What it shows | | --------------------- | ----------------------------------------------------------- | | **CORS** | Whether CORS headers are being injected on plugin responses | | **Protect Endpoints** | Whether REST route protection is enabled | | **Auth Codes** | Number of active authentication codes configured | | **API Keys** | Whether API key authentication is enabled | *** ## Configuration[​](#configuration "Direct link to Configuration") Global plugin settings, third-party integrations, and WordPress hooks. | Card | What it shows | | ---------------------------- | ------------------------------------------------------------------------------------------------ | | **General Settings** | Links to the JWT algorithm, decryption key, input sources, and global options | | **OAuth** | Number of OAuth providers (Google, Auth0, Facebook, GitHub) currently enabled | | **Third Party Integrations** | Number of third-party plugin integrations (WPGraphQL, Two-Factor, Force Login) currently enabled | | **Hooks** | Number of Simple JWT Login hooks that have active listener configurations | *** ## Monitoring & Logs[​](#monitoring--logs "Direct link to Monitoring & Logs") Webhooks and audit logging. | Card | What it shows | | --------------------- | --------------------------------------------------------------- | | **Webhooks** | Number of webhooks configured | | **Webhook Logs** | Whether webhook log storage is enabled; links to the log viewer | | **Audit Logs** | Whether audit logging is enabled | | **Audit Log Entries** | Links directly to the stored audit log entries | *** ## Quick start[​](#quick-start "Direct link to Quick start") If this is your first time setting up the plugin, start with **General Settings** to set your JWT signing key and algorithm, then enable the specific routes your application needs. --- # Delete User The Delete User endpoint removes a WordPress user account via a REST API call authenticated with a valid JWT. The user to delete is identified from the claims inside the JWT. Deletion is **disabled by default**. Enable it in **Settings → Simple JWT Login → Delete User**. API Reference Explore and test this endpoint using the [interactive API reference →](/api/v4/delete-user.md) caution Enable "Require Authentication Code" unless you have a specific reason not to. Without it, any holder of a valid JWT can delete their account. ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `DELETE` **ENDPOINT**: `/simple-jwt-login/v1/users` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/users&JWT={{JWT}}&AUTH_KEY={{AUTH_KEY_VALUE}}` The JWT can be passed in any of these ways: * Query parameter or request body: `JWT=your_token` * Authorization header: `Authorization: Bearer YOUR_JWT` **PARAMETERS**: | Parameter | Type | Description | | ---------- | ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | `JWT` | `required` `string` | A valid JWT identifying the user to delete. Can alternatively be passed as `Authorization: Bearer `. | | `AUTH_KEY` | `optional` `string` | Auth Code value. Required only if "Require Authentication Code" is enabled. The parameter name matches the **Auth Code URL Key** in Auth Codes settings (default: `AUTH_KEY`). | ## Request[​](#request "Direct link to Request") ``` { "JWT": "YOUR_JWT_HERE", "AUTH_KEY": "SUPER_SECRET_AUTH_CODE" } ``` Or via Authorization header: ``` DELETE /wp-json/simple-jwt-login/v1/users Authorization: Bearer YOUR_JWT_HERE ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "message": "User was successfully deleted.", "id": 1 } ``` ### 400[​](#400 "Direct link to 400") JWT parameter is missing or cannot be decoded. ``` { "success": false, "data": { "message": "JWT is missing.", "errorCode": 42 } } ``` ### 401[​](#401 "Direct link to 401") JWT is invalid, has a bad signature, is expired, is revoked, or the auth code is wrong. ``` { "success": false, "data": { "message": "JWT has expired.", "errorCode": 14 } } ``` ### 403[​](#403 "Direct link to 403") User deletion is disabled in plugin settings, or the client IP is not on the allow-list. ``` { "success": false, "data": { "message": "Delete is not enabled.", "errorCode": 39 } } ``` ### 404[​](#404 "Direct link to 404") No WordPress user matches the claims in the JWT. ``` { "success": false, "data": { "message": "User not found.", "errorCode": 24 } } ``` ### 500[​](#500 "Direct link to 500") Internal server error. ``` { "success": false, "data": { "message": "An unexpected error occurred.", "errorCode": 22 } } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X DELETE 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/users' \ -H "Content-type: application/json" \ -d '{"JWT":"YOUR_JWT","AUTH_KEY":"SECRET_AUTH_CODE"}' ``` Or using the Authorization header: ``` curl -X DELETE 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/users' \ -H "Authorization: Bearer YOUR_JWT" ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $simpleJwtLogin->deleteUser('Your JWT'); ``` ### JavaScript[​](#javascript "Direct link to JavaScript") ``` fetch('https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/users', { method: 'DELETE', headers: { 'Content-Type': 'application/json', 'Authorization': 'Bearer YOUR_JWT' } }).then(r => r.json()).then(console.log); ``` ## Error responses[​](#error-responses "Direct link to Error responses") | Code | Meaning | | ---- | ------------------------------------------------ | | `24` | No WordPress user matches the JWT claims. | | `39` | User deletion is not enabled in plugin settings. | | `40` | Auth Code is missing when it is required. | | `41` | Client IP is not on the allowed IP list. | | `42` | JWT is missing from the request. | JWT decoding errors (`1`-`22`) may also appear when the token cannot be parsed or its signature is invalid. *** ## Settings[​](#settings "Direct link to Settings") Configure under **Settings → Simple JWT Login → Delete User**. ### Delete User[​](#delete-user "Direct link to Delete User") ![Delete User settings](/assets/images/delete-user-031b072620a9c8b0c8d17e8d9ecb64a7.png) Enable or disable the delete endpoint. When disabled, all DELETE requests to `/users` return a 403 error. ### Require Authentication Code[​](#require-authentication-code "Direct link to Require Authentication Code") ![Require Authentication Code](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAB0CAMAAADuBmGdAAADAFBMVEX4+fpxeoL3+PlQV15sdX0mNUSTm6D////i5OcdIyfz9PW8wMS/wseZoKbZ3N+JkJZ7hIuLkph4gIeXnaR2fobBxMh5goltdn7g4+Xp6+329/je4ON/h4/t7u/j5eeepKrV2Nvy8/Stsrd9hY2iqK2xtruGjpTu8PG6v8LX2t3w8vP09faCipHN0dSPlpz29veNlZumrLF1foXV19hyeoNKT1Kcoqjw8fK2u8CAiZDLz9Lf4OKRmZ/Bxcl3f4eVm6L5+fnb3eBveICFjJPFys3O0tTl5unQ09aQmJ6vtLrb3uHo6erIzM/l5+ns7vBscHLT1dc1Oz63vMCMkJK1ur4yQE58f4Owtbqus7ihp6zm6OqxtLXN0NLp6uyzuLzl5ufd3+Li5ObEyMxweIAhJyuboaaJjI5NUlXu7/CPl507QUQ9Qkdud391eXxCR0rm5+mFiIvq7O709vdzfIO5vsLBwsRPVFdYXWEyNzuprrNXXF/7+/uXnaNeYmYlKy+Ul5kpLzOEi5KssbaPkpTR09aZn6UoN0bJzdAnLTHw8fPDxsqVnKObnZ6KkZjLzc90fIRGS06Hj5bU1tk8SVe/wcNUWl3R0tQkKS2Di5MeJChweYLc3d5/goUuNDjExsj8/P2qr7VrcXeKkpq8vb7g4+RUYGt4gIh5govHy87e4OJSV1pxdXdEUV5tcXSgpqu+v8Cnqat+ho2orbLa2typrK85P0Jvc3Xr7e9obG+kqq8zMzNrbnGkp6i5u71bYGOGiY/Iycv+/v4rMDRXYm5ITVC9wcVhZmmho6aMk5llaW2ChYjs7e6Zmpqeo6lqdH6lq7AiIiK7wMNfY2c0OT0sO0nNzs+Ym51kaGtmcHv09PW1t7hbZnKRlJZxdnitsLK0ub1gYGCwsLBjY2Okpql4foN2en1obnV2en/AxMirra+foqQ2RFJJVmJdXV2Pj4+tra2MjIxyd3kvPUzd3+B5fYC2ubqdoKJOW2eLj5FibXc/TFo2PD8mJiZnZ2dYX2VgZGi4Ul9fAAAACXBIWXMAAAsTAAALEwEAmpwYAAAUyklEQVR42u2deVxU5f7HH8YZTg8CgpIsgYooKKihiYr7kqxdN9xFzSQ3EHFMIXLBJSV/mrgQF9SwXFLT3HK9V6+5VGqW96bZZrfN277c9u7m7/uc85wzZwZQKZ2X1Of9B8yZ8+znzNvvfOdhZAoAAAD3w8SPN4ITbgMAAOAWEoJjpH0nPMIAAAC4jUeiVPtOiMFSAACAO4mJIvvGIPIFAAB3R78xTAm2YB0AAMC9WIKZkoBlAAAAd5PAlNuwCgAA4G5ug30BAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYF8AAACwLwAAwL4AAABgXwAA+E3aty+fXM0a/fmzVy9wF+edqn+qKgbzWbj2AIAaZd84zvmrufOv/r1o8/PnVHFmQynndzk98zwffHX7Psr5FMa+zc//Q3VO6Yy5lF046cAq2BcAUFPs2/Kj3Ce8K7Pvq/lrOX/nF/b3E8l7zS+xb3VPSfrRWIuyM56HfQEANcS+3xbX+ketWkcrse8+Fl7A5zMWdTq7sGgJBcGr4gry0/hsxjL4YdZJxLYi80D5gCVxGZ0sL4wvnDR4v6xt2cvH87VejD3O+QT2LO/PikjHPI/sm3bkWByFqEb5vvzA9lcnvcZGiAL8BzW9EJ1WNDtjMAvLzuD9Z61yOqXWe3qMo55KSBzfu4CxkdTw9Ny1eUfEfOZMyjtwSdh3S9+9BVtX4R4AANxS9k2r1YytqPVRpfZdUMq/Z17FfMbpIj6H9SvhcdsLNfuud7JvyfaLf8jhk9YcMSLN9bx0T4kInMm+4ap9f8jmM9LmkH1L9mbyvHBmlO/LefEazh/rd5nznLTNQrH2XH7s0vY4NvLYqZwjvGS16RQ7zQsun+B7pxj1tNCX8xe0ng/z0gN/4xmPsw/oQW4J9bBlLb84OI8fxU0AALiV7PtErRDGDhRXmvflsymtu4Nn7GdH+THyZTZleiuz79uMRYvnYgr4o1rtAzyfneJHTPY1Mg+nYraQMx3l+/I4xjL5EpleEIpdxflqxqaymDAmTr1gOhVdykcw+7/5a456gjc536z1XCy6+RO/yGbw7xjLJfuO41spEObP4yYAANxK9v1HLf1Hhbzv+FJe7EUxpMaep/kVxj7R7bvaZN89jO2RpT5QK08pIWW+w0tXC/tGs51m+37Awjh/3FG+L/8nY+MpxeFQ7Ae8UG2m/ZqtBVQmzXSK6l1gbCu1ZdRj2nYImaHeS2Jmf+FFbBKF6+wy2Xef1tMk3AQAgJph333saAb/lE3nGYenT5/+TlgOz2QUAJN9j5Hq3jTZl/aBxWTwl6jUiD1q5TnSreOENzewNcK+p0Qsqn7qJuzrKK/uWhMWTee8gabY6ZynM3aGJJq9c3om2ddxKpzzncxrrRr7TnbYl/K+2Vret1hI+QrFvlvFgxlk35940XQxAdwEAIBbx763D86t9eGHH9KPIZXYl/2T94+25/OtaWl9s0Xed8a+Y8K+xfxEWqazfen9/aRxaWtKtA252Xxvfn5+Jn/VfqaQP59TIuxLCk571rCvo7xh0VTOt6d1knnfvWl9x1OON/vwJRH7Ok6Z874m+2p7Hoppz4Mp75uRQ/niWazTWqqctnUybgIAwK1j37/U0nmiMvtuySC7RY3LLszMP017Hk6Ubv1U2HfPrJLM11zsa9k5o6B/8akzoi6lG8QWA4pYv2c74kqLTwv77tkrVGjY1yjvsOg4ipaPGnseKFs7ejwvHBxH9jWdsnwwfvakfRuYi33V/b4lp6jbx3OP5R15VN3zUHqxr/hcr9OlzNlxuZ/gJgAA3Fr2feLb+pXYtwpGCPsCAAD49fZ9mB2GfQEAwO32/V+fJ2BfAABwv33ZR9dvXwAAADfIvrkf/g32BQAAt9q3nbHnoRfWCAAA8O3qAAAA+wIAAHCrfZPre1zlbN071F+3ezo9m17nOhuPtnrpFRL0bvx8qyjs0okTPs2u2s91D+gq7VUYl8t49Lm4HFYyndr1rjXIswOve+Y3CC8fD8/a3X5R1SqmU8W6aCR4VHkv3YzuzAQFwASgBti3xWIW1rMBc4t9o5pSBlpIZ8DIa9nXyyPJ9LS3p4stw4dF9JybHPJLBtTAo2r7VhjX9dnXuZraQbXsW5/snXLfr7ru3k4DTVzetmvnCv8k3BMZxXzvvo7GYpfZrzadDvFjIxruv6YOxdV2HWGl9r0x3TXwgH1BzbPvHfWZe+wraDfwaoWNThZvCgyu2r6WSH/f8JQhzW+0fa8Vi1dh30o6qLZ9fyVO9l3U868jJ7Sc51qmWbvra2u4tevmq0xnd/2Wj4zuUrtawejV7HuDuoN9QQ20b3Or1ard7XfHe3j2oZdI49jQgyFszDN1/VrTbV53aPy0JiGqiFL8PSLJFNEPe/Tq4PCILBgUsC42VP7fRYndprU4KXIabSK60EtFVqD3os3UzuitesywNn4UHNVuVW9pr+ZGBcN2rZLrCDsJBbdufAdVCmA+ya08OmtK9vaTL7/UJI8W6Y4Bhfm0iZAj8EmOXfZK9MxpdcawRqF0PDeR9fBsa/VkAdSY6gCfJnU8ksKMSckUgs8zrXqJXvrc38Z6Vh2PNgZjLnof8tClGqF2UHtmk2liXqYR6YOU/Qn7agtejyo0Ez3J2ZjaCgrYHfuwfl06hrY5G9mbNW1CcaU1RG/6bv+srL9rKyQJ8ZOukmssL8woq4AyD4t2tZlnaqfuuhdDzYvAmsauE5ehFYXJi/ydpyOGlHWvU+v6QoTM82vzSohcZD3zIG8lQhth3Y9bLBPHN6E7taK8jWjGmzadhA3ArR/7psjYt9GmlmFD/eklM9Fuj13EfBdPaNTrATqMT7kjNFmIKDrgZJ97uvZhZ5cO71ffYV9ZMMg6lE3dpL1F3JzY/p5l97IudRuN9qeXiqwgXo9q7Eu6GhY5urnfA6y2dQFL7GVU0O2bam3QLNSwr4x9IxKHe7ZWTz+8WytmD30m7L6xPYwBTWwyvHnoCs2+u/qNiQztEtzOx7Bv0tAoSyNT7Nu249RuLxqT0jW6KZXNa81C6nRrwBqZ7avPRfahHzpXc0RvPb2nNu7lNCI5SGMRBxoLLmJf6kmfjamtIOsQ47qM7vlxn2FZDmvKpstaenn5OsW+G/TQUK6xfmEGUOxLed+gZR37jOppsm+S3WkRWIT3hsD9hg6dpkP8NZI5ta4vRFN/3wTPZLnIhn21W8kR+05M6RG66KZ0p1aUt1FQYLfgjmUroANQY+zr83d6Tx8whdWlb9Adqr1vvZ1Cpbr0vnBzvNBD7c701MwulrEpjI1yfqNPBYMCYxjzT3S8tR7AkgYw1tzqpVcw2dcylkIb70hWm+QTEmjXK+j2bbqcRQX2cLHvOsZ6L1VP1+mgFWs+jWq22623H9SWDh84q02GotUO1LjvLsO+nsMmOGUeDjK23zpVTsrQKNVbsJT18AjXMw9yDHIueh/y0KWaw760PDHWGNOI9EHq/ZF99QWX9pWzMbcVZI0xrssouhb2aYY1ZdMWj5MxLpmH3nKG+hrrF0bad5RIQNQ12ZcumXkRGmVFs7kDXHSoTUecXufp3Lq+EF3pcEuEXGTDvo5bSbNvb2pg3k3pzriudBsFWUnnB5tAB6DG2DdSfWu6Qk3O0UtzuE+E1SpCYbJgyjKhh91qgSFR1vbkY4d9ZUE12dZK+1SnX1Ibq7Uxm9uR3ntbvfQKJvtGWcNEUKdl+MhvsoJu3wiKuTu3drEvPaeKlGLfB2WCs4Uw9f16++nq+GKNrK5onEal2zeoVZv6XUz2FQpfliInZWi0mdpLxxbMxb5yLnof8tClmsO+M9V5mUakD1Lvj+yrL7i0r5yNuS11TWWx1iLgb2FYU296s39WL9fYN1z72EuusX5hpH1d2lEvt3kRnqGhD5zrosOZ8o2IIxjVW5cLEa22YJWLbNhXu5Uc9t2iHt+M7tSK8jYKakuPB3SDDkCNsa+nt+NjNnqJ3N8kyL5Y2JfeOS4KFXrooH1sY+lJBQY67CsLmu27yXuKpSHFi+QRX4p9ZQVz7NuTjNMl0rCvrCDt20h9aXUNYR7DqUZjx6duUkrefjEy9qX/gvnsbr39Hn7MaT+ZtK9vhOhSBOXh3oF9Rhv2bS1e08Ed2jntOJO99Ggbo9tXjkHORe9DHlZi39HG50aBwaYR6YPU+yP76gvup8e+6mwq2FcWG0VNWij27dCQ+rCGOJref3Cuk331vK++xi72bUrthDjaUS+3aRG8PNTFD2Keixn72N9pOmqWP2uLU+v6QhgbZ8QiV2lf7fhmdKdWlLdRkDWK/sVE7Atqjn0TdwUxS7rxEqnnzSythH072+2t1LzvyE109t7h7OxZFhVK9pWfscmCZvsGNGB9Akimc6Mt94u8r1ZBvB4fbCLzvj6W8DoPGK8zvYImkWHiV8yyjqwOjc6jMUtvYXeyr9jzYB85pLk9/iRLaJOit2/xT7awYF9X+0aNTWBdrIks0c58x7Z/JFDuD/PxC2bJscaknDUaslwkXNXxyDHIueh96FOraF+1Azkv84jkII1FHGgseOTdWt5XzsbVvrLYmLZjmDfla3uHhljOWkNk09GU3aTP8tQVauTt2PNgSZynr7GLfYPKxrCPHe2ol9u0CPcFiDzQxN1sXUM2Ya6/03SYvgkhenFtvXV9IRp3jmJeC+QiV2JfdYTy+GZ0p1aUt1FQVjILrrvCWBAAbnX7svTIsb3qGS+RLX4vdmst7Fs7oO1BuyqiMUkeuyaOpk/v41u8QrIjHQhkQbN9F9ePbVdP7BPYFT9U3fOgVhCvx6Cucs9DE/oI22K8zmQFzb52j3Tx62A9dkfS0lh62r5c7HlwSIlFD4sI9KN9AKkTPeg9tN4+a99wU8CLHV3ty+6Z2OuZ+ETWOstaRgFWa33PQ+MWWUlTjUm5aDTMZ5rc8yDHoM9F70MeVrSv2oE+L9OI9EHK/sSeB7ngm7PkngdtNq721Yulh1ofpL0KbF5s/BCyptZ0dKzVGtFDW6FR/vJCLljeNrCOt77GLvZliyKsD/ZaYbSj7gJzLEKSmtW5p2tI1MOt5orrb54O0zbg9vSINa6gvhCWUbs8ljbVF7mifdUR6sc3oTu1oryNggIGZIk9D8aCAPAb+0tj35lYb3cj7HsjCBiOtQQA3/MA3GvfRhb2QCyWEgDYF7jZvrHWsqRULCUAsC8AAMC+AAAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYF8AAACwLwAA3OL2BQAA4HbIvgoAAAA3A/sCAADsCwAAsC8AAADYFwAAYF8AAACwLwAAwL4AAABgXwAAgH0BAADAvgAAAPsCAADsCwAAAPYFAADYFwAAgDvse+fXXxw69MXXFrcO5s4nNw4atPHJ7rgsAIDfq32/+s+SHamp65ece8+NYxm60KaycAiuCwDg92nfnf/VH73/lduGUm+QTTKoHS4MAOD3aN+v/ut4/L67ot+hhnxJv6NwZQAAvz/73vkf89G5X5uGzXyswlNv8AoJ5TtF2uH19Ojo9NdF8oFVq4v/sz1V2dMbbR1whQEANce+X79kPnrpS9PBiYIwRRkxwzh+esm1u/gh9Xrsm3TeZntZe/iyzfaNp+nUSrLxtrINV4ub32oH+wIAarx9v9hhPlr/rtm+a3Oqbd9KqMS+xyniTdQeJtLDt5zs+/mPFBdXvxvYFwBQo+x7yClYTT1ktu+cgpGqfadcKTixQ3mBc/4n8fzqvJwj25URRQUXKTZevfXYkafHKXMGK0p7/pDIPPz5yIHiT89sX5u5k8rOz8v8pKJ9RdY3XHsYLjK/TvZNVhratinKQxO3nd+4WVHKlw/aNsxmC2tvs9mVP9qeVDMPHW3blq8MUFb8PGhl/J0UDv/rswjYFwDwm7Hv95fWCPt2L/ruzIjCfkbsu5q/rSiP7l11Zn6+0j17TdjOEmf7lj6uKLMGN7iQfVT5pP+jG/Krbd+nbGWKEmDbGLnSlqL42AY99S/Nvsxk34WfRSz1Pf9NxOu2tkpvm63sx4WwLwCgRmUe1ledefi+U+Fosu+FtfSx2KUck33ps7ntrynKc3ljLuQ9pChXnO2bT0WOUZFPJytXflCUC9fMPBx3zvtSKiJVmWCzvaEctEUon9uaKs0r2tfWT1Fa2JYqyme2kfG2ZUr3b2BfAECN+tRtSdWfur2pfHeZ7Hv4BB3M2eewbx79mMEFRw+Pp8drnO1L6Yn16tkjStxhRTlT0b6xNvOnbrYk57zvStv5lsoKbTvacbLrIiVas69FiTfsu1LWJe4OtHVTlB9hXwBATbKv5Zz56Fy5s31Hz54jYl96dnKOcsls31M71ccX8p5TlIvjlCWXFWWDw76PTdKKXnmBHle0b3enHWe2cufMw3NlJF2KfU9u3rzZm2LfdSJADrPYbFOVtxx5X0XEvmVUZFRYvK2N8tAg2BcAUKP+2uK99x2P3x2hONtXOb1W5H13Khvy7lJyBpvsOz17tfLcDsr7vqPsKRinrMouL5/ssG95/tvlSupjyidxbzy3r6J9lWTTX1t84/TXFiLv28Bmu4/yvsc7d97YWc37biP7KttsL8fbnOzre/788s5/XKi0tC1cSnEw7AsAqFF/afzV+1X8qZuw78hC2vMwelbBiVVk3Vf1PQ/i547xhePpsNPW0iODxynKT7lFbzvsq4Rf/ndeLqWU52cXza/Evkq9hbp8Fzrv3hX2VZbRJrSHum07//lb3kp55KBBA4R9+220/VzmZF+l+c+fDTpeJvY8LKyPzAMAoKZ9y857515aT9+y89K5Eb+w3Zxx1a/TVNfv9fydsUXYFwAAfmvfMNn9y3cPHXr3y3LFjfZVWCx9w+Tx2OvqFPYFAODb1W+UfasD7AsAgH0BAADAvgAAAPsCAACAfQEAAPYFAADYFwAAAOwLAACwLwAAANgXAABgXwAAALAvAADAvgAAAGBfAAC4Ve2bUI5lAAAA91KewJTgEKwDAAC4l5BgpsTge3IBAMDN7I9hihIVhYUAAAB3Qt5l4lefEOR+AQDATZSH7KegV9hXiQlOuA0AAIBbSAi2K9K+AAAA3Mz/A33eZsKLS9jUAAAAAElFTkSuQmCC) When enabled, every deletion request must include a valid Auth Code alongside the JWT. The parameter name is the **Auth Code URL Key** from the Auth Codes settings (default: `AUTH_KEY`). ### Access Control[​](#access-control "Direct link to Access Control") ![Access Control settings](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAC3CAMAAAB5eg2HAAADAFBMVEX4+fp9hYxyeoJ7g4sdIydsdX1QV17////i5OeUlJT09PVxeoJ2fobt7vDBxMh4gIeiqK3+/v6epKqUm6CMk5nAxMeAiJDu7/D3+PmLkpj19vfZ3N+Zn6Xr7e55gonk5uiTmqDm6Oq+wsbHy8/d4OL29/iXnqSJkJacoqeZoKaRmJ5BRkmVnKFweYGOlZvo6euDipHY2tze4OOFjJPg4+V0fITM0NNzfIPT1tjg4uNud3/p6uyxtrvz9PX09fbFyMuQl52kqq/29vfl5ultdn51foWXnaPW2dzj5ed/h479/f38/PyusrdxdXd4fH9/ho20ub3V2Nrq7O1weIDb3uHj5ebW19mwtbq9wcW1ur7S1NeGjpTw8fPi5ObQ09aorbPh4+V/goWprrONkJLa3N62u7+Tlpjv8PG5vcFveIDU1tmgpquHj5W6v8Kdo6h3f4e/w8elq7ApLjLp6+2ho6amrLHw8vPKztArMDTO0dTEyMz6+vqEi5LZ2954gIjFys3n5+m7v8Oyt7t+ho3v8fOCiZGKkZjb3eBNUlWQk5VZXWAtMzcgJir5+fnCxsmzuLy3vMDl5+jJy8w5P0I0Oj3Mz9JdYmTt7e7Gx8gyNzvJzM8kKi7y8vMwNTmvtLn3+Pjg4OF1fYVaX2P7+/u8wMTc3uDX2t1PVFevsbKhp6wiKCyWmZtXXF+eo6lITVBtcXRjZ2ro6erP09Xs7e+rsLU8QkXLz9G4uruJjI6KjpDDxsqEjJNFSk3v7/F2enwnLTFhZWlscHKCipHY2tt8f4OkpKTx8/S1uLmHio22ur6gpavNzs+jqa5zd3ussbZ6foHS09SprK5+gYSVnKKDi5HBwsRVWl07QERfY2bHys3Dx8qoqqzx8fE+Q0e/wcOytLWus7ifoaNmam28wcRqbnGIj5aqr7WFiItobG9SVlmSlZdvc3W8vsCIkJbDxcfe3t7U19manp+DhomChYdTWFtLT1OssLKlqau6vL4eJCheZWvLz9KkpqmRl5u0triusbOdayowAAAACXBIWXMAAAsTAAALEwEAmpwYAAAZiElEQVR42u3dCVzUZeLH8Wec57dPCygMjsMwohyCIAgIiCA4KHLJ4YFouIBoICJKHpCAYqOm6614lsqqea8pqZGWR4e2mmseFWlpZVbbte12blt79f8/v2tmAK2s5CXyfb9ezfU75scP+vjw8EMJ4xzKE+4BAIAWkVAex8NL+H9ueQQAAFpM3jNSfd3icCoAAFpS3DO8vnHzcSIAAFp49BtHWLkR5wEAoGUZywlLwGkAAGhpCYTdg7MAANDS7kF9AQBQXwAA1BcAAFBfAADUFwAAUF8AANQXAABQXwAA1BcAAFBfAADU94YeoEH45ABAW61v7A1fPU/px7f8PqcLH1+6adsDN1r0PP0T6gsAqK/KeGXIbyJ8m7/uVkZp7ZxbfJu8xyndsKi2DPUFAPih+u45+79//0b07zN1/Rsv+i/ddIju5Q8qCo/XLuPhHHv+7WVV3xLy2ZKlGw48SMi159fQKv76u/uq6KFv5Y1epfT/CDG/SMjCE2ue2/0KIV9Q+uWisjceJLzLvMzkBN3/8aZnrYtRXwBok/Xd9xubPY0XfUKHfCSm0bSEVg3e/w3pu4Ee+tO2i+Q7WjZkMF1bb9q07EzhV/vIDLqmsPBZZVi7gZ6QH+zcRHcPrqXjxfou/dPj9D3ybhDdXTie1/exoIvjrYtRXwBok/X9t119axotuZfSS+so/Yxco3QhIcPJERpkFu//QT8i5A2611S27J/rhxOymh66Vnla3qgL5UGVPE2P81ExrRLr+yJ5hW5SZx5O0A3D7RajvgDQJut73q6+VxsteZWuNZIgOpjPQDwnvfApfV66f51KBpNva8U7MxnC7577Ut5qLb1IlLUPEPI3Sufw+u4kL9Jltvrut1+M+gJAm6yvu119v7BfYF4qR7bW7RKl6/iolo9911aI9/vop5cuXfrbJf4jttVvLqXfEXLws0JK3ZRm174jzfs+Td8mZC9dKo59w8lTYn3fk8p8gj4rDY2VxagvALTJ+mbY4rvNZL/gn5Re3rdvH6UP8Hnf1wtPLBLnfS8feeMiH7GWfV14ZO0rZNGZwqeX0Wurtx0pHEwfq5A2yzvOf7K2b2kZ2bnUNu+r1JePpgtfUeprXYz6AkCbrG+Crb7/a7RgG/2HeHeALpKueRCf9R389jJ6hpD+29aWffLwS2QwvyRt6WI/323LKH37e2K73pde5tf77vwLv6jhn8Suvi/wOYs3lPpaF6O+ANA2r/d1ttZ3Bk4SAECL1bdSje95nCMAgBb8XTd/pb6ZOEcAAC1Y34r9UnyH4RQBALTo3/PQ92Me32ycIQCAFv47zkKP7JuAEwQA0PJ/w2Q5zg8AAP5tCwAA1BcAAO6k+mo7/1p7WudvfVj3u0ZLOnj90n2LO9zYS+jsPOInrV4hmJse0q+rx/3SXUK7Zkucw39sW01n0qHjL14FAO74+v5eELTTTzd50cfaw5XWf42o66132Mfrx+o7yJHfjJh5o42lRT9RZQohvVYQ8jv7me32QiiJF4Sk7gm/Wn3r+S5/rfre7ONDfQHaSn2vGnNSp/9QNm97fW/sVuorchrU5AWpvpPIWK9ZqC8A3In1JWQYr9AId8fccYTMdo+JGRYuCIITcf5Qb5BmHrrNSpzyYHf+mtSU0ZOctdN5vUbog2N2KAtJaKDjyT6E9HMhpFjwI84Z+tR4P3k3Uu48HCOKbG8i1ne2wbFje+LEVwkXZx6UHfSYFBIRKA9gpUVxe5K0/eQDXegVJXQkvZ2mh8zzIer2ylHwHZYIohHEL0Mj9JpvV1+Swg+Ie6Ih6qS44eYkzQpeX+WQejuNCfFQdmbcfFJoN1E+BeobuNVZBEtFk/r6XdBuneannonAufyliI2kvsdWzVSlvi7+joH1Un13LHB0579fuCOk+4KIXVJ9d1pyrB8fKdJETZa/8zCNMUR197amdWJEsN5TepTanRDLiBusAgCtvb7mAZPIaadR7TdOaU+CZ5jNneVBq3OgSZr37RM121w/2jr27XzULSViAomNynYzjVMWmgyT6mdm7bTVd4DJFFJpG/vWLfCO7upvfRMeyxTLjPrr7vIAkNdX3UEPSyi5MN02NtyT67lLKw8kA68/Y8wkvYVsUt41Wt1eOQox55F87MvnfQsMKUZf+/oaMwzS9t2emL8x0pescM70dOf1VQ5J3J+6s13aEcZYT+UUKK8N65hAOpub1Pch984JHTerZ+KoOz/YdiYywMV7V+pEub5R/xneoJfqu3Jn+2HOJrJDyCH5EWJ9c7o+aPv4ZjpFh4YkS8/NNZ6ePZLVtHoG73Ar0J72jDSWa51JQpSx+SoA0OrnfYUPYsmOQP44eYWx3ag4dcrAOZ9I9fXKbjbz0KGBFIVIj+SFu6J4qAPG2OrLR3fXL1jra8ziQ7caf/VNxFj24KNLo9Mctb7qDnpkEJKzwFonYxYfLk7NlZ533CP+xe69BX58GefU7ZWjsKuvY2aTeV9hSo5tymMlCVzJD1cwq4ck7U/ZWWenfB455RSob+A/uvnMAx/sE1+NeiYqgsvJZlcyVvwQ7q+T6xsvrjtcnXnQjiA7eKL9Ek3EMqxrb7uZh0D+zzx5CtZp94QoNa01/FQZteuIZWE3F//edj+XtK0CAK197Ou3q2smGSN9455NurnHRKhj33C5vhHdGtXXu4dGENzJmHjpmbyw8vf8pl+Arb7h0iyEWt9igQ9Gu/lb34THMld6OFGtr7oDccI0M9Vap2Khnj+3SM97h2ztuoL05vEhExrU7ZWjsNV3vrhFo3lfVXRgkiBkkFmHxTCa1UPqLU6NKDsjFyJivOqVU6C8VuGhiZpubFzfCmmRoJ4J4rGSpOaTddKL8p8GPYr4TeQIeeYhWBDyyQ4+fUASy4mz1oXY1XeWePoEKfB+Y3olCvzcyWmdLn5gIaNIwMr4mR/6uMoT5Y1XAYDWP++7I5cUTbYWJn4WmWpfXy/5n+FUrz0LcOlt4t9sFw2Qx7418tiXB6puDClyFYdy1vpOVce+Jfz57/ytb8Jj6SXPkHpax77yDuzqKy4ylvA3XZGrHNlpn8T2vcW6xruo2ytHYT/2TblJfS0+c4yuGSSQv0NnPvZVDkmqr7Izztd9unIKrK8Z8y2VTca+JZ72Z4JU+o+YYiQLtbaT2oPv5RmhnNd3ZOTE4WSerb6WlFnK37UhfeiB/MDnyGNfH/+Fp72taa0RT51mHfFpOFk+I2DeONJ8FQBo/fWNS3oi1sJ/5uXrXcHnLfnPovr0Mtnq20frTfi8b+lseYPuU4kxxJ2ERkYTcd5XWmgyjCIJSSPIjFQ/Y52tvtJupDrWkWKDP1HeRIxl/ryxxNiH5CXGKvO+8g7s6ist2tPDeNpfnvfNN5HOWfN7xySX/yd4orq9chT2875eZtJo3lfl5EnaO2WQDrMqjAHivK98SFJ9lZ2NHkTiun+onALltV3FpHzeDHI1x76+GYHFxJyjngliasfnTIjRfbORlMt/RPXQ8skIad43XGskmXZjX0u4W+pK28c30zCfxMvzvvfzP5qyrWn1dAwnG7VmMjJKQyqS2vndYBXSzxNf7wCtvL5kszsZGeg4b4BnRYggaHYSU6l4zYNSXzJ7lsBnOrvFyNc8+Gr1DdPdxesXSsRrHuSFoQMcT4r/aMYFvSHbVl9pN0S65sFwchq/5kF+EymWfXKzIniRpqvXPMg7sKuvtCjuHL/mQf7Gf3qMEHyU13JljEW8dEHZXj4Ku/ry6xGaXPOguNpVH9CdTytvnme4Ll3zIB2SVF9lZwtTBUGfp5wC5bWj/NKEaXyMmqHUV9TBWDOv3YJ+1jNBJgni2HS+q8VJ/x+5vhm9YgKHSz91O5c6YLrBbuYhnMRqdlg/PjJBExWQJ4/scz/wsktr5qxgvXgNXRKfSS4NJDdaJSsfX+8A+E3jliLXEgAA9UV9AQBQXwAA1BcAAPUFAADUFwAA9QUAANQXAAD1BQAA1BcAAPUFAADUFwAA9QUAQH0BAAD1BQBAfQEAAPUFALg76gsAAC2O15cBAEALQ30BAFBfAADUFwAAUF8AANQXAABQXwAA1BcAAFBfAADUFwAAUF8AANQXAAD1BQAA1BcAAPUFAADUFwAA9QUAANQXAAD1BQCAn1ffh+kf2Xg65Ef38jS976e82RZKH7mV9QEA2lp9X6c07GfU91FK57DBlNKlD19Sl52n9AHUFwDgp9R3NQ/okZ9f37VLNtDacUpxqyj9B+oLAPBT6nuRfkNf19nV94+LngsqrGYH6PfsPXqNbaN/Yy8/vHTNqwMZe3lR1RvPNq7vEKY7TvfKu3qHHq+ljzKW/tGmoHfF+qrrr6ZBH605z/dcFvQuYw7PBtGyV9U79sjgNVUHRjM2fnftvx52w6cJANpGfas30fVVdLWtvm/SqiGH6Hn2Jf2abaBH0p5b5vBCbdnFA/RTZl5LL3/8WNP6Hqyi/5X3dYD+9QBdzNheaRf0Eev6q+ljay+eeYUe+moR/Zb9le5ffGSbejfwOP3Lq7VvL19NP1m8eN+j+DQBQNuo71N0g05sqLW+j9N32BxK33qZfjKOvr3kZbqb3UfPMF7ig9+Lg+Q3ms77UrpWHrEWL6P3vkmDGN/Fm+wlXl/r+nx242Xx5WvsBXqcFdIzq4uZevci/YSxE/Sdz+jD6/vikwQAbaW+f+HBfYpWVVvrW0VfYmwZzUmrWvbAYw889yX9iE9ASD57gG5j7Oum877vjT8o7+pdeoi5/YtvvoGPpd/i9bWuv5qu4cuXyrshc4L47eBq5e5L+dXCNPFdFo3EpwkA2kR9HWrl+H1vN/Z9hX3Ox758HiFo3ws0iE/73kf3r1+//h0+luURfb7pzIPVJ/Ku7rMb+yrrrxZHxPzlveJutjPdvU8douuVuxdpEH/1Gh8bj7y0TZy3AABoA/V9k5YtWbLkdfpxs3lfPnvLJxyq6DIHxud9P1r89WPivO/gr+jN6stfuLxkyTd00/a9dM3iRfK8r7y+XF8+71u4eP8SNn7I4sWb6EvKHZ/3Hby4cO36S+8t5hvtxacJANpEfZfwiQXG1tPat6zXPLwjXvNAmDh6/Y4PgBfx5fc+v2HT5f3iNQ//WrL/ZvVdTL/ht+Yy+l36V5uW7pWveZDXl+vLntpddmjJXvYUn3IoW6xT7tgjz75etvv5R8dd5uPmT9/CpwkA8JvGAACA+gIAoL4AAID6AgCgvgAAgPoCAKC+AACoLwAAoL4AAKgvAACgvgAAd2l9/3Dqt3BHO/UHfOUC3I31PfU5zsud7fNTOAcAd2N9f4vTcqfDpwgA9QXUFwBQX9QXAFBfQH0BAPVFfQEA9QXUFwD1RX1RXwBAfQH1BUB9AfUFANQX8CkCQH0B9QUA1Bf1BYC2WN9OIVGCm/hgkIfz1o6nGVs+QR+smZanLE7paRG6SY+Kky2CJpyx09M0joEpyuL2k1MFF+u+xpTGDG20c9vi0X8P1vxZfXlgcuQU12r1WTdD1qxo9Umj9VBfALh761vTr0aq70BL6ehY/TEd8/6gJr/fFL2y+PCTlXJ9zVOO+aTkezKmz01xezJmpLx4lcvUY7b61k2Y3Li+1sXmqIK4zOCpyssL9F1WvdZDeZKZeGXg+4mj5SeN10N9AaAV1zdtgiErYp3yxG9PkqWgzqXRCmFSfaMFHsAuQr782hPCcOtyub7T56VLz9KF/vy2xBbIEPu9PTS06cHIi/+clMZYhkZ+aafA2z1RfYdAD7HHk+QnjdZDfQGgNdc3u3TiwHytUlVXw05zgdON68tvTUI/+bUcwdykvr3iA4NT5/IHpR2rWaXjwVurr4eY2InKTkcl8ZvtgvInQpIPv8l4TX7SaD3UFwBacX23xyzktyu95KGvmDyd9kb1HTjFNU03TdgjvWSKOMua1Ncx5uy6jOAJfHwcIQjBfdit1XfBOX7TV5DnFzIM4m3U+/LQXNjIb+/fqsxJ2K+H+gJAK67vKkGSKj0ZKZTz24Yb1ZeN7SnE1B2LFx/mGQZsaVrfrA/4zZN8TsBVM+Fw93aht1Zfd7mq8mzxdbm+o5SZDKm+SfLajdZDfQGgFdfXW/C0Pfmh+vKrGhx0W+/n91uOdaxmTes71JXfrBDYWIFf98By43/WzINJeslHTG21MENewUmaeYhoNPNgQn0BoLXXN61kgu3JD8w8SDoJfEy7XB+gY83q6yKNfbUsXBjLH/zd5dbqO8qJ7zKjl/xSqDizEB2jTO56dBdnHArkJ43WQ30BoDX/1G1YVH+H6o1XeQd5eV1T+U/dSngQ+/dUFg8PmyscDuOX9/pMjL4gTvs65Boyw8LCTPIGcWFhwuYw/jO2sYk15sPBc1m6xov/1E3IZKwgm5c8LCyiY5ivsr+xYWe7hoVtZ+z9HHnn1sUm8Uqydh34KvpYftGae/0qw2Qmv0NK4uyBcxNXyfuzrof6AkBrr6+uQ2mWJqSSj2H5FQt+rlsTpyU/yQepkcribGlamA9vi0piUvvx67185YniMHmDTOmJOH794liwQZwkCA3QOurFudqQZPFnZqKhyv700jM+ktYoQ1nrYjZS+S2KXeK419QQOaVuOZPfQfptiy+U/VnXQ30B4K77bQtdaqfbfFBbpNkJQH0BUF9VeP/ToWe3DrzNB5XvhU8M6guA+tpblSpEhozGaUN9AQB/xxnqCwCoL6C+AID6or4AgPoC6gsAqC/qCwCoL6C+AKgv/tdGfQEA9QXUFwD1BdQXAFBf1BcAUF9AfQHgV6nvqc9xXu5sn5/COQC4G+v7h1O/hTvaqbfwlQtwN9YXAABQXwAA1BcAAFBfAADUFwAAUF8AANQXAADuwPqWRt/qFp085HtN+M2W3Fz/nqxLu1+8CgDAbapvpn/UFK/w2/F+sY43r2+vbr9efesm/PL6mgU3tk4QgvW78HUCAC1S3ydKphY75FxHfXl9hzLzhZJifKEAQAvUN007VX6w/VySdhhj3k4dukaMm5EaWcMD1/1cZM/ifhZNDn/s7qgfJ6/pMMkiWLYwc8BWzVW+ICRZn+trXSFgzwDDoC+So15bwZiTIAiD0q5rtxakMZafmnS9eX0rTzr2NLP0Jw1RHvXM11nH/zSYxdRNxMZ2bIg65ivVN9TFWVtQzQ8wIyR1hVRfXUDgdr6OD38bD+YW6PhajhJm+VCUtCoLtH3ZRsGTHU2+wSq2+jKWOLFvzyihAV8tAHB767tKqJYfnCuN9dWOYt4xH+a9P6W7d2akN+uUNbPY1VCQ975Fx+aONa90TpfWXNmzCwuvZoHx9b6GXayTsIvtSnJQVwjoyseOh78YuC5ytDz2/bO+b5eGh1hsSX/zuZKm9d1piTb307PqovLYgO68kCk830XqJlIlE2scaiJNYn3DrzjszH2feQv9WIXlNK/v9p4Badaxb7rBxbwxa6z0XDkUOa3qAte5LH5oJ3Z2bvNV7OubGePm1S9OtxBfLQBwe+sbrXxvrsviI8yjpTxufDjZLpOxnt1YJz1jfaXnbtI6Wjlu9y8I5bcHo3iLR03io0j+RH9YXSEgW9kxz5xU3yl8vyM1rIiPOdOjmtY3YCV/Z6cu4sMuUYxln2PVwW7qJlJ9e/Ebw2F15qF/MvNO5Aekz2QdvPTndLaZB1/xcFyftO6fH4qcVnXB1QZmmBkgDoGbrWI37yuUzGU9zzngawUAbv/Yd7l0bxLMjC208G/s+RPnQTyMPtLUqvq8g3uwIGQyiyDs2hKgiSrQ5QuiENZJ/CY9eYe6At+MsTCvJEHIluq7RVpNYAUfisltWt9SaeGDaR/OShSENBa7Na1Sb91Eqq+yd17f+gCNIOjlAxpQyTppHcuZrb4zxEwPmyw9Vw5FTqu6ILadeeiWrnntdM1XaTTzwD/kAVu7zsRXCwDc7nnfTvLYt4SPLmeW3qy+oZEPVrB5mcpGukzLjL5aZhud9qpUV5Dqa1nRRbdHri8rkRtZxPelazb2bbgqPVmxoK+xPa8vy52YPNW6ibT3CH4TUSnWty7eO/2Krb4dPK5o5SE5c5XGvjyrk6Sxr3oo6thXWWB5yIX5P9STNV+lSX0ZW74i0YwvFwC4/dc86DKvs3MBuuULRt2svp5aHRsnyPX1NbG8odE6/UM6lteXdYoZJs7MqitI9XUqZ2anbOaXWMxnE7wGsuoUFhp8kK0QotnCq/b1zRx6kOlymI8rYzVifSd4ZMVZN5HqGxPGwvisMq+vx1WmG2BfX7ZCkyetdCFenPftwLokjRafqoeizvsqC+oir7ALkfLlEY1XaVLfzHQWnjWQDSvHVwwA3M7rfVP8oxIXHGXbp/FrHnQ3nXmYZggsOCnXdza/lmEMYwP3WJz0+fzCiAAhgo+blRWk+nbrGlLnwSeAC/g1D7qioe3c+cUU+b2OTZ4VzYr0Sn3FyYWzLKc0K9eDLS/1b5Dq6yZ0FIfWyiZifZW98/qO1OqTC+xmHvjBTUg9La50cIpyzYMytFYOxe6aB3FBByGP5Qi+N1qlcX0LYoTgK4xlZeIrBgDu4N91+/HfOQMAQH1RXwAA1BcAAPUFAADUFwAA9QUAANQXAAD1BQAA1BcAAPUFAADUFwAA9QUAQH0BAAD1BQBAfQEAAPUFAGjt9U1Ix2kAAGhZ6QmElfvhPAAAtCy/csLi6nEeAABaVn0cYeyZYpwIAICWVFzMeH3ZM+39MPcLANBC0v3q+aBXrC+LK0+4BwAAWkRCeRxj7P8Bld684/qRc7QAAAAASUVORK5CYII=) Comma-separated list of IP addresses allowed to call the delete endpoint. Leave blank to allow all IPs. Supports wildcards in any octet (e.g. `192.168.*.*`). --- # Error codes Every error response from Simple-JWT-Login includes a numeric `errorCode` field. Use the table below to look up the meaning of a specific code and how to resolve it. Error responses follow this format: ``` { "success": false, "data": { "message": "Human-readable error message", "errorCode": 48 } } ``` | Error Code | Message | Description | | ---------- | ----------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------ | | 1 | Key may not be empty | JWT is missing from request | | 2 | Wrong number of segments | The JWT contains 3 parts, separated by dots(Header, Payload, Signature). So, your JWT does not have 2 dots in it. | | 3 | Invalid header encoding | The encoding of the first part of the JWT, is invalid. This means, that the first part of your JWT is incorrect. | | 4 | Invalid claims encoding | The second part of your JWT is invalid. | | 5 | Invalid signature encoding | The signature that you provided in "JWT Decryption key" is invalid. | | 6 | Empty algorithm | This means, that your JWT has no algorithm specified. | | 7 | Algorithm not supported | The algorithm present in your JWT, is not supported by this plugin. | | 8 | Algorithm not allowed | The provided algorithm is not allowed by this plugin. | | 9 | 'kid' invalid, unable to lookup correct key | Your JWT is malformed. | | 10 | 'kid' invalid, unable to lookup correct key | Your JWT is malformed. | | 11 | Signature verification failed | Invalid "JWT Decryption key" provided in config. | | 12 | Cannot handle token prior to ... | Check that this token has been created before 'now'. Timestamp verified from 'nbf'. | | 13 | Cannot handle token prior to ... | Check that this token has been created before 'now'. This prevents. Timestamp verified from 'iat'. | | 14 | Expired token | JWT is expired. | | 15 | Algorithm not supported | Algorithm not supported when JWT was signed. | | 16 | OpenSSL unable to sign data | Error while JWT is signed with OpenSSL. | | 17 | Unsupported sign function | Invalid Algorithm provided for JWT when signing | | 18 | Algorithm not supported | Invalid Algorithm while trying to verify the JWT | | 19 | OpenSSL error | This is a generic OpenSSL error. | | 20 | Null result with non-null input | Decoded JWT is null. | | 21 | Null result with non-null input | Encoded JWT is null | | 22 | Unknown JSON error | This is a generic error by JWT. More details are provided in the message. | | 23 | Wrong Request. | JWT is missing in the auto-login process. | | 24 | User not found. | This error occurs when the user is not found. For login and delete endpoint: there is no user in WordPress with the email or ID provided in JWT. | | 26 | Auto-login is not enabled on this website. | You have to enable auto-login from plugin settings. | | 27 | Invalid Auth Code provided. | The Auth code provided is invalid or missing. You should use one that you have saved in your plugin settings | | 28 | This IP is not allowed to auto-login. | You can not auto-login from this IP. Some IP's are specified in plugin settings that can auto-login into WordPress | | 29 | Unable to find property in JWT. | The user sub-key property can not be found in JWT | | 30 | Unable to find property in JWT. | The user key property can not be found in JWT | | 31 | Register is not allowed. | Register is disabled from settings | | 32 | Invalid Auth Code | Invalid auth code provided on register endpoint. You can use auth codes that are generated in your plugin settings. | | 33 | This IP is not allowed to register users. | You can not register users from this IP. The allowed IPs are saved in plugin settings | | 35 | Missing email or password. | Missing email or password from your register new user request | | 36 | Invalid email address. | The value provided for email is not a valid email. | | 37 | This website does not allow users from this domain. | The email domain is not allowed to register to this WordPress. The allowed domains are saved in plugin settings. | | 38 | User already exists. | The user that you are trying to create already exists. Try a different email address. | | 39 | Delete is not enabled. | The plugin delete endpoint is not enabled for this website. This can be enabled from plugin settings. | | 40 | Missing AUTH KEY | Missing Auth Key from Delete. You can find your generated auth keys in plugin settings. | | 41 | You are not allowed to delete users from this IP | You can not delete users only from the IPs that are set in plugin settings. | | 42 | The 'jwt' parameter is missing. | The JWT parameter is missing from the request. | | 43 | Invalid method for this route. | The route that you are calling does not exist. | | 44 | Invalid route name. | Route name is invalid. | | 45 | Authentication is not enabled. | Authentication enabled is set to "No" in the plugin settings. | | 46 | Authentication missing email. | Your request does not contain the email address. | | 47 | Authentication missing password. | Password is missing from the request. | | 48 | Authentication wrong credentials | Email or password is incorrect. | | 49 | JWT payload is not correct. | Check your JWT payload. After decoding it, it resulted null. it should be an JSON. | | 50 | JWT is too old to be refreshed. | The JWT generated time is too old. You can not refresh this token. | | 51 | JWT is missing from /auth/refresh | The JWT parameter was not sent to the /auth/refresh endpoint. | | 52 | Unable to create user. | There was an error while trying to create the user. | | 53 | The `jwt` parameter is missing. | The JWT is missing from reset password, revoke token or validate user | | 54 | WordPress user not found | Unable to find a valid user in the provided JWT. | | 55 | This JWT is invalid. | The JWT has been revoked. It can not be used anymore. | | 56 | Reset Password is not allowed. | The Reset Password endpoint is disabled. | | 57 | Route called with invalid request method. | The Reset Password endpoint is called with an invalid HTTP method. Only PUT and POST are allowed. | | 58 | Invalid Auth Code ( %s ) provided. | The Reset Password endpoint is called with an invalid AUTH CODE. | | 59 | Missing email parameter. | Missing or empty `email` parameter when calling the Reset Password endpoint. | | 60 | Missing code parameter. | Missing `code` parameter when calling change user password endpoint. | | 61 | Missing new\_password parameter. | Missing `new_password` when calling the change user password endpoint | | 62 | Invalid code provided. | The `code` and `user_email` does not match when calling the Reset Password endpoint. | | 63 | Missing email parameter. | Missing `email` parameter when calling the Send reset password endpoint. | | 64 | Wrong user. | User was not found while calling the Send reset password endpoint. | | 65 | Invalid flow type. | Invalid plugin settings for Reset password flow. | | 66 | You need to add the {{CODE}} variable in email body. | The `{{CODE}}` parameter is missing from Reset Password email body. | | 67 | Something is wrong. We can not save the settings. | Something is wrong with the plugin configuration. The `_wpnonce` field is missing or it is invalid. | | 68 | 'The JWT issuer(iss) is not allowed to auto-login. | The JWT is issued by an authorized issuer. | | 69 | The Oauth provider is invalid. | Invalid `provider` parameter provided. | | 70 | This Oauth provider is not available. | OAuth provided is not enabled or unavailable. | | 71 | The code or id\_token parameter is missing from request. | The code or `id_token` parameter is missing from request when connecting with Google OAuth. | | 72 | The code you provided is invalid. | The Google OAuth endpoint has received an invalid `code`. | | 73 | The provided id\_token is invalid | The Google OAuth endpoint has received an invalid `id_token`. | | 74 | Wrong user credentials. | The Google OAuth could not find a user in the provided JWT. | | 75 | JWT is not present and we can not search for a user. | The JWT is missing from the request when accessing a protected endpoint. | | 76 | The custom email subject is empty. | The Reset Password custom email subject is empty in the plugin settings. | | 77 | The code or access\_token parameter is missing from request. | The `code` or `access_token` parameter is missing when calling the Auth0 OAuth endpoint. | | 78 | The code you provided is invalid. | The Auth0 authorization `code` is invalid. | | 79 | The provided token is invalid. | The Auth0 `access_token` is invalid or rejected by the Auth0 userinfo endpoint. | | 80 | Wrong user credentials. | No WordPress user was found matching the Auth0 account. | | 81 | Refresh Token endpoint is not enabled. | The Refresh Token endpoint is disabled in the plugin settings. | | 82 | Validate Token endpoint is not enabled. | The Validate Token endpoint is disabled in the plugin settings. | | 83 | Revoke Token endpoint is not enabled. | The Revoke Token endpoint is disabled in the plugin settings. | | 84 | You must be logged in to manage API keys. | You are not authenticated or not authorized to manage this API key. | | 85 | API key name is required. | The `name` parameter is missing when creating or updating an API key. | | 86 | At least one permission is required. | The API key has no permissions defined. Provide at least one valid permission. | | 87 | Invalid permission: %s | The API key contains an unrecognized permission value. | | 88 | Failed to create API key. | A database error occurred while inserting the new API key. | | 89 | Invalid API key ID. | No API key was found with the provided ID. | | 90 | Failed to update API key. | A database error occurred while updating the API key. | | 91 | Failed to revoke API key. | A database error occurred while revoking the API key. | | 92 | Failed to delete API key. | A database error occurred while deleting the API key. | | 93 | This JWT can not change your password. | The JWT provided does not match the user account whose password is being changed. | | 94 | Auth Code is required. | An auth code is required but was not provided in the request. | | 95 | Invalid email parameter. | The email address provided in the change-password request is invalid. | | 96 | Invalid email parameter. | The email address provided in the send-reset-password request is invalid. | | 97 | The code or access\_token parameter is missing from request. | The `code` or `access_token` parameter is missing when calling the Facebook OAuth endpoint. | | 98 | The code you provided is invalid. | The Facebook authorization `code` is invalid. | | 99 | The provided Facebook access\_token is invalid. | The Facebook `access_token` is invalid or rejected. | | 100 | Wrong user credentials. | No WordPress user was found matching the Facebook account. | | 101 | The code or access\_token parameter is missing from request. | The `code` or `access_token` parameter is missing when calling the GitHub OAuth endpoint. | | 102 | The code you provided is invalid. | The GitHub authorization `code` is invalid. | | 103 | The provided GitHub access\_token is invalid. | The GitHub `access_token` is invalid or rejected. | | 104 | Wrong user credentials. | No WordPress user was found matching the GitHub account. | | 105 | Two-factor authentication plugin is not active. | The Two-Factor plugin is not installed/activated or the integration is not enabled in Simple JWT Login settings. | | 106 | Invalid interim JWT claims. | The interim JWT provided for 2FA verification has invalid or missing claims. | | 107 | Invalid or expired two-factor session. Please authenticate again. | The 2FA nonce has expired or is invalid. The user must authenticate from the beginning. | | 108 | Too many failed attempts. Please wait N seconds. | The 2FA verification is rate-limited due to too many failed attempts. | | 109 | The two-factor code is missing / Invalid two-factor code. | The 2FA code is missing or does not match. | | 110 | This JWT requires two-factor verification before it can be used. | The provided JWT is an interim 2FA JWT and cannot be used for regular authenticated operations until 2FA is completed. | | 111 | Email address is not verified. | The Auth0 account email is not verified, and unverified emails are not allowed in the Auth0 integration settings. | | 112 | No verified primary email found in the GitHub account. | The GitHub account has no verified primary email, and unverified emails are not allowed in the GitHub integration settings. | | 113 | Authentication with password\_hash is not enabled. | The request sent a `password_hash` parameter, but authenticating with a password hash is disabled in the plugin settings. | | 114 | You do not have the required role to access this endpoint. | The authenticated user does not have one of the WordPress roles required to access this protected endpoint. | --- # Simple-JWT-Login Export-Import Add-on The Export-Import add-on lets you copy your Simple-JWT-Login configuration - including Auth Codes, protection rules, and all general settings - from one WordPress site to another in just a few steps. This is especially useful when setting up staging environments, migrating sites, or replicating a configuration across a network of sites. [Download](https://github.com/simple-jwt-login/export-import/archive/refs/heads/master.zip) ## Installation[​](#installation "Direct link to Installation") 1. Download the add-on from 2. Upload the zip file into your WordPress 3. Activate the plugin 4. Export or import data ## Screenshots[​](#screenshots "Direct link to Screenshots") ### Configuration[​](#configuration "Direct link to Configuration") ![Export Import add-on configuration screen for Simple JWT Login](https://github.com/simple-jwt-login/export-import/raw/master/wordpress.org/screenshot-1.png?raw=true) ## How to transfer settings[​](#how-to-transfer-settings "Direct link to How to transfer settings") **On the source site:** 1. Go to the Simple-JWT-Login settings page. 2. Click **Export** to generate a configuration snapshot. 3. Copy the generated code. **On the destination site:** 1. Install and activate both Simple-JWT-Login and the Export-Import add-on. 2. Go to the Simple-JWT-Login settings page. 3. Paste the copied code into the import field. 4. Click **Import** and confirm the prompt. The destination site will now have the same configuration as the source. --- # Hooks Simple JWT Login exposes **22 WordPress action and filter hooks** that let you extend or customize the plugin's behaviour without modifying its source code. Use them to enrich JWT payloads, send notifications, apply business logic, gate requests, or build fully custom flows on top of the plugin. Enable hooks first Hooks must be enabled individually in the plugin settings before they fire. **All hooks are disabled by default.** ## Quick Reference[​](#quick-reference "Direct link to Quick Reference") | Hook | Type | Triggered | | ----------------------------------------------------------------------------------------------------------------- | ------ | --------------------------------------------------- | | [`simple_jwt_login_before_endpoint`](#simple_jwt_login_before_endpoint) | action | Before any endpoint is processed | | [`simple_jwt_login_login_hook`](#simple_jwt_login_login_hook) | action | After a user logs in | | [`simple_jwt_login_redirect_hook`](#simple_jwt_login_redirect_hook) | action | Before the post-login redirect | | [`simple_jwt_login_register_hook`](#simple_jwt_login_register_hook) | action | After a new user is created | | [`simple_jwt_login_delete_user_hook`](#simple_jwt_login_delete_user_hook) | action | After a user is deleted | | [`simple_jwt_login_jwt_payload_auth`](#simple_jwt_login_jwt_payload_auth) | filter | Before the JWT is signed on `/auth` | | [`simple_jwt_login_no_redirect_message`](#simple_jwt_login_no_redirect_message) | filter | Before the no-redirect response on `/autologin` | | [`simple_jwt_login_reset_password_custom_email_template`](#simple_jwt_login_reset_password_custom_email_template) | filter | Before the reset-password email is sent | | [`simple_jwt_login_response_auth_user`](#simple_jwt_login_response_auth_user) | filter | Before the `/auth` response is returned | | [`simple_jwt_login_response_register_user`](#simple_jwt_login_response_register_user) | filter | Before the register response is returned | | [`simple_jwt_login_response_delete_user`](#simple_jwt_login_response_delete_user) | filter | Before the delete-user response is returned | | [`simple_jwt_login_response_refresh_token`](#simple_jwt_login_response_refresh_token) | filter | Before the refresh-token response is returned | | [`simple_jwt_login_response_send_reset_password`](#simple_jwt_login_response_send_reset_password) | filter | Before the send-reset-password response is returned | | [`simple_jwt_login_response_change_user_password`](#simple_jwt_login_response_change_user_password) | filter | Before the change-password response is returned | | [`simple_jwt_login_response_revoke_token`](#simple_jwt_login_response_revoke_token) | filter | Before the revoke-token response is returned | | [`simple_jwt_login_response_validate_token`](#simple_jwt_login_response_validate_token) | filter | Before the validate-token response is returned | | [`simple_jwt_login_generate_payload`](#simple_jwt_login_generate_payload) | filter | Before a JWT payload is generated (any endpoint) | | [`simple_jwt_login_audit_2fa_challenge_issued`](#simple_jwt_login_audit_2fa_challenge_issued) | action | When a 2FA challenge code has been issued | | [`simple_jwt_login_audit_2fa_verify_success`](#simple_jwt_login_audit_2fa_verify_success) | action | After a successful 2FA verification | | [`simple_jwt_login_audit_2fa_verify_failed`](#simple_jwt_login_audit_2fa_verify_failed) | action | When a 2FA verification attempt fails | | [`simple_jwt_login_response_2fa_challenge`](#simple_jwt_login_response_2fa_challenge) | filter | Before the 2FA challenge response is returned | | [`simple_jwt_login_response_2fa_verify`](#simple_jwt_login_response_2fa_verify) | filter | Before the 2FA verify response is returned | *** ## Action Hooks[​](#action-hooks "Direct link to Action Hooks") Action hooks let you run side-effect code at a specific point in the request lifecycle. They do not return a value. ### `simple_jwt_login_before_endpoint`[​](#simple_jwt_login_before_endpoint "Direct link to simple_jwt_login_before_endpoint") Fires before a Simple JWT Login REST route is processed. Use it to validate requests, block specific callers, enforce policies (e.g. minimum password length), or log activity - for any endpoint. | Parameter | Type | Description | | ----------- | -------- | ---------------------------------- | | `$method` | `string` | HTTP method (`GET`, `POST`, …) | | `$endpoint` | `string` | Endpoint name (`auth`, `users`, …) | | `$request` | `array` | Full request parameters | Throw an `Exception` to abort the request with an error response. *** ### `simple_jwt_login_login_hook`[​](#simple_jwt_login_login_hook "Direct link to simple_jwt_login_login_hook") Fires after a user has been successfully authenticated and logged in. | Parameter | Type | Description | | --------- | --------- | ---------------------- | | `$user` | `WP_User` | The authenticated user | *** ### `simple_jwt_login_redirect_hook`[​](#simple_jwt_login_redirect_hook "Direct link to simple_jwt_login_redirect_hook") Fires before the user is redirected to the URL configured in the Login settings. Use it to implement dynamic redirect logic based on request parameters. | Parameter | Type | Description | | ---------- | -------- | --------------------------- | | `$url` | `string` | The configured redirect URL | | `$request` | `array` | Full request parameters | tip Enable **"Include request parameters in the redirect URL"** in Login settings to forward custom query parameters (e.g. `&page=dashboard`) that your hook can read. *** ### `simple_jwt_login_register_hook`[​](#simple_jwt_login_register_hook "Direct link to simple_jwt_login_register_hook") Fires after a new user has been created via the register endpoint. | Parameter | Type | Description | | ---------------------- | --------- | ---------------------------------------------------------------- | | `$user` | `WP_User` | The newly created user | | `$plain_text_password` | `string` | The user's plain-text password (available only at creation time) | *** ### `simple_jwt_login_delete_user_hook`[​](#simple_jwt_login_delete_user_hook "Direct link to simple_jwt_login_delete_user_hook") Fires immediately after a user has been deleted. | Parameter | Type | Description | | --------- | --------- | ---------------- | | `$user` | `WP_User` | The deleted user | *** ## Filter Hooks[​](#filter-hooks "Direct link to Filter Hooks") Filter hooks let you inspect and modify data before it is used or returned. Always return the (modified) value. ### `simple_jwt_login_jwt_payload_auth`[​](#simple_jwt_login_jwt_payload_auth "Direct link to simple_jwt_login_jwt_payload_auth") Fires on the `/auth` endpoint before the JWT is signed. Use it to add custom claims to the token. | Parameter | Type | Description | | ---------- | ------- | ----------------------------------- | | `$payload` | `array` | The JWT payload (modify and return) | | `$request` | `array` | Full request parameters | **Returns:** `array` - the modified payload. *** ### `simple_jwt_login_no_redirect_message`[​](#simple_jwt_login_no_redirect_message "Direct link to simple_jwt_login_no_redirect_message") Fires on the `/autologin` endpoint when **No Redirect** is selected. Use it to customize the JSON response returned to the client. | Parameter | Type | Description | | ---------- | ------- | ---------------------------------------- | | `$payload` | `array` | The response payload (modify and return) | | `$request` | `array` | Full request parameters | **Returns:** `array` - the modified response payload. *** ### `simple_jwt_login_reset_password_custom_email_template`[​](#simple_jwt_login_reset_password_custom_email_template "Direct link to simple_jwt_login_reset_password_custom_email_template") Fires when `POST /user/reset_password` is called. Use it to replace the default email template set in Reset Password settings with a fully custom HTML email. | Parameter | Type | Description | | ----------- | -------- | -------------------------- | | `$template` | `string` | The current email template | | `$request` | `array` | Full request parameters | **Returns:** `string` - the custom email template. *** ### Response Filters[​](#response-filters "Direct link to Response Filters") The following 8 filters fire immediately before their respective endpoint returns a JSON response. Use them to add, remove, or transform fields in the API response. #### `simple_jwt_login_response_auth_user`[​](#simple_jwt_login_response_auth_user "Direct link to simple_jwt_login_response_auth_user") Fires before the `POST /auth` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_register_user`[​](#simple_jwt_login_response_register_user "Direct link to simple_jwt_login_response_register_user") Fires before the `POST /users` (register) response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_delete_user`[​](#simple_jwt_login_response_delete_user "Direct link to simple_jwt_login_response_delete_user") Fires before the `DELETE /users` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_refresh_token`[​](#simple_jwt_login_response_refresh_token "Direct link to simple_jwt_login_response_refresh_token") Fires before the `POST /auth/refresh` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_send_reset_password`[​](#simple_jwt_login_response_send_reset_password "Direct link to simple_jwt_login_response_send_reset_password") Fires before the `POST /user/reset_password` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_change_user_password`[​](#simple_jwt_login_response_change_user_password "Direct link to simple_jwt_login_response_change_user_password") Fires before the `PUT /user/reset_password` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_revoke_token`[​](#simple_jwt_login_response_revoke_token "Direct link to simple_jwt_login_response_revoke_token") Fires before the `DELETE /auth` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** #### `simple_jwt_login_response_validate_token`[​](#simple_jwt_login_response_validate_token "Direct link to simple_jwt_login_response_validate_token") Fires before the `GET /auth/validate` response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** ### `simple_jwt_login_generate_payload`[​](#simple_jwt_login_generate_payload "Direct link to simple_jwt_login_generate_payload") Fires before the JWT payload is generated on any endpoint (not just `/auth`). Use it to append extra claims to every JWT issued by the plugin, regardless of which endpoint generates the token. | Parameter | Type | Description | | ---------- | --------- | ---------------------------------------------- | | `$payload` | `array` | The JWT payload (modify and return) | | `$user` | `WP_User` | The user for whom the token is being generated | **Returns:** `array` - the modified payload. *** ## 2FA Hooks[​](#2fa-hooks "Direct link to 2FA Hooks") These hooks relate to the Two-Factor Authentication integration. Enable Two-Factor in **Settings → Integrations → Third Party → Two-Factor**. ### `simple_jwt_login_audit_2fa_challenge_issued`[​](#simple_jwt_login_audit_2fa_challenge_issued "Direct link to simple_jwt_login_audit_2fa_challenge_issued") Fires when a two-factor authentication challenge has been issued (i.e. after the user submits valid credentials and an interim JWT is returned, triggering a 2FA code delivery). | Parameter | Type | Description | | ------------ | -------- | -------------------- | | `$userId` | `int` | WordPress user ID | | `$userEmail` | `string` | User's email address | *** ### `simple_jwt_login_audit_2fa_verify_success`[​](#simple_jwt_login_audit_2fa_verify_success "Direct link to simple_jwt_login_audit_2fa_verify_success") Fires after a successful two-factor authentication verification. | Parameter | Type | Description | | ------------ | -------- | -------------------- | | `$userId` | `int` | WordPress user ID | | `$userEmail` | `string` | User's email address | *** ### `simple_jwt_login_audit_2fa_verify_failed`[​](#simple_jwt_login_audit_2fa_verify_failed "Direct link to simple_jwt_login_audit_2fa_verify_failed") Fires when a two-factor authentication verification attempt fails. | Parameter | Type | Description | | ------------ | -------- | ----------------------------- | | `$userId` | `int` | WordPress user ID | | `$userEmail` | `string` | User's email address | | `$message` | `string` | Human-readable failure reason | *** ### `simple_jwt_login_response_2fa_challenge`[​](#simple_jwt_login_response_2fa_challenge "Direct link to simple_jwt_login_response_2fa_challenge") Fires before the `POST /auth/2fa` challenge response is returned. Use it to add extra fields or transform the response. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** ### `simple_jwt_login_response_2fa_verify`[​](#simple_jwt_login_response_2fa_verify "Direct link to simple_jwt_login_response_2fa_verify") Fires before the 2FA verify endpoint response is returned. | Parameter | Type | Description | | ----------- | --------- | ------------------------------------- | | `$response` | `array` | The response data (modify and return) | | `$user` | `WP_User` | The user associated with the request | **Returns:** `array` - the modified response. *** ## Settings Screenshot[​](#settings-screenshot "Direct link to Settings Screenshot") ![Hooks settings panel](/assets/images/wordpress-hooks-integration-26bc1dff7e03524d96af1b6827dc33c6.png) *** ## Code Examples[​](#code-examples "Direct link to Code Examples") ### Add custom claims to the JWT payload[​](#add-custom-claims-to-the-jwt-payload "Direct link to Add custom claims to the JWT payload") Enrich the token with user metadata - roles, plan, tenant ID - so downstream services don't need a separate lookup. ``` add_filter('simple_jwt_login_jwt_payload_auth', function (array $payload, array $request): array { $user = get_user_by('email', $request['email'] ?? ''); if ($user) { $payload['roles'] = $user->roles; $payload['display_name'] = $user->display_name; } return $payload; }, 10, 2); ``` *** ### Send a welcome email after registration[​](#send-a-welcome-email-after-registration "Direct link to Send a welcome email after registration") ``` add_action('simple_jwt_login_register_hook', function (WP_User $user, string $password): void { wp_mail( $user->user_email, 'Welcome to My Site', sprintf( "Hi %s,\n\nYour account is ready.\n\nEmail: %s\nPassword: %s", $user->display_name, $user->user_email, $password ) ); }, 10, 2); ``` *** ### Dynamic redirect URLs after login[​](#dynamic-redirect-urls-after-login "Direct link to Dynamic redirect URLs after login") Enable **"Include request parameters in the redirect URL"** in Login settings, then add `&page=dashboard` (or any value) to the login URL. The hook reads it and redirects accordingly. ``` add_action('simple_jwt_login_redirect_hook', function (string $url, array $request): void { $page = $request['page'] ?? null; $destinations = [ 'dashboard' => 'https://mysite.com/dashboard', 'profile' => 'https://mysite.com/profile', ]; wp_redirect($destinations[$page] ?? $url); }, 10, 2); ``` *** ### Block a specific email address on `/auth`[​](#block-a-specific-email-address-on-auth "Direct link to block-a-specific-email-address-on-auth") ``` add_action('simple_jwt_login_before_endpoint', function (string $method, string $endpoint, array $request): void { if ($method !== 'POST' || $endpoint !== 'auth') { return; } $blocked = ['banned@example.com']; if (in_array($request['email'] ?? '', $blocked, true)) { throw new Exception('This account has been suspended.'); } }, 10, 3); ``` *** ### Enforce a minimum password length on registration[​](#enforce-a-minimum-password-length-on-registration "Direct link to Enforce a minimum password length on registration") ``` add_action('simple_jwt_login_before_endpoint', function (string $method, string $endpoint, array $request): void { if ($method !== 'POST' || $endpoint !== 'users') { return; } $minLength = 8; $password = $request['password'] ?? ''; if (strlen($password) < $minLength) { throw new Exception("Password must be at least {$minLength} characters."); } }, 10, 3); ``` *** ### Add extra fields to the auth response[​](#add-extra-fields-to-the-auth-response "Direct link to Add extra fields to the auth response") ``` add_filter('simple_jwt_login_response_auth_user', function (array $response, WP_User $user): array { $response['user_id'] = $user->ID; $response['display_name'] = $user->display_name; $response['avatar_url'] = get_avatar_url($user->ID); return $response; }, 10, 2); ``` --- # OAuth Simple JWT Login supports OAuth 2.0 authentication with four providers: **Google**, **Auth0**, **Facebook**, and **GitHub**. When configured, users can sign in with their existing provider accounts and receive a WordPress JWT in return. Configure OAuth under **Settings → Simple JWT Login → Integrations → OAuth**. ![OAuth Applications](/assets/images/oauth-applications-ec070789eef042ff44f165d00c451c83.png) *** ## Login Page Button Layout[​](#login-page-button-layout "Direct link to Login Page Button Layout") Controls how the "Continue with..." buttons appear on the WordPress login and registration page. ![Login Page Button Layout](/assets/images/login-page-button-layout-213750a67e5c629576e7f7bc735a6251.png) | Option | Description | | ---------------------- | ------------------------------------------------------ | | **Stacked** | One full-width button per provider, stacked vertically | | **Side by side** | All buttons in a single row | | **Icons stacked** | Icon-only buttons, one per line | | **Icons side by side** | Icon-only buttons in a single row | *** ## Shared Options[​](#shared-options "Direct link to Shared Options") Each provider panel shares the same set of options. ![Other Options](/assets/images/other-options-6448ec2d7936b10f144417a36f6fdae5.png) ### Enable[​](#enable "Direct link to Enable") Toggle the provider on or off. When disabled, the provider's endpoints return errors. ### OAuth on Login / Register[​](#oauth-on-login--register "Direct link to OAuth on Login / Register") When enabled, a "Continue with \[Provider]" button appears on the WordPress login and registration page. ![OAuth on Login / Register](/assets/images/oauth-on-login--register-913f2c5713fec154bf0fc8671bb7c754.png) To make the OAuth redirect work, register the **Redirect URI** shown in the settings panel in the provider's developer console: ``` https://example.com/?rest_route=/simple-jwt-login/v1/oauth/token&provider={provider} ``` ### Allow Usage on All Endpoints[​](#allow-usage-on-all-endpoints "Direct link to Allow Usage on All Endpoints") When enabled, a valid provider token can authenticate requests to any WordPress REST endpoint (not just Simple JWT Login routes). The plugin looks up the WordPress user by the email address returned by the provider. note Requires "All WordPress endpoints check for JWT authentication" to also be enabled in **General** settings. ### Create User if Not Exists[​](#create-user-if-not-exists "Direct link to Create User if Not Exists") When enabled, the plugin automatically creates a new WordPress user if no account is found matching the email from the provider. New users receive the default role configured in the **Register** settings. *** ## Typical OAuth Flow[​](#typical-oauth-flow "Direct link to Typical OAuth Flow") The full browser-based OAuth flow for any provider: 1. User clicks "Continue with \[Provider]" on your login page. 2. They are redirected to the provider's authorization page. 3. After authorization, the provider redirects back to your site's callback URI (`/simple-jwt-login/v1/oauth/token?provider=...&code=...`). 4. Simple JWT Login exchanges the `code` for a provider token, then verifies the user's email. 5. If a matching WordPress user exists (or `Create user if not exists` is on), a WordPress JWT is issued. 6. The user is logged in to WordPress. For headless setups (no browser redirect), skip steps 1-3 and call the token exchange endpoint directly with the provider token your client already obtained. --- # Exchange OAuth Code for Auth0 Tokens ## Overview[​](#overview "Direct link to Overview") This endpoint exchanges the `code` returned from Auth0's OAuth flow for Auth0 tokens (`access_token`, `id_token`). Use this when your OAuth flow happens in a separate app and you need to obtain the Auth0 tokens server-side. Enable **Exchange Auth0 OAuth code for Auth0 tokens** in **Settings → Simple JWT Login → Integrations → OAuth → Auth0**. note The `redirect_uri` used here must exactly match the one registered in your Auth0 application and saved in the plugin settings. *** ## Endpoint[​](#endpoint "Direct link to Endpoint") **Method:** `POST` **Endpoint:** `/simple-jwt-login/v1/oauth/token` | Parameter | Type | Description | | -------------- | ------------------- | ------------------------------------------------------------ | | `provider` | `required` `string` | Set to `auth0` | | `code` | `required` `string` | The authorization code received from Auth0 | | `redirect_uri` | `optional` `string` | Override the redirect URI saved in settings for this request | *** ## Request Example[​](#request-example "Direct link to Request Example") ``` curl -X POST "https://your-site.com/wp-json/simple-jwt-login/v1/oauth/token" \ -H "Content-Type: application/json" \ -d '{"provider":"auth0","code":"YOUR_AUTH0_AUTH_CODE","redirect_uri":"https://your-site.com/callback"}' ``` *** ## Response Examples[​](#response-examples "Direct link to Response Examples") ### Success[​](#success "Direct link to Success") ``` { "success": true, "data": { "access_token": "eyJhbGciOiJSUzI1NiIs...", "id_token": "eyJhbGciOiJSUzI1NiIs...", "expires_in": 86400, "token_type": "Bearer" } } ``` ### Error[​](#error "Direct link to Error") ``` { "success": false, "data": { "message": "The code you provided is invalid.", "errorCode": 72 } } ``` --- # Exchange access\_token for WordPress JWT ## Overview[​](#overview "Direct link to Overview") This endpoint accepts an Auth0 `access_token` and returns a WordPress JWT. Use this as the final step of the Auth0 OAuth flow to authenticate the user in WordPress. Enable **Exchange Auth0 access\_token for a WordPress JWT** in **Settings → Simple JWT Login → Integrations → OAuth → Auth0**. *** ## Endpoint[​](#endpoint "Direct link to Endpoint") **Method:** `POST` **Endpoint:** `/simple-jwt-login/v1/oauth/token` | Parameter | Type | Description | | -------------- | ------------------- | --------------------------------------------- | | `provider` | `required` `string` | Set to `auth0` | | `access_token` | `required` `string` | The `access_token` from your Auth0 OAuth flow | *** ## Request Example[​](#request-example "Direct link to Request Example") ``` curl -X POST "https://your-site.com/wp-json/simple-jwt-login/v1/oauth/token" \ -H "Content-Type: application/json" \ -d '{"provider":"auth0","access_token":"YOUR_AUTH0_ACCESS_TOKEN"}' ``` *** ## Response Examples[​](#response-examples "Direct link to Response Examples") ### Success[​](#success "Direct link to Success") ``` { "success": true, "data": { "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." } } ``` ### Error[​](#error "Direct link to Error") ``` { "success": false, "data": { "message": "The code or jwt parameter is missing from request.", "errorCode": 71 } } ``` --- # Setup ## Create an Auth0 Application[​](#create-an-auth0-application "Direct link to Create an Auth0 Application") 1. Log in to the [Auth0 Dashboard](https://manage.auth0.com/). 2. Go to **Applications → Applications** and click **+ Create Application**. 3. Choose **Regular Web Applications** and click **Create**. 4. Open the **Settings** tab and copy the **Domain**, **Client ID**, and **Client Secret**. 5. Under **Allowed Callback URLs**, add your site's callback URL: ``` https://your-site.com/?rest_route=/simple-jwt-login/v1/oauth/token&provider=auth0 ``` 6. Save your changes. warning Keep your credentials secure - never commit them to version control or expose them publicly. Use separate Auth0 applications for each environment (development, staging, production). *** ## Configure in WordPress[​](#configure-in-wordpress "Direct link to Configure in WordPress") 1. Go to **Simple JWT Login → Integrations → OAuth → Auth0**. 2. Enter the **Domain**, **Client ID**, and **Client Secret** from the Auth0 Dashboard. 3. Set the **Redirect URI** to match what you registered in Auth0. 4. Toggle **Enable** to activate the Auth0 provider. | Field | Description | | ----------------- | ------------------------------------------------------ | | **Domain** | Your Auth0 tenant domain, e.g. `your-tenant.auth0.com` | | **Client ID** | The application Client ID | | **Client Secret** | The application Client Secret | --- # Exchange OAuth Code for Facebook Tokens ## Overview[​](#overview "Direct link to Overview") This endpoint exchanges the `code` returned from Facebook's OAuth flow for Facebook tokens. Use this when your OAuth flow happens in a separate app and you need to obtain the Facebook tokens server-side. Enable **Exchange Facebook OAuth code for Facebook tokens** in **Settings → Simple JWT Login → Integrations → OAuth → Facebook**. note The `redirect_uri` used here must exactly match the one registered in your Facebook app and saved in the plugin settings. *** ## Endpoint[​](#endpoint "Direct link to Endpoint") **Method:** `POST` **Endpoint:** `/simple-jwt-login/v1/oauth/token` | Parameter | Type | Description | | -------------- | ------------------- | ------------------------------------------------------------ | | `provider` | `required` `string` | Set to `facebook` | | `code` | `required` `string` | The authorization code received from Facebook | | `redirect_uri` | `optional` `string` | Override the redirect URI saved in settings for this request | *** ## Request Example[​](#request-example "Direct link to Request Example") ``` curl -X POST "https://your-site.com/wp-json/simple-jwt-login/v1/oauth/token" \ -H "Content-Type: application/json" \ -d '{"provider":"facebook","code":"YOUR_FACEBOOK_AUTH_CODE","redirect_uri":"https://your-site.com/callback"}' ``` *** ## Response Examples[​](#response-examples "Direct link to Response Examples") ### Success[​](#success "Direct link to Success") ``` { "success": true, "data": { "access_token": "EAABwzLixnjYBO...", "token_type": "bearer", "expires_in": 5183944 } } ``` ### Error[​](#error "Direct link to Error") ``` { "success": false, "data": { "message": "The code you provided is invalid.", "errorCode": 72 } } ``` --- # Exchange access\_token for WordPress JWT ## Overview[​](#overview "Direct link to Overview") This endpoint accepts a Facebook `access_token` and returns a WordPress JWT. Use this as the final step of the Facebook OAuth flow to authenticate the user in WordPress. Enable **Exchange Facebook access\_token for a WordPress JWT** in **Settings → Simple JWT Login → Integrations → OAuth → Facebook**. *** ## Endpoint[​](#endpoint "Direct link to Endpoint") **Method:** `POST` **Endpoint:** `/simple-jwt-login/v1/oauth/token` | Parameter | Type | Description | | -------------- | ------------------- | ------------------------------------------------ | | `provider` | `required` `string` | Set to `facebook` | | `access_token` | `required` `string` | The `access_token` from your Facebook OAuth flow | *** ## Request Example[​](#request-example "Direct link to Request Example") ``` curl -X POST "https://your-site.com/wp-json/simple-jwt-login/v1/oauth/token" \ -H "Content-Type: application/json" \ -d '{"provider":"facebook","access_token":"YOUR_FACEBOOK_ACCESS_TOKEN"}' ``` *** ## Response Examples[​](#response-examples "Direct link to Response Examples") ### Success[​](#success "Direct link to Success") ``` { "success": true, "data": { "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." } } ``` ### Error[​](#error "Direct link to Error") ``` { "success": false, "data": { "message": "The code or jwt parameter is missing from request.", "errorCode": 71 } } ``` --- # Setup ## Create a Facebook App[​](#create-a-facebook-app "Direct link to Create a Facebook App") 1. Log in to the [Meta for Developers](https://developers.facebook.com/) console. 2. Click **My Apps → Create App**. 3. Choose **Consumer** as the app type and click **Next**. 4. Fill in the app name and contact email, then click **Create App**. 5. In the app dashboard, go to **Settings → Basic** and copy the **App ID** and **App Secret**. 6. Add the **Facebook Login** product, then under its settings add your site's callback URL to **Valid OAuth Redirect URIs**: ``` https://your-site.com/?rest_route=/simple-jwt-login/v1/oauth/token&provider=facebook ``` 7. Save your changes. warning Keep your credentials secure - never commit them to version control or expose them publicly. Use separate Facebook apps for each environment (development, staging, production). *** ## Configure in WordPress[​](#configure-in-wordpress "Direct link to Configure in WordPress") 1. Go to **Simple JWT Login → Integrations → OAuth → Facebook**. 2. Enter the **App ID** and **App Secret** from the Meta for Developers console. 3. Set the **Redirect URI** to match what you registered in Facebook. 4. Toggle **Enable** to activate the Facebook provider. | Field | Description | | -------------- | ----------------------- | | **App ID** | The Facebook App ID | | **App Secret** | The Facebook App Secret | --- # Exchange OAuth Code for GitHub Tokens ## Overview[​](#overview "Direct link to Overview") This endpoint exchanges the `code` returned from GitHub's OAuth flow for GitHub tokens. Use this when your OAuth flow happens in a separate app and you need to obtain the GitHub tokens server-side. Enable **Exchange GitHub OAuth code for GitHub tokens** in **Settings → Simple JWT Login → Integrations → OAuth → GitHub**. note The `redirect_uri` used here must exactly match the one registered in your GitHub OAuth App and saved in the plugin settings. *** ## Endpoint[​](#endpoint "Direct link to Endpoint") **Method:** `POST` **Endpoint:** `/simple-jwt-login/v1/oauth/token` | Parameter | Type | Description | | -------------- | ------------------- | ------------------------------------------------------------ | | `provider` | `required` `string` | Set to `github` | | `code` | `required` `string` | The authorization code received from GitHub | | `redirect_uri` | `optional` `string` | Override the redirect URI saved in settings for this request | *** ## Request Example[​](#request-example "Direct link to Request Example") ``` curl -X POST "https://your-site.com/wp-json/simple-jwt-login/v1/oauth/token" \ -H "Content-Type: application/json" \ -d '{"provider":"github","code":"YOUR_GITHUB_AUTH_CODE","redirect_uri":"https://your-site.com/callback"}' ``` *** ## Response Examples[​](#response-examples "Direct link to Response Examples") ### Success[​](#success "Direct link to Success") ``` { "success": true, "data": { "access_token": "gho_16C7e42F292c6912E7710c838347Ae178B4a", "token_type": "bearer", "scope": "user:email" } } ``` ### Error[​](#error "Direct link to Error") ``` { "success": false, "data": { "message": "The code you provided is invalid.", "errorCode": 72 } } ``` --- # Exchange access\_token for WordPress JWT ## Overview[​](#overview "Direct link to Overview") This endpoint accepts a GitHub `access_token` and returns a WordPress JWT. Use this as the final step of the GitHub OAuth flow to authenticate the user in WordPress. Enable **Exchange GitHub access\_token for a WordPress JWT** in **Settings → Simple JWT Login → Integrations → OAuth → GitHub**. *** ## Endpoint[​](#endpoint "Direct link to Endpoint") **Method:** `POST` **Endpoint:** `/simple-jwt-login/v1/oauth/token` | Parameter | Type | Description | | -------------- | ------------------- | ---------------------------------------------- | | `provider` | `required` `string` | Set to `github` | | `access_token` | `required` `string` | The `access_token` from your GitHub OAuth flow | *** ## Request Example[​](#request-example "Direct link to Request Example") ``` curl -X POST "https://your-site.com/wp-json/simple-jwt-login/v1/oauth/token" \ -H "Content-Type: application/json" \ -d '{"provider":"github","access_token":"YOUR_GITHUB_ACCESS_TOKEN"}' ``` *** ## Response Examples[​](#response-examples "Direct link to Response Examples") ### Success[​](#success "Direct link to Success") ``` { "success": true, "data": { "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." } } ``` ### Error[​](#error "Direct link to Error") ``` { "success": false, "data": { "message": "The code or jwt parameter is missing from request.", "errorCode": 71 } } ``` --- # Setup ## Create a GitHub OAuth App[​](#create-a-github-oauth-app "Direct link to Create a GitHub OAuth App") 1. Go to [GitHub Developer Settings](https://github.com/settings/developers). 2. Click **OAuth Apps → New OAuth App**. 3. Fill in the **Application name** and **Homepage URL**. 4. Set the **Authorization callback URL** to your site's callback URL: ``` https://your-site.com/?rest_route=/simple-jwt-login/v1/oauth/token&provider=github ``` 5. Click **Register application**. 6. Copy the **Client ID**, then click **Generate a new client secret** and copy the **Client Secret**. warning Keep your credentials secure - never commit them to version control or expose them publicly. Use separate OAuth apps for each environment (development, staging, production). *** ## Configure in WordPress[​](#configure-in-wordpress "Direct link to Configure in WordPress") 1. Go to **Simple JWT Login → Integrations → OAuth → GitHub**. 2. Enter the **Client ID** and **Client Secret** from the GitHub OAuth App settings. 3. Set the **Redirect URI** to match what you registered in GitHub. 4. Toggle **Enable** to activate the GitHub provider. | Field | Description | | ----------------- | --------------------------- | | **Client ID** | The OAuth App Client ID | | **Client Secret** | The OAuth App Client Secret | --- # Exchange OAuth Code for id\_token ## Overview[​](#overview "Direct link to Overview") This endpoint exchanges the `code` returned from Google's OAuth flow for a Google `id_token` (and `access_token`). Use this when your OAuth flow happens in a separate app and you need to obtain the Google tokens server-side. Enable **Exchange Google OAuth code for Google id\_token** in **Settings → Simple JWT Login → Integrations → OAuth → Google**. ![Exchange Google OAuth Code for id\_token](/assets/images/exchange-google-oauth-code-for-google-idtoken-bd5d343b57d1f10eeec8f765d512b357.png) note The `redirect_uri` used here must exactly match the one registered in your Google Cloud Console and saved in the plugin settings. *** ## Endpoint[​](#endpoint "Direct link to Endpoint") **Method:** `POST` **Endpoint:** `/simple-jwt-login/v1/oauth/token` | Parameter | Type | Description | | -------------- | ------------------- | ------------------------------------------------------------ | | `provider` | `required` `string` | Set to `google` | | `code` | `required` `string` | The authorization code received from Google | | `redirect_uri` | `optional` `string` | Override the redirect URI saved in settings for this request | *** ## Request Example[​](#request-example "Direct link to Request Example") ``` curl -X POST "https://your-site.com/wp-json/simple-jwt-login/v1/oauth/token" \ -H "Content-Type: application/json" \ -d '{"provider":"google","code":"YOUR_GOOGLE_AUTH_CODE","redirect_uri":"https://your-site.com/callback"}' ``` *** ## Response Examples[​](#response-examples "Direct link to Response Examples") ### Success[​](#success "Direct link to Success") ``` { "success": true, "data": { "access_token": "ya29.access_token_here", "expires_in": 3599, "scope": "openid https://www.googleapis.com/auth/userinfo.email", "token_type": "Bearer", "id_token": "eyJhbGciOi..." } } ``` ### Error[​](#error "Direct link to Error") ``` { "success": false, "data": { "message": "The code you provided is invalid. Bad Request. Invalid_grant", "errorCode": 72 } } ``` ``` { "success": false, "data": { "message": "The code you provided is invalid. Bad Request. Redirect_uri_mismatch", "errorCode": 72 } } ``` --- # Exchange id\_token for WordPress JWT ## Overview[​](#overview "Direct link to Overview") This endpoint accepts a Google `id_token` and returns a WordPress JWT. Use this as the final step of the Google OAuth flow to authenticate the user in WordPress. Enable **Exchange Google id\_token for a WordPress JWT** in **Settings → Simple JWT Login → Integrations → OAuth → Google**. ![Exchange Google id\_token for a WordPress JWT](/assets/images/exchange-google-idtoken-for-a-wordpress-jwt-2d5965a501e739f01bbf8eecf2343801.png) *** ## Endpoint[​](#endpoint "Direct link to Endpoint") **Method:** `POST` **Endpoint:** `/simple-jwt-login/v1/oauth/token` | Parameter | Type | Description | | ---------- | ------------------- | ------------------------------------------ | | `provider` | `required` `string` | Set to `google` | | `id_token` | `required` `string` | The Google `id_token` from your OAuth flow | *** ## Request Example[​](#request-example "Direct link to Request Example") ``` curl -X POST "https://your-site.com/wp-json/simple-jwt-login/v1/oauth/token" \ -H "Content-Type: application/json" \ -d '{"provider":"google","id_token":"YOUR_GOOGLE_ID_TOKEN"}' ``` *** ## Response Examples[​](#response-examples "Direct link to Response Examples") ### Success[​](#success "Direct link to Success") ``` { "success": true, "data": { "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." } } ``` ### Error[​](#error "Direct link to Error") ``` { "success": false, "data": { "message": "The code or jwt parameter is missing from request.", "errorCode": 71 } } ``` --- # Setup ## Create a Google OAuth Application[​](#create-a-google-oauth-application "Direct link to Create a Google OAuth Application") 1. Navigate to the [Google Cloud Console](https://console.developers.google.com/apis/). 2. Create a new project (or select an existing one). 3. Go to **Credentials** and click **+ Create Credentials → OAuth client ID**. 4. Choose **Web application** as the application type. 5. Under **Authorized redirect URIs**, add your site's callback URL: ``` https://your-site.com/?rest_route=/simple-jwt-login/v1/oauth/token&provider=google ``` 6. Copy the **Client ID** and **Client Secret**. warning Keep your credentials secure - never commit them to version control or expose them publicly. Use separate OAuth client IDs for each environment (development, staging, production). *** ## Configure in WordPress[​](#configure-in-wordpress "Direct link to Configure in WordPress") 1. Go to **Simple JWT Login → Integrations → OAuth → Google**. 2. Enter the **Client ID** and **Client Secret** from the Google Cloud Console. 3. Set the **Redirect URI** to match what you registered in Google. ![Google OAuth Credentials](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABVsAAACiCAMAAABoIu04AAADAFBMVEX4+fpsdX3Mz9JQV16UlJQmNUQdIyf////i5Of29/d0fYTZ3N+8wMS1ur73+Pn19vd2foZ7g4p9hYz29/iKkZeCipHY2t3g4+WXnaSPlpyTm6CVm6Hl5+mprrN8hIuxtrvw8fNCR0ro6eucoqdyeoJ4gIeZoKZ1foWAiI+RmJ7BxMiFjJOgpqvu8PHO0tTz9PVARUmzuLzk5uhxeoJweIDy8/T19fXt7u/9/f2OlZv//v7T1tnx8vNzfIP09fbN0dS6v8Kho6ZveICGjpRtdn6epKne4ePKzM3r7O2Lkpjp6uwlKy9/h4/Q09avtLnGx8iMk5ns7e9ESU3W2dzLztBcYWRweYE5PkLb3eDt7vAnLTFrcHIiKCzJzdA8QUSxtbpQVFje4OKtsrd3f4chJyumrLF1eXyZn6Xh5OX6+/u5vsL5+fmboafAxMedo6jb3uHn6eru7/CEi5Lm5ueMkJLd3+LV19rj5Oa2u8Dl5uhud3+5vcGjqa55gomhp6zFyc2ChoissbbFyMzBw8Tp6+2Qk5WNlJq3vMDIzM+usLK9wcXa3N5SV1qTlpifpaqhqK2iqK3Dx8tXXF+oqqy+wsbe399GU2DDxsmXnaOgp6wqLzPGys7R09XU1daKjY+9v8BJTlKHj5Wqr7Wqra6orbI+Q0fAwcO/wsdydnh4gIg1Oz59gYOkqrCNkJKkpKR+ho1HTE+BiZAgJir29vdZXWC+wMKxs7RUWl9na26lrLDBxcmZnaCWmZthZmotPEpkanG6vL4sMTVaYGPv8PGKkZiIj5bR1Nd9ho13e36FjZRjaGsuNDhvc3ZMUVTnu7y9SUo1Q1Hg4uNye4TIysyFiIu7QkO2uLl5fYHi5eYzOTyytbalqKqAhIejo6OdoKJYZG/57+/uzs7UiIj36OjOz9BKVmNeZGqrr7GXmpv78vJVYWy1MzTz3t5daHNBTlxNUlVPW2ews7eSl5vgqanBVFXcnp/McXLIZ2izLS64PD33+PgoN0bhrK3epKRmcXu4urv+RnrMAAAACXBIWXMAAAsTAAALEwEAmpwYAAAUOUlEQVR42u3dCXwURaLH8eqg1QTi5CKBECAQIAchhAlhCSQEDYdJgMhluI8EOUWOLIZbOQQjIE8RBFFRFATkUgQVFUUi4IHifa/r6tN9u7rPfXu9Xd9Z1dM9kwtJYBJY+X0/H4aZnupjqiv/1FTXTEQgAMDfhL5Jjk1tCADwg9TYZDtbc8oEAMBPynKsbM3JoioAwH+yclS2zmlNRQCAX3uuZSIw1kU9AIA/uWJFYCrVAAD+lSoCG1ILAOBfDclWACBbAYBsBQCyFQBAtgIA2QoAZCsAgGwFALIVAMhWAMBFzNanZf+zPzlaTvY9uEZ2pvIBXJ7ZuuBPL3076OZKC6fuajNq3LOHa5OtL8gn1O2+9S+QrQDI1tJnGmj/UWHhg29IOaTNwaO1z9YKyFYAl2m2Br+kgvX55xs8U/5LCMMfluMeECLvMZ2OW3d0FmVL24x64nn1FbCHH96yfq7OVu+Sx+XS41sePiz2SO0BPSbQrc1B+fj1j9nZ+sX6LXLcZ5wEAJdTto5V0fqSEC81+G35bquU1zg9zzFvfHQ65Rk54fMh8k7x4Bg54fQWla3eJSpbD44+Kj/peux6+cncuak6W/O2vP7+cTlmhJWtneTwuXMn7+EkALicsnWRHhBYpG6fL7fwQymvdbJVvifEQ/KGweI9+bJ4Xw5RQ6oqW71LVLZ+LgpVh9UeE9DZmtVN3dmh4lln63ty3OFhXTkHAC6rbH2vga18v7VEyjucbB2ubj+THmtOy2+FeFRlq3eJytZ7xGApN5XL1tafr92inpvrGRN4Vd0d9TwnAcDllK2pdrQ+07DieGtn73irerxCjjm2YsWK33Z7X+4QqvPa37dEZeujopvO1ud1n9bK1vdl589W7HCyVcy+aa6UczgLAC6fbF3wkp2t1cwTeGbMUTsdg9fLtXPnju4sHrxBjt46SmWrd4kvWz+VB99faWXrUjnk2C6n33rt8blzd8kxmZwFAJdNtqbqaF01usFHY0XV+a391fxWexZV2dYho3asX6rnCcg3l1rzBJwl3mxNWS/VEzpbU3+Qo/Y8bGdr4fGDUu74lJMA4LLJ1nk6WiOoHwDwY7a+87oeaJ1H/QCA/7K18NsGxw/8aRHVAwD+y9aN31ac1AoAuPBsPaoGBEZQNwDg12x9oUGDyVQNAPg3WwcPG1ZI1QAAf3cAAMjWn9Khec3LNg05V4kW7YRo1bi6Z6pfeha9O4mf3obej09KXM9zvoqgZrWumrDGtVgccKJu6hxAXWRrhKH4fhLbXnUeO10UUbCkeUZNf87HJqWFrkvR9/KNyHLLlzSuabbenldpoXXUVZbWLlsrbaNitpYmlf3k5vSxV5etKYsPpA2Y2aKG2dr1lrDs4vzwc2Xr/IS0sHWDyVbg0s7Wu6smTC213D2sLK/XXTX8Ob+/4O7W/XJfsaKl/eLzylZRbS7Wylmy9Wz7ubqtOJ9sdW1rEpnScJO7Ztnq6p3buOus8ZHnyNbtS3q1XvBcENkK/DNka1BUsyZJkeJq1YltJrrFxYftFCJuXVRCP/XcVZvVzZEjIjaxS0SAEDH/IkSyES7aPzIoQa86daHzJ7jsAmJ+WM+Z6htbxh6IX6YyTP+cz8rt0nuNVSY4VG1ZZLYvVd9vmDasUbB3e83Urq9uGrJhyZIN9nvsJl1yS9R/3aNz1ZGJ9i1XDdgb7owJhBeFGRFldhnPUaulWbfEh8bohH5k1QB7KyNnxBt91ZLt3aeIW5/s0nykCqkE67jsh3Zh7zbmdWwfOilF78eVH2G0s7rjbn1sQVGbm0y3X2LQ5vsaNc8r2h0WYO3EOvagzYt76gMNXxYafyTcWr4zNMWumoykglWpvhoqig97zkjRIVpd6TDvK3HqOnNKl6T5nmz1Vre9rbiOUUmJtzkHa6+n69w+iwAuarYaJ8XAJLv3FnXX7MgBGSJuiecd8uDsTBE+cU1wQsduy9NG+LI1Mdizam97U06B5SEZsd03i6aNAka6s61szQxZPbJ04khdqNCwAuS++4To2DZ8YqkvP6x+68K9saXtPO93bx8x0t0+WB1ZhsiIn6N3F5yY72Rry4ShrsIyp4x11GrpLb1TI0Oni6ZGkcjZbW0l/ER0Q1GilowXYujuXt2KckVqdoeR96njsh86hZ1tNN40Z2jSIr2fyNBZrjzPH8C5va2wDsR5iUFpz+XNTJh026LdLl+/NXtDTpGqwpjcxi2i863FU7bbVZNaEDSnZWhXZ/WdxWtazPRka3Wlw7yvxKmbvk1mZyw5UaG6nW3F7Y4VyyY5B2uvp7PVPosALt546yMiKFflUB9PSk19V4Xm9L4irsguE7VT9DolInuqxW23+7J1oOfZR9TPcabaSLJTIFG9B041Mt0z1ZPtrWwNSlR3Nz+nS/fyvNfOTxQp7XqJI9GVslUnb5OB3qNrNUsE6eGD3Put3Q180snWLiXly9i56EpT3cadvUXTPllqFWsrI9pZfwihqaGWxKnjcoW0cKt9Bvfs5Dx0CjvZar2ljtb7aRwy0GXvw8pWVUXOS9T3G+tttov1ZWsTIbLUsonqIArDrMUn5qtesmEUC7eqAFdogLN6VAdVy55srVTazlbnldh140qbpTrPJ7zVrTnb0mfp5Cv2wTrrqTp3ziKAi9pv1YOFfW6zEiZAx63RXcRdbZe5u7uYESPG6q/Ripnhy9Z+du5ss96hGslOgWLVGRXGvEm6GxZhZet2a4vjPf3Wrna/9e74cLGmT3LFbI3XUX6r55BeKTCMgSJIRaGIXiTaq0+WzWpkZ2uZ0a18GTsXk/XSkt2eUVvPVoZF+OYf9LaOIsM5LvuhU9jJ1tlxYYaRa+1nWdLC5t182aqqyHmJ+r61ol0JVrZutqow09qsYS2ObmlVX7GYtFfvZLW3htR7+ZFWtpYvPaWlN1udV2LXTbKhLqWV2v3WbZ5Czrb0WSoZYB+ss56qc+csArhUsnVEqOcpb7amvDs7LVZ1lFTHqO92MX+d+qLtctka2afQk61OgUS1jRZG1xi1yfCeVrbOn+ndX/ASPQbYdXepiLJ++Bd5txfqXMvypOLHjTJyxCmVrTpDIm4VeoS2dIC33zq0fBmn35qtNvFc7/JbGfFuljdboz2jj251XC51XPbDytk6466mwZty7WtZN+dOqpCtzkusnK2hjX1VmO37O7ruVlmebHXrzmZYgLN61NW622v1W8uV3mmV9vRb7Vdi140rW+3mKk+2fryw0O63erblZKt1sM56qs6dswjgUsjWlupyvys33yVua+zLVrFu2yA9wLdatIifJTolhLv6lstWcWTJsDJRaiQ7BZYnlIm9ary1YJ7o4BlvzdutOmo3z7ZK399luZonkKvCWGeE+zXv9rbdWiFb+7VyiRLdb10YM2d8o2TRPmJWvwTfeGvzFFFY5pTRR22Nt8a5up6YXn4r4dtUb7nEs2TgganCFSA+LpgqNhidnIdOYWcbzXYKV5SVrfMaiqxmj1TIVuclVs5WfexOFRYllomUk55fJElNIrPCJxWLBV36idLQFGf1ncWZro6ebC1XWs8TCM7zzBOwX4lTN337irKEcvMEMjcFOduys9U+WHs9VefOWSzhehZw0cZbi73BMHWiulpetm53yKCActl60litu6ZRXSL01KVlq54cXz5b9fxWI/c5X4FFYT1ntFbvWsOMlkkZ1nWVjxO7nIqye2gBen5rpnBb7227LWzqbK90oZ4n4BsTWDwgatKTKls3xxnFao5B+6CQd/cGe+cJLAvV8wTsMtZR63kCi9VVclf5bFVXy3ta8wSsPb+WlqReZ0BE8Qx9nJ6HTmFnG4Whg6InWdk6YoBhrGpdIVudl1g5W/WxO1Xoch9o1yTGO791YUG06mOXFBcMauiroaL4gg59rIms5Utn3hfWJzR6pDVPwPNKnLrJnJIQccQ3vzW73arGzrbsbLUP1l5P17l9Ft25/FQAl+rnsvKyk89zzZDZF7pvZ9qoL8p/HvqdorUCl3u2Hjmvy80lLjF9lSBbqwpeI4Lj8mmtwOWdrZmGmpt+HrobBYmxZGs1UgqMkMVZtFaA72oBALIVAEC2AgDZCgBkKwCAbAUAshUAyFYAANkKAGQrAJCtAACyFQDIVgAgWwEA58pWAICfqWw1AQB+RbYCANkKAGQrAJCtAACyFQDIVgAgWwEAZCsAkK0AQLYCAMhWACBbAYBsBQCQrQBAtgIA2QoAIFsBgGwFgJ9ptl4r25jmDfKXVBMuXbRS/BNl64PXDx+19t/SrVZ7/FBOledTpEzx3LtHFxku5SdPjI50nv36A+oVda/mrdR8dMKoNpOfPsf2HpITvPfPfE/9og6ydcUY2X/CyzLFarXVqZKtQ948KMc8ZC156z/f+uCtv3xJ1aJu1aKVPi3lE4eGPFvTbP3yL2+dUc2YKoa/s/XHcfL1TLPHY8L7bmvwruEvvz7PNK+XS9dvOTo7Vmr/Wi5b7zDzDslx06zV//yPv3/wG2oWdas2rXSP3KduY01z2r42o9ZuUvePTdgiPzfvlKNff/lR844fRrX5QgewlP2tbf/mzN+/+58e1DH8na3XSrmxwkjWU0Pk6D39d9yoWu0NkyfIPSlbpdy68pcVstXcaLfjL7/64Lszf06namHW7TBrzVvpStn5zscy1Z1dcu3S4QfXqBwd8+zkZ1S2jnl48tOPynFL35SfDT0th6+8UxdP/+8z3/3jK956we/ZeoccU/EqwYdyrWmOlk/rHoF5TL5ZdUxAZasp5THrd/5fv//g669+R9WiTtWmlQbuGaP6pPvMblJ2Na+RH5kPy3tMs6vK1k9+YaoHh82hcohvTOB3X3195vu/8t4LddFvzanQar+w3l2ptnm9fNS8TnauNludfqvquf6NekU99Ftr3EpNc/amPVJOfdBTZL35hrxWL71Tnla3b3iWivLXsv72NTWMOhlvfbbCSNaHss1111332AOq1d5htdob9e//itk62zveCpj1Mt5a41b6Xom62SIf6CYPPqTKHDbflF94+q2vmrrf+oJa+Om0x+QPVCvqfp7A2nH2FVjPSNaulfsev87batWv+skrp1U/TwAw62ueQA1b6VLZ+dA4/f5/l1y/cuWElWq8dctWa7xVZ6sab9238vQhs0T233oP9Yq6nt8qh9gzB60rsK+O2zLh6Du+VnuNeg/1Y/n5rfLlZyOpTZj1O7+1hq30waU75LjTa9Q8gTuHjHri+GE130rNEzhkZ6v5fxO2jDv0gmk+K/WQLcBnXgGAbAUAshUAQLYCANkKAGQrAIBsBQCyFQDIVgAA2QoAZCsA/Gyztev+K4BLxv7M6lourRT16KMrf9of99YoW3+1kd85uHRs3F/dUlop6tEVV57LfTXJ1iuoSVxS7brGC4GLla33kq0gWwG/Z+t/pZOtIFsBf2frlfRbQbYCZCtAtoJsBchWkK1kK8hWgGwF2UorBdkKkK0gW2m1IFsBshVkK0C2AmQryNaztdpGAZ5/wKWbrbRS1HW2vl2wbvXqxafuveBszboroWBJ4lhPi42OrGa/0S2dex27q3+Gkd1q0P2cDtRjttamlT5VFFFQPCnyXLtdlETVo2q2vtisxd4/vP3275tHLr/3wrJ1Tkgj9wOl+WHpZ+8NVMrWpMiSDou7RHM+UG/ZWqtWGvXkhozIDcPIVpxHtv76fkPdfqNj9Zug1y4oW6PbzdH/iR7ed1sLokPi+wabprtJUFjPuNa6o2oYLXzZ2l3fe8fowAlBfWVrbVppeh/nTVXW3lYFUfPUnbzN7UPWLVBlFx0wnDWX6xVuovZRIVtfmf6i+j7BjPyYk/+uHiXOv4BsTe+Tb1YcycoMccfeNulED9OdvSyn6Wu3VOm3WtlqJjbnhKCesrV2rTT+Lvvr4HJnFqZsiJ9jZjbqu+AXy0eoslNyAr1r0m9F5Wx9cXpz/V+GytV7T+p7p+aff7bGGr0qtdrxiep+j7RC091e3dmQcJZs3R7GCUE9ZWvtWmmv+J6DFr9jmkPTdMY2v92MaeUJW3f2U6ZvTbIVlbN1vjUI8Ou9+vaR3+vbiKLzztY8o1OlVjvDsJSa7hNqYUAjshUXO1tr10rN9HemRxn55k5PmcXmjLae5W6dpt41yVZUztarBlnZOknftrSy9UT+eWdrj4XTK7XatlPsx+4mP5WtjAmg3rK1dq3Ukr8w/aZ4+743W3VZ75pkK6qMt86P07clekwgQ9+LK7qAa1m3TKx0lcA9UVRqtVO2V83Web53aUBdX8uqVSu1bDJuHGH089yPCUv3lfWuuaGYqkeVa1k71bWsbzKKYgaqmQIvrk64kHkCrfXslqFue3aL+pc1Mbppj9Sip3yttqh7j4pzsCIjbwqZwvlAvWVrbVrptCknIyOHhammGpWQMa31ohG+a1m6rHfNjJ7B1D2qzMFa/r/OHCyjwx8v+LMDaX2ihvk+8ZLTdkmXJptv9LXa21pVmINlfXZgGKcD9fvZgZq20h47o0PTtsUEmuaPyxLSkhLn6QlbE42wqZ6y3jV7rGIOFqr57MCMFuvUZwf+8FppIt8nAL5PAPDfZ17fXbc6aGafF/muFpCtAN+DBZCtIFsBshVkK9kKshUgWwGyFWQrQLaCbCVbQbYCZCvIVlopyFaAbAXZSqsF2QqQrSBbaaUgWwGyFT/zbL23Jtm6fyNViUvHxv3VLaWV4pLK1uY1ydbMX10BXDL2l1XX2GmlqEcfnStaJwbXJFsBABeGbAUAshUAyFYAIFsBAGQrAJCtAEC2AgDIVgAgWwGAbAUA1DpbU9OpBgDwp/RUERgbTj0AgD+Fx4rAssHUAwD40+BkERiYU0ZFAID/JOcEqmwNzBkZzpgrAPhFevjgwYFWtgYmx6Y2BAD4QWpsWaCdrQAAv/p/cjnYmO6sZjcAAAAASUVORK5CYII=) 4. Toggle **Enable** to activate the Google provider. --- # Shortcode ## Usage[​](#usage "Direct link to Usage") Place this shortcode anywhere on your WordPress site to render a "Continue with Google" button: ``` [simple-jwt-login-oauth provider="google"] ``` *** ## Customization Options[​](#customization-options "Direct link to Customization Options") | Option | Description | Example | | ------------ | ------------------------ | ---------------- | | `provider` | `required` Provider name | `google` | | `background` | Button background color | `#c8c8c8` | | `color` | Button text color | `#f2f2f2` | | `width` | Button width | `250px` | | `height` | Button height | `40px` | | `border` | Button border style | `1px solid #000` | *** ## Full Example[​](#full-example "Direct link to Full Example") ``` [simple-jwt-login-oauth provider="google" background="#c8c8c8" color="#f2f2f2" width="250px" height="40px" border="1px dotted blue"] ``` --- # Third Party Simple JWT Login integrates with four third-party WordPress plugins: **WPGraphQL**, **Two-Factor**, **Force Login**, and **WooCommerce**. Configure these under **Settings → Simple JWT Login → Integrations → Third Party Integrations**. ![Third Party Integrations overview](/assets/images/third-party-integrations-001da3c5c42b9df22c862432128fac0f.png) --- # Force Login Requires the [Force Login](https://wordpress.org/plugins/force-login/) plugin (or a similar plugin that restricts REST API access to authenticated users only). ![How third-party integrations work](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABVsAAAB+CAMAAAAN3jFsAAADAFBMVEX4+fomNUTf4eN4gIdsdX0dIyeboqf////i5Of29/dxeoL+/v76+vrk5efFyMu+wsX9/f3m6Onr7O7AxMeMk5mAiI98hIvw8fKZn6V9hYz3+Pm5vcHp6uyprrN2foawtbnKztDb3d/q6+1yeoKQl52Vm6Glqq+KkZfV2Nr8/P1QV17w8PHZ2923u7/j5eaVnKGzt7vT1tmepKmSmZ97g4ry8/R2f4f19vd/ho2FjJN6gonz9PWNlJptdn6gpqvc3uGTmqCssba7v8ODipGGjZTh4+Xs7u/Mz9KLkpj5+fl5gYjt7vDCxslweYHS1diAiZHd3+G0ub3Hy87z9PRzfIOHj5WWnaJud391foWtsrePlpy6vsLf4eKvtLi9wcWRmJ7N0NPFyczh4uSzuLxveICTmZ/R1NaIkJZ1fYXo6eyfparO0dSOlZuorbL6+/uXnqTAxMinrLF0fIR+ho3a3N7W2dzR09b09fagpavn6erQ0tWZn6T5+vqxtrp/h463vMCdo6nu7/Chp6yCipA1Oz7V19r39/h4gIjHys1XXF/g4uOlq7CiqK3Dx8rl5+llaW1ye4Pr7O02RFF0fYRweICprK/BxciEi5Jvc3VscHIiKCxBRklpb3aDi5Gcoqd1eXweJChKT1KMkJMxQE6boaaaoKWqsLXk5uh5gotFSk3JzM/Aw8ZeaXQ5R1Sus7fLz9EwPkzO0dTw8vNaYWdPW2eKkJego6V+goUqLzOOlp4wNTlUYGyws7Scn6OmqaxZYGVKVmPc3t97foItMzdPVFdmcHvu8PGyt709SlhDUF1xdnmHjpWYnJ5weYNobG44PkIoN0ZfY2dfZWxXXmRtc3l5gomtsLPIysy0t7k+Q0iGiY3Ex8lTWVyJjI81Q1FHU2CEjZVrdYBxdnxjaW+SlpgtO0o7QESVmJuDhoknLTG8vb9KTlI4RlRRVllqbnG5u71ibXh3fIJlbHJ2fIGKjpCytbZpc35aZXFFUl/u8fKCh42RlprZ2ttLUFN8hY6SmJ42QpyAAAAACXBIWXMAAAsTAAALEwEAmpwYAAAXSElEQVR42u2deVxV55nHL3IOTy6XnYt4kUVB2QKKgl4RNYCASEFRkU1RRGQREHdcg0q87qlWExON1nFtYrYPSZomNolkoVmapUvapNO0aTttp3tnputMZqbPe5Z7z73gTjuj/L5/HDjL+77P+55zvrz3PYf7mswAAAAGGpNY9DZfuAsAAMAAcKG5V3NrSLcJAADAANEdorg1pANNAQAAA0dHCLv1r+i1AgDAwPZc7zaZm9EMAAAwoEQ0m8wX0AwAADCwXDCZ70IrAADAwHIX3AoAAHArAADArQAAALcCAACAWwEAAG4FAAC4FQAAANwKAABwKwAAwK0AAAD+7936sPzF6z30PvkBnAQAwOBxa+Kybz/zrUcKn/Lc/k/yQ7zcI3/+Kpme3vNzk+kr8lfhVgAA3Gqk+3Ry8p5HfrwnObko9sbdqgC3AgDgVneyvp38SvxfTSZ72jeTfxJ7JbeOfPj9X7z+gBgC+FfTR/KjpoJj8np9TOB+WfCe5s/fmZ6XXzX9Un4xwnRxz2svvvJdk+nL8vFPPj6uuPV5+b71Ix8+furYNzbihAAA7mC3Lkt+ZKHJ9J2XTKbI/0i2ebj1vj179rzGbi19UX797WPyv5g2yK+zH+XIX8r3mXS39p4+Jv/29HeU1YfYvb9i935Pftj0O/nUe9+Qj/0zu/XYa68+JNz6RflnI02flx86/Yfvf4YTAgC4c926MPmZOv5x+se8+Ny/J+92d6vK502fsC5NL8lfMfXIxwp+dVz+6veULq3+LMs1JvCy/JuN8nHZ/zfyDtP3uf9q+i2n/rIsf1fp034sP8qFfUP+5OJCnA4AwJ3s1peSDYOggcnf639M4CExLvBLWb7fdFx+QP76i6/+Rn65X7f6y6ce4CNePiaXmt6Xv27iDuyj7Nb31fECWWwxjXiff3m9BycEAHDnuvXHyYdcKxHPfKt/t34if2wy/Vx+zWR6VX5Urn3v42NyncGtr8nf0dM8Kj/6ouO+4/JxE/db3xadVNFvPa669fmvnBJKtq//6L957AAAAO5Ytz7zTeXHI8nKj39LjuzXraWvaeOtpj/K/JTqJVmMEbjc+iv5+6eL1fXnxRDCe7IYDjCMt2pufeDiMZbr28+fPv0z+Q84IQCAwe5WU89v+T0B0TmNPMWrDbL8vNGtH/1CFt4VfCQ+97N7/8i/F4v3BEaYDG41ffXUqZe//jNZPvV2JE4IAODOdevbybEut3qMCQAAALilZ1mqWwOT/xPNBAAAt+7W0uRXxuhu5XewvotmAgCAgfnfAX7k/+QG5X8HhqKVAABgoP7ndXRLhCnxZJ//eQUAAHAr39WS/MxPeDEZagUAgAH7jsF1//XtV771yOkZaCIAAMC8AwAAALcCAADcCgAAAG4FAAC4FQAA4FYAAABwKwAAwK0AAAC3AgAAgFsBAABuBQAAuBUAAADcCgAAfye3AgAAGGDYrQQAAGBAgVsBAABuBQAAuBUAAOBWAAAAcCsAAMCtAAAAtwIAAIBbAQAAbgUAALgVAAAA3AoAAHArAADArQAAAOBWAACAWwEAAG4FAAAAtwIAANwKAAB3rluDo2+xgKFDbug4h+Rn3Oqxeit4+w98/D6BV9oTEtdn04bhVy5i2nAKGHsTxVCI7/VUInTYDdbao8QtPmWj6e93IdzkqQHgdnNr6jJe3KssRlyfW2dMMiZ6UlLZLnbl9l5fINpx1+3W9E6iXklZ9M6QpJIpKbxx0YmSD0d/dvUb2LFtcknjTv5l+twbiKsPkb436taWnisXcUW3Xq2YyWwre2p/Wz0zuFW31ubZb+UiGz/8ig2p7IJbwSBxa89BC4VPbuKFFH7dbjUmIvKXgm4unut2a2o20YhJYhEmip9XVd9LObs22XtnxV/VrUFH0/3txfXjrtetV+LG3Xo1btqt19w6IG4NHE+37Nar7IJbwSBxa9CRhTRiuZUXk3hMoHjy5GLeOKLLd2wWr1a13lusHjauvOxEsdOtxkRGt/JHwRHWiopO9bNpdbk1byHfTFVTwiglr6Q1ljrP8faoNuUjY1qlbQnLdJ5Pk+0AOVcF6rHks39UXna4smVknIXiLx7mxX5RPNHUcRsrxugeFfmHFvpa13KaDdWN6d28LeDE6lVBFLomiQ9YMN3NrVsrbalc0lTOOiqGKN/qO1+PkuMKqsloaguijmlFUpFDTxLNHXN/n7RRviIePWJyFifcqmfXMqmyZv44MSZgaD6h0jCu+6589zGBpPNdZecKnIn7K0ZrhWG8K1CMCWRta5KmUfN+74woP3WrXgM9ztDN+8rySkmviWDUCA7MSpa0E1Jcir4jdFR74SKlFvEJvunz9BJTlTwX2MqWR2itol4NCmpRh1aPod6mdXrBakgjw3h/ZmIgJx8maqmfvuDn4sr3VSnSVnZpp8YQNa0Pq5zGbTaH/1Da+VrSai7iyz3MZ7mjvhv3LrgNx1urh9O+4hpe7KDgilXba+MmUE/RrHlbrRQsbaXuXROUo54aZ65dPUZ3qzGRh1tLZvlt2au6VUqhlMoO8k5PotiS0I6cjJnbS7aQxbtUHLfEe+QhKytucXxBaViKc5XRjiWfou1UE6X9ARhCXZGFvNitFJ9Ysf3ifGcflfOn3LqsTu8k8pkcTktbedvi/Lp7N9Hm8+IAHkgwuFWUVOhya0T0g1m1E7PUXDiuVOvekPI06hwbQkP83DuUtp0FozkeLWLFSmpxBrcGH16flVqvutXVfIdWW8KHelNImcXdrVtSY2NPtjsT91eM3gqih8puDUpoj6S1NGR3R0/eInWrXgNnv7W+uDsmj/SaGNxampFv6Y3Vd4RK2oCKz8H13e1TnCXmcr/1sejPtldvVttWuxoEelFzw/xa2/Q1LSTNrWrnVLhVDTzJNjyrZXWVod+qnhpD1LH1AVn7K1xu1eJQ4ovnlIuyceuC29GtaWNpevAsXgSwDbYQJeykk9zxtESHBE9dQWTd6TxyQ67TrYZE7m61xD24QlsJLeSF9SnyTuT7PJ1zzGgg62OUkqHceumcWankt/EgK23RNH1VGQDQjvXhXuC6QjWv1gUdlZSzoEMKIR5vlepzqWqsGESQJLuSv1p6PvnUEK2QJpA3DwM8WUONC8R2i9RjcKtekuazleLG3bxEzYXjmsh9qTE2WpDQ3OfD+pPcfS8kPWLFSmpxBremLhf6UN1qaL5ddU/FJwQHlPfzLCukzMOt7sXoraC5tS5upp5Q5Ca26jVwujVBBLVCr4nBrXujEy28pu0ItepjAquIJkjdeonCrek8shsrRSitol0N4khnUduOTtqir2kh9XGrGngPn246aXSremoMUadyRZLKnG7V41Di68mw0HMjcOuC29Gtn8XNqyRH2TzWVnCleh/OV55OpSjDr6PUC/uzZZWSFON0qyGRR7/1KWtFntZv5VuG2nOVAbaoVSKrB+liOcXHKMdlbuIPoZJfg1JUtb4q0unHimFA5YYVfwDKa89RQ3ltkVo8k9soltuFW8UA3srCEklKJB+h/8P55M1dbL5VN+eo/db7DW7VS9J8dl4JYKmay9AhDvXJHDnO2sqiLO5uXaTEo0esWEktzuDWKNFTPqGNCbiab3zuqseqincM93Br0PmjUyVuPTe3uhejt4Lm1k3TlYQFPjZJsqpb9Ro43bpZDJqE6zUxuJVq8ipGz9N3OMdlfcRfoNX5eonCrZkzeJPUrLSKdjWII51FtUgHnGtaSH3cqgbe8g6vrjK6VT01hqiVNpvudKsehxqfLSU2zg+3Lrgd3epXkcYXcV5aETltUH7A9UqWJoddxSGWHS63GhJ5uJW7QKsyVbeKe276COX+TBVv9dgaqOOIvSlW7bfyrTdE8qvL0HqT6qrSjdGONbp1XVxbIDni2pY73Vo6dYzBrZGrU7ppTaLWBQtXtvGtGmpTxlsnBhn7rVpJcTzOuTyGFiw3PP3iuOpjteMsiUUteppY/SETx6NH7OrxhQu3atmlcrMElfVxa3H7ifBZ49cs9HBrcUJdRAG3npa4v2L0VsjQ+q0HlY8F2+KDk3Zb1a16DfQ4FSexrZ01IRq7m7u5Sjd1jDVK3+FyKw85dEjheolKv5UtGCLNVFpFuxoEelHmyfE2s76mhbRXdJGH9nFrTzT/hRpb5f4si0+NIWrRZhZuswU8wHRICtLjUOObE791Gu5ccHu+32pdzT2lttXjXTLdOWkjWRrc5BAdS1nRLrcaErm71cH9mwUJ6r1RMadj6WHVfYd8/ak2g0ccsrflqbdeQKbDsk3ys1jT+G2DvfqqMjipHWt068ypYrD36Opip1up7cNNdqrV3Oo/1EJrRb/1sDp0qN3AQV3Z/vaVFcONz7KWcEk7uKSE3ZQfF0O9RQ1snAKnW2Oy7eS3jkrtFD5pHMWrz8wdU3udltMjVqykFifcqmUXXNJMAfV93Bp50EaOyrggD7cGsmCWcutpifsrRm+FxhHqeGsjd/XW0rADZBllVbfqNdDj1N2q1URQtYM6Mq3UHEkrzlXpO1xuzQintFZnicp4a5iZVm1W21G7GpRPAFpR48tp/3h9TQvJfiSElvApyIl3c2uSbS7d76u6VdmlnRpD1JEHm0m8zDEuLMgyTQrS41DjC2matI7mxOLmBbehW5+U6vhZlbTS0FFteOdI3jA3Ocyd3Dp+mObWe90Sebi1WpJsdapb209KmQu1HuHazJIpkSIfSevWUNqarq2sOPOOXdFT1jtXyXWs0a2UwG8K0D5po8ut4v1WybpEy39f2OKoLnZrzNGKZd3OG5js2yZLUi4nnS4+Z25QxxeaSgK4JP9lhdWiRpHpvmsWxzrdakmdFFc4h3bzI/c2omUr1bKixAN8LR49YmEltTjhVj27FpuUk5fi6Vaq5M5X4zLP/x2YOf+5cuFWPXE/xeirMyrU9wTmnSzjh/JjMqa0R1nVrXoN9Dh1t2o1EdjPjsrkw+vCJKnVoe9wuVVrNK1E4VZaZCvb5tDaVr0a1L8RSlEtEzsoYuhTesFqSFS7OG8/n4KNE7X3BLTAgxul6nj1kZqySz81hqgbwqQcfk+Aalq7RGtocWjxWSda6Egibl4wCP7ndWXh9R13w+9ZDgD9vBwakbmKrvFi7RWxhCXdaHFKJ78A15ob53Zf8xDh1n7ZX4X2A4PDrduntN1WbqXwtIKbdetNFDfSQotacam5qNtCQ5rsN+3WgsMYDwCDw60hvuXht5dbiegf6NZqqWTZdlxqLpZKFfPX0s269bx3MZoQ4HuwAAAAbgUAAAC3AgAA3AoAAHArAAAAuBUAAOBWAACAWwEAAMCtAAAAtwIAANwKAAAAbgUAALgVAAAGqVsDRtPf96uu7vnCNQ8RXz19Q2GpX+ns8fVdVzveNsQ4O6CgIYFu+Du0rhHUAH7/FgDg/79b+Rv5h0bNvFKS/MeusCPSt1+3tjzNcxB8SVn8D8328vrBj1hzEbPf+ulbTf5Xd+vIx8984fcX+As7vYKv7VaPsJSJmK7qVnuq5xYxjd/AuVXk1retikfDrQAMWrfOtawLi7rhvK7g1qSf8jRIP3xLLL5Gs79EpW88S5ZLl1ocQ2qGXdWtdz39Qsj9n/7g0PW51YNru7V/Gw6sW/sCtwIwmN1K1Mkmybf6zufZrRxnfTNzEpwzIvPn3ODo89VnaUSX79gs6phWJBU5RDKeT4qnZtq8ryyvlGc2rcloalMnzXrch3qfeIEXXpHCrdTilXT+TYfu0Xcef9ev8fKZCu6fPvHcn384O4m3nX/zTZ5E+d0mccQbs41u9dlQ3ZiuTkelzwLdMqmyhr9GWQmrqvVe9YuTAzmWYZSSV9KqfUe999ausn1BzjppYwI++0flZYdrdRjGaQKTzneVnStwutXVBHnafIrN+70zotiH3jGtYas4w7RK2xLNj6GFvlb+zuegGJt01KzkxkF1nuM9UW3aTn/eGk3zfJpsYqpUQ1oAwKBw65b/3U8R0Q9m1U7MommFBZ/tcnermEW+p2jWvK1W6hwbQkP8XP3W+uLuGJ64NdW6N6RcnW8u+w1KXV38Bs15i4RbLS9cpvpGvY/qlc3mas+ve/dH7Nbfr1jx+3S654PZGzufLqCnF4kjtv7Fza2Tw2lpq9GtwYfXZ6XWq26VtlL3rgnOfmtsSWhHToY6uOHdle8fluask+7Wou1UE6XXQfQ0t6TGxp5s191qbIIPVbcO2d3Rk8eReS9OSqreREu8Rx6yan7Mrcvq9E6inK4eyxizkhsHtb1kC1m8S/WdSr91cXxBaViKW1oAwKAYb5We66WVrD3avMRyJJ9V6eFWnn/+ZCfPzBcdsiCh2W1MgA20gndP5N7eGJuyfe7TQbP3ZZ0Jmj2RxHir16/n0qVtPG+ol9ez7FaTmtj/DLuV+3JLLvM27tReOmD2mqWk/sDNrTUi+wkGt6aKWe29VbdO5bCsO51uTU3nCDPUuZ69Z/AUqF16nZxu5ZlU1xWSVgf9U3xIme5WjybQCSjnDHmi0a01lJ5LVGrw49B88l3rHBMQz7Ksj1FKhnOncOvGgzyf4aJpfdICAO70fmtQ6Ydr6byYZFpaapfMrCWPMQH+db6yO8Vx1lYWZXG5dbMyXbND2Skp2UV8sPPySHp25+XzSr9V8Cel3xrzrDq2mvTpZVZuEj3BWlx3hu75gRhI+BqdUaae2vprN7eyjuhwvsGtUZwrnRjnDEubolq4NUpM5zrqQdWtPIt3/mG9Tk63qrM6a3UQNgw6f3SqxLM2q271aAJBgY9NkqzOObkzN/Ek1pofVxaWSFKiWZrn5taL5RQfo+9U3Nqg5FrtlhYAMDjGW1fOpwXLlTVLPVtkeALtFb3QoS63lh/QDrckFrWIn7HOZ1lTw6neMBfnn19gW376gle+063tb5oMbo26NM5+v3Ar94Q7f6huY7dq460/cnMr63KCFC7cOpZnYQ7gfisXGFTWr1tTxedvm9Zv5RBbwvQ6ebhVq0MG27A4oS6iwOlWjyYQbIsPTtrtcms65zBE9WPk6pRuWpNIvj3KgRmaWzuO2JtinTsP8JY6rRtrSAsAGCRuXVE5rreItTSmgKbtIHNmAtmPhNASyeXWnZM2kqWBSu0UPkmZkdMxtdfl1phsO/mtU/N74QwPpnaeeZOcbvV79tImU9Knmlv3s0SzhVsvr0v5S7bTrfniPYHZH7S4ufXw+u72Kcp4a9UO6sjk8daSZgqo7+PWnHiiQ77+VJuxRXVrdlLSqDTS6+TuVq0OjZw0cLmYh1R3q374hmlkD1PdOuwAWUa53BqQ6bBsU/3oP9RCa7mBcrL9iMdbRW7K+63Z2/JcOxuOJpHFmmah8L3OtHPX4UIEYLC4ldKsFJnuu2ZxLDnO1Q8VD8lrF+ft73K5lRreOZI3jHbz6wFtaroo8Z6A5lZL6qS4wjnq9ge9xhO/JfCuy63i/dYPfvqnFtWj5mcvvaG4dd8Xzsxe4XQr3fP4Ga9frxTvtwpyFLfGHK1Ypr4nYD87KjNKvCdgk3LyUjzdunEivyewNrNkSqRaoHdo9MFVPMyp1cndrVodZlRIgTPnP1fucquzCc52nWhT3TomY0p7lMutlLama6vW99wXtjiKG4hfkeD3BJTcFLfOlYa7diY18nsC5h27oqesd6ZdFoMLEYBB+n9ZDQn/gGCeSOmzaeSZXLd1n8B+U0YX4FQCAAaXW5u8rhN2a99tLe1J2q9tV3DrSAstasWZBACg33r9/VZP+nFrtVSybDvOJAAA34MFAABwKwAAALgVAADgVgAAgFsBAADArQAAALcCAADcCgAAAG4FAAC4FQAA4FYAAABwKwAAwK0AAHDbufVCEJoBAAAGkqALJnOzA+0AAAADiaPZZO79HNoBAAAGkoK7TWZzSDcaAgAABo67C8zsVnNIrwNjrgAAMCAEOQoKzIpbzXc3X7gLAADAAHChuddsNv8N5g4RxywiXToAAAAASUVORK5CYII=) ## What it does[​](#what-it-does "Direct link to What it does") The Force Login plugin redirects unauthenticated users away from your site and can lock down the REST API. Enabling this integration **exempts all Simple JWT Login endpoints** from that restriction. This is necessary because unauthenticated clients need to reach the login, register, and token endpoints in order to authenticate in the first place - they cannot provide a WordPress session cookie before they have logged in. ## Enable[​](#enable "Direct link to Enable") Toggle **Enable Force Login integration** to allow unauthenticated access to Simple JWT Login REST routes even when Force Login is active. caution This integration only bypasses the Force Login restriction for Simple JWT Login's own endpoints. All other WordPress REST endpoints remain subject to the Force Login rules. --- # Two-Factor Requires the [Two Factor](https://wordpress.org/plugins/two-factor/) plugin to be installed and activated. ## What it does[​](#what-it-does "Direct link to What it does") When enabled, users who have 2FA configured in the Two Factor plugin must complete a second authentication step before receiving a full JWT. The flow is: 1. Client POSTs credentials to `POST /simple-jwt-login/v1/auth`. Instead of a full JWT, the response contains a short-lived **interim JWT**. 2. Client submits the interim JWT and the user's 2FA code to `POST /simple-jwt-login/v1/auth/2fa`. 3. On success, a full JWT (and optional refresh token) is returned - identical to a normal auth response. Users without 2FA configured receive a full JWT directly from step 1, as usual. ## Settings[​](#settings "Direct link to Settings") ### Interim JWT TTL (minutes)[​](#interim-jwt-ttl-minutes "Direct link to Interim JWT TTL (minutes)") How long the interim JWT (issued after the password check, before 2FA verification) remains valid. Range: 1-60 minutes. A short TTL (e.g. 5 minutes) minimises the window in which an intercepted interim JWT could be misused. ## 2FA Endpoint[​](#2fa-endpoint "Direct link to 2FA Endpoint") **Method:** `POST` **Endpoint:** `/simple-jwt-login/v1/auth/2fa` | Parameter | Type | Description | | --------- | ------------------- | ------------------------------------------------------- | | `JWT` | `required` `string` | The interim JWT returned by the `/auth` endpoint | | `code` | `required` `string` | The 2FA code from the user's authenticator app or email | **Example:** ``` curl -X POST "https://example.com/wp-json/simple-jwt-login/v1/auth/2fa" \ -H "Content-Type: application/json" \ -d '{"JWT":"INTERIM_JWT","code":"123456"}' ``` **Response (success):** ``` { "success": true, "data": { "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." } } ``` note Users who have 2FA enabled in the Two Factor plugin but need to allow API logins without the 2FA step can use the `two_factor_user_api_login_enable` WordPress filter. This is a filter provided by the Two Factor plugin itself, not by Simple JWT Login. --- # WooCommerce Requires the [WooCommerce](https://woocommerce.com/) plugin to be installed and activated. ## What it does[​](#what-it-does "Direct link to What it does") When a JWT is sent on a WooCommerce REST request, the plugin authenticates the request as the identified WordPress user **before WooCommerce checks permissions** - so you can drive the store with a JWT instead of a consumer key / secret. It covers every `/wc/` route: * **Classic CRUD API** (`/wc/v3`, `/wc/v2`, `/wc/v1`) - products, orders, customers, coupons, settings, ... * **Store API** (`/wc/store/v1`) - the customer-facing cart & checkout used by headless storefronts. This works even when the global **"All WordPress endpoints check for JWT"** middleware is disabled - it is scoped to WooCommerce routes only. Capabilities still apply A JWT only establishes **who** the user is. To manage products/orders the token must belong to an **Administrator** or **Shop Manager**. A customer token can browse, manage its own cart, and check out - but not edit the catalog or other people's orders. ## Enable[​](#enable "Direct link to Enable") Toggle **Enable** on the WooCommerce card under **Settings → Simple JWT Login → Integrations → Third Party Integrations**. Send the token in the `Authorization` header (no consumer key/secret needed): ``` # List products as an admin/shop-manager curl "https://example.com/wp-json/wc/v3/products" \ -H "Authorization: Bearer YOUR_JWT" # Create a product curl -X POST "https://example.com/wp-json/wc/v3/products" \ -H "Authorization: Bearer YOUR_JWT" \ -H "Content-Type: application/json" \ -d '{"name":"Demo product","type":"simple","regular_price":"12.99"}' ``` ## Store API cart & checkout[​](#store-api-cart--checkout "Direct link to Store API cart & checkout") The Store API (`/wc/store/v1/cart`, `/wc/store/v1/checkout`) normally requires a **CSRF nonce** on every write (add to cart, checkout). A headless, token-only client has no nonce, so those writes are rejected with: > Missing the Nonce header. This endpoint requires a valid nonce. Enable **Store API cart & checkout** (second toggle on the WooCommerce card) to let requests that carry a **Bearer JWT in the `Authorization` header** skip the nonce check. ``` # Add an item to the cart - JWT only, no nonce curl -X POST "https://example.com/wp-json/wc/store/v1/cart/add-item" \ -H "Authorization: Bearer YOUR_JWT" \ -H "Content-Type: application/json" \ -d '{"id":123,"quantity":1}' # Place the order curl -X POST "https://example.com/wp-json/wc/store/v1/checkout" \ -H "Authorization: Bearer YOUR_JWT" \ -H "Content-Type: application/json" \ -d '{ "billing_address":{"first_name":"Jane","last_name":"Doe","address_1":"123 Main St","city":"Springfield","state":"CA","postcode":"12345","country":"US","email":"jane@example.com","phone":"5551234567"}, "payment_method":"cod" }' ``` Security note The nonce is WooCommerce's CSRF protection. It is **only** skipped for tokens sent in the `Authorization` header - browsers do not attach that header automatically across origins, so those requests are not exposed to CSRF. Tokens sent via **cookie or URL always keep the nonce**. Leave this toggle off unless you run a headless / decoupled storefront, and always serve the API over **HTTPS**. For logged-in (JWT) users the cart persists by user ID, so no cart cookie is needed between requests. ## Requirements summary[​](#requirements-summary "Direct link to Requirements summary") | Requirement | Why | | ---------------------------------------- | ----------------------------------------------------------------- | | WooCommerce active | Provides the `/wc/` REST routes | | WooCommerce integration **Enabled** | Authenticates the JWT on `/wc/` routes | | **Store API cart & checkout** toggle | Lets header-JWT requests skip the Store API nonce (cart/checkout) | | Admin / Shop Manager token | Required only to manage products & orders | | A payment method (e.g. Cash on Delivery) | So checkout can complete | | HTTPS | A bearer token must never travel over plain HTTP | | CORS enabled | For cross-origin browser clients | See a complete browser implementation in the [Headless WooCommerce store (Vanilla JS)](/docs/code-examples/woocommerce-headless-store.md) code example. --- # WPGraphQL Requires the [WPGraphQL](https://www.wpgraphql.com/) plugin to be installed and activated. ![WPGraphQL integration](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABVsAAABGCAMAAADl97SsAAADAFBMVEX4+fr///8mNURsdX3MzMz/jBodIyfi5Of29/cOFiiZoKa6v8L3+PlxeoKTmqBud4Dd3t5/h4/x8vLp6+3k5eehqK7n6Oro6uvBxMhVVVWLkpjy8/XDx8yPlp3t7vB/goXv8PGdo6k5P0LV2NumrLGCiZHz9fWtsrgUHC7f4OPb3uGho6Ta3N/T1tmxtru9wcXt7/GorbNhYWGNlJo1Oj719vd7g4pXXF/R0tLO0tTh4uPq7O3e4OJ9h49KMyRvb3B0e4R1gImQmZ/X2t0oLjLV19iRkZFDUF59hY3l5+mTl5jf4uTOzs5IVGGGjpV6gonl5ui/wsUxOEgyJyXugxqrrKy1ur6gXR7+ihm1u795gIh2fobr7e5rc37g4+ZARUmepKx9f4FWYGyXnaSFjJN7f4q6aR0TGCccHCZsRCK/w8jM0NQ1Q1Dk5eizuLxweYHExsjj5OWrsLZlZWXM0NK9vsAvNDji5ec+S1jT09SGh4mNVB/EbxzDxsvFyc5xc3S6u7xESUwhJytLUFOprK8kKi51fYbIzNAwPkxtdn6JkZmLj5HS1NaepKvJyssbIzT7+/uVm6LeexuKkpu1uLmmYB6JjpZfZG2jqq/Q09YrOkmgpqxaZXFfa3Z5fYA9QkeXm51bYGNcXFwyQE5HTVtjbnpXOSImISWyZh1vRSG/bBz6iRkeJChTNyOCTiCpYR6Pk5W2trfKztFNWGWvsrNncX0pOEa4vcEkKS2wtLmtr7BfY2dnbXhDSlcjKjva2tv1hhk2KiUOFidXV1d7e3tITVClqrFRXWmboaiIjI+Dg4Skpac6SFWztrdoamwrMDQ8QlEpMED9/f0pIyY/LSRdPCI6KySHUSGTVx9EMCSIUSCfn6DY2dmUnaRTWl3Z2tt2en2mqaxyd3lZXmFscHI6QE/yhRohICZlQCIZITLIcB3ZeBuZWh9+TCF6SyBzRyHc3+GMjIxSV1o3Pkx9gYwkICbogBqYWSDSdhyqYh4tJSWam5ubnaApLziRlpomLDe3AIjHAAAACXBIWXMAAAsTAAALEwEAmpwYAAANHUlEQVR42u2dd3QTVxaHb2R4loyEXLAFNlZkbGyKCzbYOMEEUxIMBELbpdjAYmqIKQaDaMbBDiV0CAkdU8KS0BJ6hxRCAslC6qb3tullN9v/2PtmNJIsybYIMmfJ+X3nMJp5mmFGozmfr+67M4/0AAAAAg3Jic0yMRgAAEAAmGhp43BrhNVIAAAAAoKxTQfFrRExOBcAABA4YjqwW61WnAgAAAgkVhvpLZk4DwAAEEgyLaSfiGQrAAAEFONE0gfjNAAAQGAJhlsBAABuBQAAuBUAAOBWAAAAcCsAAMCtAAAAtwIAAIBbAQDgpnLrxPSFhZ+vXPl54cL0KJwvAMBvgfDi89n1PMg+Xxx+w9za629/Nbjxcl4vfCkAgJsc4+31quF24w1xa6/cFgYPWuTCrgCAmztoza5XLbNsde9WH2ZV7doD3w0A4KZFL9Uaalu1yhbqQ67Zen/+j9AM9fWu3127W2OGGaphWICfpd1OPICvGwBwg2CjZoffouArgg2tunanJszlALo16qyhWs56d2o9KUbw7oToSXRJVNCtQojy+Vtb8jvL1lUuaLZ9W4w/bi0YOb9buw/W8tytohkuAQBAHWQE2J+JtzhI9BG5Vu3Q6nR/YONWy8tuLh1/79i5Y+f80a1Py+K5/hQhiuljIU4TfSBuZTUuaF+xT1To6YF9Yt/8+eUixw+3WiqFeG6GEE/CrQCAOqKYe6xuceKjV6vYl1tDM969cOUg0YrLOzodVBanTTuounV6px2XI/x26xiXSMcd+KK+whqXXR/xXD+xGwvyEzH/qtFWLv6kqpFVuyznqmjP0Wv42gJqLUZcqhxBny0QV39uTXQnB7kV3T5Nlm5duv1qxXSij0S3Q5T4kSh/D24FANQNs9zCVp+B6yyfbm3SmqKmWWj6Cmu/HR9S6LOzo6bsuFu6NXvalIgXL/jr1nSXWgd8U19j8L3O1kmeW2wXn1Dl/EtixXQhohQ1GkcKYW8txJ2ONVqLEzO2llHFp7NZr6ekW2dsHSGaWdmtJ5pVinYxNEN8JLMRQmyDWwEAdQPbc5XLrat8JAW8863vskwTiS6sUBMBp1i1/OO9Z0/p1p84dDVmFPvn1oJzTom+NrC+G49rzecivBOuoWLkdNHzkniOlHwrUyaTA0SnhEzEsmblgcl0wifiM+nWtVRwgoPcduJKYo4Qt1mkVJUcwVa4FQBQN2TX5tZs3zkBnoycTndfzmjCIWzoDl48NVu6tUzKt8nd/rnVLSPwmFTqNwf27//XYJ754kutfQx5JVx7iiMx5ad/5nSrkm/dvvVIohRqX1q2dIbiVkWX27a3Y9W2l249Lz36X/73IlmFmEJXxWxeIbycE65wKwCgTniPe6tcbg33dut7Nbl12sFi413s1iYFRP9R4tbLB8nvvqxkV2Hrn6Va31JnZQQ7x1nmGuyVcJ3ByYD2V2W61aXGnG7itJ1ohOJWLiWg6WLBtn5XVLeuJXu5Erc+oLr1tJhRQolbZRoBbgUA1Ance3Xe5dbzPu7NqsmtGbdTRAa79dkXKSpDybeuuBJKxin+ufWMK2x9mH36mGP+bY5cB45zVrmSZ8JVJgOWCpludVPjx/tEeUX7bk63rhXdjiy9qrp1/tL2olm4y63FzYSo4DqB2WrgyyTjQgAAUKBrsJyBq632Giz5i7/M6db7p134aTa7NePUs1qdwJSyHWWz/XNrf2c/llRr/QEGwzuD9/zbYJjLC3do7/Unz4SrGEnUTzGse9h56HRl+YkPln7ocKuxTIh1ZY64tfLEpx+Sy61KfavgDIEzYbsMFwIAIOCB66xXVbW+ml1bCRYF8p7XFM2se2SKtf5TBsOX/PKOGsTud4a0Kde3Z3arz5rXbaKyL759AEBdYazxntdZVHdufcShVkeFwN5xhvGDlRKBQbxUQ41rYNxKR5YewbcPAKgzCurVgK0O3bpOUeeXa7TCKw5V9+8ZxInWb6u4dV0duRUAAH6Tzxh8VFGnDFIHz/kXT79+xmHTf/DCG063PopvCABAeDa23259RXmGwFMs0nsNu/fyyyBHccBbPP8XQ3WdWQAAAGpwq1Ld+jh7dK7Dp/XXvPm2jF3nKLrVWImzBwAA/rt1pVbYKmPUcf909Ghx8dWbcCsAAPxatyrlrWPZo6/LmV/2qHJ9wmA4UMWtyAkAAMC19mVJoz6tSvSNuT7dir4sAAC41hqsuYpbX3tz7BPfP214Q3Xrd6pbB8zdO+c6a7BCGlT7VuOG/rfSyXtM130KzH/4VZvF/R5XDwDgmu8dkDmBpx/fqzy29Ye3Vbd+rz5lUKZix3veO9C8VD+5K1FpkJyETQ1SyPOxx34Nq3WrXYqyVVO/WhWsZrtX2/tbeNJdmSRF6XS6w5E827SwaPHm9TW71RjbfWP393mmY2d/ztyieFw9AIBrvudVunWQdveA7MR62GD4QXkQ1viBqltTPNxKsRzJRebJySZuaBDte4+1udXPVoWW9/hw3mI92WcW8URnj9L1ikk/NoSOb4zrZZ2XZa/RrR1nNm0zYeZD/roVAACucQzt/g63VmGQ+sDBwXPl/Vpfe3VlsVtT2ZphUp1hpe5uDd40NCuBH9n9ID9OOyGpJYez+RRyMtbUhZdbRZv68LOuQjbFjubFfH6vpfz1/2PbyeY0bUNna8royW0bOVdmuvI7o5zNy2PD5NiHmRtL6GTu5hJK6k7sVqItSzJnRmoe7byld0ra0Z29L/JfgM1HCw8f4rbYLYt32SnlmAxE79s43N2tJWH5cX1uo1Te3hakJ2vIwrwJjl3JnIB6+MaTzYNMKbiWAAC1uNXkcuuaX7THCgzSHpRdX73zdYyXW1NMRuvQxFyjNcji7tbkUmv86OOaWx1xa96GqIYJFJOfZl2Ub6WQoRaamqBGqGxRi+mkNTNZ21BrnTg5zZqeFaOtLGnFcauz+R7HAImbQ6jjxSUhlNdZcWuvl1LjddrdFuaZw4lS06ypO5dRpK4pNS2ykLn7hF67mtPy55U1uie5ubWRubF1k9nl1tjIqK5hKequ2K2Ow++a1cpomYhrCQDgx7OxHRr9Tr35lfmW3bp7jdOzLexebtWbkxeFUJ/kRVnkmRNovNrDrVOJboumtC48P6oxhSTxWNvRTosOaeu+odY6iVc2ZpVoK2tudW9WiN1FveMb8CSdZL5VZzY2WMzNz+t0Q8j8kGOlhS9QZCG/FqaSeQlRWiH12aWauaGbWyfxYWfmOt063JTJnytO3RW71XH4yfkbjLiSAAB+jelyhzK46xevGQyvK4HrQKXYdfycv/PsgWe8x3Rht1Lb4+sbUPrx9XFV3BoVkhcUFO3hVs63xodRutLjdVJb1Cyavt59Q601QbbGpmkra251b1YoXRxVRNadUbocNSdAtEFnU0LSIWputXRLkU73EEUe5fmjcWReTjSvtzNujXRza0K6/GROt5Yoh9tW3RW7VTv8qaPNDa24lgAAtbk1gm/N2n0Hs1sZRFvOaeMNPDNggHz5qsCHW5NWj86hQ6tHT6ji1hcih2eW8oKJxyOIS6IJbm4dEkfOkixebKTFrbHuG2qtk+SGeSWebnVvVog5FstjIhyOfYk0t9oWR7q79aWLOcbO7NbePN87SWljt8Zv7Crzrbp497h1FMfEHLcOYf32DdInZ7kOV7pVO3weuiY6AdcSAKDWMbQvGmohnXy4dYMpn+uiTEH2Km4dNYHLm3jhkVL60ZREJc0znTK1DC1hL0Vpi+EPWtR8a24Kcb7VsaHW2tfUkhbJxGpVt7o3qxTuZOd13GlyupVSuU6AuhY53FrUiixF7NZjXSxddkZobqWO3edxncAu9zoBuymY+nG+9bYwvTEuSG+MPmmkiGSnWx2HH2ynxFFTKX4CLicAQM1udR/p1RdjyJdbEx+UMWRYPlVxa05W9OoEXmjZJbrtqCTK7CPrBBx+tHcx5cU2ci4mOCoCWkWbuU5A21BrjR89OdpOnm51b1ZZoruPdaqLdLlV1rfqesfGqG6dOnOzaZjMCZh1h0vI6Vaubz2mM3PioqPM0s4ktU4gKJ3rBGhq2+ap3JdlWz40P7rE6VbH4SeHcaIgnCZF43ICANTiVv2jNan1sN5rg6EbbraPHjnMu63z8zFebdKtAAAQELeS/ZXq1fpKhJeKm5oj/j8+UA+dn0i3ejVmvj/P0bgYbgUA1IFbKWZYdWo94x3bxYU1pt9C3OoLuBUAEEC3cieUb7W+gLMGAAC/3q2UcqaFp1hbnMHNnQAAcF1u5T5+cxW7fpWLoVkBAOC63cqU5p7tf65Fi3P9zw6dh/MFAACBcSsAAAC4FQAA4FYAAIBbAQAAwK0AAAC3AgAA3AoAAABuBQCAG+rWHhjsCQAAAoqxB+ktepwHAAAIJJkW0tva4DwAAEAgaWMjvb4gBicCAAACR3iBnt2q79AhokcwAACAANAjokOBXnGr3maBWwEAIDButdj0ev3/AHYKoXaS0OoEAAAAAElFTkSuQmCC) ## What it does[​](#what-it-does "Direct link to What it does") When a JWT is included with a WPGraphQL query, the plugin authenticates the request as the identified WordPress user before executing the query. This lets your GraphQL queries access user-specific data and perform mutations that require authentication - using the same JWT you already have from Simple JWT Login. * Authenticate GraphQL requests with the same JWT tokens used for REST API calls * Protect sensitive queries and mutations so only logged-in users can execute them * Works with any front-end framework (React, Vue, Next.js, etc.) or mobile client that supports HTTP headers ## Enable[​](#enable "Direct link to Enable") Toggle **Enable WPGraphQL authentication** to activate the integration. No additional configuration is needed beyond providing a JWT with your GraphQL requests. **Without a JWT** - the request is rejected: ![Unauthorized WPGraphQL request](/assets/images/wpgraphql-postman-unauthorized-53fa35671546ea05a662e0b92b58ef24.png) **With a valid JWT** in the `Authorization` header: ``` curl -X POST "https://example.com/graphql" \ -H "Authorization: Bearer YOUR_JWT" \ -H "Content-Type: application/json" \ -d '{"query":"{ viewer { name email } }"}' ``` ![Authenticated WPGraphQL request](/assets/images/wpgraphql-postman-jwt-12fdcb40ecfdc45c84a15ed7ec1ad5b2.png) --- # MailPoet The Simple-JWT-Login MailPoet add-on lets you embed personalized, one-click login links inside your MailPoet email campaigns. When a subscriber clicks the link, they are automatically logged into your WordPress site - no password entry required. The add-on generates a shortcode that you drop into your MailPoet email template. Each time an email is sent, the shortcode is rendered into a unique, time-limited autologin URL for that recipient. [Download](https://wordpress.org/plugins/simple-jwt-login-mailpoet) ## Shortcode parameters[​](#shortcode-parameters "Direct link to Shortcode parameters") | Parameter | Description | | ------------- | --------------------------------------------------------------------------------------------------------------------- | | `text` | The visible link text (e.g., `"Log in to your account"`) | | `class` | CSS class(es) to apply to the link element | | `style` | Inline CSS styles for the link | | `validity` | How long the generated JWT is valid, in seconds. Default: `604800` (one week) | | `authCode` | The Auth Code required by the Autologin endpoint. Find your codes under **Simple-JWT-Login → Auth Codes**. | | `redirectUrl` | Overrides the redirect URL set in Simple-JWT-Login settings. The user will be sent here after a successful autologin. | ``` [custom:simple-jwt-login text="Login" class="myClassName" style="color:red;" validity="604800" authCode="1" redirectUrl="https://simplejwtlogin.com"] ``` ## Installation[​](#installation "Direct link to Installation") 1. Download the add-on from 2. Activate the plugin 3. Generate a short-code 4. Insert the shortcode in your email templates ## Screenshots[​](#screenshots "Direct link to Screenshots") ### Configuration[​](#configuration "Direct link to Configuration") ![MailPoet add-on configuration screen for Simple JWT Login](https://ps.w.org/simple-jwt-login-mailpoet/assets/screenshot-1.png) ### Email Template[​](#email-template "Direct link to Email Template") ![MailPoet email template with Simple JWT Login autologin shortcode](https://ps.w.org/simple-jwt-login-mailpoet/assets/screenshot-2.png) ### Email preview[​](#email-preview "Direct link to Email preview") ![Preview of a MailPoet newsletter email with autologin link](https://ps.w.org/simple-jwt-login-mailpoet/assets/screenshot-3.png) --- # OAuth The OAuth endpoint lets users authenticate with a third-party provider (Google or Auth0) and receive a signed WordPress JWT - no WordPress password required. The plugin exchanges the provider-issued authorization code or ID token for a matching WordPress user, and returns a JWT that can be used in all subsequent API calls. Supported providers: * **Google** - via authorization code (server-side flow) or ID token (Sign In With Google) * **Auth0** - via authorization code ## Prerequisites[​](#prerequisites "Direct link to Prerequisites") ![OAuth Applications overview](/assets/images/oauth-applications-ec070789eef042ff44f165d00c451c83.png) 1. Enable OAuth for the desired provider under **Settings → Simple JWT Login → Applications**. 2. Configure the provider's **Client ID**, **Client Secret**, and (for the code exchange flow) **Redirect URI** to match what you registered in the provider's developer console. 3. Optionally enable **"Register user if not found"** to automatically create a WordPress account when the OAuth email does not match any existing user. API Reference Explore and test this endpoint using the [interactive API reference →](/api/v4/oauth-token-get.md) ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHODS**: `GET` or `POST` **ENDPOINT**: `/simple-jwt-login/v1/oauth/token` **URL Example (GET)**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/oauth/token&provider=google&code={{AUTHORIZATION_CODE}}` ### Parameters[​](#parameters "Direct link to Parameters") | Parameter | Type | Description | | ----------- | ---------------------- | ----------------------------------------------------------------------------------------------------------------------- | | `provider` | `required` `string` | OAuth provider slug. Accepted values: `google`, `auth0`. | | `code` | `conditional` `string` | Authorization code returned by the provider's OAuth consent screen. Required for the code exchange flow. | | `id_token` | `conditional` `string` | Google ID token from Sign In With Google. Google provider only. Either `code` or `id_token` must be present for Google. | | `AUTH_CODE` | `optional` `string` | Auth Code from the "Auth codes" section. Required only when "Authentication Requires Auth Code" is enabled. | Parameters can be sent as query params (`GET`) or in the request body (`POST`). ## Request (POST)[​](#request-post "Direct link to Request (POST)") ``` { "provider": "google", "code": "4/0AfJohXmX...", "AUTH_CODE": "MySecretAuthCode" } ``` Or using a Google ID token instead of a code: ``` { "provider": "google", "id_token": "eyJhbGci..." } ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "data": { "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...", "user": { "ID": 1, "user_login": "myuser", "user_email": "myuser@example.com", "display_name": "My User" } } } ``` ### 400 - Missing parameters[​](#400---missing-parameters "Direct link to 400 - Missing parameters") ``` { "success": false, "data": { "message": "The code or id_token parameter is missing from request.", "errorCode": 71 } } ``` ### 401 - Invalid code or token[​](#401---invalid-code-or-token "Direct link to 401 - Invalid code or token") ``` { "success": false, "data": { "message": "The code you provided is invalid.", "errorCode": 72 } } ``` ### 403 - Provider not enabled[​](#403---provider-not-enabled "Direct link to 403 - Provider not enabled") ``` { "success": false, "data": { "message": "This Oauth provider is not available.", "errorCode": 70 } } ``` ### 404 - User not found[​](#404---user-not-found "Direct link to 404 - User not found") ``` { "success": false, "data": { "message": "User not found.", "errorCode": 74 } } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL - Google code exchange[​](#shell---google-code-exchange "Direct link to SHELL - Google code exchange") ``` curl -X POST 'https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/oauth/token' \ -H "Content-Type: application/json" \ -d '{"provider":"google","code":"4/0AfJohXmX..."}' ``` ### SHELL - Google ID token (Sign In With Google)[​](#shell---google-id-token-sign-in-with-google "Direct link to SHELL - Google ID token (Sign In With Google)") ``` curl -X POST 'https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/oauth/token' \ -H "Content-Type: application/json" \ -d '{"provider":"google","id_token":"eyJhbGci..."}' ``` ### JavaScript - Google code exchange (POST preferred)[​](#javascript---google-code-exchange-post-preferred "Direct link to JavaScript - Google code exchange (POST preferred)") ``` const response = await fetch( 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/oauth/token', { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ provider: 'google', code: authorizationCode }), } ); const { data } = await response.json(); const jwt = data.jwt; ``` ### SHELL - Auth0 code exchange[​](#shell---auth0-code-exchange "Direct link to SHELL - Auth0 code exchange") ``` curl -X POST 'https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/oauth/token' \ -H "Content-Type: application/json" \ -d '{"provider":"auth0","code":"AUTH0_AUTHORIZATION_CODE"}' ``` *** ## Features[​](#features "Direct link to Features") ### Google - two authentication paths[​](#google---two-authentication-paths "Direct link to Google - two authentication paths") ![Google OAuth configuration](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABVsAAABGCAMAAADl97SsAAADAFBMVEX4+fpsdX3////7vAXrQzU0qFNChfTi5Of29/fMzMwdIycmNUT3+Pl1foa1ur729/js7vBud4ByeoKZoKbX2t2hqK1vovWTm6B+h47g4+W8wMXz9PWepKna3d/n6evk5uhVVVXv8PGCipGQmJ6XnaSJkJbq6+2xtrvM0NPDx8zd3t6GjpR5gonJzdDw8fNzfITh4eOcoqd7g4pweIB8hYzz9ffe4OPx8/Tu7/Dm5+l2f4jT1tnb3uGepKvW2NrO0tWNlZv19veorrPm6Oqco6jr7e6/wseqr7WLkpi6v8K5vsKPlpxhYWG2vMB4gIdeYma7wMTS0tLBxMhvb3CLkpmRkZHIzM+rrKzFys7d3+KFjJOBiZGAiJCwtLnb29zi5OVydnc1Q1G6u72mrLKjqq+lqq/Cxsqzub3R09fp6+woLjI8QkZXY27tXFD7+/vx8vKxtbqWmZplZWWjo6Tb7eDf39+1tressbZtdn5qdH9daXRKV2PU1dXFx8gxQE7Pz9BQVFh9f4CtsrhZXmG+v8CBg4TtUEOIsvaVnKOIi45GUmAtMzc8SVdPW2eHh4iipqpcXFzJysujw/eKy51eunb49fE4PkEyNztFSk1obG5ATlyfoKKYnqRUWVvBwsRLUFMgJir62nz10M5KsWX535LwfHM7q1n23dz0wr3ual9lvX337e3k5eVVkvVlm/UkKi52e31lcHvf4uSur7ArOkkvPUxkaGzxj4fxl5HrSDvo7/r0tbDA1vio17at2rrudGnzsq2syfj6zVfg6vnNzc57e3vl5+qMkJJqbnFXt3A+rFzO6NdOtGqAuVlzwonm8uvf7uX7wBb53Ia94cez3cBIrXL4qRz54p3zubXzq6WCrvb11tSss7lqa2uMjIx4fX/ZxkX57cr6zEJgsJxLmMDvb0348t/7yj3468OX0aeW0aZYsFjuY0n5wRqtvk1Oppfu0ma33sLxfEN/x5PyiEDV69zxxC9Aid7K2/jviH/34OBRlOJHiPSVuvf0yMXe6eNGFrI9AAAACXBIWXMAAAsTAAALEwEAmpwYAAANv0lEQVR42u2dCVgTZxrH36lSYUhISMIShCSGSxQCSkCgUOUUlUNUajkFb0S8rbfWeq33Ua1az9a2HtvWarX39thW2+723B673e21933f5/PsO5OZJECwUSNi9/97HkPyffPN930zPD/evPPNSMEAAAACDUkvdqutDwAAgABgs2Yrbk3UawgAAEBA0OgTZbcmZuFYAABA4MhKZLdm63EgAAAgkOjtFGzV4TgAAEAg0Vkp2IZkKwAABBSNjYL74DAAAEBg6QO3AgAA3AoAAHArAADArQAAAOBWAACAWwEAAG4FAAAAtwIAwA3l1hMvPfXirA29N8w69dBJHC8AwJeB1EcmjAnpwJgJj6R2n1ufO9Xbiw1PncBJAQDc4GgGhXTBIE33uPWlWb078tDHODEAgBs6aB0T0iUr7N3g1odP9fbF0zg1AIAbF52k1oHZs2dnD/Qh1zF+Ra4Dy10/b7v9Ctx6bENv37z48JXOaagoDsKZBQBcT+5ggc65SWaOjwi2g6PG9WPWB9KtJ5/p3RXP+do+58z+1n2HNw2CWwEAPZhs9mfWTQpZPiLX9v9bwLhJAY5bP+rSrL2/51ObW0Rx79FW8Xa4FQDQg5kQEnLHTW7u6OzWgb7cOrD84MVPFxHt2r5z3CL54/z5i1xuXTdu5/oZfrv1RPuoddapWc9cUq26o+JeB19+W7mCe319b+vqqVx4ZO2WfWt38Zt5M/fd2yyOdrlVs+Bo68y7SnCKAQDXgRUhIXM8bp3j43KWT7f2W0DW+TNo3a7sIzsn8Mft1pU7L0huHTN/5YwFF/116z1eCwRePPkvuezjp+UE7Eu+hyuKB5W3tfvE1c2PiWU0SRTvHS3et5J28Ju1j6lu3STOXL+WPwAAQPdzZ0jIbI9bZ3d2652d860HWabRRBd3uRIB5/gjR6rz5klu/YxDV015k59ufdoTsR7zlD78VBe5VqJForiLmkSRnblJ3E90UGylw+JdRK+LT9Jq8XOitYpb59wnTqLMVtGBcwwA6PluneRJsN61ji6sL+/HIezAnfzx3HbJrc2SfPtd8M+tJzzLWe9pV3Hyoy6GmyuK50j/2lEWaDPblNaJYs5ecR7Jpp0pvTmjuHWC6GIHzjEAoPsZ+kU5gaGXcuv8RU2a29it/TitOe82ya3rF5H/17Je/qmqVn+Hy/nWmUkugfJ3fu5U3MJxazPRaDlu5TerFbdm3ifOO3LkyKIJOMcAgO6H78ma4HHrhC9ahNXBreWDaEb5Ajn9mlMu51t3fTqQrzT559af9er1F1dCwP+VrCt4ncDMtXtZoLVbfOVbP/fOt256bf1jQ3COAQDdz5wLXoFrdme1XsjqnG8d53brpPkXP9vObi0/d1hdJ7CyeWfzdv/c+l6vXr2+I124OnYZA25q3t8q7l8/VlkncI6LVkrrBBzyOgHxjJQqcK0TmLq6de/hJ7FQAABwnQLXFWq21ce9A0107e55/XkvSa6/6f3PAE2lgD2q2y9uwkkFAFx3NJe853UFXTu33tPLxZ+OBagTfeuZ10aL+2pxUgEA15+SkEtwLZ/V8gvFrd/2Krv7K514xe9OojnrOrMZd2QBAP6vnzH4XcWtL3uVffXmTnwdZwgAQHg2tt9ufU9x6/2Xdus3cH4AAMB/t96vuPXBS7v1bhw9AACAWwEA4Hq69UH/cgJwKwAABP5aFvKtAABwGW794aXXYD2quPUf3TTEsZGXsXGl51bamLBrMJikhCtrZxzp/enyh7atCr+rANzoblXuHfjtWx/4bHJaceuz7UpjB7jfDv4Cc6RYOhTkJmgN1X39devj+WnauCK5nTDdq1zu1sutDpPfI2rP9Dh+McsvNT7cqheEJbFVV+VWHtpwH38xzKGhE5fWwq0AfEndSj+S1Pq3Xwft8dXiFUWtj1Kg3JrkHFVkHxqR6J9bbYY1JUWTtdLWMZUNl3Brxyq/MRk0lJii5Rch0adbrZljwx1X41bGp1tvIdPZbXArAF9Wt0oXs34QxDzvo8V/Fbd+v5Nbq8oOJdSZaKQgCPGUN8KQzA5NjTfUVSRQlLYw31hQ2JB2qIjiuX6kWs/oMlRvZEZo0/tL8WidM99GFJVgiIwold2qN2ozhiuWKpZeI6fw7V6GpHDeRf8IIrugc3VbOTY2bYpO/eIdpS3NNw9XRmSNM8QmyTWWSt7CEav2p+yAjDFlDZKadU4L1RSP4Bez2qiqbGPCqFSjPBd2K1FcqTwlqqk3ROopOyZFSEnVNMYKhlypgxy2c4SWqLhCHbkxIsEQpydlk5iwITwkLekWp2un6rzdSo7QaCoKn3hgMjv+lq1b6/mRPBWbJ1Yrbg0vW7aqIXvpqjaOyaOWPbF8FBfdsmxzrtICANCj3cpJgd9Jag06vrBz2Pof37dlSW4VWqilzhUlZmn76sdX6qnYWGRKZrcKc9mF020240ZX3KrWS9/xhWhlHxHJNlP6KLI5q7IL07MKMsL0jjSXW8siikxmWVtkkP04wMz/0jXxUzxqdMWtZXl5ZofbrcIaKqkskasKGnboBzjz5KqMYUTxYWp/bremKP+fWH4YTRm+mOtj1EZVAncek1CUm+Jyq7WyRp6SKSVJv2YETY/MIUu0KT1PM8Mm7yE9j8zmKErJU0duNCSVbKwmZRMemhy39q+25EQ2ertVk3+AaFnGEMfmAZRUaq3ZFkOW85OtKecVtx6YZtm2ubBPWjhlbk4p+uT8MArfGuVuAQDo0W6lP7wV5OLNdzrUZJ72nRKQ3TqCY74lBbLJ+krpyvixGie7pq/k1kzXZjlpLrcq9fLXbAO/JAuCQ+PkaGx4spzv1KQnmdKlKFV2a5OhgGhUjLR1liBHu7nhLNxScqQVdHArW7N0sdutS7jb6ha5ysSbUnGhXDW9mFKdJWp/breuUebSGEn1UUn8MlZtJE1NI4l5upxvFQSjRp6SkRO+Gm1ORYL0WDKLtkW9F7m4IttcWsXhqzpyI/8RKBFKlE1Ut1byAGozvPOtoRNryLSK93yrVi4qPEsbz/KfpVWKW6u5zzY+ZgfIsYr/JKXVyUXeLQAAPdet7wapPNA+cn32dFcrsCS3xvPPJYmyyQolAQlz7QLfnzteyglI37Unxy4R2GGSW5V6qWWeID+K1uywCxzHDk2hyewhKuvrSOYfU2S3Jslb58sdpalxq1WopQKDo4Nba12BrJoTkPZUI1c56qVAcbBcZXVGDy8jtT+3W9WcaK5Br6XUNL2QozaSpmYX7PJc5JwAufadLA8sN9WYkTZZQ4vrwiP1rmzqxvERwwZP84zcWCENPU/ZRHFrqlwpeMetlrZ4qgiVWEZDwg+EhrZRfSxXLVfceitH90tZphMpbDl/jguXi9QWAICe7Vb6lVuuQb/0egj3+z9W1fpoZtduLWaTVRS7Hjfj5ARmheLW4QmWrCJ2WLrFXS9HooYql1s1nOeksRy3SiFdRpKJryZRpOxWS7qnI3e+tb8spo1UwfGsjXdbrF7L6uzWYjlu5d3FuOJWKhtQPZbU/tQduN0aHd7IU6lrTHE3kqYmzyWsvVsjh6vP1WlJkTIRtdWurGcfw5QBqSk7wtwjN3J5tnxpTNpEjVudNupwLYtM518dttX10ZBhyixto43sUt2qTm51rOJErbZOLlJbAAB6uFvpmx65fmv3C29IRQs/4MIP/97FQ7C83FrIbpuRwuFlbREVx5A9WXHrSLbiXHZYco2nXmI8rxOgJq2DIoyarATOtxqG0Pj06IKMAfS4QXarZkQjX7W3eNYJTNWWUIYUCprC7cPMOk0M71bqtgu3SlUFDX0pR+vKt9K0ZCcH1Ep/6g481/JHpPFFoqlpg92N5KnF8Fwa2ru1xdxEmiQy2SnRPKypD2UeKnXtISVtBiWkWdwjN6YnUmM+KZvw0JJiOVmwJs5O0S08YpvbrXQ2QdcWp6M+SbR0MumWtZHlCRNNCe3k1szNU6h2YotcpLYAAPR0ty48HuTN8T0PqKb9iY9FAu3d2lTJV+Wb4gwZZTZeJ+DMCMt3iSgrOSFScuv4cF4noNSr61uF+sZo13V7DhSH1jmreVRRyUJ+RKN8LcseU6mtVtwRJa1vtZHJKT/DNnYkLc6vl3Yrd+vbrXKVtcwQO0wZbapzsLougftTduBxa6mU1K0ReMmt0kieWqqxIXZqe7dSUrKzLp6maQVhKlnM/O1feUaZkbOohU6Ne+TGNbHhcSXqJjy0gmReJ6CZbjYk8EoFZ4vHrdOeyNbfsnViWwXlbm1bWs/J1Yrly8M75wTocV4nUOUqIqUFAKCnu5X+GNQVv7/55tOX1cfImCsf36Fp12beZgR5AIDr4VZ6/3hXcv3w38/6vX+blRIbcq9sbJZovvRuvybTdmRoet65OBt6lXyC32cAer5b6Y0HunDrnnf933+uIGSMusKxzRXCk4dek1kn15tw6gEA18et9M4en2rdjaMGAABX7laiFzqHrm//FQcNAACuyq1s13ax65u7F+KQAQDAVbuVV2M9v/trzNt/3v08xAoAAAFyKwAAALgVAADgVgAAgFsBAADArQAAALcCAADcCgAAAG4FAIBudatNg8MAAACBRGOjYKsOxwEAAAKJzkrBdj2OAwAABBK9nYKDE7NwIAAAIHBklQSzW4MTExNf7QMAACAAvJo4oyRYdmuw3WrD8QAAgEBgs9qDg4P/B0zWkQrxLSxJAAAAAElFTkSuQmCC) **Code exchange (server-side flow)** The standard OAuth 2.0 authorization-code flow. Your front-end redirects the user to Google's consent screen with your Client ID and Redirect URI. Google returns a short-lived `code` to your redirect URI, which you pass to this endpoint. The plugin exchanges it for a Google ID token, extracts the email, and issues a WordPress JWT. Requires: **Client ID**, **Client Secret**, and **Redirect URI** configured in plugin settings. **ID token (Sign In With Google)** The Google Identity Services library running in the browser can produce an `id_token` directly (no server-side code exchange needed). Pass the token to this endpoint as `id_token`. The plugin validates it against Google's tokeninfo endpoint and issues a WordPress JWT. Requires: only the **Client ID** (no secret needed). ![Exchange Google ID token for WordPress JWT](/assets/images/exchange-google-idtoken-for-a-wordpress-jwt-2d5965a501e739f01bbf8eecf2343801.png) ### Auth0 - authorization code flow[​](#auth0---authorization-code-flow "Direct link to Auth0 - authorization code flow") Your front-end redirects the user to Auth0's Universal Login. Auth0 returns an authorization `code` to your callback URL. Pass that code to this endpoint. The plugin exchanges it for an Auth0 token, extracts the user's email, and issues a WordPress JWT. Requires: **Client ID**, **Client Secret**, and **Redirect URI** configured in plugin settings. ### Auto-register on first login[​](#auto-register-on-first-login "Direct link to Auto-register on first login") ![OAuth on Login / Register](/assets/images/oauth-on-login--register-913f2c5713fec154bf0fc8671bb7c754.png) Enable **"Register user if not found"** in the provider settings. When the OAuth email address does not match any existing WordPress user, the plugin automatically creates a new account with the default role configured in Register Settings and returns a JWT for that new user. When this option is disabled and no matching user exists, the endpoint returns a 404 error. ### Use `POST` to keep tokens out of logs[​](#use-post-to-keep-tokens-out-of-logs "Direct link to use-post-to-keep-tokens-out-of-logs") The `GET` method appends the authorization code and other parameters to the URL, which may appear in server access logs and browser history. Use `POST` (with parameters in the JSON body) for production flows to avoid leaking short-lived codes. *** ## FAQ[​](#faq "Direct link to FAQ") ### Can I use OAuth without enabling JWT authentication?[​](#can-i-use-oauth-without-enabling-jwt-authentication "Direct link to Can I use OAuth without enabling JWT authentication?") No. The OAuth endpoint is part of the Simple JWT Login plugin. It requires the plugin's JWT configuration (secret key, algorithm, payload options) to be set up, since the response always includes a signed WordPress JWT. ### What happens if the OAuth code has already been used?[​](#what-happens-if-the-oauth-code-has-already-been-used "Direct link to What happens if the OAuth code has already been used?") Authorization codes are single-use. Sending a previously redeemed code returns a 401 error from the provider. Direct the user through the OAuth consent screen again to obtain a fresh code. ### Do I need to set up a Redirect URI for the ID token flow?[​](#do-i-need-to-set-up-a-redirect-uri-for-the-id-token-flow "Direct link to Do I need to set up a Redirect URI for the ID token flow?") No. When using `id_token` with Google Sign In With Google, no redirect URI or client secret is needed. Only the Client ID is required in the plugin settings. --- # Protect Endpoints The Protect Endpoints feature lets you require a valid JWT for any WordPress REST API route. Use it to lock down sensitive data - such as user profiles, private posts, or custom post types - so they can only be accessed by authenticated callers, optionally restricted to specific WordPress roles. When a protected endpoint is called without a valid JWT, the plugin returns a `401` error immediately, before WordPress processes the request: ``` { "success": false, "data": { "message": "You are not authorized to access this endpoint.", "error_code": 75 } } ``` If a valid JWT is provided but the user doesn't have one of the roles required by a **JWT + Roles** rule, the plugin returns a `403` error instead: ``` { "success": false, "data": { "message": "You do not have the required role to access this endpoint.", "error_code": 114 } } ``` ## Settings[​](#settings "Direct link to Settings") Configure under **Settings → Simple JWT Login → Protect Endpoints**. ### Protect Endpoints[​](#protect-endpoints "Direct link to Protect Endpoints") ![Protect Endpoints settings](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAABzCAMAAADzA1ElAAADAFBMVEX4+fr3+Pm1ur6TmqAdIycmNURQV17////i5OdsdX28wMR2fobg4+XBxcmLkpi+wsaXnaR8hIvs7vByeoJxeoJ4gIejqq+gpqve4OOZoKb29/iepKmCipHl5unz9PV/h4+tsrfy8/R7g4qqr7Xw8vPi5Oaeo6nk5eh1foXHy8+coqe6v8J3f4fV2NvZ3N/O0tTa3eChqK2Plpzq6+2mrLHFyc329vfQ09Z+ho3M0NOzuL3T1tmAiJDEyMyVm6Lw8fKQmJ6vtLqGjpTv8PGJkJaxtruprrONlJrb3uHX2t3o6evm6OqPl53o6uyMkJKFjJMlNEPu7/Cus7j09faEi5KLk5l0fIRtdn6ssLZXXF95gYiboaZweYEpN0a5vsIqLzPa3N54gIj09vfV19lud3/IzNDr7O7k5uducnTDxsqUmqHl5+k1Oj5ARUlzfIPs7e8+Q0extbo7QURye4Pm5+lKT1K2u7/LztG3vMDd3+KRmaDN0NJ9ho34+PmChYiXnaPj5eZweIDS1Nekqq+go6VfanVeYmaxs7SkpqmOlZvt7e4kKS2RmJ78/P3u7vDP09ZKV2Pf4uQyQE7p6uqJjZDX2tyDi5JscHJaX2LR0tNveICPk5W+wMEwPk3Jy8xDSEzQ0taqrK8nLTF/goWvsLEnNkU8SldeXl6fpKpgZWlTV1qfpaq0ur6/w8fY296Ojo4jIyMzMzPFys3d3+H6+vqHj5bKzdBmcXvd4OJkZGQhJytNUlWho6U5PkK0t7ldaHMtO0rCxMaSmp9SXmrLz9Jvc3VXYm5GS05PW2e+vr5obG8uNDd6foF1eXzm5ueSlpn09PVpc358gINxdnjOz9FIVGGZmpq/wseUl5nHycuEh4taZXHg4eJVWl2dnZ2tra3+/v6VnKKdoKKZnJ6zt7s3RVP29/d3e36lq7KbnaBmam1QVFcxNjpCT1w+S1l0fYeprrR4fIBUWVxyd32WnaVqbnGUnKO6vL5WXGNRWF+pqalUW2L2+Pmwtru7vb61ur/5cO0aAAAACXBIWXMAAAsTAAALEwEAmpwYAAAU+ElEQVR42u2dCVgUV7qGT0t1Kg3NooAIsgi0CK5g4yiLAoIsghBAUREEEReICnEliogYEx3lJsE1GjVxdKImJkajMeYmakzUxGSy7zEzWedmT2bmztz93v/U1tVNk2CUTi5+7/PYVlVXnTrnrzovp39ONUwkXrGG3AgAAMAlhFiLSbyM/hVaGAAAAJdhKZTsW1iMUAAAgCspLiT7FmPkCwAArh79FjPRuhJxAAAA17LSysQQhAEAAFxNCBNvRBQAAMDV3Aj7AgAA7AsAALAvAAAA2BcAAGBfAAAAsC8AAMC+AAAAYF8AAIB9AQAAwL4AAHDd2/c14XZnm+cJ9+PqAACuU/tOcLJtiSAIFU/uDG/3RoVwh5PdTwjCYmXxd4KEpXP2/XLqvT9ZOAAAdEP7/tfuH24oOObEvvOm1gtC08+x74apRHjn7NuZwgEAoLvZd13A8IM3cA6+d+BdB/s+x9jrwtfsNmH+5vr5rK5p/t49m8MXS+PaF1h60569Fz4x0DcH51/YcOq1O6TNHyv2fUouYpvwwtx5Cz+hpXcWfv3C62TfmYLw8pKK7ZVMLU7OPNwm1G+ef+mlFLXwj6dWCAvX4aIBALqvff/tBhvr2tk35SthD6lxw6UXnws9JCx8cZ5we2H+BuFf8/eFXha+arogvMOqpgoVr29b0vJnQXgvf7du7Ptnbl/hMqUh7mHrSKnbN8j2vfRDvfBUnVqcQbGvUP9ehfBFulz4MOGp/PyXXsNFAwB0X/se1Nn303Z5X2IdVyONiu8VhJtZiyC8IScH7hVO1bF3hQq+PZYxa/u875PcvksYqxe+YF8JLzK2Xbbv02z2BuFpW3GyfU/lspeEL5XMw25h4b0nwnHNAADd2L5/1dm3pl3e92ATbbtNSiSsI9OycIHkKAlynexmoXKdsJe1y/tqmYfXGXtS2MkW0iCZ7CrZt5InG76wFadkHhhrErareV8aSAt7P8FFAwB0X/vu1Nl3Zvu8L4fyvkwa+2Zzxb7BLgn7GPMWTv3j7Nmz++q8BWEFY7PZCkFobm/fl2T7HuIa/kod+zafksa+SnGyfecr9pUKZ2z82XxBKMRVAwB0W/sW2eS7verH7GtL1C4RDuXXULr3UH7+tvk877swf9uTbLwgbMv/QD/nodJm33XCqfdoPCvZ90I+HZHimPdV7SsVvnt7fv7rwin8CWYAQPe17802+77Mfsy+rO49PkmBjPj0Xpq4wNI379lbP7VJnvMgHGJssyDlh23zfVts9qU5D8KX25Sx78IN27foirO3r1T4se2n6NdwT+OiAQC68Xxff82+w1xQC7LvB7gWAADYl35bpsr3rwz2BQAA1z3rli/L99+HwL4AAOBC+1rmSvZNRIgAAMCl3/NgfoHkewsiBAAALv6Os/Gb/7MBAQIAANd/w6QV8QEAAPxtCwAAgH0BAAD8UvY1e1zhAe4+8v99e9htzoy8ykaMbfdEiKfbTx/VcyivSCf2pB07TYgvY1Fy8yym0J8Zn6vkquPZQfv9+1zLUinwPFgO90J7onpcoxOG+HVyxxUZdqt3Z1X3gCjAr8C+iRvpJUx6GdEF9u1tMkX7hDAWY+IMZeZVJT0DHh5mkhnfaftmj9YWB3bUdRomdNK+DROuzL4nttjZN7gmaHUOYzUm/hKWITclgL/j7dbV9lXj2Rl+LFDSe87t6+0kgL0DWCrNVZxgkl56y00e1e4Sdcq+SjSvnvRPHTY0+3XKvmviqjou1FkZAyFr0CX23bLIwKyl0fRisnaFfQOY2W0i2VfuqlWlAXeP906gpT6moCsZ+3ayL3TOvlc0wPLVFm32ZXkPMRY3ir/E0Qaffh2Iqwvsq8TzquyrvndF9k18hrERo/hLGG0Y5NVRsPr+cqrqpH19vBnsC34N9g1aXcmORnlVUs+izIN3aSm/NY8m+7n1otXIrDDlTg2aEhEdH6RtunPMgmD6z/2Z2kVbc+QeJx/D+mf41sbZ2YLlmIpV+5ppUcZm32wvv7GVjAUGDC9YTpMyVoRFTyH7uq8f41XwME2TS/ULTpA+1irnHkSjLh9DWrDJN0nu8AYWEE09pME+82D2yFwfqFbq2bDovlTmOFJlOp2XdnQfvipjel1gdONhuRJKg/gPCF9yUuGO2f0D/CPiQ7XMQ1p0o6fNvuPIQslcU2E1Ovv2oap5sOK46Ihxin2V+Dg5UczEyYMfZkH9Gk3BKUoIlEbFui0y1Wph6SCeaolF0Y2JVK3JFLj4fsyuIIdA8biE0U+DGdnUfuk95n84uGQNXYaljQuiLGwIt+rEkXIjpNpn+HnN1E47hAId515CLwF6+0YtpcHwIDbH12CfeQg8MDy5j1pLubHKGkVz4yDaWDBLbaPuZOpdoL8xeEn+kZOSlXoyaVnJPPj3ywqjJsgx86Cq91GvuVKgJdCvYKli36SCsqw5LFXai+g1LdrUV92qliSVYX+3y8EC4Nrnfdf3YL29p/RgcQeYubr3+Fm+dWxL6bC6Ii9SZRGbPaNO2uvTSbEhtWnappg7U2aV3MrcJ99SeEtJOu9xyjFVo3r3ct9hZwtDUaM29rV41CZU2dvX4uHea9bgXiywdDybEs/m7DjcK2AH2deUxJKiC6uSA+pGr86W7Kucm49EciKyDRMGSMdHZLOwUWZWmu1gXxM9WKJUSiqz2t6+VDzLi8vNCZPUpDaI82ARdd1UNrSmcEvBdNW+nv5DQrxs9k3yNRSWhi4wFJomtBv7xo2dkxMxXVaKEp/2J0pYdDS0rj/7PnmL4WSKEgKlURuLCg1D1LB0FE+lRF6tDJt97QuyD1RIicHa05+FLDDw9stj37xj2WHL2GiPpPHrV6n2tY19G7J7JfpXqacNWj2UJTdn0EuN3r6Ha+nndiDzrHXI+waWTtBqqTRWWaNo1kyiQaZvlXrpdSdT7gL7G4NK8k+tUuspLWv2zauqWr9MiZk0blWuuVpg34zcpFLZvgPK3AszI8LZGPnHbFDGR81sprZVKUkqw+Fux9gXdJF909xYsDmBXjzpbiO9ZNzHAim7Z/BYbJ5MA9VJ90l70dCFnWxk+k1RDcw9mP5PPsp7nHJMjgdJNdUuT2kaPETN+4ay3PjgMrfFevu6L6eXVZ4skBTW4sUSx9DwcwHZl3dvr5icBdTTBmZK9lXOzftCrMdIgzb4KgyLdOdDYAf70t5KpdQy9fal4s2LqOzpfbW6RsnPorSQhbLkv//hOUa1b2oDH3Nq9g2qjo0JZMdjY3oyR/saeE747bFy2+T4ODlRrfzQod9MXQiURrkFFNq2dRBPtUS1Wop97QtyCNSM2Ji4DDNp0mZfSvBETpEyunNMlnb25fTM1obcWUsLo9n3SwtNIXr7DvA19Pb24ENgB/v2swVYbqy6RtG0lFlZ2gHt0utOptwFjjcG8x/J1HpKy5p9W2j8P0WJmWRO5ZorBRroJzdLlO2bmErvRKxQ7RvrG67fqpQkleFwt8O+oIvsm+RbF80sC+qoU5npEzwbPoKNlVSZJKWBaVVKeUowdVPSxmiTiXo7dWU2poH3OOWYEwW8r9qN1eZ4PaSNfaVemLVRb99M6cBbWCB9GiUBxPOBT/AwueiPGk5wf42bJmce5HNLfWFKQbWbPCp/e8ysgGHTatyYY+aB54/lSqll6u1LHyVXSO+ul6MgN4hjGJxtLbOw3MBGk8lLte/EZZQ/sNmXZTWscWeZDWui2tk33UT1GlIqC0SOj5MTFcTwlRRTnT4EcqPMw6NLPdVtHcRTLVGtlmJf+4IcAjWwYc3oSO8DPXT2Pcl4TCbyupj6t7Ovu1eZyTRSs29a7SwftqJ2ltQ0W953RnayNaO5caijfQfZAiw3Vl3jeRyfBhY2Uquu7mTKXeB4Y0gpaqWeWrpasm8fqQlyzCRzKtdcKTDdlEI3n2zf+N78BnJX7bss2G6rUhIvw/Fuh31BF9k3tDqNTFSQVsq0u632sE1gsn3ZjgF2m2Z4LzY8SPblv/+ZOIL3OOWYHA8aarnZ5ynNZXV6+7KYGXr7Lo1iWnelfpdIlTHwsS/vG8EjcuiDMuub2c6+jN06Sf6A2uy7psZSGtDDmX2VSqllLj1AXdZm39gIW52UBsn9MbIhkLFpceaqGs2+qVS7oTr7Fo3ZepItG7P1bTv7vs3HvjtoPpenMvaV4+PkRLXytx35bdGHQG1UuPfkXsq2DuKplqhWyzeXatnPoSCHQHl/FGwdNrCxUmdfWTiptLzYFB7byEeLI6VGSIEtSZrNGm32bfFdM4hZfOUfODb7DqRESOQ4+ujR3r5qLeXGqmvcvssyjg026KqrnUxnX/2NIVVVqacz+8oxm+Nnu+ZKgYYdtEMPZezLG9ZoG/suKtZvVUqSynC422Ff0FXzfb1KKEm5pmSg7W67j/KohgQ7+/Zbns5CW7RNHgNYLw+yb7WUnOU9TjmmqrGG9amOpBkUzVq3ZbWRqn1D+pmrRmZN09t3Qin9Uu3WXLXfNZeZmbeJ7Fs9jqdMq5LdWUj0Mb19M6mz9W9mxT6Kk0pLJrDjJZXO7KtUqnlRf+ZNueRhYUGGvjb7GrzSaKpHrLS70iCJyogMGlL6HGaG4Zp9PbdaDNN09h25iD4nFC6SW6nZNyGYPlzHBRrCM5S8rxwfJydK6JnLKBWa+UwoO5mihEBp1H1VbOhqdZsaTzZugD6eaom8WgeoWhk17JhvP2ZfkEOgmhc1Mku0b5AUKP6eKpzRySlszSqWvjqEedLwU2oEv0I9DWymbuwbPpknxoNLvO3t613yIBtW8gxzYl+1lnJj1TVu3yrfgfG2S687mc6++htDqqpST2f2lWNmmTxBu+ZqgVF9WXpyhrJ/HzYrIlTL+x6nUfdMbatSklSGw90uBaumBXIB19y+kSbywlGTu26wmzB2dYGPnX0NiaN8M8Zpm2pKswaSc9xXBZomVso9Tj6Gfke/1Yu6e05pkM0WSb4WOe97Yrbb2LKw7y12cx6aU/0a8+Zo/e7Z4K3TeOZBKXp8nh+t6e1rHmzyiQ0zmbKUvwcXSGO2zNUGZ/ZVK5UQZsrks9imZCXfYrMvS3lwhsekZ6XdlQbJRPiSf05GTPoo3ss256ExuUhn39DJPKmQHM3s7Ft1XJ3zICdb1UY4OdHRrSY+52FKBJ/zIIdAaVR8tamsRguLEk+2eqRdPNUS06LL+FSMPhu91vNS7QpyDFQ0ZZ7HbpSftuDvaQPH6Y0LptE+s/IKApJHyo3gxIXlxSfrTptBA1wWZzLb29ds8iRlJTqzr9ZuubHKmvS0RYCp0nbpdSfT2Vd/Y8jGVerpxL5KzOL5bAblmisFWgKTg9cocx5mTiybRD8uFfvSHIwFfM6DslUNBi/D4W6XgrWxH+QC/n88afzQ9KsswP1az/EZe83+otKMO39VV/zKH8G7cgKnoGcBcL18z8Ov1r5Bo6ut15t9YwfPQs8CAPb9he0bFebJrjP7eg6ON6BnAYDvOAMAANgXAAAA7AsAALAvAADAvgAAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQAA9gUAAAD7AgAA7AsAALAvAAAAV9sXAACAyyH7igAAAFwM7AsAALAvAADAvgAAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQAA9gUAAAD7AgAA7AsAALAvAAAA2BcAAGBfAAAArrDv55POtbVdPM669OS/eeSBRx994JGVuAwAANhX5r/Lb+KU74/swnP/8ciHz2/a9PyHR/bhOgAAYF+OT5tRYVdgl536P55Ql574Iy4EAAD2FcWiXUaNtsSuGvk+YVt+AqNfAADsK35eTtZ9PMFiSXicFsofc3pguXGx46a1xjR5wWjMtXvjsPGudsf/5oh+7chP537n/rP8f/09+q2vCMgaAwC6i33zzhiNr8qLEZR7cNO99Xuj8bO7JsfS0un3667Kvo98qF976xHb8m8FziewLwDgerPv+zcZjffJizVG403v29n3zYv7jeXeTsu6Ivs+8Lx+7fkH9Pb9A8a+AIDr0b5tZN9weXE22bfNzr5povW08dtWKfPw93PlxrXpYtYZY9vpGG5fr/O71ubK9q377ve7Hm8WxcJXd51LdWLfRzfp1zY92t6+c3+4/cmDtNe6v1Rc3k2rLx6qOPhbyb6PbV74dVOrKO78uv5+2BcAcL3YV+zDh8Zk32XGc8tT379b9Hv/+KvGM7PJvme+e9N47k/cvp+/aZwcduYbRhu/Kd318+z71GJxc5MoftzyT2/NY+Lciv+xvjBVsu87U+8xf7lTvH/e7g8uw74AgG5j3/O2zIM72fe8o33Jru7cviOMa2P602oKP8Y4nUS7XKw6Y8zm9l1qPCeK1cZxdUbj3WLgFWYeOPeKc/NF8exlJd3QIs79HX/Lyu077w1RnFkvHvxYFN+AfQEA3ca+WTdpv3W7i+yb19HYt5VPibh4s5i49jNa+BeyLz2b8a3xKLfvAXm+Wt7DRqMoTr/C37r9QUv07t5DmYfLewXhrDj3C9p2aSbZ9xVJz4K45B98Z9gXANBd7MvsZpztb3Ww73gt7ysO8DxtXJ67v/zA0YuSfSeJKeXq2PebmJiYw0kdjn1X2s84a+3QvscuvWsV55N9KQmRLmziY98NH0g7HKQd7oF9AQDd52mLtLaOnrawzXkg+9a8unz5RePfbjaW/+/x/ZJ9d/G8r6jkfb9bnvdZjHjaeH55mxP7ivt0T1s8cIfYoX231LeKu/nYd+Emced2Ke+bfzBFXHlWvH/JK396DvYFAHSjJ43/psl3f5xob1+aAPxqrPy0xbHztOZnEVON+8tOS/aNuliuzXko/fbMucfNYt3j5d8cd2Zf3cNu9o+6yXnfJi3z8Nqe25sukH3zl2w4aJXs2/rO/Iq/vExzHuZf2An7AgC607fsPCR/y85n+4u68Nz7jrzFv2XnrSN34DoAAGBfmceyzre1nf57a5eefKX8DZOtuAwAANgXAAAA7AsAALAvAAAA2BcAAGBfAAAAsC8AAMC+AAAAYF8AAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAAMDV2TcE3/AIAAAupjWEidYgxAEAAFxLkJWJxXWIAwAAuJa6YiaKhekIBAAAuJL0dJHsKxb2CkLuFwAAXERrUB0Nerl9xWJryI0AAABcQoi1ShTF/wN/+Z7X6+OuzQAAAABJRU5ErkJggg==) Enable or disable the endpoint protection feature. When disabled, no JWT check is applied to any REST route. ### Endpoint Rules[​](#endpoint-rules "Direct link to Endpoint Rules") ![Endpoint Rules](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAACMCAMAAAAXx/rpAAADAFBMVEX4+fr3+Pl2fob29/jw8fIdIydQV17////i5OdsdX28wMSXnaTg4+WTmqB4gIe1ur5xeoLe4OPBxMjz9PWZoKacoqitsreEi5KTm6Dl5umLkphyeoK+wsbk5ujQ09ajqq/Z3N9/h4+6v8LX2t2HjpWgpquCipHU1tnx8vTt7u91foWepKnn6euxtrt6gol7g4rV2NuFjJOmrLG2u7/Fys2hqK3u7/GPlpyNlJrt7vDo6uyUm6H09veDipHy9PXn6Ov09fb19vfr7O7w8fKeo6nu8PHj5ed3f4ewtLmzub1tdn7p6+2orbOJkJZveIB9hYyZn6XDx8vIzNC3vMBKT1LHy89+ho2ssLbV19i1ub2boKZud390fITm5+lzfIOVm6KQmJ7n6Omqr7WRmZ95gYiAiJDs7e/O0tTd3+KPl52BiZDM0NN8hItweYHa3d/t7/DBxcnp6+yxtbpweIDh5OXV2Nri5eaOlZu/w8eus7jAxMjHyctXXF+go6Xc3uCMkJLT1djDxsnLz9KKkZff4OLR1Ne9wcWfparZ3N7d3+HQ09Xw8fOyuLyMk5mprrOkqq+8wMX6+vr+/v7j5ejJzdDb3uF4gIjM0NLa3eBBRkk/REggJip9ho25vsKho6bq6+3e4OKwtblvc3X7/PylrLDQ0tb8/Pyiqa67wMO+wca3u781Oz5rcXc0OT3s7e+hp6xWXGNobnXg4uSWmZtzeH2FiY8oLjK7vL9yeYHEyMyQl51HTE/O0dTo6utPVFeorK8kKS57gIR4foM7QUUtMzdSV1qWnKN/iI6KkZhiZmo4PkKusbJwdXgrMDTBwsT3+Pi4vcGkqa6qr7PZ291UWl25u71bYGO+wcOIi4+MkZVla3Brb3K3urtlaWwwNTmSlphtc3hTWWD5+fnS1NXFycyIj5aPk5ZZYGaDhoklKy+anZ9eZGsiKCyDiIxNUlV5fYBITVClqKu8v8F/g4eWnaJWW16ztrdeYmaYnJ5tcXMyNztESUxZX2K1uLm2ubpqbnFwoJxSAAAACXBIWXMAAAsTAAALEwEAmpwYAAAUGklEQVR42u3dCVzUdf7H8c8M8+PnD5RDwBEQPEBFRGAQlUNt4BHIIYeYuAYig0BJ4pi3poKaGoJHamamfy0VrbaHXf/a3O4sq83dsru2tv61bXt1bHv03//5/f6Omd8MA4LimMv7+XjEMc5v5nfNy+98Z5xIBAAA7yP+JaQwvB8AAHhF+GGrWl97KwEAgNe0TpTra7diVwAAeJN1IquvFSNfAABvj36tJBYasB8AALzLcJjEcOwGAABvCyexH/YCAIC39UN9AQBQXwAA1BcAAFBfAADUFwAAUF8AANQXAABQXwAA1BcAAFBfAIB/jfrOFYRbPFz8E0G4tbs38W/CXTgcAID6duY6gXupe/VtWbs2yvnbo8LP9bfy4NomA+oLAKivm6cee+jTIZ7q++DatWu/6V59XbnU98G/nRGEX6C+AID6ug1bP/N92Nf3Fg/1vVebVPjh63P/eItd893Hv13H67tOOPDnA2detxOt/+i1x595Vp15eED46t1z171Hz8uj5s8dtxJ3Tmgiult4h24VhJ8o9T3y0WvnXnqPKOT7r58TnrkFxwcA+lx9P/AdQc2f/ayTse86HtYzz38rfExxB4QXv3lAqa9w1zdn2EUtnwjPvP6c8Butvnd/9Krw4NR33hUebGqKctT3c0H4Na/vE876HvlE+Pj5f7Kb+oPwdlPTq8/i+ADA1crQWp+wZ09CemtP6/uprw/Rh591Mu/7FQ/r/9Czwif0jiCsoIFKff9k478+/T6fYlgnnNPq+z0dEYRt7vO+wu8fJbf6vs8nlH8jvMr/++VyHxw+ALhaTe13TUa93V6fYdsztWf1fdhX+9LpzMN6+l/hbvpOeJzoEaW+LxItZ529l/WTnhCEuWp9v6N6QdjgNu/7tSC8HaLUd71W33vltLObufkl9u2193AAAeDqlD03x6SaODe7t+t7K/2a1fcJnuF3HGPfXwjCze8LB/hrbGe0se+zNIbX9wfhv/S3csufhHVE54Tz9Hetvk3Cz3/J8Bfj1v/lI+EZHEEAuCplZJh0MjK6X9+Bzz/k+8ILL7AveR7nfT921td0QHip6S6lvs/9d9OLwofUcsZ13let79+Fu7/6Utfwx4QH4uht4Vu2jFrfRz4R/rOp6aXH6A/s21rhbRxCALgqR74u8WX5ze52ff/dV/NTj/O+/3TWl9a/+9xrjyr1veu7c+der2cX/R97z8N5cqtvyFo216ur75G7hS/prX88d+AHx3sebn39xd9ft/Y8vcfv5m+f4xgCwFVo6lyTm7khPanvT1sSPdS3C+vwjl0AADLsUeZ8n/7yj7/78yPK3G+uoQf1LaX7UV8AgJ5qtSkD3g98H/ve9zHlZ1trD+r7u/RPUV8AgJ6qV2Z9n/Z9aIzpYd/Rysxveg/q+xD9rGf1BQAAooR6ObijfT80mZ73/Yv8S3ZCT+r7wh9RXwCAntpj71hf+55u1jfM8Z6H97EnAQAuor7qzMPmntUXAADokmYe2KtuH4zVXnXr9swDAABcpHT131rYIhzvOOv+q27dNnDwpa7n2MALXaNVCunJDfr5X9yKhI7ocNHU0KABfvMu4rb6G5Xv1wZe9PYPHNAbZ4GHjdKLvcH9km6scWcby86F8KDeOXkXDrvUs8A7Jy+A52ZdY+rgmrhLru8oSVqYEndZ6ztkgOfHXeIwjzfgfnW3+oYFdr6oJjfIc6jKLDk0LNXloi5uSbciWpD2Jl90fe94spMFDONHNUa0dbr5l1hf3RqHdRrioZIU7x/uob454zpcdSRV57N/9C7JX2ZIioQL7JSZGT2p7xgpwWdpDNEMiX8ZXqTcx8gLrTfqC5dNv4nu8e047XsR9Z1haB6e0kfqOyKsw0U9q2+vjP3dnKxNnZhcc7nq677nPNd3JC2bb/ZQX49XbZtPlFrOvwxnFwRLF/fJoV3Xl06zlZ1Qzr+cYpf4D9L98QIf/XoPNqO+QD/mf2ncVX2J8osomT+QzNHyCXxHRFDsbWTIGyVFjpavs21e1aj7WAYnvbzpkM/spPhj6umf2hA0OJ2qeRAsZeS3KShiuVyfcROIctiDUlkumI1bjKQtlxdfslh53Pmzy0fQaEtjGvuE9oAdacN3yjerXN16Kj5JHXf5zc+sMrNBUEJ10KibaAT7Y3/XRVc1JO5aERsZykbww5X/d5KR/XlwaN6koPmF7LEcGl+ySr64TR5DzWN5mb6y1D62VqptVW6J38vLpyoHZ6zeV3ITqVuirvegEmmKqb9xSGLiEPl5fH9jTdpZ9mOrf5BlfJGaK3Z72h7k9VV2jPzEfzwbIY6gqEgDn3kIGCRv5f4BVVKmM6jn1ebI66ncq/N3bedTS1pjxS7SNkoeTcvHSbtRuvNs/GxW39BrV8ZWZ2u7i6+x3yT/TZYYZc/x5SZPr6vyt+kPMKsYJUs+k9jTgr0RfAtra+9zzDykXx8vjdXXNznSQBNOVrIvI/X1lfeCtunLiiJXhtU4zgQ28+By9jjPApl2JGu212n1HcfqXsf/Jho+w72+xfr6Uoxk1bbV48kLQFf2U3a6rO/U0yP19Y0zbkkvm5Yek3SHIUMZXM/aZiqrvJH8pGaicRGLwjOVD0pLrn1qzOoI2hDBBpuRWTRzfXp+wGR9fdXl5NGcutzigOSoCN3Yd0+jn31HUhwFVGdlVec5B3+nYqNikg4p9S1YYl9SmZNVN3LMk0vXO8e+zkX7b65c2Zxr8WOD2/26sW/JcdsANqpfMMEWM1x5JM5kY18279tfWsL+yhkcTsNCHGNfv6WLM8LqUgrf2GfQtkRekR11yYYjpv4VQxPKIuvl+kqrKXtfPYWF2mJi1fry29PVV90x3JpMNkwMpYGZ8rxvwILJk1fuperVEw3OCYE2Y7785FldT8fYV/1d3YkZVUvsk29zbBSjHiftRqOK16SfKmb1TSykJWmk7S5eX2kzRVucY9+pbXuiQl8m3QFmFTMMqiOtvgXzCjc2jlbr61M0L5eW6+vrs3QYNeRuGkZ1G1zqK+8FZdOzyoemb6lwra/u7NGfBaQ/kpMdY9/RkQZ7bUiVwS5ldFlfw+qDjm31ePIC0GX4hMnC3vh/GrN5X+m3Gfr67prPT/fFi4zR+k+RuHYm+fGgTGOjrSMlyqCNTf0ZjHNbGwspb6tyrYV36OurLif3RF2ueiYfrTjr21bNbiPpTgo4ThTd4KivgU/7rYpVujiKfalLjaliD82w6c76OhaNJhrMHp3jR7rNPLBn89teoWVVWUSHxrrW18quXrRCP/PAN24RvzwyQdsSeb2DlitlYR9mX3Rcrm8Bu1LEcUMxG6zt0uprdamvumPksEQaTgwx8iGwXN/NRKtn0+BTdv2878DBjeUjHOup1Ve/3mwnjl+p7HNlozj1OGk32sZeTZxcxeo7m8gq1Wu7i9eXbZpPQZbLzEN4FekOMJs/laZtdtRXYh9rN/SEWt/9kXFuMw+UNt4eTzvG26Vw1/paHedEjJFdWO1a3wjPZwG5Hkmtvj4Vi2aFUuyiWQtJX99kdaL5Bud6J5O2rZ2evAC98enqjrlfew8/Xb3zsa9PTOJyfX2ny6f3EpptqRgwRr5Oc3W8JA2SJ2BblZNfmWSUfxxNpTPpLHvc7HqlUZKi9fVVl+M90ZYzb+QPLmd9U4ayHyZtoYD17Ll1paO+OdIYPo5SusifpM97Yy+P8LjrnfV1LBqsTIfq5oeV+h6Sk3infMcrXerLn9q3lpZUpRic9fVXJzzZzalbwlfEJMm7oH88v69UZeZB/jFHYp+xUVbknCjV1VfbMdy+OxoKi1aUDFPqy1aV7Zz+k+ITF+sPQsga6TZtPbX6ar+rO3H6UKW+h9R7IsdxUm80ZTo/mqy+rGxU2aLtLl5fvmMKCh319Zk+pUBih8d5gIcqf3Fp9a3iu2qeWt+No9znfSkvs6yU7swsqyXXmQfnObHXwq/qWl9/z2cBuR5Jrb6UNnPnSZo+c2cYdTn2jYoIJG1bPZ68AL0kJMqWkW23Z2fYckOol+rLuhlLi/hwdqFc3/GOl6ZujFCe4+4bMtewVakvFTufz2WuUl9WL2qZZqAVlaOz6aBcn/FsJBzFHnPqcqsGOJfjk8TD1MddEh/A8j8rYcOeMjbBoVSFX91QzP5ssTr25S+rmNnYl41mxqpjX5dFO9Y3SnvVjYVqf5JzY/X1ZXcSXbtXviW3+mpbIq93ULKjLC71NRQH8/GzszvaHmTbr+0Y+aUu9sz4/Dg2U6qrL5s1GFLg+mbBhl3aeq5S66v9ru7E8acdr7qp9dWOk3qjbWwDDHzsu5N9JohUqO0uD/W9r2h/nE1upnaA1foOZjMJa/jYdyIr4gRt7Ftlda/v5shjI6g18lhYx/qqmx5jZPc+oMZxJqj19XQWkOuRdNR39TzzEdo7z7yq6/pS/8Z6bVs9nrwA1Lv/V836OKLeq681flvO0nBaLMn1zahlL2DcaFuRS1Z/5aV44x5KN6r1HTQ/h0I2yxcfL19GBnbdrEj2rI+CFxpouTL2veGsj2Ese8ypy900ZbJjuYHmVsP16uMuNpV3MpjKkqZSwKiW4LPKvK989VOhhrgidd63opma4+1ZdVsoPL6FdkxwX1RXX/VVt9aCDEeoDBF5Bipc1KG+MTlUWH6DfEtu9dW2RF6RHfNDiM37dqgvhW0lk0VXX20Psu3Xdoycusqt9FTlfNLX93gWDVtqonFKit5Itdryg4K19ZTvlR9p9Xd1JyZUNhOf93XWVz1O2o2uaFxG97Fn5KGVG7PnbSdtd+nqK+85Ut75sUTy0R1gtb41W8luZvWtyKPCAMe8byybzl3u2LX8qnEFbCKaplQO6VhfddOzymfQI0E1jjNBq6/bWZCaqP5l6TySjvpGV7HnG/YqKfcC9aXMGm1bO5y8yatQDKAr/3+U76q+lBdBZQssIxuU9zysqA46uCBq/3BJSlM+wXJGYlqYv1pfQ1t55Cb13Qg3WZZa+GUjJTadRyeGL0hpUF7zn53WwB7e2nKTY9mr+NpyeQcbVqv1nVXB3g2w3Ny4nT3AAvyMVTuz5Ivlq1tPsPc8KFN3fi+HSmZ2BwkLgtgTa1o2jb1y77Kos76GqhXqc1n+ngc1VKat+4zbN3ao7wb2xohj6kq4zTyoWyKvCHuVXn7PQ4f6tvoXLwxM071FS92DfPu1HcOnb6XF7C+DfJf6plRIjWyYuVSZ5ty1PbFyQbNjPeV75dTf1Z3IXswv5u95cNZXPU6OAfXGUebrp7D6DppSIb/nQdlduvrKe44PvGN/m8kOj+4Aq/XNKZ1kTuHveZhZoXvPw5jQKvaeB23XylctYmN5OiEt61hfbdNzi6SVJ2ocZ4JWX7ezID9UWVR3JB31DSngM0518XSh+jZHtqrb2uHkbYtAEeBHXN8fCe2Bd2lu8/fuWo/Y+uPbkxd4R/Cl7lr+ol43Ta+50DUGeD7qyyQrHsmA+l5d9fWmqAQqrGvuM/VVLZpW1ov19aw1ZQoeyID6or6dGi1JBw9RH6vvwGkphste3/KiGDyQAfUFAADUFwAA9QUAANQXAAD1BQBAfQEAAPUFAEB9AQAA9QUAQH0BAAD1BQBAfQEAAPUFAEB9AQBQ334AAOB1rL4iAAB4GeoLAID6AgCgvgAAgPoCAKC+AACA+gIAoL4AAID6AgCgvgAAgPoCAKC+AACoLwAAoL4AAKgvAACgvgAAqC8AAKC+AACoLwAAoL4AAKgvAADqi/oCAKC+AACoLwAAoL4AAKgvAABchvqaAs2Sl5kDTTgYANDH62tKm2Pz9nrY8tOQXwDo4/UNnHMl1iQwH0cDAPp2fc22K7EmNjOOBgD07fpKV2ZVJBwNAEB9UV8AANQXAAD1RX0BAFBfAADUF/UFAPBGfWOb5W+/km7v7Bo1g9wvyQ5CfQEALqK+t0cO6KS+U/i/GM68QH2zAh0/bshEfQEA9e0qg2UbnD+n7iswdVLfWd0Y++qgvgCA+nadwfvvcf58um3TG+zb5rPxq3l9x8WXfOFa3zWnSyMsLaKYsCnyr8cGiTbjjknlrN63vxmflK/MPATcs7IupT2XjZSNqC8AoL7dqq9dOjykQRRvLn4y5ERxs/hFwKLs7W71lZLF5RaxvTwlZGAxq6+UL5oSY8Q3Y29uSdqi1Lf66NFJ2zD2BQDUt6sMnlY+AnKT8tucItFa8Ih4v78oHq1qFuefFMUW/bzvIHHNdlFsL2hvMbaL4nxeX/an9xzbvZQNhzfEKvVNFsUlq1FfAEB9uz/2LdkiioN3iDvO89w2i5ZtohjiNvYtZV8KTE9Z2LcUVt8q9t3PP0sKEcVFtUp9c0UxfyfqCwCob7fru14eB09rv58ldjcf+w4RxWCP9W0x7hbFTD72ZdlN2bm7OFgUv4hFfQEALqa+b/6Vfbm9MvrpxgRxsdQsPmn51e4wj/VtL08VoypYfStKTdGNb4lvhu3+j01b9PXdbD6K+gIA6tud+rZHbubfUkrF6CmWMDN/z0P5qCX6eV+LVl8x4RXL9lL+noeTFbWLWbKPxSfN2a2v79EivOcBAFDfy5VBm1HEvzQGAEB9AQBQX9QXAFBffMYZAADqCwCA+qK+AACoLwAA6ov6AgD0Xn3NtiuxJjYzjgYA9O36Bs65EmsSmI+jAQB9u76mtECvj35tgWkmHA0A6Nv1FU1zzJKXmfMRXwDo8/UFAADUFwAA9QUAANQXAAD1BQAA1BcAAPUFAADUFwAA9QUAQH0BAAD1BQD4169veDt2AwCAd7WHk3jYB/sBAMC7fA6TaB2D/QAA4F31VhLFiTnYEQAA3pSTI7L6ihPTfTD3CwDgJe0+9WzQy+srWg+H9wMAAK8IPzxZVOsLAABe9v8TK8q9I76bGAAAAABJRU5ErkJggg==) Define per-endpoint rules. Click **+ Add Endpoint** to add a rule. Rules are evaluated top to bottom - the first matching rule wins. **Each rule has the following fields:** | Field | Options | Description | | ----------- | ---------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | HTTP Method | ALL, GET, POST, PUT, PATCH, DELETE | Which request methods the rule applies to. | | Match type | Starts with, Exact match | Whether the path must start with the value or match it exactly. | | Endpoint | text input | The REST API path to match (e.g. `/wp/v2/users`). | | Type | Public, JWT required, JWT + Roles | **Public** - always accessible, even with protection enabled by default. **JWT required** - a valid JWT is required, for any authenticated user. **JWT + Roles** - a valid JWT is required *and* the user must have at least one of the specified WordPress roles. | | Roles | comma-separated list | Only shown when Type is **JWT + Roles**. WordPress roles allowed to access the endpoint (e.g. `administrator, editor`). | ### Default Action[​](#default-action "Direct link to Default Action") ![Default Action](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAChCAMAAACs9ewBAAADAFBMVEX4+fpQV154gId2foYdIyceHh5sdX3////i5OeUlJTg4+UgJioiIiL3+PkrKyuZoKaLkph6g4r09PWQk5X8/PyAgIDe4OOPlpy/wsdcYWTt7u/Z3N+6v8KAiI+usLL39/jm5ufJy8zw8fKTlphdXV3W2dw8QkXv7+9BRknFyc1TU1PV1dZpaWm1tbX4+PnGx8j+/v7p6+0oKCgjKCxISEjQ09YqLzONkJL09fa5ubnLzM1YXF/V19nu8PE+Pj7w8PCxtrsvLy+lpaX19veenp40NDSvtLklJSXBwsK1t7gtMzdyeoL6+vpMUVTn6Orl5ulxeoKcoqe9vr/Kysp0fITy8vPr7e94e35/goWXnaR2en0nLTGqq6yChojw8vPg4eKpqammrLFweICGjpRLS0vIzNBPVFego6WDipGJkJZrcHJITVBKT1J9hYxTV1o2Njbz9PWJjY+urq5CR0q7vL1aWloyMjKhp6yFiIvs7Oza2tuhqK1aX2K8wMXk5edudn6QkJCTmqA5P0JucnTd3t+lqq/R0dFvc3UeJCjAwMCkp6nM0NOUm6A/REgkKi5xdXiOlZo1Oz5pbXDMztDp6erf4OBESUzl5+jBxcnn5+iprrS3t7fb3uA0OT2WmZt8f4JlaW1GTE/Ozs+NjY1XV1eytbe+wMFjY2N8hIt+ho7e4OKqra6fpKqtsrd7e3uXl5fExcYtLS0xNjptbW1QUFCQmJ5zd3rT1NSampqssbbDxspfY2ZoaGhiZmmVnKKjqa6zs7O1ur7Cw8S7u7va29zT1diRmZ9DQ0Nvb2+3uruJiYk7QEOjo6Ows7T29vbGxsafoaHW2NmzuLw4PUEsMTVRVVmmqatzc3O3vMA6Ojrb3N3i5eaKiori5OV6foCFjJNVWl2Dg4OZnJ+wsLCVmJrZ2dl+gYSssLJNTU3n6evGys64vsHi4uPc3+Hd3d2Hh4dgYGB4eHicnp+Zn6W2u79FRUW0ub0fHx+WlpbO0tSMk5k5PkKSkpKsrrCIjZKQkZLVjMnWAAAACXBIWXMAAAsTAAALEwEAmpwYAAAYbklEQVR42u2dCViVVRrHz+C596SAAhdTr0MYArkioAIjAhkqiCAquCvuCa6o4JaiuZeKa445KmiaaeK+Zi5ji2VmllualVpZlk011UxN0zzznvMt917AdMShafj/nocL33LOec/HfX73ve934DJB+ISl3gcAAKBcSA2LIvEy+rJnMAAAAOVGRoyyrz0KlwIAAMqTqBiybxQyXwAAKO/sN4qJsBBcBwAAKF9CwphIxWUAAIDyJpWJ+3AVAACgvLkP9gUAANgXAABgXwAAALAvAADAvgAAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQDg/8G+P4/M58+W3D2U97yT1kN4PfweAACwr0bfKUMW+bn9a/75wTGuB4ZzfnbBSJvz3qh8Hh358i3sG8HfNHdUmcv5204nrOFr6bFd9Az8HgAAsK+i8HcOxhez7+orSZwH/9GxazPnr5TWdwn7RnLOr5ewLwAAwL4GTvL9XY1i9p3DPM835QvJukOnR4x8lh3jkvfXJPH8tX26MubOX5dCbintm6qOLdGaek7nj/Kd2fTT0oOLefDSAnVwn6o82PvU67V8dAZryfm1lIiDL+M3AwCokPb9l5N9l5awL2MFPD9q805eWLCT15/ZnfOCSHv34dd7LubdpH07m/aNicznSyIf0Jrm8Lkv5/NPGXt2Ln+0+7BPc2rx1ZGRedK+2SP5Gx8s5gc9yb5JBcN4IX4zAIAKad+HDpnyvcZKse8azv84mp9jrC4/xGZK1bJltPs8X+xqX5fKwxIezQr5ZMauyMzZs6teeZD2fZb6Yw05X0r2bcee5zvxmwEAVMy7bksN+Q6NYqXnvtlzVOGAv6HbN6dwAd1U49K+OdquYvZNzedD2Kd87kw2nX/MHHVfad8n+Vn6mCPO3yT7zmSvc3f8ZgAAFXTF2XzdvkGM3aLuG8nXHiPe1FTbNZ8XdI6U9o3gP7MNpn2TZKlB8bFmaz6aRavKQld2jS935L4zWQst990M+wIAKrB9s5co+R5hJeyrrXlIZX138hmRked6avZdNpfbngyW9r3Ch0UGm/YdzkdGvqBajuXTo6Ojg/nqeKr7Lpww/FNytPsEGyte94V9AQAV+q8tWkr5TvUsaV/O5w6rK9f7bl4YnD88+me98jAknw+bIO076WD+gmumfdv14ryubLid80RZ0uC0JGJprcWc6hPZ0Zzna39tYZ9grnmAfQEAFftv3T4upe4AAADgv23fJ8m+HXCFAAAA9gUAANgXAADAf8W+52FfAAD4Fewb8BzsCwAAv8b/973UqSuuEAAA4LMtAAAA9gUAAPDr2LdKpdL3V/t9+c9jXlaJXc/VLv1Ut/tv2UuGNfsex3Wra+REavu7bAgAqEj2fWcPPWxSD/WLCSKvY9nsW/Pxe2vfd2+UiKzTn0va17v23dnXu/adzAT2BQDcG/sGtfdkYd7p9GAN+x+3bymRwb4AgN+qff0H1Gb1O3nRwyYSRE1v75qMvTfezbt/NqtktVqV2Kq1rdHx1TDGpmR19KJ/v1Nty6KBe2jTbeUiv1n+jNX36zjfTptFanPV4+2t82Wr+6l5JRY1vpL3w9pQerdVKq1ctKkmi0/fzFjMgDAVxAHv9P7+xhGW8W3HD7/Lcgzw3Yj0Thmq8lBtfI0PKRIjst/T9x7MbUVmOp0Wv9IvvUcH1oP2aa8WbSuNWEH2NSLQwrRvcbO6ZWgViyLn7s12Uw6PT59/o8htxDxjxtpM/ItGWDMDjGskaX44PVP/sdqWGn7316jP2GAvZV99Rq7TdnOjs/Vw9sixPhzMVnl1HFgbT1sAKmLdd9Gf2ZGaB+hhC6sy9ciNwe27stov2IM+/MIp9x3RvMPj/emt/yr739ziWTXvMPbwIrLXnvj4PW1ZkNuP9iIv2qwRH79oKdtTFOMZ5MgYxw/MC/LWbKh3W8VaxMLcurLHVpI+X1VHHvaqnTq/rXlkS1aHV7yzzAHqV3rlxqIemn3dbrAD/YvnvjW+XLVpKct+Jy+v2mFHDrvCLeiPXmRfPQI9zL/NT2W1tYRYD9jo3mg3ZcCKG538+od94eZpzFjNZKVfkOfmAOMaST5vHjBYvobIS+RNZREn++ozcp721MNh8wa0NMJ5ga5YXvv4jEpT7IPd7HjeAlAB7dt2PsusMo8eVpD9SEtZzTV3HXay7wHGfvTSfn5uldqMsnZlbnRmcz9W7W/0qUKVUtVm0QE2f7zd6f265wAycc2B5mjUbZWp9OkaXs1ZkLcny6qveZDEt3mEccRzwCqqR0v7agPseYdEZc1Q9i2iPV7F7fsjYwcOaG/60x0W3fMu1VWs2UYEepjfZb1nxKIHbHRv2pdmWttKkbS/YcxY2bdjS1VAcLpGki3vapeIAnO2rz4j52nTFWNHjhjhZFDW33YLmyJffnqswPMWgApo31fa2yuxjHS7NVUrTZJCOlQbYbV6udZ9g/yklwZYrc1ZNSmc9C+ZG0nyy3Q20CppqcqvDz/GqtRI915h2jfGSi4OclPberfGKGxEy7z22Vp1VmEcibEGUF4p7asNkPk57ba+p+yrRVLMvpvVwP79M6darf6mRTPp00Pt1mwjAj3MjG9HpPf3NNdKUDuje9O+PfQiLR3XZyxnEmC1m+XbGtqLxit7qARS5CiNO+xrzMh52rIa/O5h84J8+y7b1JytVOe1xfMWgApo3+ypbUk3H7Z1c5il02NV4l8oad/30luGSWNUm0WfImQNY26DSZJ+7PGazFlmjHWpOdXuyH3JaSu03Ffv1vTXw+OLtmhNB+QxJ7N5DqCe/iztqw2whxSbau1ya/tqA9fMWpXRwcm+srJaW+a+WgRGmMyzuezX0c7ovhT7GjPWct+g4vZ1q5nqucXJvvPpMz9WaLmvPiPnaVvpH9j3f8y8IEuzvqTSxned8JQFoMKu9/VK/4KxWemdHGbpUZN51vBiGVNvuNj3/uc8WUuZ+6bPCzv8D5JP5pf3+7VlzTe9zzznmTJrHs9qDwiQzeZlxlPdt5pnlyyt7qt3a/orNX3TK9oARa/GsOzm5pEtW1iMX5Y5QH2/ADZLr/tqkZiRrXzMYdHf0wzakn0H1tff7WdmeHaSdV8tAj3MoBgWtulHZ/sa3RvtnOxrzFjNZOWr2Yzqvk72rZTH7JWc7LtyC7NnavbVZ+Q87altqajd0rwg8e07USn9hhtduc0dWFBNPHUBqHD2PWClN/ifW6c47LvZ+x+H+1P1s7+x5kGvPBzxq9Hfj+xblDlVrXmYUqn9LNLSvIEDPuxhyqz/VGtH7XPf4gfKNQ9H6Ba/9k5f79bhLy83/XOOPN/Z1D7rYfNIxrd+mbOyHAN84VjzoEdiRPa+m1zzoA3cZWDW49K+n0811jxs8iuSax70CLQwX6BiwSzXZF3v3mjnXHnQZ6xmQssY1JoHh31f8F7UqYeTfWO+rZHZX7OvPiOXab87Va15MC7IeKtMtt/b03FTjTz2jheeugDgL41vh7H89xf+xuzOGL/yl4+XeQAAAIB9S9IhPQ/2BQDAvuVt35Vut6t1wr4AANgXAAAA7AsAALAvAAAA2BcAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAACqufQEAAJQ7ZF8BAACgnIF9AQAA9gUAANgXAAAA7AsAALAvAAAA2BcAAGBfAAAAsC8AAMC+AAAAYF8AAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAIAy2nfmobO8XYm9nD/ttOXO67gcfZDXK72zWvyB0nZfW8uH3WnYI0uJ5lb93pYWfOytg1WM5t3vbGoAAFAW+07nc1evHTrJac8HfK1tUqn2fZR3/k/tOyH6WCl7l3FeMKRM9nXp1xHXLfDh3Mdh37ej5/xCU9gXAFBO9l2e4s6bOjnoIO9dSuO7tG/prOPBd35yqfZ14T+07y83hX0BAOVk3wdE2GQenCzsC386W/i+uMKJS6N78aTJTYTowyeIAM5DpH2XyyNrdPteW5v0ARPigZReY08rRdnemH6e3KW1e54fEupBVghYZL1eKW8KUZcPLTz7PLXeLjuaIfZNTjqzcKLsbM1azcbJkWN7ndsu6wp9oiMOLRPi5+DVBdK+dfmSwqRhaUJMXHgmafI+rfJAO4cmpbQQWlw+PcfyiOvGi8Oa4UnXk1V49SKTl8kT+DqXykPdR/Pn1npIn9K+Wkk/XT8lxL6UiIM9dfvmBXP35X185NmjfzpDc9Q7C53OZwsRTA/63C/xCDy3AAB3ZV8xk9x0ajlfcj1/QUjvBbzQZp8RPWEJ7zWR7DvatO+QM3yO7UFdb4s/2Eli7s2D+6Tw86So/KYpvOkyobfz6eUeJw7xDcqSC3lwtwhKqOvypsP2koVF3548ydZuUv7cGSP5cn/qrFfPQ6rbvfxcnzPul6iVe89z/DrlyHNnpDRV9uUHD/Jey06N5SOH8vyXdfvyWkP5WqHFVZfPsI2ebNh354Sd1Kw3j+gWzPf6jOZ8tK2Os33T+DmbLfopremk/IiCQ3yOyF7Nryxpqtv30uqFfRbQFGlqa/c2pRRZ70xE0s51fLk5d9gXAHDX9iW35rTj54QYyt8ksVF+GkA7r/DXXezrUnloQhnsYjGMPys+IRM9yHlDkcJzzHYL+fk494hkaUk752HiAT6cbLnax3g3T7lud14gRD06lxJpbbedz80WQ/gHMvcVOTyFTlkoWISy7zlZJXiyHY0lutFRzb4pMrYALS6SYlqcGV4ORd6HwtsgnqYzXCsP0r7b+cEmN43KQ3eapFjNl7Xjb4RS4UWzr3+IEMco6gd5xCnqfIbZ2U2+OLQPJczG3O22unhuAQDuPvf9q3p7ziM1+26otZo2nlT2tZdm35viKc5Dk7RG7EH+kxDR1JXR7hivdZ40Ki25jzeV1ksiW84RTvYt5B/L46eps5na7n1ab9EqhCbkyKHcJsRwZd+9gowe+Vd+UFYwCnX77hWhnCrQKq4OY6npwmQzPBvvJs7yFnKjYUn7+hbS2Sl600Jt3O1D+GRZa9Hs+1DB8KacXmBUrL0pKKMzenVJWzz3aWHMHU8sAMDd2reDrPu242ObNGmSuE+p72n3/L82oVyT7kEVyDKtZt+RlFIa9k0UnVXu+zE12pCsSqlkX7Nd6BvuKdJWWu57U5xXuW834ZL7kjzPqNy3jpH7unem7p5VbpX2lblvcpKy70ghzsnclxrOMXPfbjJrr6PHFdry9WBKyY2bgtK+w2gq9MoSEMJ5l+IrzvISJ5PbVdPufIachb0dny6oXqLZt4BPzhmi7JsfICao3FfrjObyqHwRMOZ+qkkanlsAgLtf80B134W2yMVNlH3r8Px2E9zJom9ShXaYYd8lfLLtKV1v01Xd93keHGmbES0M+5rtSNt8gdDujs0x674u9nWq+xoLKPbyaJvtnM20bwvedPQSruybX1DAI4rXfXX7qrjqdrPZdkrhO9nXKNWKnbynLdnZvscKbbYUSr5V00n5vSbY+jSVdd+Ffbhu3558Sbthmn1d674iIJ/zn4U5d9R9AQB3Z1/Ozy6R63vtPYMjzh3qq1UebNx9xmSZw/ZJWn3NsG8LerOdqOttw+qzcs3D649GBEevMe1rtiMnyaqBY83DBlHcvqLh5LNn5kx0Xr6WXHd5r2GTHbkvrXlw75mi7NtzL1drHubQmoeGwtW+Kq7X63HeyxbqYl+xQS5ToDCHzJVzcLLvX+TSjjkB+pTePrRz55UZcs3D3OgZun37LiC7KvvWG5Kv1jwYnVFBJEJ2ps8d9gUA/P/+pbFD3AAAAPvCvgAAAPsCAADsCwAAAPYFAADYFwAAYF8AAACwLwAAwL4AAABgXwAAgH0BAADcA/t2OVkZ3FNOdsEzDQBwe/uenInrcm+ZeRLXAABwe/tWxmW51+CSAgBgX9gXAAD7wr4AANgXqoB9AQCwL+wLAIB9AewLAIB9YV8AAOwLYF8AAOwL+wIAYF+ASwoAgH1hXwDAb9e+DS129fW/TaPqpdqvwZ338JSlTil7X6x+u1FbNYZ9AQD31L77Etb/avat+oc731u6fdW5ZbfvM61/aXw56sYmsC8A4J7at/rlVn+p8Pb95fEbVUflAQBwr+0b0qpv9a+c7dt7UPgg+peJT1RNJlNtpbQwUDvxdOCO2MvJ0l+NRrW5MEn4tv4sfDeljHFbY6vmNhTC55vvLeHbhPjn7gRLo+KDBn6zcdzFr6i1xyO5O6YZY8RaLJZRQnRuUDV2mq8wetT3StblVo296i/12jp2x65lyoO928ggXtOG0M6t3OC0dth3f7PwQUaJwNzw6BdYtdkY+iFxUPjuxmTfNMvJQeENZgtzsqryYJym9dmw0SjLqGOoPAAA/lv2HbNbpEmfGfZtbGkd18/ST/h4tBD9xn0vRK7eoHJal8QGJ4SY2OrCpId6p4ln2hztMptsu/61dfaT4+qIy7mf+Gz/SCSOSzu1r3UJ+3r8EJfYZhopbtSfQroYY2hZ5rE2Yya2yL0qzB7N3LNO+GsT01pdoLETvuq777NvlAdDWv1JiICEHOfcd1xuv9Zt6PAzuxMDcmL1Q+aGR7PEuP1/7yv6emx96ImLyr6fzZ64dUecOVnNvvppWp8Nrr4fdzTNxb6J9GNciP6iFQf7AgDKZN9cMuXFxg77rt8oM8tmpJ8fxIVpHstCPNIcJx9rI8S0WJl7iuSEfmrX9nC5+fU2ceEbtd3veGgpgQTK2sB+au1xmX4wx1CeU3pfF2726LDvM+Mo733EMlFUlrnwye81D1an1qcv+jrbdwed98NxEZIgY922UfOjueHxCP0w7qg4MYpCnabs+wQdH3fSEYiyr36a1mfsmBJ33Si8txIClX5DAsObwL4AgDLY96bHRDLS1w77tpFvxMd4hIoTX4tRLXI/OqbsSqRtbENvyU+JXa+pzUmWSer7SYtiq0j0+PqfL4VSajzo8hj9o3Z2WyzHdfvKyulb1NqDElfHGMpzbbQenjZ6dNh31y6ZAFvStMJu41aaB9+mkD+7LJztu5sejraimBTH9QCNDY/OtNmstWgkI2+h7DtRWv+qIxBlX/00rc9nwi9sm+1qX2oUussi9RsSaNkVCvsCAMpg38tKUX9f5rCvzACPelCRNOEvVZOnbTXKvk9VbXzTN80S57DvJfX9kXFGV/t+eK0q5ZJPt65+MXaipvZLl/q62DdOeDwhfWuMoTw3Sv9gHqNHJ/vKoZYVt69osK2h5WaJu26NpX0/cczMsaHGlPalGoaY7WJfIxBl3yec7Stypn399/0l6r6+L5J+Sb4v+qLyAAAog319R11+i2j2T0flgW60iav0ZtzH45uN4q3j6/Xzx1ykh9bkz2KVhzTLbEd3iZYA+e2Uxx9KrTyM0xVnjjFOZsKBWqXAUXlQe1XlQWaxL8nKg4t9e8dWzzU6Vucah5MT9juGdGwYWj3RTL5aOCoPpx2BuNjXHP/yZyXvuvk2sgQGWhr54q4bAKAs9n3JQ909qnwx1LzrFj4m7mhV6cEGpK8QjwS97PtJQkPxh1Fk3+J33QK/TwxZtj9N7M/x9f2qTWjjfj4ixzkH1eybsE2/6yYVZ47RYJry9zN9fY9Nc9x1U3sleeFfTWzx/QVRzL7+OxLMoqw61zxceUfvh/w/0iVubhhafcpjWvK648q+u/W7bkYgLvZVfV6dLbrk7nKxr+bf5ECLZaMv1jwAAMpk3xe1ukKeJdFccTaGFmHJN+TihMxqc42yr/io2fHPPiL7ikkvtrHENpQLuhI8SEs+Xx0PH/R1Q7FtnMUS+5ZIPG6x7DhdfNDAq7ss2oqzJ1QirY/xUlW5tuyt3B3j1p8QZo/aXsns9caKM2f7iq1V/c2Xj6pqxZl+OPSR3eGxuUe1Q+aGqdVjg2Jjjyr75rRJUCvOjEBc7Kv63JVgsayvU2LNAxGyPjAZK84AAL+N//MQeOKe9ra1bO3TLCFlae4fgvW+AICKaN8mlrd/VfsK/LUFAKAi2vdibD8B+wIAYF+ASwoAgH1hXwAA7Av7AgBgX6gC9gUAwL6wLwAA9gWwLwAA9oV9AQCwL4B9AQCwL+wLAIB9AS4pAAD2hX0BAL8B+56cietyb5l5EtcAAHB7+3Y5WRncU04G4JkGALi9fQEAAMC+AAAA+wIAAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAAGBfAAAAsC8AAFQA+6b64jIAAED54pvKRJg/rgMAAJQv/mFMRNlxHQAAoHzpGsWEiInBhQAAgPKEvMvkN7s/ar8AAFBO+Pp3paRX2ldEhaXeBwAAoFxIDYsSQvwbDQl/wk//hssAAAAASUVORK5CYII=) Controls what happens to any endpoint that doesn't match a rule above: | Option | Behavior | | --------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- | | **Allow access - protect only the endpoints listed above** | All REST routes are public by default. Only endpoints matching a **JWT required** or **JWT + Roles** rule need a JWT. | | **Require a valid JWT - keep only the endpoints listed above public** | All REST routes require a JWT by default. Only endpoints matching a **Public** rule stay public. | *** ## Example Configurations[​](#example-configurations "Direct link to Example Configurations") #### Example 1[​](#example-1 "Direct link to Example 1") Assume you add a rule for `/wp/v2/users` with `ALL` and `Exact Match`. The rule applies to these URLs: * `http://yoursite.com/?rest_route=/wp/v2/users` * `http://yoursite.com/wp-json/wp/v2/users` #### Example 2[​](#example-2 "Direct link to Example 2") Assume you add a rule for `/wp/v2/users` with `GET` and `Starts With`. The rule applies to these URLs when called with `GET` only: * `http://yoursite.com/?rest_route=/wp/v2/users` * `http://yoursite.com/?rest_route=/wp/v2/users/1` * `http://yoursite.com/wp-json/wp/v2/users` * `http://yoursite.com/wp-json/wp/v2/users/1` * `http://yoursite.com/wp-json/wp/v2/users/{any_other_path}` #### Example 3[​](#example-3 "Direct link to Example 3") Assume you add a rule for `/wp/v2` with `ALL`, `Starts With` and Type `JWT required`, and set the **Default Action** to `Allow access - protect only the endpoints listed above`. This way, you are making all the endpoints under `/wp/v2*` protected and they will be accessible only with a JWT. For example, all these endpoints will be protected: * `/wp/v2/users` * `/wp/v2/posts` * `/wp/v2/comments` #### Example 4[​](#example-4 "Direct link to Example 4") Assume you add a rule for `/wp/v2/users` with `ALL`, `Starts With` and Type `JWT + Roles`, with Roles set to `administrator, editor`. Only users with a valid JWT *and* the `administrator` or `editor` role can access `/wp/v2/users` and its sub-paths. Any other authenticated or anonymous request receives the "You do not have the required role to access this endpoint." error. ## How to Pass the JWT[​](#how-to-pass-the-jwt "Direct link to How to Pass the JWT") The JWT token can be provided in multiple ways, depending on the options set in the plugin’s General settings: * Header * Request URI * Request Body * Session * Cookie ### Examples[​](#examples "Direct link to Examples") #### Sending JWT in header[​](#sending-jwt-in-header "Direct link to Sending JWT in header") ``` curl -X POST "http://localhost/wp-json/wp/v2/users" \ -H "Authorization: Bearer YOUR_JWT" ``` #### Sending JWT as query parameter[​](#sending-jwt-as-query-parameter "Direct link to Sending JWT as query parameter") ``` curl -X POST "http://localhost/wp-json/wp/v2/users?jwt=YOUR_JWT" ``` #### Sending JWT using `rest_route`[​](#sending-jwt-using-rest_route "Direct link to sending-jwt-using-rest_route") ``` curl -X POST "http://localhost/?rest_route=/wp/v2/users&jwt=YOUR_JWT" ``` #### Sending JWT in request body[​](#sending-jwt-in-request-body "Direct link to Sending JWT in request body") ``` curl -X POST "http://localhost/wp-json/wp/v2/users" \ -H "Content-type: application/json" \ -d '{"JWT":"YOUR_JWT"}' ``` --- # Refresh token Use this endpoint to exchange a refresh token for a new JWT, without requiring the user to re-enter their credentials. This is the standard mechanism for keeping long-running sessions alive. A `refresh_token` is returned alongside the JWT whenever you call the Authentication endpoint (`POST /auth`), provided the Refresh Token feature is enabled. API Reference Explore and test this endpoint using the [interactive API reference →](/api/v4/refresh-jwt.md) ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `POST` **ENDPOINT**: `/simple-jwt-login/v1/auth/refresh` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/auth/refresh&refresh_token={{YOUR_REFRESH_TOKEN}}` **PARAMETERS**: | Parameter | Type | Description | | --------------- | ------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `refresh_token` | `required` `string` | The refresh token returned by the Authentication endpoint. | | `AUTH_KEY` | `optional` `string` | Auth Code value. Required only if "Require Authentication Code" is enabled in Refresh Token settings. The parameter name matches the **Auth Code URL Key** configured under Auth Codes settings (default: `AUTH_KEY`). | | `payload` | `optional` `json` | Custom JSON object to merge into the new JWT payload. Keys provided here are merged with the standard payload generated from the user record. | ## Request[​](#request "Direct link to Request") ``` { "refresh_token": "YOUR_REFRESH_TOKEN_HERE" } ``` With an Auth Code and custom payload: ``` { "refresh_token": "YOUR_REFRESH_TOKEN_HERE", "AUTH_KEY": "MySecretAuthCode", "payload": "{\"custom_claim\": \"value\"}" } ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "data": { "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c", "refresh_token": "f6e7g8h9i0j123456789012345678901234567890123456789012345678901234567" } } ``` Token rotation is applied on every successful refresh: the submitted token is invalidated immediately, and the new `refresh_token` in the response replaces it. Store the new token before discarding the old one. ### 400[​](#400 "Direct link to 400") The `refresh_token` parameter is missing from the request. ``` { "success": false, "data": { "message": "Refresh token is missing.", "errorCode": 51 } } ``` ### 401[​](#401 "Direct link to 401") The refresh token was not found or has expired. ``` { "success": false, "data": { "message": "Invalid refresh token.", "errorCode": 51 } } ``` ### 403[​](#403 "Direct link to 403") The refresh token feature is disabled in plugin settings. ``` { "success": false, "data": { "message": "Refresh Token endpoint is not enabled.", "errorCode": 81 } } ``` ### 500[​](#500 "Direct link to 500") Internal server error. ``` { "success": false, "data": { "message": "An unexpected error occurred.", "errorCode": 22 } } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/auth/refresh \ -H "Content-type: application/json" \ -d '{"refresh_token":"YOUR_REFRESH_TOKEN"}' ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->refreshToken('your refresh token here', 'AUTH CODE'); ``` ### JavaScript[​](#javascript "Direct link to JavaScript") ``` fetch('https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/auth/refresh', { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ refresh_token: 'YOUR_REFRESH_TOKEN_HERE' }) }).then(r => r.json()).then(console.log); ``` ## Error responses[​](#error-responses "Direct link to Error responses") | Code | Meaning | | ---- | ----------------------------------------------------------------------------------- | | `51` | The `refresh_token` parameter is missing, or the token was not found / has expired. | | `81` | The refresh token feature is disabled in plugin settings. | *** ## Settings[​](#settings "Direct link to Settings") Configure the refresh token feature under **Settings → Simple JWT Login → Refresh Token**. ### Allow Refresh Token Endpoint[​](#allow-refresh-token-endpoint "Direct link to Allow Refresh Token Endpoint") ![Allow Refresh Token Endpoint](/assets/images/allow-refresh-token-endpoint-b65060ee8cd8c56e98880dc12c93a601.png) Enable or disable the refresh token endpoint. When disabled, the `/auth/refresh` route returns a 403 error. When enabled, a `refresh_token` is also returned alongside the JWT from the Authentication endpoint. ### Require Authentication Code[​](#require-authentication-code "Direct link to Require Authentication Code") ![Require Authentication Code](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAB0CAMAAADuBmGdAAADAFBMVEX///9QV168wMT3+PkmNURsdX2ZoKb4+fri5OcdIydxeoK6v8KXnaTk5uj09PXt7u/Z3N9/h494gIfq6+3l5ul9hYxveICcoqfBxMiLkph6gonM0NPv8fLe4OPw8vPW2dyCipGVnKO1ur7m6OqGjpTV19g1Oz6mrLHt7/BscHJ7g4rh4+WPlpytsrd2foaJkJbO0tT29/jf4OKTm6BKT1KMkJKQmJ5tdn6NlZvIzM+wtLl1foWytruzuL3c3+H29vfr7e8yQE7Fys3y8/SFjJOhp62Ei5LAxMjT1tklNEOepKrX2t3EyMx5gYgkKi/R09aJjI65vsJNUlVzfIN5gouTmqBye4Py9PXe4OKboKbBxcmPl56+wsZTV1rMz9Lj5eZ1eXzBwsR2f4fMzs9XXF/p6up/goWkqq9jaGv9/f07QUQhJyu3vMCssbZDSEvp6uzi5OWiqK2RmZ9eYmaeo6n19fb09vdud3+us7iAiJBKV2PJzdF9ho22u8Dn6et8f4OEh4rz9faGiY6wtbqZn6UnLTG8vb6KkZd0fYSorbOXnaMjKCw8SldUWl2Hj5fQ09WPk5WMk5nZ3N7a3d94e36xs7SUmJqprK+rra5rcXcpLzMrMDQ/TFoeJCiUm6H5+fkoN0bDxsg5P0JtcXTb3eBGU2DEx8pmcHs9QkfR1NdhZmlVYW3Y2tplaW1RVVgwP03c3t/u7/GLkpmbm5szMzO9wcWgpqu+wMGgo6VARUguNDgzOT1bZnIxNjuqr7WwsLBkZGTT1db7+/usr7FxdXh+gYQqOUi5u73Hycukpqlvc3VHTE/a2tx4foJobG6Ym52Mj5FfanWmqauboaeprrPV19ouPEskJCROWmdnbnRaYGNTX2q9v8BZXmGanZ+/wcNfX19ibXhyd3lWXGNWW16ChYcgJir29/dfY2eDjJRDUF1dXV2QkJCNjY3Jy81LV2Rpc36ytbZ0en81Q1C2uLlxe4WdoKJ1eXsgICBTWmE4RlSLj5FdY2qAhIeKjY8rMzkBEpzdAAAACXBIWXMAAAsTAAALEwEAmpwYAAAUKUlEQVR42u2deVxUVf/Hr8ydOR2EUJYpEUmSZFdQQBDhAUGiVFAxMVDIxBRNVOJBcSfCJSNL00pwyT13zBbXSk0tW36PpZXZ7tO+PG3P+vv9Xr/vudvcQSxRf6PU5/3HOPfec+4953tn3n75zmGQJAAAAFeIa318rwEAAOASfH2qNPmGBjIAAAAuI7BBlW8VQgEAAK6kSui3KgCBAAAAF2e/VHzwsSAOAADgWiw+kuSLMAAAgKvxlaRrEAUAAHA118C+AAAA+wIAAOwLAAAA9gUAANgXAAAA7AsAALAvAAAA2BcAAGBfAAAAsC8AAPwu7RvG72hmj8780V9vcBPn3Zp/6HzM4vfg3gMAWpR9Yznne4vjfv170eKKl57nSMRyzrc47dnEZ/26fUdyTl8ElFJc7NmcQzoTD5fWjH39WdgXANBS7Bv946ePD2vKvnvP7uH80EVe7z8k75cuxr7NPaTxIo21tPSzTbAvAKCF2DflX63ebdXqWBP2fYWlL+NxjDXMLq05/gElwc/GLjsbx7MZG8ePsm6c36RUHqge8EHsuG6W5wbVjJ2VqvW2rOaD+J48xp7gPJQ9yjuz46Rjvp/sG3e6LpZSVKN9GH99zd6xb7AlogH/u1JeCIw7nv3ZLOZV+hnvfM+HToeUfocnOvopxMTy1QsZG/UhYyOK9+w/LeazdOz+1w8L+w4NW71s+LN4DQAArir7zm3VmmW1+rFJ++Ys5z+zvFq+7X9K+VL24gIeu6ZGte8cJ/suWDPG814+9q73jUxzDl/+6gKROJN90xX7/r2Ub4tbSvZdsHoj35vHjPZhnNe+xPnCFx/hfHbcd0KxFcW87vCaWDahbuvs03zBDtMhNpsvu4NU62v0U1Nfzp9Tr3yUL3/9Cz5uPXuZnry/gK4wdA8fM2s/P4YXAQDgarLv461iGHv3X03WfXk2lXXP8HGp7BivI++VUqW3Kfs+RH884zPaV7WMj1R7v86L2Vb+vsm+RuVha9VQcqajfRiPZWw3/0ArLwjFfsj5DsZ8WJUX9dhIXnUcClzOl7CKzvwNRz/Bz5x/p165VlwmjI9h2/hrjAm/D+DbKBHmm/AiAABcTfZ9t5X+cE7dd9ByXptHOaTKq4f5F4xEqtl3h8m+9PHaq1qrl5XOvgtImYf48h3CvoHshNm+LzMvzp9wtA/jnzA2iAzuUOzLvEY5TcBdw5dRmzjToS1cCH44ncvox9TlEEvUca8mMVNifZyNpXSd3UH2fUW90li8CAAALcO+r7BjQqIj+IKjI0aMOOR1L9/IKAEm+9ZRTeEHk31pHVjVOL6UWv3wqtJ5qebWAcKbEewlYd+tIhdVPnUT9nW0V1atCYsWcl6kKnYE54WMpZJEd58YsZHs6ziUzvkJlrdHyX3vcNiX6r671bpvrZDyJiX3pSfbyL7/4cfpSiOW4EUAALh67Hv9rE9bvfbaa/TQswn7sk9450Aqwm6LiwvbLeq+216pE/at5cfjNjrbl36+Hzsg7q5sdUFuKV9dXFxM9d2K1Bq+6d4Fwr6k4LhHDfs62hsWncn5mrhuWt13dVzYIPZXXnr0sMh9HYfMdV+TfdU1D7ULNpnrvuNmU734HtZtD3WO23YHXgQAgKvHvve20nm8KfsOHUd2axhQWrOxeDZjH8YuH/6csO+We7I3vtHIvpYT25Z1rt2qLHqgcgMtPhAZ68/sTOzy2tnCvltWCxUa9jXaOyw6gLLlY8aaBz6ceQ7iNbNixboLxyHLy4Oyx74SwRrZV1nvm72VVjY8UVy3//RIZc3D8jFh4nO9boc3ZscWH8KLAABwddn38RT/Jux7HpYI+wIAALh0+97HjsK+AADgcvueDn0c9gUAAJfb91P244XbFwAAwOWy72v/DfsCAIBL7XudseYhAzECAAB8uzoAAMC+AAAAXGrfnv7uv3LUu4Pyz/XdnfYWdr3Akwda8/QOvvplwtucp3Gji5ixtT7vId8mh3/9bRc4wuDo5oXLzaM5rbW56mFoFJXLeeE8W24TU47o0ux4XkiIym/Emw2AS7Nvx/XMy17EXGLfhl5UgRbv2rsnNMu+Re7nt4U/yU2c99y9Kf0us33921yMfbW5Nm3fIvcLPIvS8DcunJgRwH7dvtfdeNnsO+2GJs8KAOzbHPt28Geuse9vv1Uvzr4XuveK2LfpZPf/w76tr2Ousy9jsC8Al2rfvlarVX1b96507x5Kuo1KaDs6hk18xjs8hBzhPaUyd1KMIsaUdu7Bi0gd97lnzHDYV2sY0eVAQlvtbxctXJHbUTztmeSXT57ROlCFoLVyMfppvKpPUjilrG6RHnMz+hodNPtWzK/M9ejEWA8fxkKiWBfq1MHWM9K9jLa9bEl+1NL2TGQGbXrQodai8hD6ZpK1XB+KsldUHmbGu3dsbzRWSEmwT3bTL88K2yaNJ7XEjA9PColR3RrUZ173CVO8/ahfZG9K8tqx0PL+1v6BykmVFmUrhmTSmE2dbOUJwfF0Ae8DD1eyrAx7gidLFjENGa1UHrQwaEPXNwllZmyGX255oHKek23pITOH9W43eXKycUP0hm73T8oVwdLPIy58a2RlB3U7WYzPLTJo7kBtYGtvG2JdQbdlmL+/2loNvh6T1iy0Yy/9ljpFSN2lvQz0EOlTVGcnKg/avWttvH4AgH2bmfumaLnvDf2jvaa0o7ddQUVFwjTWZn3oDRkDabMypUPbnkKMgV2eDk28M5SVz+2U5e+wr9YwwjqF+Xirf3Oo98KAxHlDWb73Sc925Bmtg7CkkiiRkfoEe/YNH8jcrE+ynAyjg2bfvGRPT1uQYV819/XL6XRbCGMFkzr1bZvFbP1nsvEhakJK543pGlTEThpjFnvJvhWVz3j1s681GhMThlSHVizSL+9pvzm0jz2a9dq52HeF+vVvbvb8CeWVIT4DvS26fZO7+7I2eY7ct0d1aPW8BnMnm78Pq06gWMVX0DndQt8KT59pz2MW775irnoYtKHrm3pK269L1syE+53sa4/Oy1ts3BAj97UP84nKMEKgXniCsX035b5uVtqvDSx+SoPlJIuYPHpmonuqkaUaMWndif6v1G+pKUL6Lu1loIdIm6I2O8W+2r1D7gvApdrXRtmWpYsv836SsSnj1UrACjJKIpUUK4UY3cpo1/35FnsKY8nOlQdqGNGjirGdOcau8rtZ/N2M9bXm6R1M9rXYKYcbFszcSC4xPSr0DqbKg29uI/seoAx5Lps4hBoPLGe2KMaenGvYd617umkoun375lLj6+YbjYkZCeJRv3wyta3IjWZ3Uq431E91K41osZWm4j5Tt++MrhOdKg8d6aGyt7mTjcJVZU1l3jT95Hg6f3gha9ePZYUr/9NoYdCHrm0aUo2nuHtaA032tbg/XWW6IYZ9u4qrVOnnUS5MM9O3FfsKWWsD695H5M0R4kpdcwz7GjEJCU9k+i01R0jfpb0M9BBpU9RnJ+yr3TvYF4BLtW+wVZClFHp7TWKdbH5Wq0iF19IPo/OEGOcrDaobrPTpTqLDvlpDpcAofEVkxSdZrVEsk7483cuap3cw2bfBSn9N6GR/tZRJktU6aPaNmd+xh9Ua42zfgYqcCpUxJChlS+Eqzb6FHc1D0e07TeztdbvRmJg/Wjzqlw+ZL0IQHaic1GpUdZWpUBg0+wbe55cbYnHYl3zEVtxt7mQjobJ5KUroQsQVIp8WzSZFKfbVwqAPXds0pJpJFmTWiU6Vh52TMxYbN8Sw7/1KsPTz6NVbfVuxr4eoKasDi4hM8s9nEUmO2yKCb8QkPJiGoN1Spwhpu7SXgRYifYr67IR9tXsH+wJwqfZdMczxMRu97d6cFFGxXth3Gr1l2woxzlDzLYudGtzosK/W0Gxf72G+llujWDy9p9uI3Fft4JT7ksryg413sNZBs++wrmsDO5F93an2Wx7FPPVP3cgPa8MdHxoJXYRrue+QKtNQlL1K7kt/orl8vtktMwrUKaiXF8VZCyV2dk9mXtal27d7PmM3i2zSktN/mrFOzi1TKLK3uZONnJRq9VFClyyWffkVsgZ7Q5KnmvuqYdCHrm2Kp8rM4ikkvlYld18sUulwkaimjs40bojeUAuWfh49DPq2bl/HwNKH9Qg13xY199VjUp5Qod9SpwiVO70M9BBpU9RnB/sCcBntmzN9IrO0N952HsOYJVLYt6yiIlKp+07oT0eHdmLl5SygkuyrfcamNTS/zbt4stAuJNPMQMvtou6rdhD2fWuSVve1WdK7DjTewXoH1b6tSQDVZN+u+SzFPYoF9phg+MHSrqeF+Sw2dBHcW637BlfTtjFmsVep+z7NfJNSzG6ZOS+Libqvevki94lsmDWaRZUFsLwnz7HvgVtZaGY71reB+UyPVk6qtJicxbKSQs2dbPMKfYIeVkPn6d6BJYaTXMvezFDnqoVBH7oeFVFjFTPrVxnARqt13wa7L8u35gRSvkufUuo3RG+oBUs/j25NfduwrzawnArWxh5gvi0i+I6YWILiY/RbaoqQvkt7Gegh0qaoz85kX+WW9vLEmw/AvhdtX9Y+2J7hYdh3aPjDQSHCvm5dhoyuUMRYFO8+vcCTfhKv7Di6K7MMUdcJaw3Nb/P1/gnXedCP3T2nV05R1jwoHYR9J96prXmYRIsOLMY7WOug2Tc9uOsKYd8O8XMTxGlCxJoHzQ8Bt3p3ebjQ0EXiZHXNg5ctl9Y86GMWe5U1DwXu9EOz2S0sZaey5kG9PFUsMm+nFpbk6e5ze51j34b7IjPpdPm04mC0elJ1VYTNmkmlVVMnW1THycqaB7E672Sm/WERmfVW7RNGPQza0PVNgZgZG+iX+2agtma3IOOZypzABKvVb61xQ/SGerD08+jrxrRtw77awEImW93XO90WJfiOmMSUrYjRbqk5Qtou7WWgh0ifojY7k32Vs9pz8OYDsK/LftN40f2I98UsnsUUAYB9AdSEKQIA+0JNmCIAsC8AAADYFwAAYF8AAACwLwAAwL4AAAD7AgAAgH0BAAD2BQAAAPsCAADsCwAAAPYFAADYFwAAAOwLAACwLwAAAN2+AAAAXA7ZVwIAAOBiYF8AAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYF8AAIB9AQAAwL4AAAD7AgAAcIV9P9/5Xtr2dx5kV2pcf/r26127vv7WgjsEAPhD2bd61S2CI6sOXJlhPfb2U2dGjZrz1NvP4xYBAP5A9vVIkzW2267EqE68oD974THcIwDAH8a+U7bLBmnJVyDzfcHx/AVkvwCAP4p9Pz9C1t3QPjCw/QZ6smrl5blSkDy4ib0WWfZqvO9Pb5u33r7w6z825tx9swfgJgMAWoh9C07J8t/Up4Nl+dRtpkMPyF+VSE/KaY49D8oPXtiVpux78wLt++1T5q2nvjFt3MX5/rCI813ixSWwLwCgBdt33y2yvFB9ul6Wb9nnZF/5wEXat2masu/XZ8xbcz4y2/cRaceY2OZcAPYFALQY+6aRfdPVp6lk3zQn+66qP6jYN/WXB9L2ZUnTRW34Y+XYX+QHNx8p8pr3wPYNRZIU+rdT78XLU6WB8nuS9I58s1J5CJLtG7aPl6rfObWujySVPPjTV32asO+uUeatUbuc7SuN5CslrzV7Nj4qSdeuWRZ773BJGkc9/vpfSuWh84D3S6Ufji8bQ6fdMbxu60uwLwDgd2HfwfJbwr6fr5M32+Uja5/eLG8uq9bsu+rjDYvXyT3aHqln0sdy/eDtin03m+276vs7qw/I9V++I8+XbPL2wfXNtm9J3G5JumdW0cjSY9I/aovWd25k3y+YNHL1s14PnZVW7r7L60Q27AsAaCn23eyoPLiRfTc72XfaV/XRZN8Z8jpRFf7SVHn4i7xBov2U6k6We3nJ8kypz7n2/XeFJH1PW4uo/1SqYkQ3VXmYc/7KA+d873fSjjr6KO65f5TUvChJSxvZ9wlJWvMGJdb7J47cf1CSvoB9AQAtxb4Jtxifun1P9i1wsm/7akp/06RbRbkhiJqZ7fuWRPsVChbJskTm1ew71bDvLyK3Vtus/EmeJgU081O3R6RuZ9+Q5nDB6QBOKfrPjey7RZK2KYePHR0kesC+AICWYl+2yrziTC5xsm9hydRVSu5bL0m/UO67Uw427Fstct+vEhMTb86i3DeCSgtTpXxKcqtOGfYdrCjdg9okHxS578Im7GtxWnH2z4ON6r6LalIXjlW2SrJJtR+Qfeuo0PyJw75bH1UOj9xPQx8D+wIAWsxvW1Snne+3Lci+UrJsqvtSdaG+rJ/DvrR/XlnBvxOVum8a2ddXloNJ4mb7jpfrC8rc90ke8gNl7zRhX+n5FxzPP3JaRSbsK23935KzD5VIoxZK/3hESo8l+w4/JN1U57DviN07pJIzVPc9JG1ZAPsCAFrQbxob8l3VR2psX2mdsebhpCR5rZPlnQ77Sl6D60+993GEFLrhyLoQsq8U9dWRL6c62Vca+N6p+n02qeTLtDRbU/Y1/bJbo191U+y7vu7a9Ec6731/jnRtWPZGkftu2VR7OsxhX+nMoJpBYWLNQ+zZMNgXANCCvmXnRvVbdn6Sp1zKyW8W9r0onn/7qTniW3b+ueQ3m84ZjrsIAPj9fMPkyoTNaWn7gkqkK2NfaeU3H+3a9dE3ByXYFwCAb1d3oX0vHNgXAAD7AgAAgH0BAAD2BQAAAPsCAADsCwAAsC8AAADYFwAAYF8AAACwLwAAwL4AAABgXwAAgH0BAADAvgAAcJXZ1/cgwgAAAK7loK8k+cQgDgAA4FpifCSpygtxAAAA15L6Z3poCEAgAADAlTQ0qP+ExqD2CwAALuJgTGqD9vTPPr7XAAAAcAm+PhX4LwgAAK4Q/wfXuu2BfeL6wQAAAABJRU5ErkJggg==) When enabled, the client must include a valid Auth Code in the refresh request. The parameter name used to pass the code is the **Auth Code URL Key** configured under **Auth Codes** settings (default: `AUTH_KEY`). ### JWT Refresh Window[​](#jwt-refresh-window "Direct link to JWT Refresh Window") ![Refresh Token Settings](/assets/images/refresh-token-settings-b1d875c0fe767310252e6fa750370049.png) How long (in minutes) a refresh token remains valid from the time it was issued. The window is **rolling** - each successful refresh issues a new token with a fresh TTL, so an active client never expires as long as it refreshes within the window. Default: **20,160 minutes** (2 weeks). ### Refresh Token Secret Key[​](#refresh-token-secret-key "Direct link to Refresh Token Secret Key") A separate secret used to encrypt refresh tokens stored in the database. This key is independent of the JWT signing key. Use a long, random string - the **Generate Secure Key** button creates a cryptographically secure value. caution Never reuse your JWT signing key as the refresh token secret. If one is compromised, the other remains safe. --- # Register User The Register User endpoint lets you create new WordPress users programmatically via the REST API. Useful for headless registration forms, mobile app sign-ups, or any external system that needs to provision WordPress accounts without going through the standard WordPress UI. Registration is **disabled by default**. Enable it in **Settings → Simple JWT Login → Register User**. API Reference Explore and test this endpoint using the [interactive API reference →](/api/v4/register-a-new-word-press-user.md) ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `POST` **ENDPOINT**: `/simple-jwt-login/v1/users` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/users&email=NEW_USER_EMAIL&password=NEW_USER_PASSWORD` **PARAMETERS**: | Parameter | Type | Description | | ---------------------- | -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | `email` | `required` `string` | The user email address. | | `password` | `required*` `string` | The plain-text user password. Not required when **Generate a random password** is enabled in settings. | | `AUTH_KEY` | `optional` `string` | Auth Code value. Required only if "Require Authentication Code" is enabled. The parameter name matches the **Auth Code URL Key** in Auth Codes settings (default: `AUTH_KEY`). | | `user_login` | `optional` `string` | The user's login username. | | `user_nicename` | `optional` `string` | The URL-friendly username. | | `user_url` | `optional` `string` | The user URL. | | `display_name` | `optional` `string` | The user's display name. Default is the username. | | `nickname` | `optional` `string` | The user's nickname. Default is the username. | | `first_name` | `optional` `string` | The user's first name. | | `last_name` | `optional` `string` | The user's last name. | | `description` | `optional` `string` | The user's biographical description. | | `rich_editing` | `optional` `string` | Whether to enable the rich editor. Accepts `'true'` or `'false'` as a string. Default `'true'`. | | `syntax_highlighting` | `optional` `string` | Whether to enable the rich code editor. Accepts `'true'` or `'false'` as a string. Default `'true'`. | | `comment_shortcuts` | `optional` `string` | Whether to enable comment moderation keyboard shortcuts. Default `'false'`. | | `admin_color` | `optional` `string` | Admin color scheme. Default `'fresh'`. | | `use_ssl` | `optional` `boolean` | Whether the user always accesses the admin over HTTPS. Default `false`. | | `user_registered` | `optional` `string` | Date the user registered. Format: `Y-m-d H:i:s`. | | `user_activation_key` | `optional` `string` | Password reset key. Default empty. | | `spam` | `optional` `boolean` | Multisite only. Whether the user is marked as spam. Default `false`. | | `show_admin_bar_front` | `optional` `string` | Whether to show the Admin Bar on the front end. Accepts `'true'` or `'false'` as a string. Default `'true'`. | | `locale` | `optional` `string` | User locale. Default empty. | | `user_meta` | `optional` `string` | Custom user meta as a JSON string. Only keys listed in **Allowed User Meta Keys** (in plugin settings) are saved. Example: `{"plan":"premium","source":"app"}` | ## Request[​](#request "Direct link to Request") Minimal registration: ``` { "email": "test@simplejwtlogin.com", "password": "SomeSuperSecretPassword" } ``` Full registration with optional fields: ``` { "email": "test@simplejwtlogin.com", "password": "SomeSuperSecretPassword", "user_login": "myuser", "first_name": "John", "last_name": "Doe", "user_meta": "{\"plan\":\"premium\",\"referral_source\":\"landing_page\"}" } ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "id": 1, "message": "User was successfully created.", "user": { "ID": 1, "user_login": "myuser", "user_nicename": "myuser", "user_email": "myuser@simplejwtlogin.com", "user_url": "https://simplejwtlogin.com/myuser", "user_registered": "2021-01-01 23:31:50", "user_activation_key": "", "user_status": "0", "display_name": "myuser", "user_level": 0 }, "roles": [ "subscriber" ], "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9..." } ``` `jwt` is only included when **Return a JWT in the registration response** is enabled in plugin settings. ### 400[​](#400 "Direct link to 400") Required parameters are missing. ``` { "success": false, "data": { "message": "The email address or password is missing.", "errorCode": 35 } } ``` ### 401[​](#401 "Direct link to 401") Auth code is invalid or missing when required. ``` { "success": false, "data": { "message": "Invalid auth code.", "errorCode": 32 } } ``` ### 403[​](#403 "Direct link to 403") Registration is disabled, or the client IP is not on the allow-list. ``` { "success": false, "data": { "message": "Register is not allowed.", "errorCode": 31 } } ``` ### 409[​](#409 "Direct link to 409") A user with this email already exists. ``` { "success": false, "data": { "message": "User already exists.", "errorCode": 38 } } ``` ### 422[​](#422 "Direct link to 422") Email format is invalid or the email domain is not on the allow-list. ``` { "success": false, "data": { "message": "The email address is invalid.", "errorCode": 36 } } ``` ### 500[​](#500 "Direct link to 500") `wp_insert_user()` failed or an unexpected error occurred. ``` { "success": false, "data": { "message": "User could not be created.", "errorCode": 52 } } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST 'https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/users' \ -H "Content-type: application/json" \ -d '{"email":"myemail@simplejwtlogin.com","password":"test"}' ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->registerUser('email@simplejwtlogin.com', 'password', 'AUTH CODE'); ``` ### JavaScript[​](#javascript "Direct link to JavaScript") ``` fetch('https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/users', { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ email: 'email@simplejwtlogin.com', password: 'my-secret-password', AUTH_KEY: 'my-auth-code' }) }).then(r => r.json()).then(console.log); ``` ## Error responses[​](#error-responses "Direct link to Error responses") | Code | Meaning | | ---- | --------------------------------------------------------------- | | `31` | Registration is not enabled in plugin settings. | | `32` | Invalid Auth Code. | | `33` | Client IP is not on the allowed IP list. | | `35` | Email or password is missing from the request. | | `36` | Email address format is invalid. | | `37` | Email domain is not on the allow-list. | | `38` | A user with this email already exists. | | `52` | User could not be created (`wp_insert_user` returned an error). | *** ## Settings[​](#settings "Direct link to Settings") Configure under **Settings → Simple JWT Login → Register User**. ### User Registration[​](#user-registration "Direct link to User Registration") ![User Registration settings](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAADeCAMAAABWgVMVAAADAFBMVEX4+frw8fLu7u4hJSmqu7tsdX0mNUTMzMz////i5OdQV14dIydAREdtb3GNjpDDw8TIyMgsMDQ5PUCtrq8zNzr4+PkxNDjAwMFOUVQ2Oz67u7xqbW+ys7SwsbGXmJlbXmG/v79LTlGXnaTz9PXs7vB/gYOanJ1SWF99ho2UlZd4gIfR09UqLjIjJytIS07KysrU1tnc3uCIiYtzdniFh4lYW13Ly8vh4+Wio6X19vf39/hjZWh1d3mlqKyen6DCw8Pl5ulCRkn6+/tlaGpxeoKhoqN3enzo6usnLDB2foZFSUxER0pTVlk/QkVfYmSoq69PU1be4OPk5ufHy8+0tbaytrtoa221ur7q6+1LT1J9f4CTm6C/wsZfYWSqq6yPkZJRVFddX2J6fH7v8PKJi401ODzu8PFwc3WLkphiZGeepKlvcXTGxsatra63uLklKi44Oz8lKS2QkpT9/f2lq7C8vb6lpqdVWFuAiJDi5OVweYGiqK53fYJ0fITFxcXt7e68wMTBxck9QETq6upITE8oN0aChIXExsm8vb0uMjUxQE709fbY2tyYmpuMkJIvMzfx8/SPlpxyeoJZXF/M0NOqrK+Xm5+xsbKQmJ/a292KjI6ipqk7P0Kzub2rr7WdoqeSlJV6govGycyMjY41Q1Gtsre2u8CnqKnW2duaoKVtdn6FjJTm6OmDhYghJiqus7hWWl1+g4hud4COlJqHjpRXXWRzeX5maWyFi5KgpauIkJenp6jZ3N+prrNgZGewtLk9QUWusLOVl5mEiZC6v8JkZmi2trjNzs+Um6FucnRfZWxUW2J7g4qpqqs6R1VzeHp1fYW4vcHJzdFyfIbS1NfO0tRaYWiOlZxwdnuTmJybnZ98gYdXXF9bZnJXYm5kbnhTWVxfanVpb3VeXl4zMzO/xcW5xsZncXtMWWUtPEvg4OChp6yBhotUYGyjpKXi5ea5urpjaXDBxMZATVpEUV4iIiLDzs6+wMKztLVaX2Jtc3knNkS0wcFrdoBnZ2fAy8taCqixAAAACXBIWXMAAAsTAAALEwEAmpwYAAAgAElEQVR42u2dB1wUZ97HR/aWZ7JDWZpSVECKCAuKFIUoiAZFghwCIioKEpoNRCBRDBZsQRRr7C1q7C1qYi+xt+SSnCXJmXLJpZoz5nJJLlfe932eKdsAg6icL/y+nw87sztPm5ndL//9z7O7HA8AAKDp4diNV3qvpwAAADQJvdKrZft6t+IAAAA0Ga3yRPt6V+NQAABAU1KdR+1bjcgXAACaOvqt5vh0JxwHAABoWpzSOb4XDgMAADQ1vTj+KRwFAABoap6CfQEAAPYFAADYFwAAAOwLAACwLwAAANgXAABgXwAAALAvAADAvgAAAGBfAABoefa1Fvo2qJyL8DLODwCgBdo3b9u852o/OkTI57hdwm+YcYggCLm3M+v89rTM22f06/OFmXWU0Alt6W3a7V9wfgAALc6+GS9qKP5/a6x9XfYtEIQ3f6v7+9kXAABann37/Ukj81q/+uwbfDlG2HOyH+fU3Vl3euhUlirIua17WV9qoU7IpBH07pi4mb40CP5liG5fjVAkZR7kukMFRkB3IWaVVQxnXSToEmJZ4xQ3KfPwt9sLHH/dyCqlXc6tXIYTBgBo1vb1ep969yzHHaaLNyLqse8hIb9m1afzuK7CaZ9fhURm38B9+b/oSwUIwj3Oa5+Q9Fq8cIbrUiwk5esU+8p1XUcKuTU1yd2F4gUv5nPOv4ZSATvk1RQLbjVvivZ1FYS0k8KeObSS8KkPFTXOGACgOdt3tMZgX03Peux7Ulj1t4Ect3CPUMZV64SLVJcjjfO+QhHN7/4i7JnKbRTsuFAhnqZ8FfvKdeXMQ3dB2MgCbvoXIlgrmQdm30+FoRznJhyilYZwnJXwIc4YAKAZ2zfiprF9r0Qab/uU5gS4gYJwgbtoTw2bFLxSkNhKdbnaYF8XZxqtenGr5a0r84WTHPeyYl+5rt6+9qzSsl9d6KO3je27RqDJhhxayFoI4ThnYQLOGACgGdu3i0bz4osvUpXeoQuNZpvxtnzhdD/m1OtU0gEXhgih1XuE+dHR0f9YaTxFjEXIGwOFWC5DCHSlWx0saH6CowGwbF+5LufLImJq3xh6WyYULfvlELPvAvFynRT7/oGjgfIhqVIS7AsAaNb2zdBo9HPNntNoTOY9XAwUiuIFFsiG+NTUnBZWcauEylU1PkUDze3L/UFwWRhxW0ioqbGOYXnfrBxHxb5K3VRhT+gE2b6FQtybNTpm3yHCpzVzzPO+sC8AoEXbl7tx0l4XVLOQ43zXCMKekHTOqWeWzmXfoam17DtwD7Vl3qr4OKvbu9mcB+HTZcICyb5KXa/bND0s29cpXxCevszseyFOEDpJzc25bef460UO9gUAtPTMQ6Nh19T6Cgk45AAAUO9VtysmV90iHklPWYdqsgXBFYccAAAaNuPszqPpKSdOsD95EUccAAAa9mmL9yNwlAAAoIk+abzrfeWTxu/vwkECAIAm+5Ydr2WvM/e+3sELxwgAAJryGybz3l29+lwrHCEAAMBvWwAAQIu37+jB3PRh/8WB0/5/m17P1H7Mf+BjGc+JdQ3pHAAAGm/fAxURj9m+TzXAW+9ta0DhvEEmd9cPrtO+3up+8xbTbyA+It5MPqoWOSJtPKWeR29T1Orygi6sZMPta9R5xjA80wAAD2vfXWr/lCfAvo0pXL99I8uPc9xEP3bDvuuyw6v6jX7+k5l9/Tjvdfv7PZB9jYB9AQAPb99BB9YNM9i3y87yA8lcLxo13nmH6m0LK9Gt/7oDfhl0ZePEZ4Z5c6O3cP3U57jkxeKvvA2iMstTRzqdOqte3IWLXHftndJIWuPEre3Hhy1WXxK76E9Dz4HcFr+K9QvF+9MWdSg4JxflXn3Hb7rai/UvVZAKS11x/usKJrIaK87Rm50p7M3/tIJnaNTKOEdLduD8p5+tYO3INST7cosGc97+ewfL0a3BvtvK32OhPrUvx+24odjXe/s7bAfZuHbS0Pj7o4svTV5H96L0Fnu4+s471wZJmQf/Vw9MLI0cSDvuj+caAODh7OuXMXCHt2Lf5PJp3ieuLeSuBdPIsRtbMPuq93Lp/t7cNv8b3nsLuOmXuI1+29nCyL7zrgU79UvmBhUc73XpFK1xihpzb57TNkM4u7H/9X63Okj2VdPvs5SLZhw+3mu9ZF+pglhY7orzXyF9NmQOXX9qcQQT4JZg77X+EUax76LgYL/39DVk+54axqWsvzFM0qyRfY+sj2ShPns4wBD7Lpq8a97ELuK4AnZyEX6l3tP2rxP3Iv3ade7OweR5185J9l0UEXHrPcS+AICHt++2/a24w1sU+65dQb+b7NpSGvR6T1w3rZcU3nbbUc1xBQHc9rV0Y/9dNOidnNGfhcBG9j3eP4CV9afv9Qf6UW/RGsPueBsnE1bQ2slqMfidVmAoumg6x02S7CtVEAvLXXH+8k8PtSpP506N1l/4kv4ryPa9wXHrXtXXkO17fbFT6bRWFU6lo03s67X4Bld6Scz7qvdvUfK+kxZTm58bLY4rckfEvP40lF6xTtqLVyc7ldNwOOOgZF/6b2Pvq7AvAODh7XuEhqODDyv2LS1lkeA0LuNSyp0b6+VEcDf2LnvRRu6gePWqC+cfPDH96PcsqWqwL7du5/5h3q2kC1xSjW6L3rk23WDfwyy7rP5etC/tUyl6eCnTpWhfqYJYWN+VktTtsIXzC+CkzEO5Wh1gmvelg1BqyPb12h98diB3MPjsdBP7znknkju+I08OiRX7LhXr3hLHxe1If28nXZRS+1bQ5buX8tTeLBiX7Ct1BvsCAB7Wvl6LRfN0U2JfphW/pfRdfumcVq8cGWxi30sZUp31e/24dYOkuJjbQoPLXmr2Y0UDC0q5/cmGGvQn4jJ2iOFvshj7DmZX+BYq9lWKLqIZ3eOSfaUKYmGlK7193zsa7O/EBPh9RZd0JmJz+yo1FKcW7KV569K96mQT+y4S9/ZdM/sevyZtle07rz/dtWEs9qWjL53stJ/+n5l+EPYFADxK+27sz1Koi07I9u31zEAu5Rr9NLJ/RT/uaMVxE/sG+E3inGiomlFxhLtRIQvoxsRIp9HqyO+f4qo7rONeXfEc53VdqhEQwR0vFz9c12pHP3ZVrBVX2sFgObloxuFWTkck+0oVxMJKV3r7Rixef0K88DXwmhPXRY59T0w22FepoTj11QraSUrFK5yxffupWXtrd5rZ16nglBOXflyxb4TfHG4gy/vu75C+tLwLd2e708Kj54ztu/QsPWrbMvB0AwA02r4rTrDbFP9IZc7D4fIC1sB2qqcT5U4m9uWW7izf2YGlaadToa6VW6CzAE7RvO9EtfpAK85prd/igkFSjdL96vI5UplSNo3hXTrnoZXBvnJROuehfPqOSGZfuYJYWO7KMJ3siPq4NO1g8sRFpRMl+07yZ3MeJCEqNRSn3lBvYWvbTey79qC4fX83U/tyrY749y9YqtiXznk4XNCBzXnYst+fzXmYTOc8OBnbN+IgnfOwtgBPNwDA/+9PGg/0e6TNTWJXyx4B3TCrDADQfO0bcZyL2H7qUbbYqvQsB/sCAGDf++NVru4/ufpRtuh3dB7sCwCAfQEAAPYFAAAA+wIAAOwLAAAA9gUAANgXAAAA7AsAALAvAAAA2BcAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQDg/7t9AQAANDnUvjwAAIAmBvYFAADYFwAAYF8AAACwLwAAwL4AAABgXwAAgH0BAADAvgAAAPsCAACAfQEAAPYFAADYFwAAAOwLAACwLwAAgKawb8Smz//yl883OT2eXiMK/jp37l8LnHD8AQCwrwnjVL4eM2Z4fPiTw+PodO8sS5FZp3ACAACwrxFb/0dZGzXi0ffZYa6lzNzROAMAANjXEPn+j2F9VLtHHvnq5Uv1uxanAAAA+8pEqIzv/VRndvYPvmYPXO4uLrrZmTzqJdSqHcHSDl8tXbhw6Vcs+cA1ZJSzLHdJUbPlK6Yb/mq5BecQANBc7LvJxKzzbYzuzBQEl33de/P8PdJY+674xtJSLa2qLS2/GWa06Y9iPHwE9gUAtEz7fu5hfO+lz43t+yafXDgzpI6GGmzfj6lgb0irN+jqRyb2ffujjz7aAvsCAFqmff8yw/jejL+Y2pcaNnAbyzwE9LETDvFcaNAC60nUvkM/1Z2cKtp36uXWVuxi3QRHq5dr25dlfRdKqwtZ5tfEvpJc/2y586NvPunHJ/9oOevvOyOYfUd/Pdevt2TfLn+e+/ZE+uDeHzf7wb4AgBZkXz5+BLPvyQl5JeF85Jlvv73sRu1rV5butkS0b+LQSRfjtfzLLqTbvge0L4t9j1P7zvL/q+VEPvjtP+780fIos+/bfpvpCrPv8W++8fvE8hkWOD/z9SzYFwDQXDMPrp/Xsu+SDcy+fbIt5Ee7LaD29aFBr5BO7RtsR/PCsX/gT0bx/MXfzDx8XCvve4PFvvw5y6/5SHpJbjpdUvum8CmWb4v2nWhZwPObLftNtPwj3/sb2BcA0Iyuun1ofK+9TS37Wr3M7LsysfWal/neoUP2CEJv/jKrtKALtW+ZwPiVH+LKfFzLvrcsja+6Wa6oM/PwKpXt3/k8PxrcUulS+37Pd7O0LGH2/Uqaq7bxP5aXeP5r2BcA0Hzs6/ST8b2fSsztGyBclGacRby1x+KthIDqZGbf3TyfJ8yg9g2olMqe7M6K1rKvk8mMs3+V1GnfU6J9/Sz/fG6yZN/pfIY+9i1PSUlZayHGvnNhXwBAM/q0hcN5w/rwtrz5nIegkyXMvn/rzQfELexOJ0BsYPatnMFPcGd535KwDSX8jAD+5SFeJfm17cufMv60xSC+Vt53st6+r1iqB38t2dck73t0xc5ZNG0xq+A/lrAvAKA5fdJ4RKKylmj6RQ90vq/9vq29xU9b7C4WdA58RFLCIdG+NUOKT6aLV90W9nXJXVJG5zxYzZxQh335Dv9S5DtrPc/Xyvvu1Nu324+WP96S7Lt2s37Ow7xPNm/++Bk252HWK8g8AACa17fstPtp/kszZri2/6nt4+h0kPwtO//C54wBALCvKU7iN0xmljyeXrlb9BsmP75VguMPAIB9AQAAwL4AAAD7AgAAgH0BAAD2BQAAAPsCAADsCwAAAPYFAADYFwAAAOwLAACwLwAAwL4AAABgXwAAgH0BAADAvgAAAPsCAACAfQEAAPYFAAAA+wIAwJNp31YAAAAeMYh9AQAAmQcAAIB9AQAAwL4AAAD7AgAAgH0BAAD2BQAAAPsCAADsCwAAAPYFAADYFwAAAOwLAACwLwAAwL4AAABgXwAAgH0BAADAvgAA0Izs21FD+YAtl/H8i5qV/O81mpuffddF2nT1jXN0ZeV3V15/v7CE5/+kmcN30dCbEs3r/HcakbNiM78X1y16f6bZyIs3fMkVzRVahdbpmM7zNRpNsFjoyoF01nIro0o4MwCAFmnf9T17prDl1XTZvm9s/6fm9XnipmWvU5Gu1Gj+9MHrmtV6+35Wwuyb0XO1RrO6Z4Zs3zd69uwZwQd3vGnxoaaGPnJRc1VzUbSvZj2f11Gy7xt3XtS8b2RfqRIAALRE+0q/QNSx4+sFsn2X8SUfaPylTcs022mQS2Pj65qO1bJ9b2reZfbleU6j4eRmWC2R1Zp/aq4s5Fm0+3vNQdG+P9zsvVrzg2jfZXwrjSbCYN9lcp1BODsAgJaYeSijy6s9O05S7Mt303QsYY5M/qfmBP+DJoAWvKKZJ9v3tRd/4Grbl/IDXSn5TCOGvJFXr5RcuerF7PumZtDNw29I9i15U3O1xCTz8APsCwBosZmHYGbfyJvfmduX8tlzte27kgq1ln1pEmEvXaFJX5b15QfTZj7UDGb23fb+VU2XN+S8r6bjm6aZh704MQCAFp15uMqfojkF08zDxoDrvXmaeegp+ljJPLzGn71Zb+Zhu6bm6k0LdgGP8Qaz77xzNNcr2fdsQMAunjfPPAAAQAuNfTNE+/b+QaO/6nZznkHMKzteXd/zM8NVt9f4SR3rjH17TuUDNJ9xhbREsuazgICAf2qSWexb0vO6bN9lJp0qlZB5AAC00Lzvd6J9+TLJvhrN6wfTjcJifuVrdMbZ4BKDffkDdeZ9NSurr3Sk2vbXDFrNZM2zW2pfVsDMvmKnciXYFwCAT1sAAACAfQEAAPYFAAAA+wIAAOwLAAAA9gUAANgXAAAA7AsAALAvAADAvgAAAGBfAACAfQEAADwm+3r//OXvAABPHF/+7A1pNWv7ev/7i3ACAHjiCP/i39Bvs7bvz1/gWQ7Ak8kXP8Nazdm+XyLyBeBJjX6/hLWas31/h6c4AE8qv4O1YF8AAOwLYF8AYF8A+wIAYF8A+wIA+wLYFwAA+wLYF4CHIfqDCvWDUvFBNOwLYF8AHkq+/dWNob+Rfsu+2mzZADZ/VQb7wr4AAJkP1I3jgEG+DXKv6N8y2LcF2jd4hsWDM3VGMF6coJlT0Uj7Vuhb+MqywXwC+7Y8+35r0Ui+xasTNG/UjUXfwuaG23cz7Nvy7DujsfadgVcngH3vb1/LBwD2bXn2ndpY+07FqxPAvrAvaLx9LRoNXp0A9oV9AewLAOwLYF8AYF/YF8C+AMC+4Em3r4tKpXI5xB7q9KyudVYbutLF2sUua/a8DSoJazP7OjjKzcRLi+Ht6n4euzq2URY+KlWnep/vL6hUrKBd2zq3xhvf6R5fOWAVbTJpjX2a9IivZ73talXt7vcyC4o1rHcaX3t7fWMOcTe6Y7rvOpVVXTWsbEzvm4w5y7qO8dyHwiW6ATn1bxb7GqFSuRkeaq/aSo8FsRVP5gY7B/ZYXKq8MWwoIbF070OsdAl3lTJsUemjb8CaPXia9Aj0IPNVIwgZp5pNH3Vjj8YSmyCpkI2ns02jlfeCvqq13VgS5UnHzCgzG6zdVkJ6jCLRibmth7sqZcwGG6NS5VqPpSv7qtiPuUj7RSZ4xs1cRfbtFo94jvZpXa6NuF9xCf+g7QTaW9vWY9+dx716dzsB+4LHZF+rrDhV5QyLvipVTJVqzwULCyuVLikrbuxbCQnjVVUJCTb12Ne2tfyCr0dybtlGC+dO93nxBdZvX6UTuatV5HmdLXE7r30pt7v4yIDu9bYaHjvlPn12SjK6U3asriJ1jznVwXhApvvevU77bnU1vW80Zq1ba+s6xnMfBqQVtrOKqnez3FdfY/vGjZLsK/4zfNaX3ngEak3tG6UbYbvbUSuXoYvODgva640oNdajqitJrKL2DQmU/n0khTLryvZ1sdW6PAr7xm0S7SsdSLPByvYNCbrgkeiulDEbbEynzlH2dKdsiwLpvzN5v8YW29jG6hysx4hHMDbbszC29XK2Xx4hMbQd7fOeS+q271mnlKP9LwU03r6l0ouvF+wL+9Zp3+4W22j0OVZFV2Ycoh5eqSpKtrCYNIlu9FEtqZ15cMjtq4vvTtqyyIPGHI508QINNayH2J9kMUcfOVpNzR1rtBBNpu0TY9WVLru62I2kL/MNQZX7PAz23Z3rEqov0znEMyltir4TkqmizYSraHGdA3HeQF+wLP4imS8Q20ApnhxnnxY0IMoo4lOx2Fduh9yNj89yJeOssuMH+IraGzCOvq4TPZNo421UKhb7ug8fP9Q5JprY9XUe72M0ZqvTRrEmDa1o7BvD/Dk2UCvvu5l9pb6Ir5VnD5e2LEZkbtk329nFXSuPmSwJEePU1JjZIZJ9xfGE0R1372oYc4xV1kvUpGNWtValkhEJngm+5KWkzoSk9SBk9+nKNK1+zOOyrDyPEaUvM/tmVXkY7EvbvztlnD0xte8q5tPlxGBfQhJDzO3r7qzNnUntuyZkj2tt+5LMGBoWyydBHo98gKVFe2dWbkwP5fjI++XhHJ+QZLCve7yRfc0GK9s3ke5+G1cj+xoPNoaetGzaU2bucPr2SN6vC0zg/9CGuhOHe8Su0J4+BdLGiPuVqtKydu4F3qvTvte7yCtb8pwC6DdAeM3pNjVlf3nkLbX6Wolfw2LfFV0Q+8K+9dt3uUp1cZVqDbOrSkWSi1T58zunW9Rr3+J8D59EQtrJYWlrMf4Ls5qi9bQxsm9iqPFCNNmYRNLG/i6Jqjzm4d6HhrXjtAnZBvvuu3DXUV9mhH04CT1j6ES0L8nK1HZyHEuy+3RezoIworWnznJkb0xn93EIpFGTSfjFBia342q3nIQmEYciXxIq6iKH5Q98nqbDvcDeqjP7jhwVFRcdFEXszpMy3QVlzPkvdI52WW7UKn0Jk5HMx+PWKPtual+5r3DHTDI7sK0S2YUljbW1j1LG3J7uqUMc26Uekn3F8cj2lcdcpjtGZtOHJ9i7F9KNCTbENkwytUsUicr10C4J1Y85aTcZmmQURYr2tRLfmmvbJ6T5GOybH+Khaj8/ycy+qXbn52uJsX097CeY29en9YTEoBHEYY+HVWgt+yY4j6HnQTkJ8njkAywt2uaKHU6Qj4+yX4fcyLhAmzbiWIOI9dDTIwz2NRusbN8NVfnsvYqRfY0Gy+ybM4T2Y32mdbiyX9rKrBy6Z1FBpNJ6StEUFVXtbmdxv3ZXSu3k3q3TvtV3pOWJiO1nB26j9g0uLw/OUL83Xa1ee1zdcPvmlV7/vsN0emfvXtgX9jXJ+6pU+yzGiKKdqlI5WLiyl23lxXrtG9eZONjXsi+NPkKsDX2Ms9caLSSTudAXTchlMmqovlT2eYN96caqe0qZ5QuixJi5nUnmwUGnCpxPyJQBKpUY7IQmsqajbIo80mY70PhGq7I1s6/czqYslgee4qBjoTuLW+2ZsnPij0k/9CzZt2vb8cR9ArGjjgxqr4x5Taw+h2Kwb9+QwsAzncLqtq/cF3vDrDWyL40Bw3KUMWupWceMInr7SuOR7SuPOZM6xKMonMwvFt8gDD8kp2amOPcl5DyN/zo568fMIm57c/vKzE9wsFfyvoEkZ/iG+DGhh8zsS1LTHB1tlDJskZtjmvftS+2btsaX2jfEmfRwNrfvhviZpN15YnQS2HjkAywttMXap+PJgHHy8VH2a83zNLlviH2Hzj6v5H2dzQcr25fEuutm3lXKmA2W2tcjZjaZUtR9SvFdZb9IdF+ruBBtau5LMfHLK1PZADOtxP0aKcfQVp3qsm85v0JaCT6nVh/k+6u91qvV69PVlxbuUCefeBD7vveN5Y+9N1vOyvsz7Av7Gud9E9J8ky1CVUHsghuNlaiD29xdI15sq9u+NG5r51jLvvSKRvYoQx9JmcYLyWRx1B8+I0lCV/mVVqlSjTLJ+7Zuq5ShL2c7emXF1L5TXHynvJWbStx7tEn1pA1H5zJnHerqnrYhKcphAV0vLiS2VVVVxwwDk9oZOpJdFPuHMnQaPUvhXKVjiFZvX5u29mRkJrGj1ZI2KWPWsdf4KJb1rArT23eCe9e0tOx8vX2dq6p89PaV+0rVKclsyb6SWeUxkzS3cMdYg32l8ShlpDH7iP8XC2kGQ+wjerijdPnOeah0qZJeLdWPuWtQoJg9qcu+7RPITF997Bvr6ZbjGeJjbN8o0dvhnYraGmLfqAWG/2P62PeunZba1343GRHoYWpfrePYkXdXZRPlJCjjkQ+wtKhsG59QVjRWPj7KflU5iHG93r62dp30sa/ZYNl5DXlaPBh9HY1iX+PB0tTQ6b5akkkD3xfclP0S/8Pad9UWb7hsNf+FNiz2DR3C9itoqBxDO9YT+x6Rlv1K6Q1/VO21SK1eFKlW520/yFU8iH3305WlRy3/uAuZB9jXNPPASFWptlrMcFNVJe96i6Z8N6iGP6B9aXw4Zoy+i9gBxgsl9t0qxscs9n3pLfL86WjZ18b2lcuwl9XwRDP7jmN3aI6wqp1k+h7iy2t2SJBDH/tCBxomjmX5CVdXV+OBie1sSmDxlq0y9OgFyoWwC1Y5tezLgjFfZcz2b0kFo11dPfT2dfAMcw06b6PvwsPV1dYQ+0p9sdh37J5a9pXGTI45xkpZEtG+8njcqc6SuipjtpEzyr76aR/dddTcY51ZOHleUpI85rF0HM+PrzfzQGzC9Pa9V/msx+lRZ5Qm+9D3EJlBJHYcm17SySjz4BxS275sZsYIB7HVrqb2HRFEXK2ClhP5JBjGIx9gcRE2u89un/HK8VH2S4p9DZkH8nSY3r5mg10TJQ54Ex3kWFUbo8yD0WBjpCA2jDXXWtmvtvNZ3suN2CeeGZVmTezo2T3fh+3XVp2H2Fe7QI/75n2Dt9DpD/w7ai9q4dKpavW0pRk31A9i34/pysQbltNGw76wb237WuRLcx4cLL5VFWUlqVSZv2XfwmLXcJYeHd+J0PxdWPyUKfad9HnfIF9itJBNdpnmdMdvpXnfaO2SNOKzhNjGjzS3r1zGdza93tXH0ImY951Cg5979IWdNZQ6qCudyyY6yzfGmnja0XS0DcmxMs/7yu2wXOPsLP3Q5X8TQ7uT6JjMWvbtQ5YXlyljDhnZmWQfM8s8jB3vSdwHbFX2vXbel/ZFXOaT7EBz+8pjplZP6Guwrzye/FHEY0FXZcwerUeQC256+7q3IcvjaNA2NpbZN6qSamOTMua3FoSHH3KsP/bVLihW7EtynyXD7fXzNnIqp2iTxtD5Ym2IQ1WhkX3HFbnWbd8e7EKWdZapfT0cC8koXbRyEpTxyAdYXuTHnGk7IEF/fOT9GulGRhQZxb5ka5HevmaDHT6clDnOJ+ettWTVaeO8r9FgJftOKaKi9ig+Ju9XqmM70oZuycr1yLGfTfruI1FxDuJ+JbjRdsJHVFrXP+dhx4EA9Yl0f3UKy/v2W3TAO4OaODJv+wPbd27E19zfYV/Ytw77Wpxh831t6ReZnVlSHOd5Zupv2ZfOzVSxN8yZ9qpKape+zvYntYp9O0lzkuTF89K8YaI9byW+ee5q5eh8j9xzmRkWpdudLW5sr9hXLqPNT3S0umfUiXjV7S3n+HiakXV1jxwcWOwAAAONSURBVLHqG07cekjRlcqXJMbQfG52kFWsuX2VdmKfjX/BQxm6a2tJRPeeDosbGU7cxRG46u2729nFxzDmNCv3EFsz+xKXMWSVmD0U911JtohVbOW+SPv4Admt27YTH+yj2FceM3UZe/tbJm5MVMazvGqN2/lQ/Zifj88aHqu31N1E52I2z4NepSfiMQzrk6rYt3OWlfPd1qOUvorZIsbIvjTFKc/lTSOVaSRHPJjSFbw0x6pEOtgxMXGesUoZUcLuo0zyvqoy2b6V7Ay2DYxW5vuyRQKZP0CX2Ldok3wS5PEoB1herAq0JY7WyrlQ9mucTrXPfZORfclpZb7vBrPBFu7TudDj5zrcvso9VSljNljJvhPEZMrIMfJ+kU2ecWwmzaFKevhoHDzbRZzvS+27vDiVtuPo1rm++b7BXny/FHqNLc/puj+176AIp5Ry+ni36h0PbF/LLcevY84D7PsYPusW1vW//CEl/YdA9MQVNqqhej72of8UxtMNb8o2sKxlfVKs9kloXp918zogryydo35w+/6HL4B9Yd/mb19t2ZTsNeSR2/de5xEDMhvYTo8+4bPtn1TJZD8t4vuwZZrEvo9psA9h38ORBxvxWbe/934b9oV9m799bXV74o89evtmq6qstQ1sp3BJZfxdgti3Gca+G732NuaTxnvfxactYF98yw4ATf0tO5v5936EfWFf2BcAfMcZwC8LAQD7wr4txb7p+FVNAGBfgF+UBwD2hbVaiH0vTmpU2sFi0kW8OkHzpqKR8q2AfUGD7AsAqJtFjbTvAX0Lmxsu382wL+wLAJCIXtwo+S6O1rfwScPt+wnsC/sCABT9Lnrw5EPFgWijn6ma21D5zi2DfWFfAMAjo+yTBiUfNn9i/CUgsC/sCwD4bwD7wr4AANgXwL4AwL4A9gUAwL4A9gUA9gWwLwAA9gX3se+XeIYD8IQS/iWs1Zzt+/MXeI4D8GTyxc+wVnO2r/e/vwjHsxyAJzDy/eLfebBWc7Yvn/6/X/4OAPDE8eX/ekNazdu+AAAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAAD2BQAAAPsCAADsCwAAsC8AAADYFwAAmr99e5XgMAAAQNNS0ovj0yNxHAAAoGmJTOf4anxrEgAANDFTqzmez3sOBwIAAJqSvDyeYwvvSOR+AQCgiSiJnEq/Jp/Zl69O7/UUAACAJqFXejXP8/8HRQaSwxRO2BsAAAAASUVORK5CYII=) Enable or disable the registration endpoint. When disabled, all POST requests to `/users` return a 403 error. ### Require Authentication Code[​](#require-authentication-code "Direct link to Require Authentication Code") ![Require Authentication Code](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAACoCAMAAACL+r3JAAADAFBMVEX4+fomNUR6WADAigDwwzwdIydsdX3/////+OXi5OeZoKbt7vD4+PmJkJZ7g4t4gIdxeoK6v8J/XwqXnaR2fob99eB/h4+8wMX+9+RQV16ljUyFZhOfhUFtdn7Jt4iLkpjY2tzk5ue1ur6KaxucgDutsrfn27vq6+19hYyDYxDx8vPz9PWNbiDZ3N/BxMjo6uvv8fKXfDPc3+HN0NO/wsfe4OORmJ/Q09bFsoGTdiv09veTm6CIaRicoqemrLGPlpzBrXrs4cPV2Nujikfp3b/YyaHl5unb3eBveICrr7V5gop+XAfj1bT27NTw5crDx8qRcyjHtYWegz7IzM+vtLny8/Tm6OqGjpWafzeAYAzf0a1yeoK9qHPi5ebT1tng4+UpLjLPvpMyQE6eo6nWx5+prrOCipE1Oz63oml2en1scHKFjJOiqK3889729vefpKr29/iTmqCqklLV19iMkJKullpjaGuxtrskKi6tlVjGyc306tL58Nl0fISym2GUnKOrk1SPcSR7WgNKT1KEi5Ly583f4OKYn6XKzdCgp6y0nmXUxJrr7e+CYw/czqiGZxW2u7+/qnawtbre4OLh07G4o2w6QEO6pW6zub0hJytIVWKJjI6qra7r38H47tePl52KkZihh0Pay6SVeS9YXWBeYmZ/goVTV1qoj06anJ3SwZikqq+GiY3LuozBxcluc3VocXl8f4OwmV768tzi1bONlJpVWl2PkpXk17bP09UpOEfLz9LBwsS3vcFUYGw8SVfS1dddX2DDsH5PVFf9/f3OvJDl2LjRwJWDipFBRkolNEOusLHMu42xs7RBTlsyNzv87srzzl1FSk3t48a8p3HLuYuDhomVmJrs1p49Qke/wcNna26goqRyd3lga3ZNWWZ5gYhzfINNUlW6vL68vsBjZGUzMzO+vr4jIyMlNEP05LvImR/++ev43pH44ZsuPEsuNDhbZnL7+/tVXGKkpqlnbnamqauPj4/CjQfv26jNz9Dy6M+1uLnhw3jixHrQpjmduo9KAAAACXBIWXMAAAsTAAALEwEAmpwYAAAgAElEQVR42u2dCVxVZfrHz70zh3MEBGUTFxADBFkC1FBuuCugKCJqiA6K+8qkDSnuilpqqJmKa664N67plJppaZNTaS4ttkyj1cx8mhazpmaa+S/Pe877nnvu4WpoSGi/7+czA+ecd3ne59zz7b3vfblKCgAAgOpHYv8XG5VWCwAAQLWQFuXg9vWKkQAAAFQbMV6afb0cSAUAAFQnsV5kX0ciEgEAANU8+3VISpQ38gAAANWLd5SkpCENAABQ3aRJSi1kAQAAqptasC8AAMC+AAAA+wIAAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAA96R9x8ijb7HGSHndzQv8TpYfu/VLN2K/vBX3HgBwV9l3jizLI8uLbv69aEXl79zgyiCq/juXMxPl/Te373xZpi8Cal5ennYrlwT5H54pKHv/PdgXAHC32LfF6G/2tnRn35GHr8nya7fZXxHZd9vt2PdWL3FOUKwXzqyeCPsCAO4S+zb/pv4/69ef4sa+e6W+BXKRJCW+fabgwk6aBL83p+BwkVwsSavlj6XH2NyWrTzQesDOOasf8/7gakHZ/lJe27tMvipfi5WknrLsJa2TR0oXSMfyObJv0cmCOTRFNcqPkd/fO7Jsp/QGKyB/oC0vxBRdKF69X/I6s1oeufU9l0tavb35znoa4+fIZa0kKYEaPlZ+7dxJNp53ys69/yGz77IxZQXb38NrAABQo+z7h/p1pYH1R7u17wlZ/q8Ue1h+edsF+R3pRLE8Z2+Bbt9PXOxbvHdi2jNy2bZyY6b5sSyHFbOJM9m3r2bfD87ILxe9Q/YtLrssn+srGeXHyPLhbbL8/InRsvx2UW+mWEe5XPDhmDlSVMHEZ07KxemmS9LbcsFoUm2aUU/iS8IfGD2/v1Ve3VP6ln4pL6Yell2TJ+4/J0/BiwAAUJPsu7f+eEl6/xu3675yMS3rfiKvLpWmyNfIlxfYioIb+/6B/vEMNh92FMjz9drvy+W01FBusq+x8jDRsYyc6Sw/Rp4jSZflnXx5gSn2PVlOl6QoyeElsUsfmC7FyPIbkmMkFTfqMf4ry731ng+zbsbIE6WX2S/M72vl7TQRlifiRQAAqEn2/Wd98X8V1n2v0uwyls0hNcL2spnqOrHykG6yb5gkhfFS32qV04pJma8xh5J9Y6TvzPb9VvKS5Z7O8mPkDyXpKhncqdhv5QKtmcRt2wuoTJHpEtX7QZK2U1tGPT73fUOPu4z5mP2Hooym69Joinmv3lMZXgQAgLvDvnulKatJosfk1R8fO3bsNa9n5MvMa2TfAlpT+K/JvrQPzLFafodKvRGmVX6Hu3Ut8+YgaZvZvus0+zrLa7vWmEVbyHK+rthjstxCkkqpszPfHbtM9nVe6ivL30mx17S572infWnd94y+7nuYSflTmuluZ7+8TPYtki8cY13hRQAAqDn2vX//N/UDAgLo//q4sa/0oTwyhhZhtxcVjTkj/a5Yfllf9z0szym67Gpfen9ftrZoW7G+IfeMXFZeXn5ZHukoLZAnPlPM7EsKLlpn2NdZ3rBogiyPKXqMr/uWFY25Smu8Fz7+kM19nZfM674m++p7Hg7TngfTuu/qt2m9eKv02DWqXLR9NF4EAICaY99n6gv2ubPvstVkt8S1Fwoul7/N9jzI2z9g9g3bWnx5p8W+3t+9XDDy8Pvapof7ZZltMfiBfWj3yRz58NvMvmFlTIWGfY3yTouupdnyFGPPA63WNrkqF+yfw/ZdOC95f3u1uGzvIMliX22/bzHb79uT7XmYr+15kCeOYaslj314uXhO+Tq8CAAANcu++5r/xY19b8AbzL4AAAB+un09pSdhXwAAqHb7bvXaC/sCAEC12/cbaXTl7QsAAKCq7BuwFfYFAIBqtW8bY8/DWOQIAADw7eoAAAD7AgAAqFb79ulW5yZXfR/Qftz/oMvZo7Ur2XiMR6yokCa68Ym/QWFLJy541r1pP5UO6CbtVYjLEo8Yi+XQzXDq+VcmhLQ6N78+9L47/oLp/apHvG/z26rKXxg3YnjXyo1oUMCd6+4WXj8AVLt9R/SUSjNqSdVi38RJtALNHr8XEn7MvrEDkk2nW06wPD19F0RnzO0z/nYCqlXnxk9jhbgqZ1/XaloHlbMvS4hphJJ1yPM7/qQXQxuz6tykjPHqHkm6L+rH2xroscraslmHblp3q0PLiLrF38C+VdSdOQOwL6iB9n2gm1Q99q1ghBvbt6dvSNSN7eud2zi+b/Onwqravj82F7+Bfd10UDn7WkZ40xM/0b7uUsYIqOTL5WHfoJvo0F3rPzoZvZl9q6g72BfUbPuGeXh46K6YMqLOg/RVu76Rh4J2j5fyF/j6tI1lh0FXxo3XRNS8cZ1cel5iHq8z9kmn7HjBQQFdDwXxf7vo+ZlXRrBf+wRE7yFF8Qr0Rruu1hm9VY9dEOBDM7967fw3jg0zKhi2a9enNntwmILbRj5AlQIkzz7t6iTrSm7pw7WXkFxnRAtnQKWe06N5BJ59Dk3fHeN/pXa+1JE9yHNbSekTrng8KAVQY9pz7Dmudp3kUmNQfAnBc0G7sawXrzbTPYZq8egxGGMRffBDSzXmM9ZBPf9xV9i4zBE93C7oAZFBf5EQaUrjkJBVfISsRL2NdRp3lPQT7H36k9FXhsa4JFcrxhumkc8dXtsZpH4LvfuM8BgwsK5xY80pGzg241ATSQSc4cFoLgIS7bDbUnd8V5/pbceL9yItQihunkq9Zd/7R0zfPd5t6/m1B0wY11XkVg9HrDyIW074Uzt1BwW07NaNhnIHutMr6hk17jcANWju25zPfTv+pUVpZGPS7QaH49B8Kb6nV8exL9BhUPMHgvowEcUE1PPq7eslDd340IluTvvygoM8IqUoX/3lPeX5xN7Tl0l7fDumNSZF8QpMNtpshHS1ILdJmE9dqZ7HCanVWKOCsG+CR5O6QYZ9+dw3utVDE9pqlx8frhdzBC0onZKRbgS0YdxDYUH6Y+4ZfSI/N2hP1FBPw77JkV7eHU1z3ytHo2Y2NgYlNPqXBKlrW2l87Zm1pI5m+4qx8D7EoWs159w3o2VU5FjXiLolGJ218XwoLFdPSEaL2Nh4PkIqIb2Q7rXK16GfIFdNCTiRcMjfJblaMd4wG7mv05r8Fob5NPdOaOIy8xMpa5JRz2u4T18j4On0cqF1Xx6QYV+6LdKkxvFpD/LvxOvp4+2/29Ahn4xuaJ4eNN9d647o3V71MrqK4fJwhH35LTfmviG7E3oPKL0j3enrXHpG+f0GoCba15OW2rwD0iRf+gbdyEj9nfdMetXTvybRO4iJqB5bi/Xf451Bn9Kscn2jTwUHhZCLGrcyTg19QUomeYd5xIoKJvt6Z9Dsp2WuVI8eh/EhDlFB2HdSbckrJN1iX5rcPL9Ru1z7Sb1Y2BWq2Wa4aH8QO6w7VB8MDeBJajw+2niGH1zg5bLyQI93qUcUH5ShUap3YqOUPqCvWHngMfCxiD74oaWa076UnlhnaRGRkcE0rQglxHtAvVhjbSWSh+bT3LBvMt2UJh4x5uSyYrxh41bwIPktjA9o5W153y1Stooi8PY5agSs21cEZNiXWcqX1Lgsmr8X6Sr1nu6w6JD+taeuke5aDwugOWpyVzFcHo6wr+mWa/ZlWazd6o50Z2SAMsrvNxwBaqJ9c7V3oQO1BbZJ46SHPKM9PNhUmCzYfDoT0XCtwFOJHonkY6d9eUFt/a6d/s+qnUim99+R0tyj7AUfKyqY7JvoUcom2/r6KD3yvIKwbzSt0bF5rot96/LJkHPuM38EM3Ub0f5RLb5Dxiofa5yiEs/woHbTu+0x2Zc9wtOb80EZGtV7OTpCstiXj0X0wQ8t1VzXfUOirBEZGYwxEkIrD2PjTSvb9TbSakArw75z2b+k5JFvTi4rxhs2bgUPUtzCrmNDJpS6nfu23c0aqmcErNtXBGTY15+tamvw9yLLJMeA+RYdLtNeJ25an8+mtru7iuHycIR9+S13WfdtN+WOdKdV5Bnl9xuOADXRvhNaOj9mo5d5m3GDHD2Zfend3nxt7vukPonzzqAC9zntywuaBeHbMs37YZov0iMez+a+egWXuS89d3tyjUeRV+D27ag9Rr7jpQEP0QNb0b5i3S/sCk1yhg4X7af7uH7Gwu0bzyZUPmze2LdliFcTw75kdy+PKD4oi0bTr8QK+/IY+FhEH/zQjX2bmOxrjcicwSfFFrzS3XOdI8yfPjBKinbaN5nylebR12pf3rBxK3iQ4hbSLLJxWxf7ipStYu1GH7XYVwQk2tHCz2hi1J6k3ZCZRiqNj8G4Di2thwXQfZnQVXLmloXjxr4+Tvveke5YRZFRfr/hCFAT7dsqepDk3cJ4mfu3lLzbMftOcDjaaeu+CX+hq8sekoYOlRKD6FHlHwPxgmZBBDSRvAJIpnNjvNuwdV+9ApPN8HF83dfTu2/tusajKCro9l3AfsROPyrVpugGREotXnW42Jd95u1IeCrMEVRPSgtoLtr3btzHW4qKt9o3kd5W76HJTyuHFJ+RGBPC94d5+kRJfQ4Zg3LV6Phcmg3r6748Bj4W0YcYWkX7ah3wcVkjEp21eVhK1Nd9YwZq2jNG+ICPN/3Hp5V+gq37BiVKu/0lq31Fw0Opobm1jSD5LcyvJcX6d9VzPamJS8rS6jwg9SZ5udpXBCTa0cKPTE6UYk/o70VeYP9NDEkUqdRaNunQ0rojmnbShHQVw+XhuLFv7hSnfe9Ed6yiyCi/3yIhANQk+0otcjPG+hsv82U+jWe2ZfatF3Blt0MTUX5ynegNTeiD9qARu0l2V/L1iYZe0CyInt0OtfFn+wSiR0Rqex60Csy+g3z5nodxtOfB23gUeQXdvo4BLdgPks4DyRsP0WlHLtsR4BScFLMgOsSHPtxP2FBnxPOSaF9KfNg3oPFRq32l3hvGLhjRSmob4lGnJ71dFXseIl8NYdsU+KAsGi31vML3PPAYxFhEH/ywon21DsS4LBEZGfTP8LnvkGbfQx4e0enOEUrjgja0pWC1E2zPwwvRV9rEVLCvaDjm8QwfNmcVQeq3MD2IViVi9FxntHJNWce5GY1rSVb78oBEO1r43quiB2zUdiSHZSSyH6/WFanUWjbp0Np6fu25jZkA9eHycNzYt3cI2/OgD+1OdKdV5BkV9zujFTQB7vq/NI73R75/AnUfrqKGbvmv/O50QADAvqCmkpYgRQWdqEH2rdKAAIB9QU1lIC03VNmfXlWFfas0IABgXwAAALAvAADAvgAAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQAA9gUAANgX9gUAANgXAABgXwAAALAvAADAvgAAAKrAvgAAAKodsq8CAACgmoF9AQAA9gUAANgXAAAA7AsAALAvAAAA2BcAAGBfAAAAsC8AAMC+AAAAYF8AAIB9AQAA9gUAAAD7AgAA7AsAAKA67PvbjceHDPkoV/q54vrt2pN//evJ771xhwAAvyj7TjryJ8aRI11/nrBe+/vOvyUk/G3n31/DLQIA/ILs6z/ExvnK8+eI6rtPxW+frsM9AgD8YuwbacjXZhuy6meY+X7q/P1TzH4BAL8U+/72CFl3X4uYmBb76Jcj16ump5m2bm7OettsXhX6/7v56O+VX/tdN7HiuWfW4iYDAO4S+274ymbz0H/tRmsPE0yXXrSdPaWcsA1xnqltq125nvp83aaS9l2703z0zvemg22yfG7MoBt1ceIN2BcAcBfb9+s/2Wyt9F972mx/+trFvraut2lf97iz78m/mY/+dtJs39FK+sQ5t9IB7AsAuGvsO4Ts21f/tZTsO8TFvkfOXtfsWzr9xSFfD1Si2drwn7Vrf7blHj9Sy4vO76MmvfZ9dTzZtkapazuuKB/Z7tdWHmbaMvYNiVT6fPTVmgWKcip3yNkFbuz71wTzUcJfXe2r/CB7K6V7r12mz+NixxTMeWa7oqymGm8XaSsPI9eWX1DeuFAwkZpN314wcT/sCwC4J+zbzTac2fe3a2zHM2xH0usdtx1P7sPte+Sf++LX2EKCjpyV6Ohst68q2vfIR76TutrO5n5kG648bhvic/aW7Xuq6IyibN2f/8OFnsrow/k9R1rsu1VS5pe9V/qHw8r1M9u8viuGfQEAd4t9jztXHuqRfY+72Hf+2RdbkH2fJLEqPraxppWHP9v2KXSeimfYJnnZbAnKgor2fdHBjloq8XRpDa1iPH+LKw+yLI/sraRfo48CPxh9quAErQtb7Hu/ouylheNT5/J/OEeltsK+AIC7xb6H/mR86vYR2XeDi31bPEXT3yHKULbcMJOKme07XFEe1vepbYi32RQyL7fvGsO+V9jcWi9zfYhtvpLoxr7fu3zqtvN717nvY4d3Kp/IjJOJMk3R/2uxb5iivKxdnvLxVVYD9gUA3C32lVx2nNlOudj36Kk1R7S571lFqUNz38a2XMO+fdjc92zv3r3vH0hz30GKJ9l3D/3P8ZVh326a0h+nMquus7lvKzf29XbdcXbdsu4bX1Daqkw7OlVMqt1J9i3IV5QPnfadqP+Jxg/nKPSJsC8A4K75a4s+N/xrC7KvsspmWvdVxtnOJk9x2pfOT0/e8GJvbd13CJk3zWbLJYmb7RtpO7shuc7XtO77YvJHbuzr8tcWJ112kTH7klBPHf7DKSXheWX0aKXvHLLv9nXK7wqc9j12Jl059Qmt+76mhK2GfQEAd9FfGjvtu0Cx2pfWEdiehyu056Ej7W1YY7M1dtpX8er24lfH/zmI9jwcWdOWLQ5Hnj0yd42LfZUXjn919uvH2Z6HIY+7s6+y7tMb/KmbZt+eBbF9R488V/4x7XkovszmvmGfHj45xmlf5ZOrBVfHsD0Pcw6PgX0BAHfRt+zcp3/LzhBbn5/S+P3MvspP+padN3606CfbcRcBAPfON0xeP0TfMPn1zFPKz2Nfxft77RsmK/FXzrAvAADfrl519q08sC8AAPYFAAAA+wIAAOwLAAAA9gUAANgXAABgXwAAALAvAADAvgAAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQAA9gUAANjXjX0///L8rwEAAFQR57/8vFL2/fz8F2+qAAAAqog3vzj/eWXs++UXyBUAAFQlX3xZGfuex8wXAACqdvZ7vjL2/TUSBQAAVcuvYV8AAIB9AQAA9oV9AQAA9gUAANgXAAAA7AsAALAvAAAA2BcAAO45+wZ+9lkgsgcAANVr33//36+I/3vXbZOz2qu/b+TmfHj3ygb1IyUfaa9W6nqD1lWRoc7Nbn49pYv5yO3I7wiu/VoP730q/3IC4B6y7//+ivM/ruf75QXexL4vzatsUEbJDn6WK9qJJ/rfvDpdD210Q/tWaNOFS/blpqPU7hb7bt6S1zDn2Zto75XTN2k8tXs12Ve/EXeS0EY/R1XLiyS0ER5g8Auz77vk3X+o6j/oh8vsN8ve8I83se9t4N6+lX3Cb8e+4Q0P3MS+T2S2ntdj2KjbnXRWl335jbi37VulLQFwl9iXafdfqvovXcJOftNvVCOnfRenZPbroF70C1YnL1LVHS+xt4oNJkek5NDEtvMWv02P6hLrFdEpqfXUBovC36KDFYvCX7cXspLPNcqzb1Kb2e32pg1mRcQ13bwpb3aoqp9gKwt662rDFf3iDgSKd6Kn7U3V0E208tCUijVTG1yK8GO9ZeX4zR6mqhGDSZ9JehPaPFZvsnOzUf3iQvkQ+mc+waaNvGgnKtq6c7PQ1FT9emBqL16ufXjeI9NUdVjcolFMe4Nn+zWaKlYeglfOtvst1o5EeHpxrTljzIGjUhfNoGu7sksaPqsWTl6U+hu60mlyXqN5K5eEU7wNVvbLOzCtU96Wp2lKneSXQlNukT9Lv+LQciN46fad6PcZM0QaRBsi52xcK8Lt2esLF87O65TlklMeXEPKkAhBz5qeYDEE4ulZDVNnFFKg/TJLevEGLYnnDetVByeVlCzVavKRm26DCJhf+c2jqtrDHqhHQfSYtcS+ZBrd7wpBAHCv2/czbdEhWNV+fGaeN4Y2LZkq7Nshs1ePhakH1dTn1Li4zuwHs++SLHXUDDUwvP3UJ/K4fe0kqohHs5bHLVZDs5+9+Ihu35yVPYL76/PUBqnkij9uXr8r7xX9BNlXtN4worCw3xNaQ4+8pD4a14v9oOv63Dd8c1Yj6i1u8tTBmc8JCRhzX95kZ/tK9T9LpvI16x2BDXc5faHNfUsOZO3y0643tR/Uiw1utjgrohNF8dbUyZld1P5LukxdmSTsuzz1leB5HXT76uHx4sbcVxvz0qTuFzetVIflDS6c+rQ6OaXD8tTWaq/M1+c9EjfjPy8tCabwFz+dEkfHDdRpzUKn7mo4VeTP0q84tN4IXnpq5jQ1sOGzIg38rMg5Y+Hs5cFN1x9c2qFDg06qOac8uIY5hUYIPGtagvkQGN1P9+if8pI6L+9Sj8JneYOWxIuGtaqZXQoP6tngIzfdBh6wuGLYl6JgLG10Ue2uvUisQQBwr9v3XU276wu1H6alh/4l09Tsl4R9l+aoanDqMFJhj7hRvdgUmNl3Bc1ak8hPzI3cvvRYdmbzzdaz1Byai3XW7dtocg+xSsAqCb8K+4rWG25W1ZX69bc2qXGvN1DDn3Pal3roQr3l0VO7Y2EF+/ImO5fQ5aTN+jzMr4s6Y5PFvky5W7TrXUTVHJq2dbBPW0pFC/O6qA3oMLjZRW7f7s02B/NyPDxe3GlfZmrSi9o0XN10iZ0JzqTl5tAU7Up3yoDql6WNuz07jlN70XDVTq+L/Fn6FYfWG8FLqzmhapdwIw38rMg5w89YSL+Yp5pzqgennREh8KxpCeZDEPx+k9o+wtSgJfGiYVY12C9UV6kxcvNt0AMWVwz7bubvO9ibAdWwryUIAO59+775ptW+k2ne1D5b2HcGWz+NCKWVgF2Tu+x4vZH2uLCV2P5x6hMpdO0Aty/VGmZn9FOz6W3qVN2+nSMWpb7O7cverS/OWWS3rzDsK1pv2FR/Z6qZemrctNR5pHnDvry32ezN+I4K9uVNauu67BpxelGg+mxJD1f7LjKuG3PfbJofq/anZyykH7O7qCla/IvFnodRKSV8HYKHx4s77UtjnqbVsaspu7R303aq0H+JdkULiGqy8PnxQq3sJTEiS7/i0HojeGn1dD91x2+MNPCzIufEersWbeDC7BI7s5wzp3pw2hkRAs8aS7AYgrbU3CDcbk9SFx4wNWhJvGhYuzd/TCpJ6W4euctt0AIWVwz7NtWHN61BeN6MYGFfcxAA/DJWHjjOlYdCP+0x6CzmvuwZo+XLDn4HTk9LpXMm+/ZvRpPDRk77PpeqNxHRWp/5aZuJDoaWTHXad0noxeBZTvuK1k2mUJesnKxuWdlItdp3eR71Nmuh2ogmbm+Z7MubND/2EdoQXhJFnZ+66dcDw/m6bw4N56L94FKKPZgmnZvesuw4eyVphtm+vLiLfdVMfXFi01J9BkiXXk+5kX3bP6Iae+hoRJZ+xaH1Rgj7FuZlZWYZaeBnRc61qaq2zyN0y3PTslztqwennREh8KzpywcdjCZ2PNo58HSS2j7H1KAl8S72pf/MHsg2j9x8G/SAxZX2s1j2nPalOpuXPGHMfU1BAPDL+NTts88sn7oNbsY++shZyO170a+puotWZtUlefPULXnPmu0bGH5a7ezntG9w0qVgdR49TdnTgifr9t0cqHbPXL++ZB63b7MO6tRmK1TtBNlVtG6274680+qovPba9WHZhYarAulToouLXlFHzVJ7ZCfpTajOJk2PfZb2cdzSFFFUTRnsYl9tz0Pw5lHq4Lj16oFO6tN+ndVQexd1My1sBw8T9n26g1rYaZTZvry41pxh3xU569XCxeqw8CyVrfs2CD64pfWN7DtvCbX+SpYYkaVfcZi10PVGCPuqs7bQHFekgZ8VOdfWfRsVqk3Xt36EbbhzsS8Pjp0RIfCsaQnmQ2B0eksNjkhSs/IWq2zdV2vQknjRMKs6bTFbQdBn6vrIzWnWAxZXusQFBs8y2Xd5D/U/cV3Yi8QcBB88APf+jrN/vfnmv1wXHnK0l/+uhoF8z0P/bG1XAn14RI93ZrDZvrTnwR7x6CWnidbPWtKs3zC258HvrZJAVnJGid2Pts7OYHsemH1Pp/bb0WmFfoLteeCtm+3byz6P3k8v1+xbuIXteeC9ZUX4sfflPRpEZM9I0ptQnU2aHvulKdqkrKSzKLqrhO15MGlh8Za8ki30yfxL4Xk71pOdZmfvyKamh6VkpnQS9n0ujt7RrzfbVxRnzRljDl4a55dEH+kPzrazPQ+P0uf7wTeyr/p0jl94RAdjRJZ++eFyu+uNMOy72M42E/A0iLMi52xOPyqVtigcTNmyyWJfHpzmPR4Cz5qWYDEEtiiT2m8Ty9grSdqeB61Ba+J5w6zqtH52O63QaxNdfeSuadYC5lfUFf1mXzLZ93XatXJAezmZg1iOxQfwi/5ri1uik/u/S8AHKFXPvMweCBiAe+Mvjd9liw+/+se7t9vrcwfV7ovWVzhN71kDG2DzUJVz4BEEDMA98y07/yZuv9dL9pIUN38ufNDP3uzRQtyUqmWaPec/CBgAfMMkAAAA2BcAAGBfAACAfWFfAACAfQEAAPYFAAAA+wIAAOwLAAAA9gUAgLvfvuffRKIAAKAqefN8Zez75RfIFAAAVCVffFkZ+35+/gvMfgEAoOpmvl+c/7wy9lU+//L8rwEAAFQR57+sIF/39gUAAHCHgX0BAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYF8AAACwLwAAwL4AAABgXwAAqAH2TbuONAAAQPVyPU1SosYjDwAAUL2Mj5IURynyAAAA1UupQ1IUr0QkAgAAqpPERIXsq3h5jcfaLwAAVBPXx5fSpJfZV3FEpdUCAABQLaRFORRuX+tXbLwAAAALSURBVAAAANXM/wP3kEAciNfnfQAAAABJRU5ErkJggg==) When enabled, every registration request must include a valid Auth Code. Without it, anyone can create an account on your site. warning Leaving registration open without an Auth Code is a security risk on public-facing sites. ### New User Settings[​](#new-user-settings "Direct link to New User Settings") ![New User Settings](/assets/images/new-user-settings-215c83a3fa8af10f878ff254e3a41a3d.png) #### Default User Role[​](#default-user-role "Direct link to Default User Role") The WordPress role assigned to newly registered users (e.g. `subscriber`, `contributor`, `author`, `editor`, `administrator`, or any custom role). You can also assign a **different role per Auth Code** - when a user registers using a specific code, they receive the role tied to that code. Configure this in the Auth Codes settings. #### Generate a random password[​](#generate-a-random-password "Direct link to Generate a random password") When enabled, a cryptographically secure random password is generated automatically and the `password` field is no longer required in the request. The password length is configurable (minimum 6, maximum 255 characters, default 12). ### Post-Registration Options[​](#post-registration-options "Direct link to Post-Registration Options") ![Post-Registration Options](/assets/images/post-registration-options-3ccc7ff96f87500b8f17b57d3299840c.png) #### Auto-login after registration[​](#auto-login-after-registration "Direct link to Auto-login after registration") When enabled, the new user is automatically logged in immediately after their account is created, following the redirect flow configured in the **Login** settings. Requires the Auto-Login feature to also be enabled. #### Return a JWT in the registration response[​](#return-a-jwt-in-the-registration-response "Direct link to Return a JWT in the registration response") When enabled, the API response includes a signed JWT for the new user. The JWT payload follows the configuration from the **Authentication** settings. If Authentication is not configured, the payload includes `email`, `id`, and `username` by default. #### Send WordPress welcome email[​](#send-wordpress-welcome-email "Direct link to Send WordPress welcome email") When enabled, WordPress sends its default new-user notification emails (to the new user and to the site admin) after a successful registration via this endpoint. ### Access Control[​](#access-control "Direct link to Access Control") ![Access Control settings](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAC3CAMAAAB5eg2HAAADAFBMVEX4+frAxMhQV152foYdIydsdX1yeoL////i5OeUlJR9hYz+/v7r7e5zfINxeoJ/ho1veIB1foXh4+XHy8+Lkph4gIeepKm2u795gYiVnKGiqK27v8Pf4eOZn6WDipHk5ui+wsaMk5nm6OmXnaPz9fa8wMTp6uyJkJbw8vP29/f9/f38/PzT1th7g4pBRkmAiI/V2NrY29xtdn6ZoKbz9PR8hIulq7DZ3N/FyMvMz9Lv7/CTmqBweYGprrO3vMD3+Pn19fa5vsGboqedo6h5fH+KkZegpquQl52OlZvw8fKBiZDDxspZXWDb3d/W2dy0ub2mrLFud3/6+vr19veHj5V3f4fj5eeFjJOTlph/h4/i5Oafpap/goXl5unt7vDKztCzuLzO0tTd3+GwtbnBxMiqr7XQ09by8/S/w8eorrP39/jc3uHq6+3g4uQrMDTo6eqyt7uTm6B0fYSRmJ7Jy8zm5+issLXV19mjqa7q7O2PlpzN0NMgJiojKCyXnaQ9QkaGjZT7+/vt7e/5+fna3N6Ei5I5P0ImLDDT1djg4eKNkJIpLjJdYmSSmZ+JjI6ho6bX2t2xtrrEyMutsrfGx8ivsbLJzM/V19p4gIiVm6LFyc29wcVMUVT4+PiaoKYzOTyhp6zHys21t7ivs7jR1NctMzeusLJESUyCiZFgZWhtcnRbX2MwNTnLz9GQk5WkpKTu8PHn5+mEjJN0eHvDx8prb3La291SV1qXnqPAwsOoqq2ChYfBxcljZ2o7QERXW19xdXd8f4I2PD+YnqSFiIvS09S4urvm6OpobW/NztClp6qwtLne399ITVCKjpB+gYTt7/Df4ODR1Naus7dmam13e32NlJrd4OKkqa4yNztLUFNPVFdUWl28vr+Zn6TY2drj5ObU19nKzM2eoKKytLZvc3Xy9PXk5ulQVFiHioyWmZuRlJZydXj09PRGS06qra5xdnje4OKDh4leYmd5foCVmJqUm6G+wMGanJ6UmqHa3eC6u72Ul5m7vb6BhIdwdXi/yqzzAAAACXBIWXMAAAsTAAALEwEAmpwYAAAgAElEQVR42u2dCVxWVd7HD8O5nJmH9UFAXBEFIRAQVMpEWUwUBRGBSC1xyR1BQR0XSMQ1yNRy3PclX9dITdNcWqxs560sW5WpKFvHFqepmXnf/7nLsyAoLjE4/L6fep7n3nvuOec59/98n3P/9/LIBPFtzhd/BAAAUC98kRNA4mX0f0UwAwAAUG8El6v2rQjAUAAAQH0SUE72DcDMFwAA6nv2G8BETizGAQAA6pfYHCa+wDAAAEB98wUTf8QoAABAffNH2BcAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2LdGlvBwHBwAQGO1b/sa1x7g/PQ1tzOm9PXte3YvqWnTTv4s7AsAgH0NYje7/iFrxOXrK8o4L3riGptJep3zjR8WlcG+AABwJftuSuy98w+SnaeG3FHdi3tm85/pRXDpdwsLSZyeB2YX5r7C2P3J298/foixIzsX8Fxa/+nJXH7iFW2nNzn/C2NVWxhLeXLBwi+PMvZnzn9ZV/bjIfYdJ95nT/Jdp/ccsGyGfQEAjdK+J/9gZZP9psP8rlN8B2PpyTz3b7s+YC038hPP7v6J/cbLzjzDN5ak7ym8UPrDSTacLygtPaNPa9/nT2ovRuzhH/6tiN8j7bv92df5O+zTcP5l6T/JvkXhP/3Tshn2BQA0SvvutLHvMLst5zg/Movz+9kRzlMYm8He4OFV8vkjfoGxH/lX6WWFjy2fwdgUPvvv2WO0nVw4/6f26mH+Hc2Kea607xZ2lO8xMg9P8o0zbDbDvgCARmnfAzb2PWi35U3+XCwL5//HXuEL1RWf853q8wmu8gx7ZSE9/a2KnaGnhb9oe200cruf8+OMfcz5E3+W8n6RF1rtu8t2M+wLAGiU9vWysW+l7Yaq7ZpkF1bQ3HcWzWpp7rsxWD6f5J8fOXLk4yN0iW3K0e38N8by7i/lvEJ39kIt7/swn83Yz3y7nPte1Oz7Dv9Jte8BdWqsb4Z9AQCN0r5vW+W7O912w2Ocf3Ty5EnOl1De90Tpk+tk3vfkGz/+xP7Oy/5d+sZz37MPL5Q+XMiPTNn9RunfeJH2DyYn7aB7Hk5uL2Mjtlvzvrp9aTZd+r1uX8tm2BcA0Cjte5/VvjPtNuzmh+XTcb5OvedBLk18ZnYhf5ixO3ZvLDu8+2X2DN2Stn3f+Iu7CzkP38Ks9/vyj5bo9zw8xmzse45yFj/q9rVshn0BAI3zfl9vi32HY5AAAKDe7JttyPcAxggAAOrxb92CdPt2xBgBAEA92jd4lyrfVAwRAADU6+88TDxN8l2GEQIAgHr+jbO8N07GY4AAAKD+f2EyB+MDAAD4ty0AAAD2BQAA0JDs2+X2upTyufKtFPd3q32bp+M19KZrkPY8btTNen/UtfucrItXrrhug1ETE9+NSu3Uw7Jout3u7Wh4X9R6NPnah0i+hascgzoUAQDUq33/R1G6DBhTbWUbiy57WP41It8rqCe7v/7ibrdqW9QVEx65JvueTaylW7+Dfalrdbdvj8v+aaYm7nVrJrp5Omuy9Mbt26Yb7AvAf419D8YuGjSgVvta8a3LxK9m+16J2ux7MHbbZd36Heyre6lu9r2cutr3gTZ2i7AvALAvaY6xVLLABC+34nmMrfFKS0u9qCiKI/Me5R+hnmw3mR+VufQBWtdC7hA4s12v+PHTwszR4xl71Gw6plTJj/Wv3VyVS8yRSl1USwxO9A4bUKWtkJmHDlkx7/ox1ilxZtbiHFbh46v4BmtqGeXr24al57/HWLnHDKt9GRumySmwl5vXSvpzkVZuWU1pzeAgp39MH2XXDa1ta50sr8CtNf1cZqchMyNUpZV0MpvG0vKrffKjg9u5Bg221GqTedArZk1Nrj2DqV+BvvNXZg/Kp1uk9fciB0PvfzX76vWPXu3amjRbIMcpa4UxpESBIqHMw5q+bpOHqvbV345Np723RrhOH6/aV++c3pi07zHTS1REOzABm8xh+o3bes8MtWpd92nK2tOx8nOKraEIAKAB2beqdyILdlw7dEXmUBYzvKoqRZtieRekq8KZ5bqmymWwZe4bqCxibJJXyn2XXmVj58+7r6dm34Kt5bEdtamuWuL2fhX9s+K1FaQ4v5jAiu5hY1gn3zw2bQBLnXwfu71KtW/U6pyuMZWsOXkvfrHN3JdVzZyune//OjTVO5359HppkW8QS3efPnStxyi7bmhtW+tMj0gsecTjV2pMTxX0bv7S0kEdWCfTosHFEcdyenay1Gq1r1HxI46L8vq0Y55pA3LiM9t5bsv3NN6Lal+t/9Xsq9ffZHTSCvoW6edFc36ndGNIJatJypT37e87vGSrl2pf/e1YO828I0ZcjHhVta/eOb0xsu+w1jOsc99NxX5Lw7Rbt/We6WrVu+5wia1x78Tuv1RDEQBAQ8r7KkHtWaAUX7tjsU5rA4wPufdopgrnH8vsMg+BZA+WSTnM90ystwPpU7Pv5E0VRqJBLaGeRK+22HdYAf2rymFdWadHGdvWizWV00/ttFpxYWz6dNY/LJYFrbHN+yrz8yy97DIh1mOCOhte6khT7oJRdt3Q2rbWudSVvjd6jlMbU9uQy/E+6nJT2i/F3ajVxr5GxQXDGPNTgj0VGggnGoLJB433otpX67+9fY36JT49WHBMDnt1iDGktvbdQPqLdXyC7Gu8HWunmXcTqi/CknmgzumNeTqeDQq2Zh5iPehdjy229IF6pqtV7zpNeqe3cZRT4MuLAAAa0Nx3/FLflWycem48kjXxSssy5r4XNftmNbG37wOUBVBLK2x+V8aGavb1nGn2Pabbl0qwlzqZFMXLYt8Bch47cy3rRGflHQfRebfJdUCsZi45vSW1mSr9nKps574Ggb1iFGV0uZJEcgpi2Vm0SmYebLqhtW2tM/t/6GHZBrUxNb+qFuujLsv95Km8VquNfY2K58u3qwxWk61yCGgn/b2o9tX6b29fo/5FBWZFIWM+34MNGm0ZUhv7FqurKsm+xtuxdpp5/0r5n3w986B2Tm/MM8bcxCbvW66U0GpfdVnvma5Wvets1YS+OUGD9eSyfREAQIPK+wYWs6Y9jRUu0+ezsbb2/ccwdX2YjX2Zh592xk16SNHsSz+43iZqqJ/FvgnNPdPpFNzPmPvKGk1drfaKHe2brc19yxkb0JxsuWmrD6vBvoPzK2cw0+hYj4tqgnqpI7mq2yi7bmhtW+tc6kplfMZZ7PtrmPZsY1+9Vru5r1ZxAb2XJ5QxtvbV30ut9jXqX9XmidghZN/soBGZsTZDarHvP8Yy/aqb8XasnWbe9JQ9SNrX6JxhX8f3MrdpO45V5750JI5pc1+9Z8bcV+s6S9hqYqOWaWnfakUAAA3KvgHm4e196SrVey8FV8ozeDardbrVvrO6vMQo75uxxsa+jy4uZ1XbKO8bHJuo2Xd0OrvdIyk4qr1e4oGxLHamF1NXyLyv20W2IqzKEMrScpbjrv7Ou2faqyzHm5p9wuy+qCb7tuwSy1bSRNDHh5VHUN7X1I+1TBtl1w2tbWud6RFr2X3mERb7xnq9GstyUmzta9Rqk/fVK34kIomdbcds7au/F1v7LvOzsa9Rv6MfG+pI9k136kmpYX1Ibe072t2Txc7S8r7a27F2mnkvTk+fqeZ9jc5Z7MtSzNovg6oHZtOG2DFBWt5X75mR99W6ztrkD2HD87UkerUiL3XHZwSABmRf9qoXG1zgZurtF9xHUUy/svQMec+Dbl+2Zr5CCdYmafo9D1J7scPcnXotk/c8xDhEjZcf6wFpSkw/msXKex5kiffC/FcP8NJWyHseVs6P8b+bGULpR/dCROu3U/VIo3seCK/M2Jrsy6YP6j2g72g6R49oHa3e8zDf64FRdt3Q2rbWyfJ6u7Ueziz2ZUlDVjn6d7XLPOi12t3zoFbM4k2uCcF29jXei419PUZr9lVTCffp9R/0fTfhAZlrTlTkvQ7akNral80q9sh6QL/nQX07Np32DnR0PZuuZh70zlntyyrN6t3C6oEJmG4Om6SNld4zY2KrdZ3OJygPE6VPdO2LLFXwGQHgv+UvjVuablJFiaNw+AAAsG+dSJ/H0ju9enPqeinfD4cPAAD71omqGMVxesBNqWqcdxscPQAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAMC+AAAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAAD2BQAAAPsCAADsCwAAwLAvAACAeofsKwAAANQzsC8AAMC+AAAA+wIAAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAMC+AAAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAAD2BQAAcH32fYj/RdzD77pqLQ/ze+vS2HrOS66lPADXw00N23v4GfFXHn4t7U+5tuIA9rXjBOeHriOM/5fzqeIZzvn2h44Y2w5wvgT2BfXB9YetjNmaCz2W/IvVvgs43/jdk+euUu+55M9xLMD12ncKBeMb12/f55I38qIU3bi5nH8E+4J64AbC9nBy8vHaC9rYd8e6Ql70McYa/G72fZZ/wE8424TxY+sWhpcOFMf5FvEO/7vYzT8WLzy0fcGbcUK8sC535xl7+54Rzjv4V1pVn/EdRfxBIUJP7Qn/VNrXKE+nZ6cWHKCay3Z8KkTcmR287E3jSZR8syD3+Hk67fuwiD90Jw4TqAs3FLYSzv8Zvuer5d/tOeUsXtzDF374SrXMwwL+mGifzGfPETOeWbB99wtCJPMfvszddf5k7jsu4vxsXrjj6Tg180D/XzixgPY/984CvuAoDg6oo30H7uHLc/kUaxgf5bl3zeYHxC/8afE+fyNkYeG35xaWPXucfy7GbOQfnS6qbt+8XP6KVtdx/jX9J8RXahW8xFJ+Ci/a+OyF7/nsp9dR2a/5rn1v7Dae4nbw028unD13Cj+8b9/J/8VhAnXgRsKW5r4XpH2LdnBeFl5Iqn5lx70Hcun5MvuK1zh/mSL08JN84SGybxEVz11Qxi+IQxu/eXo2PWv25Tt+4IV5pPwL+97EqR6oq31f5O87fyPnDkYYv84/E1M5T3qBf3mIhye/wD8U91KUiY08b4ucbeysnvel9Jg2Y72zkJ87KmP3dX5UvEz2tZSn8HxBrv67OMd3iFJ+YQrtoT9t4YeFeJJ/tpw/tHwiDhKoEzcStsROad+jYgfp+gAvFTJ+3+D/rsG+VOy3LRSz4i6yejL/RvzEd8z9np8Ut80V4gj/QLdv4Z1iHf9NnOR/efk2HBxQV/uepoB7kecOtIRxLv+rEIV8UUhu4ZKiJQs/5afoTE5l+RK+W4inq+d937knT6tqCZ8t7qS5As09pogksq+l/BS+gLZv16phT4TT4zcD9adPtbWlIbKVdX44TKAO3FjYapmHB8Vh2vkUafWF0zIWd9Uy9/2F/yiTEu+QfY+KC/wn8TFZ985nPyji/DndvrNlWuIxsZxCvOhTHB1QN/t+W6SF6BabScT3MuaSKI8QfvIcD6f82b181/Llyz+juSxJdGf1zIOFw1pV99rMffXy2m05r/OfZTVzhPOfX5zNl+tPW3g4rT1Cc+PzR3bzfThM4OrcYNhq9p1KEbtFte8O/uaRMzXZ94lkfmLOFinXz9W572Pq1Ttp32f57t+WWOwbrtlXsJdfKSycg+MD6mTfo7wsOTn5BD99WQKNsrd05pbLC78VlEA7te/pIplAe+YHXpt9acVHyckf8D1zfuYL9q3T8r5aec2+lPct3bcrWdxz1759e/hf9SfKqn2zr/S55fe/s492+hmHCVydGwpbyvsmf2tn33D+9ZL3L7evfs+DTd7Xat8z/PSW16vbd9epfT/wslAcH1An+ybTGZoQy3lRkuXi8Wfy4jETcvb6L5pJrKPt53a+v+ejXfLiMU/eVZt991FMCjGmjP8r9Ok927/S7nnQyuu3pL/4Ydns5K/Ei3SaV/a1s/4kSs6cKPvy+IMpH9Fc5vMkHCZwdW4obCVJdvb9OJcfrmHuy3nuaXm/74zP6Z6HRcLOvg+G8xOl1e379R7OT7yIwwPwl8YAAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAADYFwAAYF8AAACwLwAAwL4AAABqs++Yx/8EQMPl8Rp/+QNhC26xsK3Jvo+/hm8l0IB57fGa1iJswS0WtjXZ908YKNCg+VOdVwLQcMMW9gWwLwCwLwCwL4B9AYB9AYB9AYB9AewLAOwLAOwLEMYIWwD7AgD7AgD7AtgXANgXANgXIGxhXwD7AgD7AtDg7NtugBD5XTHQoGHb16GPq1IhX9z9ibd58hgh5sb7x5iijZ/z6d9sldJEfVX+1CrF1JJ+iira5FbQX99c0jNCaW6pa1xGmrtd5dbNg4NiTE2N1ent8jN9BhpLTSI85ncwFuzKAdj3+hgZCPuChm/fYcuGqfZNX5Vxvr3/fmfRNmjY6GWZ/vrmvdOyNft2ztzfpv9oPyH8i/tXTEs7r22e2nzsfqt9feJ72tvXsrnKtXvcypix+upe/i5TW2/QFzpGbU4PjNLrsy8HYN/rB/YF/3H7hsT39ciapS+M32T2HefT3K5ApGrfDgoJ0EUZra0brcywbNfsO8A9VF0KVe6gRw+rIPvY1jbJvXpntM1NzSFCvG3SVk2QTVUaLRR8In2cqC3YlQON2L5XCdv2vd0GbfalyIw6NtOp94OdmztmzKPzt+hBbv6e1TMPlf5u7uPmiqSETPMnJUKkKIv25/uMmbja9VKFTY3OLYo9MmjKbBRL7dXC5DsyZK+XOZoiP2qSV0xf+UFY29vVtDVEbg40uW5Ioo+MbM/BUX46Qt82xXjNky28td8jsqbPGmhk9h2ZUZk+ustb2sKQiAmduzvWbF96jFOWaeu2KVXV7Ns6uiBmUAt6kTF5oMh2y7s2+37SSn4K9ErXmulhjqJ/tMxt6OHt1tqCXTnQiO175bANNTWb4dfNSdrXfWTXd8O6LevaK8xZpBxzKemRn2Rv345Kj+D2qenO81tPnRFEc4gUxavFI10KvAKP+frYNpi597aWPYSlWKp55uZUjw2L905KO0bNOA5PH6tQwi015bbKXo/Ss8e0GZ7Fm2j2MI52DpqmzlCcKgPOpuVRCxkjQtbX9FkDjcu+c9JS6LFHN20OoVBEOofVZN/0TJ8Q52hlk7oqLitRVLOvW1rirLdj4ml+nKUoMbPEtdm311l6mKho+YW3I+Sja6A2x1FW0GO8Wc9J2JYDjde+VwnbbVFjaP4rIzOKrhLkKS1k1JRo2/zH2tu3j48u4YlCtKWaUpQJNFmVU9Z4m2gNSetnXyzVdY4QCXJO24w+FFEkXHFJz5b1zyT7etOLNhTJXfNDqQNyNjIwjT4eIb4DqIXKWj5roHHZd6qiogpPnFdy6HF1TfYVns2UNJ/90fJlUt/e66vb1yOIHqZRTsDHFL/3eadrnPt62Vp1q2bftXomw9a+XrAv7FuHsF0bJh9jpH3fkjHUUZ63TRRzl81PU5Rp9vbNdFCfxmbKR/em5EYK7pUKZQ9mOdk22Na+WGqGDFV5/WNcM2pmr4zuYsoqTM6kfs0VqfLz0DWfGnfcK0Z5aVVMpcfmBdRCXC2fNdC47NtW8bMuXMm+dFdDgLOZvr3F+v2TB4rq9nWXM4hjivBU6L4HURx9bfbdoGUU4tRVbaRqByrDtQKOauYhS1uwKwcar32vErY29u0gz58ipX1bik2LB8eJmd1rtq+vfIyQ9h0op7i0MNzN1r559sVSe8l0RB966H7JsG+WaB/T1SVkHgWoulnaV7y9ONSxn7WKswVaC7Av7CtCPOKtC1fIPKg4yPiZ65/gLC6zb3N17ttFtFSvMgQ1vzb7rnWkKh/Vk7t5cm7bIU1P7n7yvMw4jNM/VbblQOO171XC1ibzYGvfQQcpZ5FZzb59hugphXK6cyetay32DUk7aF+smn3VzEMr0URqP9DOvi5Rbdxi5a4Do+RpXPEArQVkHmBfSlC53hEwcAWFVh+KhiGD6EqAB0XEHc30zTMiWyh7I+lCRZvKDtNk2jeguG/HyMjIOG2HuMhIZWskOdkzaljV3pgWdL2jG111U1ZSUI6k6IqMzJocOUKvzzMy0TcyktJlgdu0yi2b41zHxXV0up+K+LcX4l2vkql9ewqthf50x1mLqKlafZZyoJFfdbty2IZ2mTzDr09adftuSAjp3MrDxr4ypoyrbvsL2s5op151s7Xv+Ulzhd1VN6NYNft6a1fd7k4bLIavsrOv6C17Jrs5wHQoYFJae60Fa6dB47Wvs0OGh6lPNs1h6dLE+CHmqOinKDE2KV/fPFLNr1EYN/VIi1hGybARWsYtUtuho7ogQ6hyf0yETBLkJYS5+csv+T5PybiXuOv1+atLNJM2ddcnFMZmcV7/K4pIZTB9UOivLXrKoJctqH9tUanXZykHGrl9rxK27Wd6OB00v1XNvsEb3L0nXbKxrxpTi3q5Kf5zRXmrTPNTLqKafTcbaS66xS0tik7BjGLV7OuQpah3nK3oO6h4hb19V8jLeLKb1jvOpH0tnQb4awtrXEc4/M69XK9mJwC4iX9tcXnYVugXym6IaZPrVCyqQ+3bUiP+g581cOvY98FHxuQlmtN/516+tRhHCtxE+14ettmLxo8I6nMTupLheaP2rXJc+x/8rIFbx75TI5T8mYMxjuCWsu/lYZttVnyHBNRfj2u3r4/ruBB81mBf/MYZwO88AAD7AgD7AtgXANgXANgXIIxhXwD7AgD7AgD7AtgXANgXANgXANgXwL4AwL4AwL4AYQv7AtgXANgXANgXNGb7Pv4aBgo0YF57vKa1CFtwi4VtTfZNevxPADRcHk+qKbgRtuAWC9ua7AsAAOD3BvYFAADYFwAAYF8AAACwLwAAwL4AAABgXwAAgH2vg4wO17qHQyvt2dSyti21c0cz4eJ0w0VAo6ehh+0V++fihgPYgO3bMcg1s9uDv0d77d1qD+PWTW5eGPvE33gYVykVoquixLwbiTi5JUDY1s2+cU0RKw3XvsM9xpYHbNsK+5J93UXnRz3KESi3AAjbG5mbg4Zh35CwsdqLOWfNYalCtHV08M2aN3xQ/jCKlOen5zcrX7bKtI1ee7n5z9NKBiT6Kr7rRecEs+kgbZjZzr/4oqVAwqbefe+ubOfa+pgQjoqi3B2yNcw8LkSItyLMWy8P4+y+bs2qROi0vq4bSsQIb2f6WM0Xxi4yWCevdt0/Qg3jvObeYd0HUgcf7TPomBrGzgkFc6hMG2qmlahY7NZ6mx7hWlf0GNU3dJkoVih+ol+7GopY7StEVOXES65KO0RLgwZhq9vX6F+8yXVIrN0w6A3LzENC897F3ZKMEQANxr5TlYHai7MZOSPC1oq2aaOSAjOfb9sxv61w8FhTPqRv96TAVc6ihWdVD+9QtWSPZi6i5UBREF0yIiJSOCiRItIcYBRI8KW5497K22bln9cmEU39J7q0myRyPB6pmu5RPYwn+C7qvMxfDGyak5PwvBBh/SlSmhq7qOEWNSxgWH6cDOOWmwMmFAeKtsoyEbxqDIXxnGYJIZZJRGjf5p1XeHiqy3pXtBg1NgxpIc66O4jEFpcXsbVvx7SKxcvinFMQLQ0ahK0Wtkb/VjhGVsz8xG4Y9IZV+/pWiK3djREADca+HfTvUGcP+qrul0FRQt/LTh2FaNZEOPgLMVFdrlDLdNGiJL5XHj3muVJQr02kr2Na8N9rFEgYqVdM8aKGcSZNMM6bRFP68g51rR7GCT2oZUcX+dLFVYiR08XAmApjFzWMW9ND373GKdwd7UTbKOqQ/0rh0M1/urP1FG6E7I7PNEv91BUtRo0NB1eLvmsS5FzisiI2eV/Fo4VoNj0AsdLAQdhqA2D0bzFld3OUWNth0BtW7Uvvrr+XPgKgIc1956rPcUpnIVJ86dyFFrzvpiPWRs1RGcsOXjGK0lGsUpTI9RtMrt2d31IkM4WDPCd6KtAoQLsJEbnYrCgj1TBerxZTRPdRMnarh3GGuvFQyKj5UYoSInLMIdn+ll3UMF5ND+0CZRiXJJgUxV/rUO9s4RDmlmOTQBsu4z21p35+pnZFi1FjQ45TZ/f1vklOzpcXscs80FvubfZdg2hp4HNfhK3E6F9WV3pW8myHQW9YtS+9u5QIoY0AgqcB5X27OOiTCPqaXpNRWxjn5R8KFu4d9Z2cO/oOnxgmrF/zrbONAmoYrzrm4rxppMiRkwgPLdiaUl3Ol00iVh9UF471mhhbQmEsiiufGmvZRa09ix6ysmUY94xuG7rZJow3bA6rsJ1EUFglqpMIoyvGJELfsGpScxE06ZK4vEg1+wox91hUFcKlQed9EbZ2/VtMdbkoc22HQW/Yxr7aCCB4Gtg9D84rt4qzCc5ze62tLYz9ujiLeYoWxiPiRJJ7B2f/Sc4iaaJwSEuVKS6jgBrGjjmiynGkGB9FybSR3dLFwP4iLyZPHFM6iJSDtmG80j1POG8TbYYIMUyGcXwrjzjLLmoYp2npOQrjVgeFc2/bMBbHTNqPaE6Llgm0+4WLebBcNLpiJND0DT3zN4tH87XrzPZFqtl3Zaho6XGbSM1BxIgGfc8DwtbSvxV9bxMDPrEbBr1hG/tqIyCa9Ef4NJj7ffsHuUb16ifmRNPFY+daT+GiIwq699XCeDNdFB4nxG2bVjm+O5quMCcoWXTfpV5ADeMmvn18WlGuqTtdPHZu6u7kRVelR7fe33N+B7o0oYexPEtLFNsyPIpbibkZQavVMK5QJstvaH0XGcZ67RTG58Pefaq7TRhT5+IHjVFDMFNePC5wM84Q9a4YF4/1DQ5KktimjKipiL19u6cpMZtpKtMREdOAQdiq6P0TgSbXnuPthkFv2Ma++ggsHono+W/5W7er//EOAA0OhC2AfQGAfQHsizAGsC8A+I0zAACAfeIDu8gAAACNSURBVAEAAMC+AAAA+wIAAIB9AQAA9gUAAAD7AgAA7AsAALAvAAAA2BcAAGBfAAAAsC8AAMC+AAAArtG+X4RiGAAAoH4J/YKJnPEYBwAAqF/G5zARUIJxAACA+qUkjglRXo6BAACA+oS8y+TT0PHI/QIAQD0ROr6EJr3SviIu54s/AgAAqBe+yEkXQvw/9b/YXZZ8O78AAAAASUVORK5CYII=) #### Allowed IP Addresses[​](#allowed-ip-addresses "Direct link to Allowed IP Addresses") Comma-separated list of IP addresses allowed to call the registration endpoint. Leave blank to allow all IPs. Supports wildcards in any octet (e.g. `85.*.*.*`). #### Allowed Email Domains[​](#allowed-email-domains "Direct link to Allowed Email Domains") Comma-separated list of email domains accepted during registration (e.g. `gmail.com, company.org`). Leave blank to accept all domains. ### User Data[​](#user-data "Direct link to User Data") ![User Data settings](/assets/images/user-data-f72eb25ec3254b62b066cdab4331ac07.png) #### Allowed User Meta Keys[​](#allowed-user-meta-keys "Direct link to Allowed User Meta Keys") Comma-separated list of `user_meta` keys that may be set via the `user_meta` request parameter. Keys not listed here are silently ignored, even if sent in the request. Leave blank to disallow all custom meta. Example: `plan, referral_source, subscription_tier` --- # Reset password Simple JWT Login exposes a two-step password reset flow entirely through the REST API. Step 1 requests a reset code and delivers it by email; Step 2 applies the new password using that code. Both steps share the same endpoint URL with different HTTP methods. *** ## Step 1 - Request Reset Code[​](#step-1---request-reset-code "Direct link to Step 1 - Request Reset Code") Send the user's email address to trigger the reset flow. The plugin generates a one-time code and delivers it according to the configured Reset Flow option. API Reference Explore and test this step using the [interactive API reference →](/api/v4/send-reset-password-code.md) ### Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `POST` **ENDPOINT**: `/simple-jwt-login/v1/user/reset_password` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/user/reset_password&email={{email}}&AUTH_KEY={{AUTH_KEY_VALUE}}` **PARAMETERS**: | Parameter | Type | Description | | ---------- | ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | `email` | `required` `string` | The email address for which the password reset is requested. | | `AUTH_KEY` | `optional` `string` | Auth Code value. Required only if "Require Authentication Code" is enabled. The parameter name matches the **Auth Code URL Key** in Auth Codes settings (default: `AUTH_KEY`). | ### Request[​](#request "Direct link to Request") ``` { "email": "test@simplejwtlogin.com" } ``` With optional Auth Code: ``` { "email": "test@simplejwtlogin.com", "AUTH_KEY": "MY_SECRET_AUTH_KEY" } ``` ### Responses[​](#responses "Direct link to Responses") #### 200[​](#200 "Direct link to 200") ``` { "success": true, "message": "Reset password email has been sent." } ``` #### 400[​](#400 "Direct link to 400") Bad request - the `email` field is missing. ``` { "success": false, "data": { "message": "Email is required.", "errorCode": 59 } } ``` #### 401[​](#401 "Direct link to 401") Unauthorized - the provided auth code is invalid or missing when required. ``` { "success": false, "data": { "message": "Invalid auth code.", "errorCode": 58 } } ``` #### 403[​](#403 "Direct link to 403") Forbidden - password reset is disabled in plugin settings. ``` { "success": false, "data": { "message": "Reset password is not allowed.", "errorCode": 56 } } ``` #### 404[​](#404 "Direct link to 404") No WordPress user with the provided email address was found. ``` { "success": false, "data": { "message": "User not found.", "errorCode": 64 } } ``` #### 500[​](#500 "Direct link to 500") Internal server error (e.g. email sending failure). ``` { "success": false, "data": { "message": "An unexpected error occurred.", "errorCode": 22 } } ``` ### Examples[​](#examples "Direct link to Examples") #### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/user/reset_password \ -H "Content-type: application/json" \ -d '{"email":"test@simplejwtlogin.com"}' ``` #### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->resetPassword('email@simplejwtlogin.com', 'AUTH CODE'); ``` #### JavaScript[​](#javascript "Direct link to JavaScript") ``` fetch('https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/user/reset_password', { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ email: 'test@simplejwtlogin.com' }) }).then(r => r.json()).then(console.log); ``` ### Error responses[​](#error-responses "Direct link to Error responses") | Code | Meaning | | ---- | ------------------------------------------------------------------ | | `56` | Password reset is not enabled in plugin settings. | | `58` | Invalid Auth Code provided. | | `59` | Email address is missing from the request. | | `64` | No WordPress user found with the provided email address. | | `65` | Invalid flow type configured in plugin settings. | | `66` | The `{{CODE}}` variable is missing from the custom email template. | *** ## Step 2 - Set New Password[​](#step-2---set-new-password "Direct link to Step 2 - Set New Password") Submit the reset code from Step 1 along with the new password. Alternatively, if **"Allow Reset password with JWT"** is enabled in settings, a valid JWT can be used instead of the code. API Reference Explore and test this step using the [interactive API reference →](/api/v4/change-user-password.md) ### Endpoint[​](#endpoint-1 "Direct link to Endpoint") **METHOD**: `PUT` **ENDPOINT**: `/simple-jwt-login/v1/user/reset_password` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/user/reset_password&email={{email}}&code={{code}}&new_password={{new_password}}` **PARAMETERS**: | Parameter | Type | Description | | -------------- | ------------------- | --------------------------------------------------------------------------------------------------------------------------- | | `email` | `required` `string` | The email address of the account being reset. | | `code` | `required` `string` | The reset code received by email. Not required when a valid JWT is provided and "Allow Reset password with JWT" is enabled. | | `new_password` | `required` `string` | The new password to set for the account. | | `AUTH_KEY` | `optional` `string` | Auth Code value. Required only if "Require Authentication Code" is enabled. | | `JWT` | `optional` `string` | Valid JWT identifying the user. When provided and JWT-based reset is enabled, the `code` parameter is not required. | ### Request[​](#request-1 "Direct link to Request") ``` { "email": "test@simplejwtlogin.com", "code": "MY_CODE", "new_password": "YOUR_SECRET_PASSWORD" } ``` Using a JWT instead of a reset code: ``` { "email": "test@simplejwtlogin.com", "JWT": "YOUR_JWT_HERE", "new_password": "YOUR_SECRET_PASSWORD" } ``` ### Responses[​](#responses-1 "Direct link to Responses") #### 200[​](#200-1 "Direct link to 200") ``` { "success": true, "message": "User password has been changed." } ``` #### 400[​](#400-1 "Direct link to 400") Bad request - `email`, `code`, or `new_password` is missing. ``` { "success": false, "data": { "message": "New password is required.", "errorCode": 61 } } ``` #### 401[​](#401-1 "Direct link to 401") Unauthorized - the JWT is invalid or expired, or was already used for a password reset. ``` { "success": false, "data": { "message": "This JWT cannot be used to change the password.", "errorCode": 93 } } ``` #### 403[​](#403-1 "Direct link to 403") Forbidden - password reset is disabled in plugin settings. ``` { "success": false, "data": { "message": "Reset password is not allowed.", "errorCode": 56 } } ``` #### 404[​](#404-1 "Direct link to 404") No WordPress user with the provided email address was found. ``` { "success": false, "data": { "message": "User not found.", "errorCode": 64 } } ``` #### 422[​](#422 "Direct link to 422") Unprocessable entity - the one-time reset code is invalid or expired. ``` { "success": false, "data": { "message": "Invalid reset password code.", "errorCode": 62 } } ``` #### 500[​](#500-1 "Direct link to 500") Internal server error. ``` { "success": false, "data": { "message": "An unexpected error occurred.", "errorCode": 22 } } ``` ### Examples[​](#examples-1 "Direct link to Examples") #### SHELL[​](#shell-1 "Direct link to SHELL") ``` curl -X PUT https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/user/reset_password \ -H "Content-type: application/json" \ -d '{"email":"test@simplejwtlogin.com","code":"123","new_password":"test"}' ``` #### PHP[​](#php-1 "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->changePassword('email@simplejwtlogin.com', 'new password', 'code', null, 'AUTH CODE'); ``` #### JavaScript[​](#javascript-1 "Direct link to JavaScript") ``` fetch('https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/user/reset_password', { method: 'PUT', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ email: 'test@simplejwtlogin.com', code: '123', new_password: 'test' }) }).then(r => r.json()).then(console.log); ``` ### Error responses[​](#error-responses-1 "Direct link to Error responses") | Code | Meaning | | ---- | -------------------------------------------------------------- | | `56` | Password reset is not enabled in plugin settings. | | `60` | The reset code is missing from the request. | | `61` | The new password is missing from the request. | | `62` | The reset code is invalid or does not match the email address. | | `63` | Email address is missing from the request. | | `64` | No WordPress user found with the provided email address. | | `93` | The provided JWT cannot be used to change the password. | JWT decoding errors (`1`-`22`) may also appear when a JWT is supplied and cannot be parsed or its signature is invalid. *** ## Settings[​](#settings "Direct link to Settings") Configure under **Settings → Simple JWT Login → Reset Password**. ### Password Reset[​](#password-reset "Direct link to Password Reset") ![Password Reset settings](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAB0CAMAAADuBmGdAAADAFBMVEX4+fp2foaqr7WTmqAdIycmNUT3+Pn////i5OdsdX14gIdQV168wMRxeoLg4+XM0NO1u7/e4eOZoKaLkpj09veXnaTs7u9/h4++wsb29/h+ho16gon29veJkJbk5ejl5ul7g4qTm6Ds7vDq6+2epKlyeoLZ3N90fIS6v8KQmJ7x8vRud3+FjJOPlpza3eB1foXm6OqorbPQ09bU1tmmrLHBxMitsrfi5ObX2t2Vm6Jtdn7Q09bFys1ucnR9hYzt7/CcoqiCipHn6etweYGxtruhqK2us7i/w8d2f4d5gYjDxsrz9PXw8fLV2NuHj5bHy8+NlJpweICKkZfv8PGjqq9KT1IlNEMnNkWaoKbO0tSwtbqiqa6Ei5IkKi6MkJLIzNDy8/QxQE7r7e7o6uyGjpTEyMu9wcWOlZvd3+KBiZDk5uc+Q0fc3uCRmJ74+Pnb3uGfpapveICZn6Xu7/HZ3N60ub3o6erGy86wtLlfanWgpqu0tri3vMBXXGHT1djm5uizuLw8SleMk5kpLjKRmaB1en2LjY9scHLBxclye4N8hIvt7e7Jy8w7QERKV2P8/P3p6uq5vsLLztAhJyuXnaPW2Np8f4MqOUhESUzR0tMxNjp5foLW2dygp6zJzdCho6XZ2tu9vr5hZmnw8fO6vL4uPEt/goVVWl3DxcdeXl4zMzPR1NdrcXdmcXuyuLyssbbe4OKBhYf6+vpRVVhBRkmGjZRna26kqq/BwsTi5ealq7Glp6laX2JTWFtkaGwzOTy+wcZSXmqeo6lXYm5PW2eanZ8kJCTg4uSQk5W/wMI1Oz6FiY9OU1ZfY2f09PW4vcFvc3eEh4pdYWVGS06vr69iYmIuNDdobnVIVGGrra5qdH6nqazY296prK+eoKKUl5mXm5w4PkGGiYydnZ2ampqQkJCysrL+/v5aZXCOkZSmrbE3RVNeaXRCT1wrMDRmZmZTWWCws7RxdnhcZ3Pg4eK/v78gICBbYWhbZnJyd3m4vsGWmZskM0JgZGhRWmRNVFuQ6InGAAAACXBIWXMAAAsTAAALEwEAmpwYAAAUsUlEQVR42u2dCVxU5d7H/8CZOQ6yyY6EoCMRsimgIh8BUcQFFxQNcUFFyVRyzSUTtVCM0kxcMM3SyKVs0TSzcsnUNF+j0pu35Za37d7221vv3d77+vm8z3PO85w5B/GWpXNLfl8/DjNnnu38z3++PPOcMwOpAAAA3A/xmwZndAsAAABuIdrZIOybU08AAADcRv1szb45DQgFAAC4k4LZzL4NmPkCAIC7Z78NpDqnIQ4AAOBepjlJjUYYAADA3UST2gJRAAAAd9MC9gUAANgXAABgXwAAALAvAADAvgAAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQCg2dn3v5UxCDsAAPa9UvsOVxSl6sypcb/cvneylsZsWF777wo/qqzHMQIANC/7liyrfDO8KfseqZyqKHuuin33MpdvgH0BALCvi4rvWv6+ZcvuTdg3i+h7ZSP98bwy5tyeMqIPK79VVr5EBdvPjFHOrKAjymO0nUnzMeW8nQ5Unt94cAXRciVr/8Zl9Nrwqh2lJvtuoVOKEkG08+D5jYdvZ50u36eseX0u2R85U7VyfSidY9Nj1hUAADQf+37R8iZa9N2yJu074AybsW4fvn3ZaWUZlSgflZYuW08nlB2lpYffpyzlLVboHH2sLGcGVva/rqzpz+y7Zt+mC4vGKHvfrDLb175cOUOsWNWyN5UjobRfySqtPrSF1V25/aBylj7cp+wtvYCjBABoRvZ9syWbk+7/rsl1X8ZL9AB78L5ymlYoK1+rHUd0QXn0wLoIvm1vR2WfMmUvK3OILxwsVw6z/0ecRG/xZYYvzOu+inJoHbFiHxOdVf5IryvVO3cTdVjD5s8NVUotVh4AAM3Ovr9vKW8uXfe9uKecTVgPT+X2JFrGz8OdoAmH2M+PXqMpivIB+/fSGmU3fcSMyiay5/jKAze6cpHoA/O670ZlzByilbrR36Taj9iPMxVbFKl42BcAAPua1n0ZZWOU9Vu/4PaluTtLFSWHrdpuXa7sJdqgbNgYcWQDn+fuUP5JdFGb+/I1jI+VqXwCbFp5aDisrBxHlUrWgQMHth4gCk69c7jyVsMa5V9sw51b6LCyCccIANCM7Nt5fWXLTZs2sZv5l7HvXEU59RKbtNKKg6Wl3ytrOpzIKi2tVHYQO+XGdLtf4d40rfty+y5aoyyvtqz70u41bHr8mlK1p7T69Af0z+2lpSuVaqpWVlaXbh+zm7V1uvQDHCUAQLOx73+1lDx5GfvSI2OU4W8x++4+uEZRpt7JrmdgawU7dmlWPUEfKsqdrNDOym83HqwlYV9eZrhl7svXLTbmUPnBI1V7z9bSCabzNd9PIPv7e6tO79hfRlvYhrM4SgCAZmXfJ2+NbMK+AAAArq19Z9FjsC8AALjdvn9v9yTsCwAAbrdvJS2DfQEAwP323fR32BcAANxq3x7GNQ+JiBEAAODb1QEAAPYFAADgdvu2D6DObX/Tu97J88rKR/tessnPw11D6+zljp6a2MXL4t3qCrq590aeMJfBP8p13yfkyvfBXP+nEXjTrzC/AOz74xTGBV8F+0be+DMH7Ou2V0ejIRblWR72CGjSvqGOnhmxdqIF2s0Mh065/uR8Rwa7Hexw9Lo7jdo5ev70oU0vN+6GW0RcEHvbj+5puNdPDEKjXfy3bV2RfRdO+HH7akf2F9g33OunHEytFOwLfpv27ejoO69Z2rcRl7dvRC/2RfFhrfkNd6ZHqvFktvcobt/WFOo5c8IV2feyLu3vnem8avb9Cfw8++oJA/sC8Ivsm1fo6eWyb1pir8IpFM0meptTmJEW8hIDw9jN6FRK9qpxsCLTg3wnMhN5e94dZp+f64hN42VC2ITwJlFbfzGzp6n7ZN+27ZjUomIn9fCkvN5sNuaIoIhnYlLSI0RzHqyi9rpP7VaT+7J4uzqpW1DiH4xNesGc9v0c/er5GMPYK9p7uuwscEZSWKuuUbFeo/RXh/Y4NDAluw9R96CEBPaNl/ow9CGy712LZf3NnlnG35b7DPUNWqdVu4k9G+LnER4Zyf/8khi4bl9KmkM5/fIDKMcxwWLfgUNq+fsGZl+izBJpX9F34IKkxKVMpGJocp8KNqfE5OkrD95dCsOej2jFOjZJP2l+VIBcBuk0aZYYiQi0HjlXjXYjUhzt5UGTPZkGz3dRxIAaRcPPw7MwLJxcbXnnT64ZFREct1sLjl5Bb8i7z+RInxcGxQaOo64LvGPSC8wrD2KLaI7qZ/kmBuj21I6sz9pRNYkZRlB8kkKG8occ/lsmvUujrHLV10cmwsWxFJQHUy8VOD/Jl8da9KLtjhZcWdyUNlpk0ye1DjfyS88sPcSmzO8Z75vrf2l+AXD17JsdfjKzTNq3TS+fnE4x4yimgk32/Ciywmzf2/Jn2wdSB49b2o3t246844MpI2a6fUIbYy4ia2vZz55+qF9JaH4QBbce1u6WBJd984KSo9vOF80Zc995qQPGxt2q29eRRmkpOXKTXnBO22i6sWBxnN15rzdF19hlZ4GRE/QeZgr7sseU1LtjRlga9SopKEiWwzCmSzPyWRfxmpoWVrSb4x3smvsmDOs5NrbMqCHsO9KL5vVIZTfZZLHvgh4Rfcfq9k1N6CntK/oO7NeTnvnSGJrcp80Tp2TErNbtmxQcPKnWOsfr6WhzU5iwr2MkyZGIQIvIyRoRUd1a0DoZdtmTafB8F/UYcCzR8HPkU5l3mWnuO3l6q7D51JtFcbW+TTbkfZvfrrhJi1o850M39s95KPF/zfYVW2Rz7Yd2XBRpnvvODC/rkmgExcexi1ITLfa1ZpWpvjYyES6OtaB17pud2tHrS6MXbXf04IrirrSRkXVGLpL5pWeWCLGR+cFhC0LLh1Rckl8AXDX7Dkyop9ELpX2XxBPZY/yZinLCPH34RMBk37abc/jraSm7WXsPeTMJJXuk2k3vBGVtLfvZ0yPYTMvuEZ3hweYg8S779mVTwN3ZojnLysMrC3X7DmU3QfPkJr1gQFRXrd3keb2j/Ji8ZGeBXYhkD5p92WO/GmbU1e3tsbeweZochvGC3cX2p7C/cUrq3uku+zpY+ahUo4aw76JY+zCf+hr7sFcs9i2ILaH0ttq6r2PmQrnuK/rWxrFrqDE0sU/2IWzm12eibl/2BXL5z1jtmzeIZmdWCPsWGGMXgRaRkzWSY7XfdCISsifT4NkuihgwrNHwy2QPglJN9h3M9mQyPRRjp0H6n/+TDfFD2ZbtTcACbXPnbo3PurEtojn7EBbMJWb7svsFjgIZFB8m84jMYLN9LVllrs9HJsPFsaaf1b7s0JcMNUKv7Y4eXCNbZdoYke0ySuaXnlkixEbmZ/DGenS6JL8AuGr2XbCWaM5oad/0YXzydgv16TZ2c8mI/nqySvv6JaVE3kOdtNNOI/V1wmcSE7xCDfvK2nIZcaJWNO1hPtkZZti3Xj9xJZoz7LvothSHo4tuX74A3e0NuUkvWD8ruybdzt4SPl/u+fKMAKMzvuYne5Dnv/21HibRvKCExGQ5DOMFa+9b4exVT/rKQy+HI9Vl3xTeZnejhrBvQUJF7kmaWJHb2WLf8pQIuj2zSF95IGlf2TcfB4ucHJrYpyIHC9fAfrp9WYhYTCz2zWbzPK901wUYciRaoGXkZI3aXO2HiITsyTR4vot6DLR3F+ZoaK2zXXXZlxWaHsdGkNYmVve1bIiPk+8NW8PtGJjtcASZ7Su2iOaKHAOYw832Xat5VgZFWwYWC9vCvpasMtfnI5Ph0uJhST+rfVdrsZa9yPxjwZXFjbTRf0Gymze6yfwSmaXnspH5D/Pg5o24JL8AuFr2LYjV0tNPzn15Lmf7U4vY58vrIxfoyZrM33Dfy50zLjyzXUAPy1maW4N0V8Twua+oLZ/20tfgMjzYpMLLkwJmEC1mc9+ZbUTnvLkp0r7e4dH2GcK+PPFzu7s28YLMmqn9HqbwbrnOkh7sFJjsjL86ZA/Svskxcv/Kho2Ww9CGqPGl5xuzNDW9EJdWRq1TrWfdmJJkDWFfCspnWv4y39HGYt8kLXRvNLKv7FvYVw5N7JN9JhvEPRPN9u1jsu9DWpN9Iwz7ukbCAy0iJ2sk12iaFJGQPZkGr0/veQwuiYbcVaN374eZZdjv2bzN+frs0WjIZN8Rvf2C+1vsK7aI5uwzW/F3KdozU4yzbplOGRSzfWM7sqB3sWaVuT4fmQyXK19k+smD2cfLFWvXYTeCK4sbaaPPfZnTh/V25ZeWWXqIjczP4KsU7Ttdkl8AXC37lnvwt4HxnYR9F/u2orEx7DXdL24CDYrTk7VoSDTdw2aIqcF045ABE/oxvd7aUUvvri2oIERPyons3apRW2R/KltAs/uzVbNyOunrSSVhEfb2zL5dlhZRwS7RXH3mBH0kHm2onYewb0Jezsi4IrlJL5hRRM7WJfRCTTbVp8RGGJ3xV0dw6/7UKsFlX3vQfDs5k+vTtJeyGIY2RI3bY4bWampqda+d1om5b6feLiXJGtK+XeLYFG5sXCSZ7dvTwU5Q0dPPNbKv6FsaQQ5N7tPmEfZxUavN9vXPZYdgoG66zXyGXBDnb/hRjEQEWkROq8HXfQexleF1MhKyJ9Pg2S6KGDCs0ZC7Ktsib6/g4CT2l0+iU1ov0rfIhkz2DelD9iSLfcUW2dwr7akoTLendmSFbmVQzPaN6k/TY7s0yipTfW1kIlzacCwF5cHUSolYy15M9pXFjbTRIpuw1unfK03ml55ZMpdl5gdPvoXFYro1v/LaQDHgqtmXeZcxtm+EuOZh3ehed/MGRrD5bqchYlF3bFLigsmplJ7g6NWf6IV439ZJU7T0Tg5zOArrtTKDE9g5aFlbTo39nxuSyF5vLaIck/gZ42cKJ49k9rU/3Tp2aJ5sLl1c81AeWdgjRNh37QjH6NuNTXrB/uwc+ovsyRQ2M5vIr4kVnWlXG3WNGh0U4rIvDZjh7XG3f/0khyO7whiGNkR94hQbrE8MR4UlpU/WberXl1/zoDtE1pD2LXEw1eQ4Rljsu0SbkoUm+FntK/qWRpBDk/tUMIqdxLeb7Rs8iJ21X6KdJguO1az5fIjrox/6SESgReS0GlrnI2r4NQ8iEjIIrsFz+4oYEFmjIXfVaMvbx6PmeW7ioL5yLV80ZLLv7pi7u6Vb7Cu2yObqZ03OfVF8WoIfWalbERSzfVvdNnSScXRlVpnqayMT4dKasxSUB1MrJWMtejHZVxZ3pY0W2YUJ/V428kvPLJnLRub3TPLNLWmUX0NSoRjw2/uk8ZVcLflzLhK9VmhnaK4Cv6Z9+pEzAdf9O+xr9ZFGAPvCvleR+vRcal727Rg3BfYFAPb9j9M6KqN52beT98sE+wKA7zgDAADYFwAAAOwLAACwLwAAwL6wLwAAwL4AAAD7AgAAgH0BAAD2BQAAAPsCAADsCwAAAPYFAADYFwAAAOwLAAC/AvsCAABwO8y+KgAAADcD+wIAAOwLAACwLwAAANgXAABgXwAAALAvAADAvgAAAGBfAACAfQEAAMC+AAAA+wIAAOwLAAAA9gUAANgXAACAO+x7Q9DR8eOPD6Jr2vkN1Y8/8cTj1dNwGAAAsK9OXt3NnLpiz2vY9+9e/eSvc+du/eTV3+E4AABgX07IeJtgW+A16/r9v8h7b7+LAwEAgH1VNd+Qr802fsm1mvn+xXX/7T/hSAAAYN8b6ph1n/Lv0MH/KXan+NkmKxbbOjbedIdtpH7HZptreaKz7f5L6t/wqvnRqz++9pv1iP5z6oPmrQ0KVo0BANeLfZO22Wzv6Xcj2dqDl+mpu2y2r+7PTGb3vv5H6C+yb/Un5keffua6f5/COQH7AgCam30/v9lmS9Xv9rfZbv6Hxb7vHC+21YU32dYV2ffxv5ofbX3cbN/FmPsCAJqjfccz+47T75Yx+4632Hek6vzB9s0qbeWh29E62x1FamGdbfzXg7l9hx7bdsdc3b6hKXeNf4o1nfPetqPxTdj3CYug5z5xqX2zNp0d/ugDqvrSoaodK9jD9YeqLt6n2ffZ6pUb96xS1VMbp74L+wIAmot91VZ8aszsW2s7ujT+85Oq7+eD3rNtK2P23db3HdvRP3P73vCOLTOs7htiG7+J3Pbz7PvRYrV6j6p+uOu+f50mNevbx5z7KzX7Xqh88OT+U+q7p1ec3AH7AgCuG/sec608+DD7HmtsX2ZXH27f7rY7BndlDwfwOrY3mGiXqsF1tuncvgttR1U1wfZ0qM12Ug1sauVh6+VXHjivqVmlqrpzh1huWKRmbWe/DBQnt+8Rtviwbqp68UNVrYV9AQDXjX0LbzbOut3P7Bt/ubnvKn5JxPFodckdX7E7LzL7evIS87h9Z+jXqyX9wWZT1dVXeNZtsbHQu2IDW3nYUaUoO9Usfh7ufBqzb4OmZ0Ud/hgvDPsCAK4X+1Kx5YqzVY3s2/MH2136uq/a5p6vbUvnFtfNmHdcs2+QOqBYzn2/GTx4cOe0y859p1muOPvbqsvat+L8Cqe6j9mXLUIUKQ/wue+Y/9EKXGQFHoR9AQDXz6ctRpo/bfG02uQ1D8y+5e8tXXrcFhJtqwsYVKzZV1v3VcW6b8rSpK8Gq1/bji0d34R9L/9pi0b23TJ1lbqCz31XPqCeOqit+5Y+OkCdtlN9d3jDn7NgXwDA9fRJY0O+xZtVq32Zj99L1j9tcesx9si3gxpvK+71g2bfV47XGdc8RN617ehTfmroU3XfDGrKvuq7bxvytXzRg77uu8dYeVi/4eyec8y+pcPHXHRq9l11Yd+3hy6wax72nfsC9gUAXE/fsjOn+P/4t+x8VZx/Dfv+06ufbmXfsvPp3/A5YwAA7Ct4tvDY+PE/dFt1TTuf9hn/hsnPVuEwAABgXwAAALAvAADAvgAAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQAA9gUAANgXAAAA7AsAALAvAAAA2BcAAGBfAAAAv8y+0fiGRwAAcDOrokl1RiAOAADgXiKcpDaEIg4AAOBeQhtIVWcXIRAAAOBOiopUZl91drsIrP0CAICbWBURyia93L5qgzO6BQAAALcQ7QxWhX0BAAC4mf8HTeC5087q/FkAAAAASUVORK5CYII=) Enable or disable the password reset feature. When disabled, both Step 1 and Step 2 return a 403 error. ### Require Authentication Code[​](#require-authentication-code "Direct link to Require Authentication Code") ![Require Authentication Code](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAABzCAMAAADzA1ElAAADAFBMVEX////3+Png4+XZ3N9sdX0mNUSZoKb4+fri5OcdIyeLkphQV152fobz9PV9hYyXnaTBxMjx8vR4gIeTm6BxeoK6v8J/h4+Plpy/w8d6gomJkJbq6+2mrLFyeoLV2Nvt7/DO0tStsrdveIDm6Oro6ux8hIu8wcXw8fPc3+Hl5+ne4OP19veGjpSVnKPs7u/Fys3a3eDX2t2Ei5I1Oz6qr7X29/iMkJLi5OZzfIOQmJ6zuLwkKi7V19h1foVscHJtdn7EyMyCipHQ09a1ur709faxtrvf4OKiqK3R09bJzdCepKl7g4qTmqDu7u/N0NNKT1IhJyuAiJB3f4ekqq+orrMlNENud3+RmZ/j5ee2u7+FjJN1eXy4vcHe4OLk5uh0fITy8/SPl53Dxsqdo6jT1djv8PF5gYh/goVYXF+Zn6WvtLp5gosyQU/Hy8+OlZuwtLlTV1peYmZKV2PLz9LM0NKHj5eboafZ2tussLaCiZG5vsPj5ebIzM+us7jBxcmJjI6PkpQpLjL09vcxP03Mzs/9/f18f4M7QUTS1decoqeKkZc7SVfExsjr7e7BwsSfpaplaWygpqtvc3VhZWmGiYyrra53e37LztG/wcPU1tmHjpWgp61lcHpjaGoxNjpVYW3u7/G8vb8rMDTp6erN0dQeJChga3a+vr75+fkoN0aprK9yd3mNlJs5P0JNUlVWWl2KkZk9QkfW2dxOU1ZRVVhaX2Olq7Dc3t/IysuJjI8jIyMzMzOws7RrcXdCR0suPEunqqygo6VUWl0nLTFARUhHU2AzOT1ITVBbZnJFSk1kZGT7+/usr7EqOUikpqmDhok/TFpobG729/fg4uSYm51xeYGPj4/p6uu7wMSFiY9OWmd4foNWXGNnbnREUV6+wcaztbWanZ+WmZtrbnGwsLBfX1+Tl5mhp6yChYfGy85vdHi5u74tMzdyfIZBTludnZ2amppdXV1pc37Aw8WdoKOlrLBSXmq2uLm4u7x5foCRlJZXY298goiAhIdgaXM9RUyPXFVQAAAACXBIWXMAAAsTAAALEwEAmpwYAAAVjElEQVR42u2ce3xM19rH9ySzs7oimRARchMSFZFkmiCRSEOlISVOLqQhVEQIQYhLi7o2CKpoXKqqGkS11K2UUhR1V9dW2+Pthd6d03tPz2nPe973/XzeZ19nzxiXKCNpf98/Yu/Za+317LX2/npmzZoRBMI7qOAeAAAALqEgKE1QCI1gAAAAXEbEakW+aegKAABwJWmSftOQ+QIAgKuzX5p8CDKhHwAAwLWYggShAN0AAACupkAQ7kEvAACAq7kH9gUAANgXAABgXwAAALAvAADAvgAAAGBfAACAfQEAAMC+AAAA+wIAAIB9AQDgD2nfjrxfDWu05a9cv8D9nHet+aFrMZuPwdgDAOqUfbM458dKnrj+76I9UfL5NY5cWMf5/XavLOGzr2/fWZxHMtaqpCSyJoc02m/cXz7nneWwLwCgrtj3xX4ff/OLM/se2/od56dvsb0EkvfQW7FvTQ+pzKVYT+7PXgL7AgDqiH1bfVzvk3r1djux72JWWM6fYKz43P7Dxz+jJHh5VvnWBJ7MWDb/N+sq5bbSzAPNB3yWld3V9NaW8jmzrWpt02b+Gq/yZmw+56HsFd6WHScd8yqyb8LO6ixKUfXyHfk7i4/NeY/tkwrwf8rTCw0STiZnz2bW/dm87Zjldoeo3uE537S31ZOJz+KbH2Lsr3TiX0q+q9opXc/Xc6re2SjZt3/HzeWjl+MeAADUKvvOq9eIDa63zKl9H1pHmvU+xF/7v5P8azY3mWctLlfsu8bOvsmLX4hcyucM3alnmmv4ugnJUuJM9i2U7fvP/XxHwtdk3+TN2/ixQqaX78j5oaGcN5u7jPNzCbslxUaV8OqNHbNYi+rKpTt58i7DIXaOl/c7zjdH6vXk9gZz/pbS8rd83TtjePZ8dpY2diZTC/2reOXsKr4bNwEAoDbZ95t68Yx98rHTeV+e/Lkk0mwr282ryZcnaabXmX3/w1gD6bW0cj5Lqf0OL2GVfKfBvvrMQ2Vaf3KmrXxHnsXYEf6ZOr0gKXY557sYC2JpUiq9jbxqO9RgHd/Hotry92z1JH7jml0PSc18wSvZDv7fjEl+n853UCLMl+AmAADUJvt+Uk/7c9W875Z1/JA35ZAKE76RBPaKZt9dBvtOYGyCWuqsXDkymZR5mq/bJdm3ATtotO9ZZuV8vq18R76RsS00xWFT7Fl+WD5NxNDR5VQmwXCI6pHgR9O59HpMWQ6xT4l7M4mZ/qM4zuZQus76kX0XKy3NwU0AAKgb9l3MdmeTRBfy7G8XLlx42rqUb5O8RvatpjmFTw32pXVgadn8cyr16QS58ueqW6dL3rzAhkr2rZRyUflTN8m+tvLyqrXXyKKZnE9WFLuQ80zGFlBjRw4u3Eb2tR0q5Pwg8/5Ozn3VekyZ9z2izPsekqS8RM59aWMH2TeBH6eWFu7DTQAAqD32rT/743offfQR/SlzYl+2kbdtQJOwOxISOh5hg5P5jsXVkn0P8eMJ2+zty97gc95IGJqsLMjdzzeXlJTQ/G7UgsN8ydJkyb6k4IRXdPvayusWXct5x4Su6rzv5oSOW9jf+P5vN0q5r+2Qcd7XYF9lzcMhWvNgmPfNPkfzxWPYhSqqnLCjH24CAEDtse9/1dN405l9+2eT3YrfOHl4W8k5WvNwfN3otyT7ThiTvO09B/uaDu4ob3uocoFUl6YbpCUGj3L+G1uTte7QOcm+EzZLKtTtq5e3WfQNypZ362se+GhWsIUfnp1F9jUcMp3dkjxn8QXmYF9pve/h5Epqdn5JddXOWfKah3WVHaXP9bp+sy05q+Q0bgIAQO2y75ut/teJfa/BPsm+AAAAfr99h7FvYV8AAHC5fXeGvgn7AgCAy+37MVt28/YFAABwu+z70RjYFwAAXGrfQfqah77oIwAAwK+rAwAA7AsAAAD2BQCAP7x9ywL8rnPUt7X8T/2Gdq8+GniTJ48we2sVIrVm7nW/RmGHRuzwaHTddm46oOuc76q4HOLRrsVh95qXUwNy293Fu6bM189twC3VdPO6/vHoZk5edNJfNxjc39Wck5sZgNpg385FzBrWh7nEvsVdGHvyQdrOb3Ej+3qHJBlevtzD4QEtvGIJa1MWfysB9fG79gN/VVw3Z99rXs7ttK/ccTVB7jQHInv7+nk+4PiqNWwys3a4GUub4wx7Ae4OOkwNTOzZ2/3GOrTvL3lAnNr39jTXxw/2BbXWvq0DmGvse2OJ6I0U+XYKurZ9TdGe7oWthsfdbvveKBe/hn1vBy6xb3ji65MbbB/k+PINbgAbFt/06+jw2bCLLUIzJ9YsGb2efW9Pc7AvqL32jTObzT7y9n05fg3ph859m2/y7xXP2i/yzQgmvfhOzUlMj5dF1MrTL5qegYhhfn3zbbJTC7p5tdvkf1lNS2ISO0ubZSmWaaQotQLNPDSSG6O3nmlXUjIoFb7Y2Gde3zi9gm67xmWBkm0kBQc3b02VvJhHWWO/3oqSm2So2gtP8uucaQvI6pFiaaK6tWzUgNcjfBID27Om/rTfJpXF9kg0N2RedDL5EfRID/RLsuoXpb4l9ljUuK/UinV8irm7HI8Sg34tWhvqrkM1+d1x8CjLZf2SQrsPMQ+JMJV1Noc8FxliYldSyKT5WuQeTzfOad0+MKRHumLfi41j5k2Kn5iR8q94NV41vkbaKLl55Y4appZg4/xTupNxGt/HWDdP/frv88zL66B0mrxpM/gwLfu0JA5qoI20dAOYzTTz4KbEofWXHJuhS1nTsGcHRDGtNR+q1MjN63JAgDLo8RkX7c/+qH/KREmHym2l9IOT/pIHRBvcO9CcfH6HmxmAWpL7tlJTn+1DXrROpWfYd+CMGaOeZe5Fodv7PkK7Oa1a+5dJImrg1dI6paeVdZ8XPjjAZl+1oJt5KlvgK//4Gft7avGUAf3ZNN+mBZ6kKLWCNO8rp3D0+F2JLojLmMQumuey1L56Bc2+4eaCRjm6fdXc15Ia3iNYPjwsVykWlbPI+kBYrB7QwPTwOP/nFPtaBk+OzpkWNMhDt0nS1NWmpobcN3HcghhP/aI0LQwJZxODWXxgTB/W1Ghf7VrUNrRd+2qyHs1dWFDAYO2SOjSMZO7ecRmtTC0KWEYs87e4sYBYLXKPgBYsytLL2jJMta95MGNdPGMjG5ap8Wrxabmvm3m4XqIgrL71Sp7Nvmps77/o7R2rdJqyqdHzUeXfB7wGh4/y0UdaugFo3jfK8qC12wCDfSk2Y5eyRU/G95yi61BJRvN6hU8JkQf9gvZOQD27HFxYM+22UvrBSX8pua86uHegOfn8DjczALXMvh6UJJm8Ipkv/X75VOUdXf0YumFHMjYyRxJRy970ks80U1grxjrYv9Gngm6d0hjzTNVf6p7PkvIZizN7axUM9jWFUcLbJJpdpMcqvlOUVkGzb5dAtrpTrIN9yU/N5smHA/OVYnGJM+iMudr53RLpRJO6KxdD2Wo+nTzWotuk4ZVQu5mHXvTL7uYF6kXpWqB6c+ex2JBCbeZBjUG9Fq0NddehmqJH6ofm6dol5VP2TWF4pZqkb73kh/q3u0gpsBq5XC/Oi5KxJNW+npIkqW/6W9R4tfhs9k3TS3Sg4ZmRqNtXjc0U0jJNnXlQN1WizKqIk2ikC8wNtJFW7bs9Q+ll3b4Um7FLvUNeZP9q6KBDqQsC5UFvFsLszq4Fp95WSj846S/Fvsrg3onm9AE33MwA1DL7RsvvQJ+T58a6pLNwD4vZLKXC9Mi2GiCJKFcuMLzYXEy3sM2+akF5Tk56VIjBSSlmc3PW5ll6L2n21ioY7Ftspmyz6RB20UfJcNUKmn0tkxjrHexgX3pNFoMt9+32uGTq8dr5H5XjG6XP6konp6g0m7g1TgmYZrCvpPABrdSL0rXQSG7l2ceZg33Va9HaUHcdqsl6TKQ/j8RolxQxzJIYbGIT++b1sLImMVOuNBtf1EOLXK7XTfr+YS/Vvj7SdLKMGq8Wn25fL1uJYCl7fFy3rxbb3z3z+qq5r7Kp576Zyr9tyEHM3F4badW+3aKVOHT7UmzGLi1KiWfunYrtdZiiD/oFc6Hd2bXg1NtK7Yer+0uxrzK4d6I5+fwONzMAtcy+PZrYPpmgZ3J8ultUkXTDdqO7318SUb7yeY0pjAo8aLOvWtBoX9/LkaanKV+kZ8xdyn2VCna5Lz1L06J1+6oVVPtul5+gnvEsJJzyxeasifapm/rANrk3Tc196fnqnqudPzaD2S1hUu1L6S81KSVMhZc7WQt0+9LjutoclD/IbimU2kpsYppmXzUG9Vq0NtRdZ/aV/mPpla5dEvVX6hDqQtbfM5j1CelVFBGw6EEtcrlenBdt97DZl4UVqPFI8WrxGe2rlehApU2U7zUsolA9Dde/oFcbpdOUTX3e10MNns4VSfayt+92KY6G7fT+kmIzdulAeVQe0VpjGdrHYMqgx9970e7sWnDabaX1g2N/FfjZBvdONCef3+FmBqCW2TeVZiRNmbp9fZowU2Pphu0dFdVYnvdtMYSO9g9n3buz4hyyr/oZm1rQaF+vAmb1Ipm2iTCNl+Z9lQqSfXPT1XlfD1Nh4CTdvloFxb5XpH/SBoxjgRRdSHOW2XmGnX1pzUPsjBbD46JyWrLIlFba+U2eZSYWFOto3+KwSDbNnMpSo5h7WHFEJ3W9k0dGECvbpF+UvRbiV1A2rMz7qjGo16K1oV2aE/vm+QSNe/857ZLiilmQpVn7PizNhwQ7ZEALFjjAnWmRS/WiLLTuJM9g3+a9i5n3XDVeLb7cdIN91RKTE9uzyzTX2e5pFtrGU7v+CJo3pc8gpU5TN8NzbWseTK0HsQdyilkvH+ZgXymOC37t9P6SYjN0abi5vyT8aK01tuI+Ox3KixBMqRO1s09+341dNjfTbiulH5z0lzwg6v6daE4+v8PNrHUIALXEviwzOqyv7Znsn+EZEyzdsBe9EntFySKanORnGVhAb6ZzOr9OskucLFdTCxqfjKKATU/6SOsELDlT5TUPcgXJvm491TUP6bTmwaTbV62g2DcqRH6HTI9U66R5o+jlGSukNQ+2B5Y1uGLplEGfbIcP9OvcjGnnZ8VP+3p5jnO0L5sysO+inFQWnGd+n/KoYG3NQ/POeUkL9Ity0ILVI1Fd86DGoF2L1oa668S+Xvl5Qy7rfVBEn7m/zmL9zeZNEdKnS/QfUBjlmGrk8kqr9oFtPH0M9jV1sITM66LFq8Ynd5xmX7UEy/Q359Ln/MXDGreRhkqJLWKU2WyJlTtN3YwzM329r7kzzXc/YkkcH+FoX+a2wjwqvUzvLzk2W5d2WCH9tea5aa2NzJMWIdgGnc0NTOwU2EQ/+7jH24yXrlG5rZR+cNJf8oBo+3eiOen8Djez3iEA1M1vGrv7oL9Zzb+Pdbu5iSW1NcCnCCMIAH7nAfZ1rX1jvZl7SjFGEADYF/Z1rX27mPOim2IAAYB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAAGBfAAAAsC8AAMC+AAAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAKB22BcAAIDLIfsKAAAAXAzsCwAAsC8AAMC+AAAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAAD2BQAAAPsCAADsCwAAsC8AAADYFwAAYF8AAACusO+7r66aOfPDx9jdiitq+s979/78gQkjBAD4U9m3y4aHJc5saHd3wnpmz48vr1378o97vsQQAQD+RPb1KRVVZnrcjagOvq1tvf0MxggA8Kex79SZos7MDnch833btv02sl8AwJ/Fvu+eIeuuzGzQIHMlbWxYf3taihFHOHnVJIpWx9ei9hj39tx8+8+8cPVrS6djkAEAdcS+Aw+I4j+UzRGieKCH4dBT4qUKYbBYanvlMfGxm2tp6onxN2nf6T8a9376wLAzlPOqLy5cq4m5+2BfAEAdtu+Jh0UxVdksEsWHT9jZV2x3i/Z1jjP7/vyyce/lr4z2XSbseiGrJg3AvgCAOmPfUrJvobK5gOxbamffDedPyfZd8P1TM08MFizS3PBL8rGXxBWrzvSx0usr+whC6D8O/JokjhUmib8KwodifXnmIUYMWzlzojD8wwOXnheEihWll553Yt+9a417a/fa21eYxdcL1sVV2w4KgnfH8qylowUhm2r8LUGeeWg7veSk8Onx8hf+Igi7RldXzoZ9AQB/CPuOEHMl+757SVwVJp6JbblKXNV7uGrfDStXxh4VO/mf+YHR3g8jZsr2XWW074axPbu0E89HfyjmCh7izBHna2zfiieOCMKY2ZNn7d8t9Ds0eX5bB/suYcKszcutT2wV1h8Z+pezybAvAKCu2HeVbebhItn3f+zs2+2H8y+SffPFo9KscF/DzMNL4kqBXqdUN0/sYhXFvwrPX23fp6IEYazYRHCn+mNpFqNZDWceOOfHdgu7qumjuLf6VRyeKwifO9h3viAsfo8S66r2s6pOCcIS2BcAUFfsu+lh/VO3sWTfgXb2zRxO6W+p0F2aboihYkb75grC08o6tYFxoiiQeVX7jtXt+z0VVNezrS8VuwkRTuz7wXU+dVsmdN36nrCGS+ws5pSi/+Zg3wmC8Jp8ePe/t0g1YF8AQF2xL9tgXHEmVtjZd1zF2A1y7nteEPwo931VXKHbd7iU+14aOXJk/eco971AUwtjhWmU5KYd0O07Qla6D5XpcErKfVOd2Ndkv+LslMO8r3v5gofmyHsVyaTaz8i+1ZMFYaPNvpUH5cOzqij0F2BfAECd+bbFcMO3LUrtvm1B9hU6iIZ5X5pd+KH3Azb7vntU/L73wKdGyvO+pWTfSFFcQRI32neieD6pt98JwUd8qveHTuwrfGn4tsVXnwoO9hUq36jY+p8KYe1DQr9lQmEW2Xf0aeH+apt9fzmyS6hYQ/O+p4UJ2bAvAKAOfdNYl++G5wVH+wpH9TUPTQXBelQUX7XZV7COOH/g15VuQujKM0eDyb5C80tn2oy1s6/wyK8Hzp/wECqiS2d6OLOv4ctuDl91k+07v9q7cFnbYyVraM1D8jYp952w5NDOL2z2Fda8dnjLF9Kah6ytX8C+AIA69Cs7Dyq/slMqTv09J68v2feW+HLPT9Kv7Py059MbFl0zGqMIAPjj/MLk+k2rSktPxFQId8e+wvoPvtq796sPTgmwLwAAv67uQvvePLAvAAD2BQAAAPsCAADsCwAAAPYFAADYFwAAYF8AAACwLwAAwL4AAABgXwAAgH0BAADAvgAAAPsCAACAfQEAoJbZt+AUugEAAFzLqQJBCIpHPwAAgGuJDxKENCv6AQAAXIs1jf6sLkZHAACAKylWvLs6NB5zvwAA4CJOxVu1pDctqOAeAAAALqEgaIYgCP8PVwCaAW5tFFUAAAAASUVORK5CYII=) When enabled, an additional Auth Code must be included in password reset requests. The parameter name is the **Auth Code URL Key** from Auth Codes settings (default: `AUTH_KEY`). ### Reset Flow[​](#reset-flow "Direct link to Reset Flow") ![Reset Flow options](/assets/images/reset-flow-1457f0f4f16f0dc21f9eec18f7a3a616.png) Choose how the reset code is delivered to the user after a successful Step 1 request: | Option | Behavior | | -------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | | **Save code in database only** | No email is sent. The reset code is saved to the database. Use this when your front-end handles its own email delivery. | | **Send default WordPress reset email** | Uses the standard WordPress password reset email template. | | **Send custom email** | Sends a customizable email with your own subject and body. Subject and body are required when this option is selected. | When **Send custom email** is selected, you can compose the subject and body and choose between **Plain text** or **HTML** format. ### Step 2 - Set New Password[​](#step-2---set-new-password-1 "Direct link to Step 2 - Set New Password") ![Step 2 - Set New Password](/assets/images/step-2---set-new-password-752cd54e5f2fa60ed44ce91e1a112191.png) #### Allow JWT-based password reset (skip reset code)[​](#allow-jwt-based-password-reset-skip-reset-code "Direct link to Allow JWT-based password reset (skip reset code)") When enabled, the `code` parameter is not required. The plugin identifies the user directly from the JWT payload. The JWT must be valid and not expired. #### Send WordPress default password changed notification[​](#send-wordpress-default-password-changed-notification "Direct link to Send WordPress default password changed notification") When enabled, WordPress sends its default password changed notification email to the site admin after the password is successfully updated. *** ## Features[​](#features "Direct link to Features") ### Custom email template[​](#custom-email-template "Direct link to Custom email template") When using the **Send custom email** flow, the body supports the following variables replaced at send time: | Variable | Description | | ---------------- | --------------------------------------------------------------------- | | `{{CODE}}` | **Required.** The reset password code the user must submit in Step 2. | | `{{NAME}}` | User's full name (first + last) | | `{{USERNAME}}` | WordPress username (user\_login) | | `{{EMAIL}}` | User's email address | | `{{NICKNAME}}` | User's nickname | | `{{FIRST_NAME}}` | User's first name | | `{{LAST_NAME}}` | User's last name | | `{{SITE}}` | Website URL | | `{{IP}}` | IP address of the client that triggered the reset | Example body: ``` Welcome {{FIRST_NAME}}, Your reset code for {{SITE}} is {{CODE}}. This request was made from: {{IP}} ``` To use a fully custom template via code, use the `simple_jwt_login_reset_password_custom_email_template` filter: ``` add_filter('simple_jwt_login_reset_password_custom_email_template', function($template, $request) { return " Hello {{FIRST_NAME}}, Here is your reset password code. Your code: {{CODE}} "; }, 10, 2); ``` --- # Revoke token Revoking a token immediately invalidates it - any subsequent request using that token will be rejected. Call this endpoint when a user logs out or when you need to terminate a specific session (e.g., after a password change or suspicious activity). note Once a token is revoked, it cannot be un-revoked. The user must authenticate again to obtain a new token. API Reference Explore and test this endpoint using the [interactive API reference →](/api/v4/revoke-jwt.md) ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `POST` **ENDPOINT**: `/simple-jwt-login/v1/auth/revoke` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/auth/revoke&JWT={{YOUR_JWT}}` **PARAMETERS**: | Parameter | Type | Description | | ---------- | ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | `JWT` | `required` `string` | Your JWT. Can alternatively be passed as `Authorization: Bearer `. | | `AUTH_KEY` | `optional` `string` | Auth Code value. Required only if "Require Authentication Code" is enabled. The parameter name matches the **Auth Code URL Key** in Auth Codes settings (default: `AUTH_KEY`). | ## Request[​](#request "Direct link to Request") ``` { "JWT": "YOUR_JWT_HERE" } ``` With optional Auth Code: ``` { "JWT": "YOUR_JWT_HERE", "AUTH_KEY": "MySecretAuthCode" } ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "data": { "jwt": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c" } } ``` ### 400[​](#400 "Direct link to 400") Bad request - the `JWT` field is missing from the request body. ``` { "success": false, "data": { "message": "JWT is missing.", "errorCode": 42 } } ``` ### 401[​](#401 "Direct link to 401") Unauthorized - JWT is structurally invalid, has a bad signature, or the auth code is wrong. ``` { "success": false, "data": { "message": "JWT signature verification failed.", "errorCode": 11 } } ``` ### 403[​](#403 "Direct link to 403") Forbidden - token revocation is disabled in plugin settings. ``` { "success": false, "data": { "message": "Revoke token is not enabled.", "errorCode": 83 } } ``` ### 500[​](#500 "Direct link to 500") Internal server error. ``` { "success": false, "data": { "message": "An unexpected error occurred.", "errorCode": 22 } } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/auth/revoke \ -H "Content-type: application/json" \ -d '{"JWT":"YOUR_JWT"}' ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->revokeToken('Your JWT here', 'AUTH CODE'); ``` ### JavaScript[​](#javascript "Direct link to JavaScript") ``` fetch('https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/auth/revoke', { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ JWT: 'YOUR_JWT_HERE' }) }).then(r => r.json()).then(console.log); ``` ## Error responses[​](#error-responses "Direct link to Error responses") | Code | Meaning | | ---- | -------------------------------------------------------- | | `42` | JWT is missing from the request. | | `83` | The revoke-token feature is disabled in plugin settings. | JWT decoding errors (`1`-`22`) may also appear when the supplied token cannot be parsed or its signature is invalid. *** ## Settings[​](#settings "Direct link to Settings") Configure under **Settings → Simple JWT Login → Revoke Token**. ### Allow Revoke Token Endpoint[​](#allow-revoke-token-endpoint "Direct link to Allow Revoke Token Endpoint") ![Allow Revoke Token Endpoint](/assets/images/allow-revoke-token-endpoint-4972020a487ec97e6456285a6010d1a0.png) Enable or disable the revoke token endpoint. When disabled, all POST requests to `/auth/revoke` return a 403 error. When enabled, clients can invalidate a JWT for all future requests. ### Require Authentication Code[​](#require-authentication-code "Direct link to Require Authentication Code") ![Require Authentication Code](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAB0CAMAAADuBmGdAAADAFBMVEX///+ZoKZQV168wMQmNURsdX2XnaT4+fri5OcdIyf3+PlxeoLBxMjx8vTz9PXZ3N/m5+nq6+26v8KLkphtdn7t7vDv8fKCipF2foaTmqB4gId/h4/P0tV7g4pzfIOTm6DX2t3V2Nvn6eucoqd1foX29/jf4OJ6gok1Oz6JkJbs7u+tsrfe4ONscHLV19jU1tnk5ejg4+WMkJKepKmGjpSEi5KPlpzFyc19hYyFjJM6QEP29vfHy8+AiJC5vsJKT1KxtrshJyvQ09aJjI5weICQmJ5SV1p5gYi1ur7u7/ElNEO3vMCzuL0yQE+vtLnS1deMlJrN0NKmrLF1eXx5gou+wsbN0NRveIDj5eZ2f4dKV2OPl57y8/Tb3uGUnKPk5ud8hIvz9fZeYmYlKy+wtbqhp609S1jLz9Lr7e7BwsSHj5fZ2tvMzs9XXF/p6uqVnKJ/goXl5+miqK18f4Pd3+L9/f3BxcmgpqzZ3N6RmZ/p6uy/w8e9wcX19fbDx8uOlZv09vdjaGra3d+Eh4rh5OWKkZgnLTFlaWzJzdAxP02orrNOU1YkKS1UWl10fYVlcHo9QkessbYyNzx9ho14e35yd3kpLzPIyswrMDRhZWgeJChga3ZESEzDxsr5+flBRknDxshNUlVtcXSZn6Xb3eCLkplGU2Cqr7VVYW2wtLmfpaqprK9aX2OPk5Vvc3akqq9eXl4zMzOws7RYXWCZmpynrbKqra6go6WanZ/d3t+8vsApOEZbZnK+wMEuPEuwsLBrcXfFys37+/usr7GOkZN4foJobG6lrLC+vr6Pj4+FiY9OWme/wcNGTE9nbnS7vL6GiYxTX2qChYd+gYSWmZvd4OK5u72kpqlWXGPi5OWTl5krOUhBTlsmNkUwNTmlqKo5RlSytbYjIyNiYmKdnZ3Gx8mnqayWnKNpc36rrKwtMzdDUF1JTlE2PD9tc3h0en+doKImJiZmZmZkZGSzs7MgICAoNkZTWmG7wMS2uLmRlJYvNTiPkpRfZ29zeoFMWGVV8srzAAAACXBIWXMAAAsTAAALEwEAmpwYAAAUKElEQVR42u2deUBV1dqH95F9WK2DEMgoAiqI4kFSEAwIRBRQCkRQgwTzolaYoqGhol3ECRwAUVPRHNJErbxaarccspva9JXZZGWZzd2h6Y7d2/2+P7537elsELug3qPU7/kDz957rbXXfvc5D+95z+IoSQAAAK4RHl5lNwAAAHAKZV7Fmnx9/RgAAACn4ZepyrcYoQAAAGdSLPRbjMwXAACcnf1S8cHLhjgAAIBzsXlJUhnCAAAAzqZMkm5AFAAAwNncAPsCAADsCwAAsC8AAADYFwAAYF8AAACwLwAAwL4AAABgXwAAgH0BAADAvgAA8LO0bxQf3c4eEfzxn25wE+e923/oUsziE3HvAQAdyr4pnPOIg6d++nvRTpW+c4kj0Zs4v6nZno181k/bdxrnnowdLi0ta88hnXPrtlUnvvgs7AsA6Cj2vf37978b25p9I0r/xPnJyzxfDMn77cuxb3sPaeTQXDdvTt0I+wIAOoh9D/+z0+udOm1oxb77WNF6foqxzMXbqk8/Q0nwsynrS2P4JMZS+bust8htReWB6gHPpKT2tj29vTpxll3rbUvkK/kFD8Ye5jyTPc4j2GnSMV9D9o3Z25hCKarRPoq/uCMi8RA7IBrwPyvlBfdTpyelzmL2zak8YuJrzQ4p/fadc/RTCE/hiUMZm/4aY1MO/mnNXnE9HyReeHGdsO/ZqMT1Gc/iOQAAuK7se6pTF9a/0/et2jdnE/+RedTxlW9t5h+wnFqesqNate+RZvat3bGw7A2eeN9eI9M8wzdNrRWJM9m3SLHvn7fxlTEfkH1rExv4miJmtI/ivO5tzoNyHuR8ccwGodiqg7xx3Y4UNq+xZvFeXnvYdIgt5utHf8MTPY1+TCsJP62e+V2+6cWJPPVh9h49OFhLZzh7gdfMWsM34EkAALie7Ptdp3DGXv9nq3VfPonKus/yVDvbwBvJe5tJ1q3Z99+MuafyM6x4PZ+m9n6Rl7IavtdkX6PyUFN8lpzpaB/FUxhr4M9o5QWh2Nc4P8yYFysWqXQDedVxyH0TP8CqvqXmRj/Bj1y3a504TRSvYRn8BcYOkn2H8QxKhPlCPAkAANeTfV/vpP+4qO67fROv86AcUmXuPk5V1d+q9j3DDpvsO5WxqVqr95TOnrWkzJN802FhX3f2sdm+7zE75w872kfxdYxt578xKfY9Xq0M43dfxnpqE2M6RP1I8Bk0ltFPy30PqPNO5FSMeIOfpgcfMDaa7LtPPVMingQAgI5h331sQypJdApPPTNlypST9jd4A6MEmOzbSDWFT032pXVgxan8HWr16VSl8zuaW4cJb0azt4V9a0QuqnzqJuzraK+sWltJFs3lvEBV7BTOcxkrIYlu+3hKA9nXcaiI86+Yx/8qua/Wj6l1321q3bdOSHmjkvuuE5qeSB8AnqYzTTmAJwEA4Pqxb+dZ73d64YUX6MejrdiXreMR7lWlPCMmJmobu6mWZ+xrFPat49/ENDS3L72/TxwWc1+tuiB3M08sLS1t4BFVJdV84Ru1wr6k4JjHDfs62hsWDeV8R0xvre6bGBO1nb3FN59ZJ3JfxyFz3ddkX3XNQx2teTDVfVMXU714Iut9gTrHZIzGkwAAcP3Y93866fyuNfueTSW7ZQ7bXN1Qupix177ZlPG0sO/UibUNz7Swr+2rlesj6mpKRF8qN9DiA5Gx/siOpGyqWyzsOzVRqNCwr9HeYdFhlC1vMNY8ULV2wnZePSuF7Gs6ZHtv+6TEfdGshX2V9b61NbSy4eGDjWv2TlPWPGyqiRKf6/Ve1zAp5eBJPAkAANeXfX93f59W7HsJDgj7AgAAuHL7PsLehX0BAMDp9t3r+x3sCwAATrfv++z7ttsXAADA1bLvCxNhXwAAcKp9w4w1DwmIEQAA4NvVAQAA9gUAAOBU+z7ax+0njgb2U/7p3L3Z3ty+bRzc3eqhdyjTT/OrGy/RuMVJzFi6XPJQWavT79y1jTOMDWpfuFxc29Nau1Y9DC2i8t87cXTAVRvq4gC1ObYAwL6XxL+S2fMLmFPsmzmEKtAj6PFt89pl3wK3S9u3D8lNjHvx3vGVV9m+fW68HPtq19q6fQvc2jiK0vAK7Tu261Wzrym2yg0FAFyWffv1Yc6x739+sV6efdu695rYt/Vkt4Pb1wTsC8Bl27eH1WpVX4vPJ7t19yXdRo7qtj+cnZsTGJznITaTQ2aGK2Ic7+0WO5fU8YhbwgiHfbWG0QG7R3XT/u+ioBkh/uLhyF7xs8kzWgeqEHRRTkbvxovv6hVMKavLINelCT2MDpp9q1Ykh7jSd036eDGWF8kCqFM/y6OD3Cpo226pj59PMp4zKIE2XelQF1F58A2rtw7Up6LsFe+OQ9Pd/HONxmraNirNx0U/Pcvt1ms1ySV8dXD9S+Gql34/J6T7vMjAeOo36GbGlnkz34HDrcPdlUGVFhVdQ+JozqZOloELYtPpuy8Cdzcls/4JaaMmsCwR07yXlMqDFgZt6vomoVwZGxEfEuaujNOzG/2IG8qe9/bxyTJuiN7QxXVmiAiWPo448WODkvup2z0C6f8lWebPtOGEfWfHezom2Y+GCDDi7spslsJibST9LijxUe+xHjItQC4LZngnzDUCSrHVbncX49kDAOzb7tx3vJb79hx+uz3SmxRSWFW1YBm7cYtvz4TBtJk8vl+3R4UY3QMe8E26w5cNXOqZ08dhX61htDWSlQQqX7/DkoL8kkLuZ7MDew7wJs9oHYQllVSJjHRX7IQewYOZizWHDU0wOmj29cgaMMHye8O+au4bP9Szax5jhTM9e3TrzyzDQ9nqPDUhpXHD+84oYD2NOYu9ZIiq5Dn2yrSdRmNiXshk36q5+ukn5Hf2nZMfxIY0LSrrPlK1b9rseWHJeV6DSWaafbO6l7EbPRy5r89k38n1meZOlj5ebPIoilV6FRuQ5uK7IrgoNM2D2QJ7iGvVw6BNXd/UU9rKgJzQBa7N7Jt2u4fHIuOGGLlv/tiSyAQjBOqJ5xnbwTm0naUPR/bN8i8xT1LJffW4uxZ3t4TrPfW7IJJy7R5rIdMD5GLtz/r38tUDKuyr3W7kvgBcuX3plctsAZ4skL5BN3K1WgmYQUZJIjkmCzG6VNAu19m2tPGMZTWvPFDDaJ9ixpqGGrsG3sbSb2Osh9VD72Cyry2NUq35scyF5BLuU6V3MFUeykJa2Hc3ZchL2ZIQajx4ILNE0tdNLjXsu9OtyDQV3b49ROOwFUZjYsQC8VM/fRa1rQoJYndQWnc2XnUrzWiRlS7FLVS374i+55pVHii/ZMnPmztZKFzF1hIldFnpNH5wLvOuZP2Dld80Whj0qWubhlTTKe4TrO4m+9rcHig23RDDvn3FWYr1cZQT05Xp25FzmEdaqD7ckoD9ff2YeZLCvkbcK7zn2Iyeprug3WM9ZHqAXET0vJP0gAr7arcb9gXgyu0baxX0Vwq9Q2YyT0u81SpS4Z30drReiHGF0mByppVe1UkO+2oNlUKj8BWRk97LSrlR3D30NtnqoXcw2TfTahfJtlp/JMlqHTT7hj/l72O1hje372BFTrnKHBYoZWDhKs2+9/ibp6LbV7wPZ0PCjMbEU/vFT/30eU+JEAS5K4NajYqocikUBs2+7o/Eh+TZHPYVOeSM28ydLCRUVj9eCV2eOMOgB9i/urOZkYp9tTDoU9c2DanG0a83Zj1nzn2TmnwSFhk3pFnd18dLH0dfCaJvT6gPf97bGC46rT5J1JcdkxT2NeIe7DbA0VO/C4R2j/WQaQFiLt2Va9YDqlQe1NsN+wJw5fbtOt/xMRvZN2xmdNUWYd9lpKBuQowjwpTjtnxqYKr7ag3N9g0c62l7LJKl00v4Rsp9tQ7m3DefVDY71njdax00+47tu9Pdk+zrRnlfWCSboH/qRjrYGexYgCZcFazlviHFpqkoe5Xcl0qhA1eY7TuiUL0E9fSiOGuj1C5/ADN/HqXbt/sWGka89bcNHb5MGVRpEScUebO5k4WMW2L1UkKXJeRMVePMtMz6CWruq4ZBn7q2KR4qV5ZOIfG0Krn7IpGl/kq8fyjZH2fcEL2hFix9HD0MxnZC0Ix/GcMtCbj/DipFmCY5v6vjwl1ctwSHGj1N9tXusR4yPUBKvu9/sx5Q2BeAq2rfoWuXMFuuYV/X+cw2SNi3oqpqkFL3nTecjt7vyQYOZH7JZF/tMzatodm+AQOYbwDJNM7dFibqvmoHYd8VM7W6r8VW1Hew8brXO6j27UIKmEz27buFjXeLZH4+8wwd2LwftTGvRYZQY59X676xk2nbmLPYq9R9H2Blvcab7RsaksNE3Vc9fYHbEjbWGsQiK/yYR85F9t39GPON82Y9MpnX2iBlULXum8NyevmaO1nq7ymZ0aSGboBbP7YsmORaEZagXqsWBn3qelQI5coqk/3YfrXum5lWxmZbh7r3V35b6TdEb6gFSx9Hl6SxPcI1LdMYbkkAW9Srp3mSuf5UNnDEfWy8MZLJvvo91kKmB8jFZ4iodesBNdlXuaGVOXjpAdj3CuzLcmPTElwN+54NbpqRJ+zrEhCyv0oRY0G629rCCfROPNn/pb6UE6nrhLWGZvtW9hkV5kpvu0euTY5U1jwoHYR9l9yhrXmYSZ+924zXvdZBs29RbN+uwr790pcuEMPkiTUPmkH9HgsMaLrHEGqSj7rmwW4JoTUP+pzFXmXNQ6EbvW0225eNb8oXax7U01PFIi6MWtiy1rotHXKRfTMfGRRHw22hFQcvqYOqqyIs1jgqp5o6WSL9fZQ1D2J1Xs+4tCYRmUqr9gmjHgZt6vqmQFwZG0yLFPzU2S0rTJiTPNR9gdUav9O4IXpDPVj6OPo6PH071CqKttpw4hr69+phmmRVrFjz4Ij7iG4lWk+TffV7rIdMC5B+zVpATfZVbmh6JF56APZ14l8az8VKozb8Id7PAxfcawDwPQ+wL+wLAOwLYF8AAOwLAACwLwAAwL4AAABgXwAAgH0BAADAvgAAAPsCAACAfQEAAPYFAAAA+wIAAOwLAACwLwAAANgXAABgXwAAAP8V+wIAAHA6ZF8JAACAk4F9AQAA9gUAANgXAAAA7AsAALAvAAAA2BcAAGBfAAAAsC8AAMC+AAAAYF8AAIB9AQAA9gUAAAD7AgAA7AsAAMAZ9r1l6ZvZy1+9l12red0y7Iknn3ziFRvuEADgF2XfIUdvFXz4w+5rM63n/vLFy9Onv/zFZ8/hFgEAfkH2dc2WNZZbrsWsvvqr/uhvf8Q9AgD8YuwbuVw2WJ51DTLfvzoef47sFwDwS7HvLUfJuqty3d1zV9GDo1uvzpnulMe0stcmy/aLzv8X89ZnbT//bxdevG/xMNxkAEAHsW/hcVn+g/pwjCwf72o6dLf8dbmUI2c79twr39u2M408FtZG+w77wrx16BXTxn2cX4g6d6lT5ByAfQEAHdi+x26V5SD1YaUs33qsmX3l3Zdp39Zpzb5PvGzeevkJs30flA4vTGnPCWBfAECHsW822bdIfVhC9s1uZt+j508o9i2p/yT7WI60VtSGH1KOPSTfu+dogb3+7uWrCiQp8w/H30yXx0mD5Tcl6VW5s1J5uFPOX7V8tTTy1eO75khS+b3ZX9/Vin2fnG7emv5kc/tK0/hWyb7jQgN9HuexY33KGxmSlEo93opRKg8Rww5ulj49vX6hryQdzmiseRv2BQD8LOw7Rl4h7HvLLnlPvvzhzgf2yHsqRmr2Pbpq1aJdsk+3D88z2jo/Zrli3z1m+x4dd8eQ3fL52FflpySLvHzM+Xbbt/zUNkmaOKtg2uYvpdF1BV9+28K+G5k07dtn7f9XKm3ddp/vx5NgXwBAR7HvHkfl4V9k3z3N7Lvs/N23k31vk3eJqnCCqfLwkLxKov2U6ubLQ+yyHCrddbF9P6mSpHHyfGku9R9HVYygdlYeOOcRG6TDjfRR3NOjy6tzJOmdFvZ9WJJ2HKLEes25aWtOSNJG2BcA0FHsO+pW41O3cWTfwmb2vWcypb/Z0kBRbriTmpntu0KSHlPXqRXOlWWJzKvZd5xh3xCRW6tttn4iL5P8WrHvKz/xqduDUu/SQ9IRLtjrxylF/7GFfadK0krl8IZ3t4sesC8AoKPYl/1gXnH2UXlz+5aPO6rkvuclyY1y3yY51rDvSJH7fp2UlNS5P+W+0VRaGCfNpiS3+Lhh3zGK0l2pTdaJS+W+ts/MW/840aLuO7e6ZGiislU+iVT7DNm3kQrN6xz2rVH/RGPaGpr6QtgXANBh/tpipOmvLbKb/bUF2VfKkk11X6ounK+odNiX9tdXFH6SpNR9s8m+ZR/JsSRxs31Xy+cLK9yOSa7y3RWvtmJf6bm/OR5//nephX2lmmHlpf8ul6YHSaMflIpSyL4ZJ6WbGh32nbLtsFR+hOq+J6WpqbAvAKAD/aWxId+P7pJa2lfapax5CKE1Dz0lyb5Llpsc9pXsY+4+/uaqaClz1Ye78si+UuTXH8aNa2ZfafCbx88fs0jlsdnZltbsK/3x80v8qZti3y8bPYoe/HbNwTOSR9SkBpH7Tt1YtzfKYV/pyMrq7VFizUNKaRTsCwDoQN+yM+IH5Vt2sj8aeSWDdxb2vSye++yQ+JadQ//4+39seiQDdxEA8PP5hsmto/ZkZx+7s1y6NvaVtr6ifMPkCQn2BQDg29WdaN+2A/sCAGBfAAAAsC8AAMC+AAAAYF8AAIB9AQAA9gUAAAD7AgAA7AsAAAD2BQAA2BcAAADsCwAAsC8AAADYFwAArjP7lp1AGAAAwLmcKJMkr3DEAQAAnEu4lyQV2xEHAABwLvZf049MPwQCAACcSWam+o9vOGq/AADgJE6E2zO1h7/2KrsBAACAUyjzqsKvIAAAuEb8P8sVpXxtLnBPAAAAAElFTkSuQmCC) When enabled, an additional Auth Code must be provided alongside the JWT to use the revoke endpoint. The parameter name is the **Auth Code URL Key** from Auth Codes settings (default: `AUTH_KEY`). Configure the codes themselves in the **Auth Codes** tab. --- # Validate token Use this endpoint to verify whether a JWT is valid. On success, the response includes the corresponding WordPress user's profile, their roles, and the decoded JWT header and payload. This endpoint is useful for: * **Server-side token verification** before granting access to resources * **Debugging** - inspect what user and claims a token resolves to * **Client-side session checks** - confirm a stored token is still accepted before making other API calls API Reference Explore and test this endpoint using the [interactive API reference →](/api/v4/validate-jwt.md) ## Endpoint[​](#endpoint "Direct link to Endpoint") **METHOD**: `GET` or `POST` **ENDPOINT**: `/simple-jwt-login/v1/auth/validate` **URL Example**: `https://{{yoursite}}/?rest_route=/simple-jwt-login/v1/auth/validate&JWT={{YOUR_JWT}}` **PARAMETERS**: | Parameter | Type | Description | | ---------- | ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | `JWT` | `required` `string` | Your JWT. Can alternatively be passed as `Authorization: Bearer `. | | `AUTH_KEY` | `optional` `string` | Auth Code value. Required only if "Require Authentication Code" is enabled. The parameter name matches the **Auth Code URL Key** in Auth Codes settings (default: `AUTH_KEY`). | ## Request[​](#request "Direct link to Request") ``` { "JWT": "YOUR_JWT_HERE" } ``` With optional Auth Code: ``` { "JWT": "YOUR_JWT_HERE", "AUTH_KEY": "MySecretAuthCode" } ``` ## Responses[​](#responses "Direct link to Responses") ### 200[​](#200 "Direct link to 200") ``` { "success": true, "data": { "user": { "ID": "1", "user_login": "myuser", "user_nicename": "myuser", "user_email": "myuser@simplejwtlogin.com", "user_url": "https://simplejwtlogin.com/myuser", "user_registered": "2021-01-01 23:31:50", "user_activation_key": "", "user_status": "0", "display_name": "myuser" }, "roles": [ "administrator" ], "jwt": [ { "token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkpvaG4gRG9lIiwiaWF0IjoxNTE2MjM5MDIyfQ.SflKxwRJSMeKKF2QT4fwpMeJf36POk6yJV_adQssw5c", "header": { "typ": "JWT", "alg": "HS256" }, "payload": { "iat": 1516239022, "email": "myuser@simplejwtlogin.com", "id": 1, "site": "https://simplejwtlogin.com", "username": "myuser" } } ] } } ``` ### 400[​](#400 "Direct link to 400") Bad request - the `JWT` parameter is missing. ``` { "success": false, "data": { "message": "JWT is missing.", "errorCode": 53 } } ``` ### 401[​](#401 "Direct link to 401") Unauthorized - JWT is invalid, has a bad signature, is expired, or has been revoked. ``` { "success": false, "data": { "message": "JWT has expired.", "errorCode": 14 } } ``` ### 403[​](#403 "Direct link to 403") Forbidden - token validation is disabled in plugin settings. ``` { "success": false, "data": { "message": "Validate token is not enabled.", "errorCode": 82 } } ``` ### 500[​](#500 "Direct link to 500") Internal server error. ``` { "success": false, "data": { "message": "An unexpected error occurred.", "errorCode": 22 } } ``` ## Examples[​](#examples "Direct link to Examples") ### SHELL[​](#shell "Direct link to SHELL") ``` curl -X POST https://simplejwtlogin.com/?rest_route=/simple-jwt-login/v1/auth/validate \ -H "Content-type: application/json" \ -d '{"JWT":"YOUR_JWT"}' ``` ### PHP[​](#php "Direct link to PHP") ``` $simpleJwtLogin = new \SimpleJwtLoginClient\SimpleJwtLoginClient( 'https://simplejwtlogin.com', '/simple-jwt-login/v1' ); $result = $simpleJwtLogin->validateToken('your JWT here', 'AUTH CODE'); ``` ### JavaScript[​](#javascript "Direct link to JavaScript") ``` fetch('https://simplejwtlogin.com/wp-json/simple-jwt-login/v1/auth/validate', { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ JWT: 'YOUR_JWT_HERE' }) }).then(r => r.json()).then(console.log); ``` ## Error responses[​](#error-responses "Direct link to Error responses") | Code | Meaning | | ---- | ---------------------------------------------------------- | | `53` | The JWT parameter is missing from the request. | | `54` | No WordPress user found for the claims in the JWT. | | `55` | The JWT has been revoked and can no longer be used. | | `82` | The validate-token feature is disabled in plugin settings. | JWT decoding errors (`1`-`22`) may also appear when the supplied token cannot be parsed or its signature is invalid. *** ## Settings[​](#settings "Direct link to Settings") Configure under **Settings → Simple JWT Login → Validate Token**. ### Allow Validate Token Endpoint[​](#allow-validate-token-endpoint "Direct link to Allow Validate Token Endpoint") ![Allow Validate Token Endpoint](/assets/images/allow-validate-token-endpoint-f62c72e8727b5cf12aaf211cf90afc48.png) Enable or disable the validate token endpoint. When disabled, all requests to `/auth/validate` return a 403 error. When enabled, clients can verify a JWT and retrieve the associated WordPress user details. ### Require Authentication Code[​](#require-authentication-code "Direct link to Require Authentication Code") ![Require Authentication Code](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAB0CAMAAADuBmGdAAADAFBMVEX///9QV17z9fb3+PkmNURsdX2ZoKb4+fri5OcdIydxeoK8wMR4gIfZ3N+6v8KXnaTx8vOTm6Dl5umLkpicoqft7u92fobq6+21ur5weIDBxMhtdn5/h4/e4OPV2Nv29/jv8fKtsrfk5ejh5OU1Oz56gon19vemrLF7g4rV19jR1NeQmJ6xtrt8hIuJkJZscHKCipHf4OJyeoOGjpSwtLmEi5LM0NJ1foWzuL3O0tSeo6nIzM+OlZuAiJDX2t2FjJP29vegp6zAxMglNEOqrK6epKry8/SPlpzGys59hYzu7/FKT1KMkJLj5eZXXF/m5+l/goUqLzOiqK0gJipNUlXa3eDb3uFzfIN5govQ09W5vsLBxcmPl52RmZ91eXy9vr9TV1rt7vAyQE/N0dSUnKPk5ufExsklKy/d3+KVnKK+wsYjKS1UWl2ssbbs7e/m6Orp6urBwsQxP03Mzs98f4PDx8v9/f0nLTF0fYTp6uzn6eteYmYpOEbr7O6us7iKkZc8Sld3e36pr7TT1dhucnVBRkl9ho2JjI6Eh4q3vMBKV2OorbPU1tl5gYiPk5XIysyMk5lVYW3Z3N6XnaO/wcNxdngeJCj5+fk5P0Klq7CHj5eZnJ6Zn6VeXl62u79mcHtjaGrJzdBhZmnU1dbY2tplaW07QURRVVijqq9ATVqPkJI9QkeMj5EzMzO9wcXLztJ4foLe4OJobG47QUXd3t+xs7ScnZ6HjpUzOT1bZnIxNjuJjI9kZGSwsLBrcXeFiY/7+/uyt7tESUykpqlHTE/EyMza2txfanWDipGmqavy9PWsr7FOWmeho6a5u72GiYxaYGOChYeYnqQvPUxrbnFfY2hJTlEsO0lFUl/W2dxibXhWXGNobnVIVGGamppkaGzO0NLKztG7vL5DUF1ZXmFSXmolJSWNjY0hISEvNTlLV2Rpc36vsrP09PUtMze2ubpueIKytbZtc3h0en+VmJo3RVOeoaPDxcaWmZuUl5mTl5i2u8CMlJy7wMR8goi1u8Bh/a8VAAAACXBIWXMAAAsTAAALEwEAmpwYAAAUJ0lEQVR42u2deUAV5d7HR86c8/gAKat0LioQChQkKqsgEmUubIoIeBREKDUFdwM01FI0S03cLUvTXFLbTMuluq+ZdhNbbLu2L7Z327tt997e9/09s505iAXUPUp9P38cz8w8zzzz/Gbm43N+85yDJAEAADhHfB7k1x4AAIBb8Avy0ORb5sMAAAC4DZ9MVb4eCAUAALgTD6Ffj1AEAgAA3Dz6peRDkAVxAAAA92IJkiQ/hAEAANyNnyS1RxQAAMDdtId9AQAA9gUAANgXAAAA7AsAALAvAAAA2BcAAGBfAAAAsC8AAMC+AAAAYF8AAPhD2jeWj25hjW68/y8XuJjzXi3fdDZm8utw7gEAbcq+WZzzA7m7fvl30Xbl/vMsW8LXcr7VZc0WPvOX7TuD8yGM7cvNHdKSTUaDaxZWb39wNewLAGgr9r3q29e/mdiUfQ/kfsH5iVa2dw/Je2hr7NvSTRp30bEeOZK/BfYFALQR++57vd0b7dotb8K+dWxAHt/FWObihdVHN9AgeHVWXm42H89YPn+W9eL8YiXzQPmADVn5vSzPDK/eO3OyVtuyng/nnzQwNo7zTNafd2NHScf8ENk3+2ReFg1RjfKx/MG6A9s3sIdEAf69kl7wyT46Pn8mCzySz7tdt9plk6i3fU24s55CSBZf72BsKu14Wu4Xh06K/vxr76EH1wj77oldnzdmNa4BAMB5Zd957TqwBe2+bdK+jrX8S9ZQyXc8f4T/i91VwbPqqlX7lrrYt6LuziHP8b1D3zdGmqf52icrxMCZ7DtAse/3C/mO7J/IvhXrd/MDDcwoH8t55VDOHXfdwPni7OVCsRG5PG9NbBablbdt8Ulesc+0iS3meaP/ztcPMeqpQ1/On1FbfpavffBlnj+OPUFv3q+gFvZ8wt+eeYgvx0UAADif7PtNuxDG3ni9ybwvH09p3VKeP5kt51+Q945Qprcp+95Cfzwjn59mHnl8hlr7QZ7LtvH3TfY1Mg/bPPaQM53lY3kWY7v5w1p6QSh2Nef7GAtiHoFMbHrGtMlnLX+IRXTjG5z1BF9y3a6VopmX+NtsB3+AMeH3G/kOGgjzLbgIAADnk33faKe/nJH3Hb6WVzbQGFLlyTX8ZUYiVex7mu0z2Zcerz2plXpCqTykgpR5gq/dJ+zrw46b7fsEC+R8nLN8LF/D2HAyuFOxT/BqZTehQ8fkUZls06atXAh+DO3LqMfU6RCfqce9nsRMA+ujbDv/ibHRZN86taXtuAgAAG3DvnVseQX/nk3jFaenTZt2IvA5vpvRAJjsm0c5ha9N9qV5YB75/Ecq9fWTSuV/am69UXgznA0V9t0mxqLKUzdhX2d5ZdaasOg7nOeoip3G+TuMzSGJLjw+bTfZ17lpAOfHWcMnyth3tNO+lPddqOZ9K8XqLcrYl+y8g+x7Dz9KLU37DBcBAOD8se9fZr7e7oEHHqCX+CbsS0PHbj6UhN2RnR27UOR9d9TlCftW8qPZe13tyx7h2x/JHlqhTsg9wtfn5ubu5Qci5lTzLc9VCPuSgrP7G/Z1ljcsOpvz2OxeWt53fXbscPY8P3J6jRj7OjeZ874m+6pzHiortpjzvvmLKV98Hev1CVXO3jEaFwEA4Pyx7/+00/lrU/bdk092y3zkSPXu3MU05+Hva8d8L+y79bqK3Rsa2ddyfEdet8ptc0TdHzgXUwwSOT20K81aW7lY2HfreqFCw75GeadFH6HR8nJjzgMfw8YO59Uzs8i+pk2WJ4aP314XzhrZV5nvW7GNmh0n5jyI9PNPe9e+HSue6/Vas3d8Vu4JXAQAgPPLvn+95n+bsO9ZeEjYFwAAwG+37+3sWdgXAADcbt+TZd/AvgAA4Hb7vs6+bb59AQAA/F72feBl2BcAANxq3wBjzkM6YgQAAPh1dQAAgH0BAAC41b7x3T1/Yat3F+Wfv/i6rE3s0cyd+1gb9Ap+ejOXXnCWwo0aMWPrcNZNfp4t3JcrcX1aFi6vji0prfVVD0OjqPy+DYtANN1eK6LanEClXIhbDoDW2rfntSzQnsPcYt/MxykDLe7Xm2a1yL45nmf3RHeSjdjvmWsLj/3O9u1+QWvsq/W1afvmeDZzL0rBZtn3zPYCGinSvPwb7bv5VXa2VgCAfX/dvl26M/fY99dv0tbZt7lrz4l9mx7s/vfse2Z7/0X7nmWvAMC+zbJvP6vVqt7Wg9I8fctIt2H1ne8OYe0zvKMi6Rb2nptWNCxEEWOhv2fcSrqzb/dM3+i0r1YwvNP8+s7a3y5yTCjqKd7GJw0eRRrQKpAcOiiN0adjj4ykqBgSysAX5qX3Mypo9o1Yklb0whTGgoMYiwxjnahSF1v8QM8SWg60JQ2mkraMgem02JE2dRDSKQtIsqboh6KsFfuaHe3ZM9EorFBYbw/20ptniZ2TJpFUQiZFJd0aorp1VUaN76y53oOp3kAaPm/2Z2Upy6zLfJSdKiVKfHsn0DGbKtlS+u6Ppt++8J5fn8aWptvrx7LkF2h95K1KJkALg3bo+iKh9IxtHFyU4qPsp2tneklwsEH+wcHJxgnRC3qtGlYkgqXvh7F+3vS3SN59Sg+fnnnQGvCa5+nfVQu5s466rEemAyt7KkY/sS5xUldpF4MeKL2jah9F5kE7gx2MqwgA2LfZY99Cbez76rKrAuf60w1XHBHR9112wbiyV9NH0mJaYZfO8UKMPp3uK0v1LmMp86Ys6O60r1Yw3DqXzfFW/+bQIEdoas01bJR3Vz9/0oBWQchBGSKRITLixvaLGsm8rJcwR7pRQbNvQ/JFY22rDPuqY9/Bjim+kYwVD5vSr/NSZls2m02KVAektN+QHhNyWFfjmMVa2ldEWkbgMXuhUZiY1Tu+LGKl3vxY++VlGfY+7HH/Aj9f9effvOyjZqWkRQaNJLFp9k329WMXNDjHvsExZTE1meZKtu5BLKaeYhUdwS6ye5UtiRow297ALN79RF/1MGiHri/qQ9pjnRbM7rvKxb72qxoaCowTYox97RPnhKUbIRBEXUKNJ+vh0+yrN3BTYVmyd4QaclMdsWxEpsMU+h9TP7GmOOmrtItBD5TWUa2Pin21M4ixL4B9W29fuouZpdMQ5k139NxJaiZgAhkllbHUNCEzrxJatWqUhe5aluyaeaCC4cEejPk7jFUpN7Hom2h4Zm3QK5jsa7HTGG5iHPMiuYQER+gVTJkHv6JG9qUjcsxj4b2p8MgUZgtj7JJ5hn0LPAeYDkW3b78iKhywxChMbOwrXvXmk6lsRFEf5k2jvD2DVbfSERVYqSues3X7buzR3iXz0JNe0gaZK4mD87BOZt7U/eRo2n9UIvM/xpZGKTbUwqAfurZoSDWa4j7W6mOyr8XzPg/TCTHs20O04qHvRxCWwRrss/XwafY1NcAuLVRCbq4jlo3IREalMv3EmuOkr9IuBj1QWkf1Pgr7amcQ9gWwb+vtG2cVLFUSvTHD2BTbYKtVDIUL6GNojZDZEqVAfKY1lHzstK9WMLwTUz+rEwuik6zWMJbwLn1MtjboFUz2zbTSXxPqukxNZZJktQqafUOWPBVstYa42nekIqdE5Rj6KglL4SrNvu/2NB+Kbt/NYm1MgFGYWHK3eNWbj1wiQtDHR9mp1cjqKl2hMGj29bl9cFGkxWlfcZATbjJXspHvWE2hErpI0cLA+9jPvmxYmGJDLQz6oWuLhlQTyH/M2r5R5iG9wDghhn1XKcHS9yMYmxQyyN+It2ZfvQGveXar1aGE3FxHLBuRuTSODkQ7sS5x0lZpF4MWKL2jeh+FfbUzCPsC2Lf19vWd6HzMRjdcwLDwiHHCvpvpZu0sZLZRHTtZ7FTgQqd9tYJm+3pPHGK5MoxF0918gRj7qhVcxr6kslFxxr2rVdDsO7FHgc8Usq8n5X5TwthY/akbmaEgyvm4SIgiShv79vYwHYqyVhn7Ulo0ZYnZKhuL1S6ozSdT8xYa0tkvYuZpXbp9fUcxdrn46G9xLNus7FQpkSAUecxcyUY2mmwNUkKXLPpAWeNMe2bSWHUsqoZBP3RtUZGnMvalkAyxKmP3AjGUvlR8fph8d4JxQvSCWrD0/SikOyb8bMRbH/uqDeTULJ3DFqn2NddRx756ZFL6Rugn1iVOKS4Xgx4oraN6H2FfAH4X+zoWhTNLonHDdZzILAOFfUsiIgYqed9Zy2jrNVNYSgoLTSP7as/YtIJm+3a6iJV1Ipkm+FgCRN5XrSDksGSYlve1WQb0GGncu3oF1b4d6NaPJ/v2GMUKPcOYT/AswwwW/3gLCyowRLF/kJr33U8J2K7GMYu1St73PuaXVGi2yuyaBUzkfdXmczzD2URrHxZWEsoaLjnDvvOvZGUJ/qxfJgta1EfZqZr3XcAWJJWZK9lq7p8zoV4NnZ9nF5YaRXItCUhX+6qFQT90PSoiuyp6diwtlN2t5n0z7X5slNXhQ+NdekqpnxC9oBYsfT8KF3a0Zxrx1uyrNdDlUgvrSmNfEXJzHbHsjIxlQnSIfmJNcdJXaReDHiito3ofTfZVTmzMRbgFAezbCvuyxDh7ekfDvnui6idECvt6dep9d4Qixpxoz0XFY+mTeFrPW3swS291nrBW0Gzfa7vXB3Skj93xi9LmKnMelApCDuHe2pyHYTTpwGLcu1oFzb4D4nr4Cvt2iZ7XV+wmUsx50MwQeqV3p/r7DVGkBqtzHgJtRTTnQT9msVaZ81DsSR+XzVahZ/nKnAe1eXZ/z4SAp/owS/Iiz3kxZ9g38/aBCbS7UTTj4FZ1p+qsCJs1gXK+pkq2sKeClTkPYnZe1wR7vYjMtVbtCaMeBu3Q9UWB6BkbObgoQJ3zwFKL0zPSHD59rdbBhcYJ0QvqwdL3o/xvYi1xxtuY86A2MKxzcWSaQw25qY6y7IxMSIlviHZizXHSVmkXgx4ovaNaH032VfZqd+AWBLCvG1i5CvFuzbRZdBQA2BdASugoALAvpISOAgD7AgAAgH0BAAD2BQAAAPsCAADsCwAAsC8AAADYFwAAYF8AAACwLwAAwL4AAABgXwAAgH0BAADAvgAAAPsCAADQ7QsAAMDtkH0lAAAAbgb2BQAA2BcAAGBfAAAAsC8AAMC+AAAAYF8AAIB9AQAAwL4AAAD7AgAAgH0BAAD2BQAA2BcAAADsCwAAsC8AAAB32Pcy/xXl05++jZ2r47rsozvuvfeOjyw4QwCAP5V9Y2qvENTWTjo3h/XYhw+XTp1a+vCHj+EUAQD+RPbtWC5rvGg7F0d1/FH93aP9cY4AAH8a+86dLhtMTz4HI99Hne8fxegXAPBnse9ltWTdTYk+Pomb6E3tut+npavlEU2stchy4Bntf2he+rj57fe/88x1i2/ESQYAtBH7Fp+S5X+ob0dQ7sHXtOl6+b0qaYFc7lxzm3xb81qaezCgmfb96GHz0lu7TAtDOT/0UvjZmrjrM9gXANCG7XvwCll2qG+vleUrDrrYV57fSvs2TVP2vaPUvFR6h9m+N0j73s5qSQOwLwCgzdi3nOw7QH07h+xb7mLf2p2HFfvOqbm+/OACaZHIDb+mbPubvH9FbU5gzfXTN+VIUuY/XvwgWr5ZGil/IElPy5crmYer5a82TZ8kxT996pUMSaraX/5eRhP2vXeqeWnqva72ld7h66TJdZ/spudxn9flZT03RpLyqcbz9yiZh243vn9E+vpo3tu0231j8rbNhH0BAH8I+46Q5wv7XvaKvOIr+VTBfSvkFSXxmn1rX9tU8KYc3PnUTia9Ju8c8aJi3xVm+9Z+6h0zSd4Z97S8RLLJ00fsbLF9q3YtlKTrZubMODJOGl2ZM65bI/u+zKQZ61dPviVXWrdwaODx8bAvAKCt2HeFM/PwM9l3hYt9N7+38yqy7//Jb4qscLop8/A3eZMk/VsMdb+SHw+U5dlSxpn2/S5Ckj6lpZXyK9LNlMXo08LMA+f8wHJp3xf0KO770VXVd0nSj43s+4Mk1f1IA+tD4TMOHZakl2FfAEBbse9/rjCeun1K9i12sW9iPA1/y6UrRbrhaipmtu98idYrFK+UZYnMq9n3ZsO+vcXYWi2z7jt5sxTawqduN0i9cjdIpVxwMpTTEP3LRvbdKkk7lM3Lnx0uasC+AIC2Yl/mMuNMrnKx7/1Vb9aSff8t75Sk3jT29Zf3G/aNF2Pf91JTUy9fSmPfcEot3CyNokGyxynDviMUpb9AZZIPi7Gvown7WlxnnB1ulPddWT3HsV1ZqhpPqt1A9s2jRPMap323qV/RmHGIDv1O2BcA0Ga+bRFv+rZFucu3Lci+UrJsyvtKw+SdJcec9r3sTbmmpPi7VCXvW072HSLL+0niZvtS3je6xPOg9IJ8fcnTTdjX5dsWdzwkNbKvtO2RqtxbqqSpDmn0DdKALLLvmBPSxXlO+/6wcJ9UVUp53xPS1grYFwDQhr5pbMi3NkNqbF/pTWXOQ2+a89BVkgJfkWV/p32lwBE7X/zgtXApc9OpVyLJvlLYe6cSbnaxrzTygxd3HrRJVXHl5bam7Cv1f/QsX3VT7Dsu7/MBN3Q78P5p6fPY8bvF2HfrlsqTLzntK5UOrx7+kpjzkJX7EuwLAGhDv7JzoforO9/Jc3/Lzi8X9m0Vj338lviVnbc+fuhXi5aOwVkEAPxxfmFy3X9WlJcfvLpKOjf2ldbtEr8wueuwBPsCAPDr6m60b/OBfQEAsC8AAADYFwAAYF8AAACwLwAAwL4AAAD7AgAAgH0BAAD2BQAAAPsCAADsCwAAAPYFAADYFwAAAOwLAADnmX39DiMMAADgXg77SVJQCOIAAADuJSRIkjwCEQcAAHAvkyPoJTMUgQAAAHeSman+UxZyGMEAAAD3cDhkcqb2NiLIrz0AAAC34BcUgf+CAADgHPH/obfVF28r1oQAAAAASUVORK5CYII=) When enabled, an additional Auth Code must be provided alongside the JWT to use the validate endpoint. The parameter name is the **Auth Code URL Key** from Auth Codes settings (default: `AUTH_KEY`). Configure the codes themselves in the **Auth Codes** tab. --- # Webhooks Webhooks let you push notifications to any external HTTP endpoint when plugin events occur - no polling required. Use them to sync user activity to a CRM, trigger CI pipelines, send Slack alerts, or integrate with any service that accepts HTTP calls. Webhooks are **disabled by default**. Enable them in **Settings → Simple JWT Login → Webhooks → Config**. *** ## Configuration[​](#configuration "Direct link to Configuration") ![Webhooks configuration](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAC/CAMAAACVKY/qAAADAFBMVEX4+fpQV154gIe8wMRsdX0AoyodIyf////i5OfHyMmXnaT3+Pl2fobg4+X39/ja3d+1ur5zfIPz9fa+wsbp6+2us7iZoKbO0tSfpKqDi5Le4ON9hYyiqK3s7vCCiZFxeoKGjpRVVVXi5ebb3uDU1tmJkJeLkpixtrt/h4+6v8Keo6nx8vT19vd6gomTmqDN0dRweYHY2t2AiI+wtbqPlpyFjJPn6evl5ud1foXu8PGXnaOgpqymrLHJzdDBxMhtdn7x8fLEyMz+/v6coqfy9PXu7/CVm6GQmJ709vfr7O2do6hud3+2u797g4rm6OqMk5mprrPAxMfl5uns7e+lqrDLz9JyeoLn6OmTm6Cqr7WNjY3Fyc2zuLy0ub2jqq94gIiOlZtveIC3t7fQ09bCxsmPl52SmZ9wcHCNlJqEhISssbY0Oj58hIvGy8719fb8/PzCwsPo6uzR1Nfk5un6+/uboKZye4OprK/d3+Lj5ee9wcVcXFzk5ORhYWHW2dw6QEN+ho3w8PLe4OK5vsG1tbUpLzKvr6/Q0tbv8fPM0NKKiorDxsrf4eOTk5PW19jZ3N7V2Nvh4+RXXWK3u7/Hy8+vtLna2tt2f4ZXV1emqq1JTlHo6eqkpKVoaGiorbJzc3OAgIBdXV3FxcXn9+q6urp1eX02PD/Ky8u/v79SV1qHh4dTwW/5/frR79l4zo4EpC2ZnJ2MkJI+Q0dvdHZdY2mtra3Gyct9fX1gZWq3vMB9ho2ZmZmenp7z8/MeJCjf399lZWVOUlamp6h1dXUZrD8kKi61ub2iparS0tKJiYmanaGqr7TPz8+QkJBqb3RgYGCIj5aTl5mxsrJ8f4O+wMIlsEnD6s245cNdxHeu4rswNTl5eXnU1NRaYGRtbW1kam+ztbZ/goVGS06L1Z4ytVP5+flYWlyws7V7e3siKCyDhomIi44erkKPk5V4fYCKjpGpqam9vr+1t7lra2u55sQPqDZHvGVhxnv0+/XZ8t92e4Fvy4Z/0ZSH1JqVmp7Q0tSheW+mAAAACXBIWXMAAAsTAAALEwEAmpwYAAAW20lEQVR42u3deWAWxcHH8cmTZcfyQMiThEgIJOQEISCJhCQkgQAhIWC4wn2FcIOUcChyn1KDUDkExAMQRK3YqiDFCwRvaj0QrW216qttbX17ae/2PdrZ2d3neXIAwUJA+H7+eJ5lZ4+ZnTy/TGY3QUgAQMMT1ktE1PyrAAANYn5UhJO+faoEAKDBVOXo9O0TwaUAgIYUkaPSN4KRLwA09Og3QsgoL9cBABqWN0rI+VwGAGho84W8iqsAAA3tKtIXAEhfACB9AQCkLwCQvgAA0hcASF8AAOkLAKQvAID0BYDLI31vN83V9tIN5s2n2+gMRQBA+gqxeeWWf05ylu869PsNQUW/Mw8KkWSabwvxG/Nu0hcAzmP6GiEhIVvK9OJhtfhAUNFk00wUd5nmISE+Mz8hfQHg/KVvYYjlWr08SC0dCi5bqyL0CfPTtd6cz80/itVvrlj78Ls6fV+7e+2WZlbEHvhw7d1qlffe59eueCIxaMFK30/MGyYVfvL8y+bzh7n4AEjf6g5Z6btZh+07aumu4LIPzQfEwU9/Yx7+0jTvWf2++fE775uHrfS94fcrzBVlKmJfXnHQvKFQ/Le59oG7zRVDAgsPmjc/YK5IEq+Znx048NRdXHwApG91g7c4kZs2K+TNV9dVK1MTv0nmO++ab1vTvr8xHxbibfMpK33fFWUvm/+l0vfjiNWm+a8Oz5m/EmkPmo/7F1TRQfPTzXqHObeHce0BkL41RYa8Zr2FZYR8PKJG0Xp1x8081eHzpx5W075PmNoKK303CjW4fU1F7KuizDQnbzfNYUI8bL7jX1BFpspgIaIeVgsPvsvFB0D61nA45FX16s0M+XhRzSI18fu+OUBsWfu5Guj+wfx0jnLKSt8/isTn9Nj3Zp2+HUzzLlH4vhr7ugsqnD9Z+5weUyd9+ab5PBcfAOlbZ/oeCHlqc+2yD03zU6FyV037ig3vm28eOPDwA1b6Pvj7g+aKHH/61j3vO+dzFb+vPXHgwBbzMy4+ANK3rvT9/5BDq+vY43emmkQQc0z9tO/qJw6+fPeWm/XY9+DLW7aLQPp6X33+5RVPqPj2L6j0Fb967rm73r1bRfdnP+PiAyB9q+v7h5At/4wJObSR6wMADZi+M/UDvx+mW8sdlvN0AgA0TPo+pdP3TWux1ZaQj5O5TADQAOnbIcTW4tVXbwqp8ZvGAIALPPb1e5PLBAANkb6/0qF787BhwxZbC69xmQCgQZ44u8bY4lmjl0I/PPR2AZcJAPi/LQDgyk3fWRf5UeD24TXXdO9Un/2GxJ+PszdtcvHaee5ViL6m1qp1Kf7F0Man3bHN1edW2Sqj8AylsXV+yewadZoW16xXvSpz2stVxwaelvbXzUhCAF+X9I0zlI1Pz61VMD5XvUQZUSmGdqf9lltmGD3iQs+tUoviz/1jltSzPkfOaesu9Q7/ahes48ZziL7IOr4lDJlaHp/asx4bWvKX/0dV0If9eqWvarHu/q+UvnVertNsQPri65e+609T4Kavem08U6/Rb2VG14jJ/fMvePqeq4uVvl19QxM7LO9Xz/T9D6vwNUxft/u/UvqeC9IXX9P0VTMP0S26ZLQsi86OHXy29BViyij7p+VdE6LFmLj4ka2FGJaR3V59otq2UgNSI0w4B2rWaYFRJJqoQXPLMan9+4+zD319rK9fB7X7qOntIgPpa68V+SuzZ6oDqZmH4A3052vUwAyRlBrfxkqrk8OLWo2yZh682+KM4cnXqFM0ds8a2qVbyhp/PBbHx6k/aaybp+MpJT51k3Ar2ljtd03TJpEdOzonsg+RNlz953c5FSVu6zwzp7cbH9ZSbdxEBDXESv1o+91tuC61N3TOHNot1zdybvPy2HW6ne2sHyGudtthXdbgKoTNLM3Os38bMXg/e7V92OhtXeKnRvkbVhUdn3l9UPp2a+XLTHfbIRJzPaV5KkTXZeir6rRH91yf9uVGeZW7n7uh3VIhtmXHTnbS1zNIr+q7K8PXeIAI76ZW5eXp9LW7zCkQiSm6T/TXUzPR09ggIousFuvud+ulv1noyqT5VutrHNqlcYpVMqnIFxdZ63KJrTE9PPpCjbPyO2+o24G6k9UG7tk9zTN8rcJ0+jptr95RwCWcvh3V7MOUVgPS2yWfLX27er6p09e4Tojl5deWNU8VWRXdW+f2D6Svc6Di5jneTfbgp/O1hYXN9HF6NknuOqGb2r25KCkvc9PXXesb1npshZ2+QRvoFCjuKzrcubj1Vk/rtNjw1vk+nb7ppUneuYvssa9z1lAj8Ot8aRm5ZT0rkuzmWZ5Oaj3O09dfUT3w7D++69bh9omcQ7Rorj7fxW7rhGdK374T8u2xZ6AhulLrqqevXWpt6J45tGLy3H4ZeVFryr3OGD+/XZXTjsDY16lC29RmQ4q22TkatJ+z2h77xt46oFOe//DtUwYkdwxK34rIkpmZ/nZsXN9neeYau3vUVXXao3tu3MghYqN/dOts6LZ0smdTVqqbvsVpacXbROHYRVnR3URZRZUIU3mo0tfpMqcgbeX41osr7PTt97RotTJUtH/aarE99nXqpbiVsZJ6zVTVW/PEJFXyzUlVW30La16uaxeMKSxL1N9GOxcKryfd7UDdyWoD5+zCk7GwZcY2nb5O26t3FHBJzvvG6fRV2dp0QZr6QLS309ee6K2dvkq0107fCJUFanThbTJkbJH6Yz4+f/q6BxqZ28f50dM7fHGEc8riseoTaHRo2kOtSL3VTV9n7Vjrh3iPnb5BG+gUUP8vc+hUtdBt8vJSK4Z0+jZrMsnrzDy4Zw1NDbQv3ddXFe7SzfOblVQ9fa2YSdEncg8xr50Q09e7rROeeUI0n6nTL6ghVrgbzaqlr1Nqbeie2apNM+tSDe9qp2/L8kVuOwLp61TBGuatjrVzNGg/Z7Wdviq0rk51D+9VASzGBqWvWowwIoJ7snuRcLvHaY/uuetTEmt8LagN3ZYWP60a4KavujKT4uxJbp/Ktkhx7TN65sHpMqcgvYkaMhfb6Tu4SGRMjraGwP70tetlFbqVWV7qFSfH6HaG9Uizvw6ernm5iq7zV0/NrieX+jtQd7IzY2VVy7NVjZMzrPR12l69o4BLeeyrphPX6cCdcNaZBxG4T99G75Kct8s6lj993QM17ZLdcbL98ftmav9MO6litlr/z3Ki3r3LGDd9nbXugfTMQ2ADd2Zvlz7wdfltrBrq9BUzM/t3KtPp6541eI4x34qNtjcFZktDUzsbxqTq6ZvtP5F7CK8nKapzlds6fWq1h06/QEPqGvvapdaG7pmt2uimqINYadFn1jx/OwLpa1ehyv6W55/BdfZzV9vpq0aom9q5h88x1OTB1uCZB/XSI8ptx4DoWMNIFe5VddqjD1sVHevL87r7ORu6LY0ZZnW1k74q3xf6RNiuuB6GauH6CaJ3W52+Tpc5BfmZdp/o4e3wspVVHaOGewPpa9fLKnQrI2KTFw0vtHtLlSQXZxvGzJqXK3NroGlFotVMfwfq3dQGbrU8qk+SfFb6um2v3lHApZ2+zUpFPe66VUvfInuaeKz6LHjVeOb6FtZwKCxwoA6RPVpn2XfdysbH2GNfFUFD1Ni3evo6a9uqA4X5Tpu+19v3t5Y3UbExcpTzxNnC1Dydvu5Zg9M33ae2bL/Ln76JvuQS8cwkt6Ki1L3lZZ/IX/G8UWui/a2rlr6BhgTP+7rHs0vtsa995hpxEpZ6vfC3QwuuQsWiavfP3P2c1f67bip9ncN7K1TVwmvcdesR5bajd6umaetT/d3jtMe5x+edVO6/feps6La0WJ1ko5u+1qiynYhMadZhgGph4YIBFV3tsa/dZU5ButUnnZy7buXbcsXJbZ10z2bFB+oV/LUi2uY2bx8oKY8c4m1RK32LxvqbllORk53l70A3fd1qefKtKR0rfQNffMEdBVza6etN3eYVUc3OJX1vXdlUeNeJxAWJIlLN5V2dEeZtr34Adw50a5rYWFFV1WOuqEq2fta1530zqsT4bqJG+rprOyeK7hXV0jfKWOSPwLnlaqy5cEBa7HqxIV6nb+IiEdF4lBjUKlB9/cEc09GZ910shmQv9KfvhllesUkNnZyKijZjqqWv/wpsLE0Z5m+dm0nr4vq6DRkwKPDMg7dlP/d4Tqm1oXvmGnEyXse10w59iOAqzJy6ShTOq5W+zmrrsG76uodv316sylAX1rk/6WSZ247Gg4W3S6pI7NxURKp7fU579GHTc0TUSjX72tvuXHtDt6XdY6q8N7npG6dnVK9R3zCus76/tDg5UOj0dbrMKUh7RvVJfyd9e/vWix/6wnXPWt0fnL5uZVT1V84LlDRZJFo3qZW+62YNEGXOFMnU3pmBDnTT162WZ2paWhc97+u0vUZHAZd2+oqqFuV3Dhx2Lukr1rWpyGxs3cc2Blk31WdOj7M+C86B8vobndUJ8gwjfYJhxCbZO66J9fWuqpm+zlqRH2sMykwOTt/0jmGBZ4oSi+OfmZKlnnkwJrTapud91UME09XRPOqZB+es+oM5zhmUdp0Sb/2U6595aNVuSl7cJH9Ft/a3HjgI1MR/BUqHpwVa52RS35NGkyq7IemG8D/va8SNd4/nlFobumeuESc97GcenHZYgqvgHbtyeErbWunrrNaHddLXPXxVdEbc0BThXZAYnL5uO1aXDizKU6E6LC7mJmtruz36sOvVswhD1U8i9sPb7oZOS8W2Z+Kau+kb2mTB+DTRoc3JIp2+84zFzhNndpe5BYkpMamNnfQNVV8464x0u2fzrGceAunrr4xI9XgDNV7fcXrvxrXSV4yJMTzOw23rjfBAB7rp657dqaV1181ue82OAi7n3zQ+b89w3jkg+F/ha+reqvH6Mx2jU8srquM3dvtq+3nb9RX1e5LWb25FznmqdO4P+cSC9L100neTV6yZftatmhWKjdmr6O+GUDN9h7Y/Twce4Mvi6oL0vXTSd4LRubjrWbe6zujfZhPdfRHSt8qYGnV+jrvLE8nFBekLACB9AYD0BQCQvgBA+gIASF8AIH0BgPQFAJC+AED6AgBIXwAgfQEApC8AkL4AgNOmLwCgwan0lQCABkb6AgDpCwCkLwCA9AUA0hcAQPoCAOkLACB9AYD0BQCQvgBA+gIA6QsAIH0BgPQFAJC+AHDZpu/3fv7IS41qeOmRn3+PSwYAFy59v/voY43q9Nij3+WiAcAFSt/v/ajRaf2C4S8AXJj0/Xtd4fuTn95//09/ohZ+VK/R78Tb7Pdvf+ssG46+Rb8tXXamUgC4EtL3f2pn72//bBf9+beNGj1afetpCcqM+qXvjO9LWZKgX0pIXwCkbzXv1THyfS+48L3q6fud+o99v69Ses6frJePGPsCIH2re6R2+P4tUPo3NQlRV/pOvO+2D3bfLuXr+/dM26f+OWP/nt3b7fSdM23JjAK90c+WVMpnb3lLvXxbHvv1khfVBqOf/cAqXbps3/Hjaj95aueeN8KkPLF7yZNZOn0Lpn1R+cK0hCUn6C0Al3f6/qJ2+v44UPpjdeOtzvRNOCFf3y3l3tdn791zTE7c8UXBF28dtdL39uMPFbzwa71R5Wfb5bSlH6iXL8OW7SvYu6xAjt7zjT77n5RLdzxbsnfJKjln2YmS+34gs5ZMLDiyM0ylb8lH++T2nccqS7LoLQCXd/r+pXb63h8ovb9Ro7/Unve9V05U+VqZcKM93XBKTpym3j+aY6XvaDXP22vZPbrkyW8VvCWPfKsgYcREa6r4B1+qsa+UqxL6LE34pZQfvK5nhrMSwqwpisqdD8nRR3bulXL7std70VcALvf0fels6ftSnWNfa6J3Rx95YsZbOoz3q3/uP2Wl74tWPCfYEwcv7N97m3xo/97j8ohe+4UcfUqt3nNs6Vvq7b45crcKW5mw9Miz1j/3ydE7X1SpLO/dvcOZuwCAyzZ9/3q2mYe/nil9j++7p9e3VfqqSQi5W4999+8LbHxiyeO3yNlLHn9DnnrDXjP6iJRH1dh3mZ2+M9Q88T322FdaY99b3rhPj6eP/foIvQXg8k7fR2un7yMy+J7co2dK32VZsmCZSt8dJ+SJtwqs9H39T0tlr4fsjcN2qDlhOW3PPllyXK06VqJGt33kC09KN33nfDRbPm7N+x6Te3f+UqVv5f4ZlUuXyhtvu5feAnB5p+8/HjvD4Pen6reN/1F73ne3P32/c/zJN1RSTvzB6AT3mYeHXvxst/MAmvxAPfUgn01Yqp4xm7HkT/dlydH3Ttsxo48/ffUzD7PV0xHqmYel+pmHyhn7t3+UkPDkbHoLwGX+2xb/Wzt93V9w+7v6bYv/47IBwIVI3++e8TeNf1HJZQOAC/JXdt47/R/ZafQYf2UHAPgLkwDAX1cHAPA/CwEA6QsAIH0BgPQFANIXAED6AgDpCwAgfQGA9AUAkL4AQPoCAEhfACB9AYD0JX0BgPQFANIXANCg6fsNAMB5xtgXAJh5AADSFwBA+gIA6QsAIH0BgPQFAJC+AED6AgBIXwAgfQEApC8AkL4AQPoCAEhfACB9AQCkLwCQvgAA0hcASF8AAOkLAKQvAJC+AADSFwBIXwAA6QsAl2n6FoTHGA0uJnwV3QHgik7fgumvjGj4mowYN534BXBFp2/4KxenLuHj6A8AV3L6xoy4OHUZEUN/ALiS09e4WJUx6A8ApC/pCwCkLwCQvqQvAJC+AED6kr4AcOHT92SyfgszbjzNBoOj7XfPorpKe0eSvgBI3/qG4I3Dp9advndY69vpl3zSFwDOQ/rmrw8sjynvUVBn+iYt6CULOmarF6OA9AWA85C+d1wXWJ4yNmWNepuXkd3cSt+22bFj7PStrNgg81sMVC8r5dHe2bEqsQePLFqQuVClb88YX16llOltOk+IkrLP1PiYeTp9C2NeIX0BkL71SN8+RlRkhpRRFT0Lx1ckyzGeZiUDnXnfLmvk0MnN1UuuLB5atjAjXQ7uMTZirG+29BQnbm53tYzqPDhiZukvKzNaHc2v2KzStyxjMmNfAKRv3SE4xf4DkCn2v15JkbN7bJZ3dFODXV+ynHqNlAud9G1bJONGzFMvh+9ZoAa6i3Pl4Di1OmOY9KhBcvNtema4V+m8hT5V2mKU7D2odB0zDwBI33qNfWMXSzlykBz0Q7Uclywz/yXlUSd904cfzZZhvqNGyTyd113k4CK1uluo9CRKOW68HJRnhXn3a61MHtdP9p7V5kbSFwDpW5/0TdK56qm8Q91P62WNfdWdsw1O+t7Yv61a26Ztudxcam89OFO9ZObru24qfe+wwjhWjX17SZmrxr6RLbpUkr4ASN96pO/4blbM+ibN7XyPnGwky8OZYb36uc/7DvSFSrnL1172GjhWPfqwQQ7uny7TsyPc9C2JXyTXlYrKuO6yJDtRpW+vblMrSV8ApO9Z07dy+DzrLS9aTorL7BdjPfOwMq6tm77Njc1SDjO6S5mWW37n9ElycOPeRuYG6aav3JjZefpcdeeuON7aVT3zUDmyWyXpC4D05TeNAYD0BQDSl/QFANIXAEhf0hcASF8AIH1JXwAgfQHgUk/fmBEXpy4jYugPAFdy+oa/cnHqEj6O/gBwJadvwfTwizD6HRE+fRX9AeBKTl9Z8EqM0eBixhG+AK7w9AUAkL4AQPoCAEhfACB9AQCkLwCQvgAA0hcASF8AIH0BAKQvAFz+6Tu/kssAAA2rcr6QUWFcBwBoWGFRQkaUcR0AoGGVzRZS5vCnHQGgQeXkSGG9tQ5j7hcAGkhlWFmO1OkrZ0fNvwoA0CDmR/WVTvoCABrYvwGS9Cg06CFcowAAAABJRU5ErkJggg==) ### Enable Webhooks[​](#enable-webhooks "Direct link to Enable Webhooks") Toggle the **Enable Webhooks** switch at the top of the Webhooks page to activate the feature. Each individual webhook also has its own enable/disable toggle, so you can disable specific hooks without deleting them. *** ### Adding a Webhook[​](#adding-a-webhook "Direct link to Adding a Webhook") Click **Add Webhook** to create a new entry. Each webhook is configured with the following fields: #### Endpoint URL[​](#endpoint-url "Direct link to Endpoint URL") The full URL that will receive the HTTP request when the event fires. ``` https://example.com/webhook ``` #### HTTP Method[​](#http-method "Direct link to HTTP Method") The HTTP verb to use when calling the endpoint. Supported methods: `GET`, `POST`, `PUT`, `PATCH`, `DELETE`. Default: `POST` #### Trigger Events[​](#trigger-events "Direct link to Trigger Events") Select one or more events that will fire this webhook. Each event corresponds to a specific plugin action: | Event | Trigger | | ------------------------ | ------------------------------------------ | | `login` | User successfully auto-logged in via JWT | | `register` | New WordPress user successfully registered | | `auth` | User authenticated and received a JWT | | `delete_user` | WordPress user account deleted via the API | | `reset_password_request` | Password reset code requested | | `reset_password` | Password successfully changed | *** ### Custom Headers[​](#custom-headers "Direct link to Custom Headers") Add any number of custom HTTP headers to the webhook request. This is useful for passing authentication tokens or content-type hints to the receiving service. Example: ``` X-Secret-Token : my-shared-secret Content-Type : application/json ``` *** ### Custom Payload[​](#custom-payload "Direct link to Custom Payload") By default, the plugin sends a standard JSON payload. To override it, enter a JSON template in the **Custom Payload** textarea. Use the following template variables - they are replaced at delivery time with real values: | Variable | Description | | ---------------- | -------------------------------------------------------- | | `{{user_id}}` | WordPress user ID of the user involved in the event | | `{{user_email}}` | Email address of the user | | `{{event}}` | The event name that triggered the webhook (e.g. `login`) | Example custom payload: ``` { "user_id": "{{user_id}}", "email": "{{user_email}}", "event": "{{event}}", "source": "my-wordpress-site" } ``` Leave the field blank to use the default payload. *** ## Webhook Logs[​](#webhook-logs "Direct link to Webhook Logs") ![Webhook Call Log](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAABX0AAAGQCAMAAADFpDO9AAADAFBMVEX4+fodIye1tbWzs7OUlJSqqqoAoyr////i5OfHyMn9/v35+fn09PX+/v729ve8vLzl5eXBwcEhJSn6+vrQ0NDNzc24uLjt7e3Hx8fO0dTq6uqkqq/S0tKtra3KzdD8/Pzh4eGrq6vJycn19fbi4uPCwsKurq7n5+e+vr74+PlVVVXv7++6urq5ubmxsbG/v7+3t7evr6/e3t7U1NSsrKz39/fr6+vc3Nzw8fOmrLGGjZTa2tqwsLDDw8Pw8PDb29vz8/OprrODi5G2traSmZ/j4+RwcHCXnaPx8fGBiY/W1tbMz9Lt7u/Y2NhKTlHy8vPf39/Ozs81Oj0wNDj3+Pnn6Onh4+Xq6+y9vb4pLjKOlZvLy8vKysv7+/uAiI/DxsnExMTk5ujv8PF6gonV1dZ4gIdsb3JBRkmMk5mNjY1bW1vZ2dne4OFhYWFFSUyKioqrsLTFxcXm5+moq6yqra9wc3Z/ho17g4o2PD+0uLx0fYStsreEhomho6ZmZmbb3d87QUSepKrr7O6EhIRiZWegpauKkZfy9PVdYGO4vL+PlpzV19no6usqLzMtMDRHS06Vm6FXV1ekqa6boqfFycyZnJ0+QkakpKSwtbmRl53k5OSFjJMzNztzc3Pm5uZWW16lpqiHj5bR1Nbj5eZveIDX19dqa2wmKy95gomSlpgeHh7Z2910dXaorbJTV1rf4eOMkJKWnaKgoaNeXl7T1tiOkJE5PkGdnp9sdX3Hy84lKS2do6iprK/Bxch+fn53e31vcXTX2dyIio16enpNUVSWmJi6vsJ2eXuip62Hh4fl5uaaoKYbrUCampqAg4a+wcS/w8a0t7h+gYR7foJaX2KAgIBmaWv5+vrO0dNxeoKQk5WvsbJTwW/5/frR79kEpC1exXiLjY9fY2ahoaGAiI6RkZHV2NqoqKh2zoyxs7QuLi5QU1YiJyslsEnD6s245cOK1Z2u4rvo9+vl9ukytVN9hYx7z5E1NTVERES55sQPqDbZ8t/0+/VHvGVOTk5myH/8YE1SAAAACXBIWXMAAAsTAAALEwEAmpwYAAAgAElEQVR42u3dCXhU5b348ZmMx1+ZMElIQoCYELKHkMwkkEwia0oIBExIAgKBECWA7CD5WxcEQcQFUVDUglI2UUARt1Klta0LuNRapVVrXbqrta3e3vbeLnd//u97lpkJCYg2SW34fp6nZOacOSdnTtKvb945mbgEAND9XPqf3jNavgQA6BYtMzLt+taUuwAA3aZ8rlnfmkxOBQB0p5vmqvpmMvIFgO4e/Wa6ZMZgzgMAdK/BM1zSwmkAgO7W4pIvcRYAoLt9ifoCAPUFAOoLAKC+AEB9AQDUFwCoLwCA+gIA9QUAnFl95z+7c8vGazhFANCt9b354Eu1LXu3Pcs5AoDuq+99rz95zOUqdLVMfe9Md3WL273MujXF/Z1TPeg0q7Rr3AtdrqvcX+ELA+Asre9N8fG/ci173eV6bE+7de/qRK5zux90uX7lnvz31LfusclTp755zanqO9l9OV8hAGfZzMPByftcP/rY5Xr7YLtVF7vd0113uN2/drn2uF//O+pbPtnt3vnxU5upLwDq6ziq/tzQpNu+7tq3uf24eKZK6GH3ii0Xzv3E/SPXsgVPbn7khFnfo5NnvrlOJ/axNzdPVosuvOb5mddePj3ihq7va+4p+8wdve52q3mNm37kqlkY757y6xOnqm9o6/Jnpm47dpsedANAD61vy/WlKnvfKftq+5kH15vul1zbVhxzz250u29dNtX91us73Xfp+k555lr3kzUqsU89uc298ybXGvfmZya7n/x/4RtXub/zkvvaddZ+droXWDdmbH5rzZvup9ador6hrS93z3xm4VPUF0APru9N217QH/Zv+ZGro4nfde43TrgfPKamfY+5H3G5HnRfr+t7wnXdU2o0PMX9VuYyt3tAndv9O1fMVe6vhm6oVQvdK7Ks3VzndjqaWaP+2ea+puP6hrYud7tXuuZupr4AevIVZwMPPjO75rKdazpYpSZ+H3S/V/fJ9Y+oad/L3aZrdX0f0uk8qhK711Xjdl88wu0e6HI94n4jdEOtcqsGu5xJ4DesG+WvPbJZrXis4/qGtn7I7f6Wy7WQ+gLo0b9tsW9j/FMf7+1wXDzTPdU9zbVni572fcx9W3Z29on3dH1/5Lov3hz7fsesrxq0Xua6aao59rVuqLK+PlPddtnzvgd/Z877HnMvvCN726nqG9q6XN+YwcwDgLP2N43fdLtvUxejqeHqra5Hp7qffeyxR17S9b3qmYXua+eG6tvhvO9Xsj9x8lu+Ql3zsGfqZvU63IqbD3c09p2yZ8+etyLnfTe/sfEg9QVwttb3XbeeM8h2m1f7Lrt828Hn93zFHPtue+rNEa5wfS/c+/xB65oH54Yu6+/infzq633de65xtTzvnvn65A7qq+0Mbz33makzr1kYnroAAN5lpztcpy6DW/aJu5GvGwDq250Kn1zz2Ar3npv4ugGgvt3pG5PdM297rJwvGwDqCwCgvgBAfQEA1BcAqC8AUF/qCwDUFwCoLwCA+gIA9QUAUF8AoL4AAOoLANQXAEB9AYD6AsBZWl8AQLdT9RUAQDejvgBAfQGA+gIAqC8AUF8AAPUFAOoLAKC+AEB9AQDUFwCoLwBQXwAA9QUA6gsAoL4A0GPr+/M//vQH557kBz/94885ZQDQdfX92W9/cW6HfvHXn3HSAKCL6vvzfzn3lP7M8BcAuqa+/9NRfH/5p3//9z/9Ut34lzMa/RZdan08p/hTHrg4yvxQtfx0awHgbKjvb9u39wf/aa36TzUZ/Nu2jx6fr2w4s/puSBXpl2/+0++z1nd8gC8XgB5d3z90MPL9Q+TKP7Stb+DMx74lqtLZB8x/hPoCoL5t/LSDaYfw2l+2uReuYtGPLz2+q1ak4eUj4wvV3Q0vH9m11KrvqPFLNlSbD5q/xCsvVB5R/5wjZceXHB6h+vrCcb22annB2rUF6iH+t458WCqSsmvJ07vN+laPT4/4PAkvLF9rqI/9DyzffrivjDq+dWsOX0YAPaK+f25f338Nr/1X9cJbh/XNT5SGXSJzGjJbj9RL0daP6j46UqHru39tU/VHx80HpS0ZI+Pjjqt/8kqXF1a3Lq+WxUcyhrz8tFRtfTXYumS09FmeEnz6UsldUlT3/tpSVd/ggcLIz/PC4d21az1SdSSjumRrX1nSFB09hi8jgB5R3/9qX99/C6/9t3PP/a/2877vS5Hqqze/2Vz0oV+KxutVo3R9F6vBqW95srnm6ZF1y+X9kXX505L0VPGljbL4VZHR+UOq8qNFjjeYM8O780tT1Vrv2tmy+Oja1sjK+5ao4XXBYSn5UN1Z3te3pDCBLyKAHlLfH3xafX/Q4dhXT/RurZGUDcvz87dL0cvq7sseXd/DOs/5KeajPnq59VKZ/XLrWjlqLv1IFvvV4iNDzXnfH2fLLh3b/B1HX9V3C2Xx2sPRkZ+nIl9NYcxXWx/VS/rKnONbdzH2BdAz6vu/nzbz8L+nq+/agmTfOaq+ahJCdmXr+r5cEH5w4pJXoyRzyasfiv9Da8nio7qpNU59N6h54mRr7CtvqbFv1IdPN0eOfbeq1jYelnT12bxH+qolo1/dxZcRQI+obwcXnP1UIl+T++3p6rs8V6qXq/puTZGU5XW6vg0HqsTXZD24dKuaE5bxRwqk31q1qD6oRrc18tHT4tS3z/hMeVXP+9ZL69poVV/vyxvSIud9F/tKj6t53yU7JHZr3xg1oh55nC8jgB5R3//+xWkGv39Sv2383+3nfXeF6htY+/QTl6r6Xro4f9cI65qHpsNLdtkXoMlxddWDvJpfJRK3YcmBH++WxdvHb90wJFRf8bx15IlMNbugrnmIM695SNvwsjf0eT5MeHX52nSfvuYh//1dKTFP5+e/VcaXEUDP+G2Lv7avr/MLbv+jJoX/+EU5+OVBvoAAelJ9f3ba3zT+s/eLcODzfeJ5mq8fgJ71Ljt/OPWb7Jz7iy/Gu+w8nb9kA0NfAD3uHSb/eqp3mPwt7zAJALy7OgDwl4UAANQXAKgvAID6AgD1BQDqCwCgvgBAfQEA1BcAqC8AgPoCAPUFAFBfAKC+AADqCwDUFwDO5vr2AgB0Msa+AMDMAwBQXwAA9QUA6gsAoL4AQH0BANQXAKgvAID6AgD1BQBQXwCgvgBAfQEA1BcAqC8AgPr+86jYfg4+r+11fAOB+uJz2j6Uc/C5Dd3OOQD1xed0DqeAswdQX/rB2QOoL/0AZw/UF/Tjn+vsee//tE33tVgfvzyww9WZE80Pt09vv9V5A061P2vNgPM+y1N4dMLneuYt+063pu2TUs/l5GMKPa/h5dbH6B92eFDeb94gkvbOneE9nuJ8Rap4/J3z+d6kvtSX+p7C+RdYH2fUfZb66q06rm94TcWt3VDfC84/3Zq2T+pM6lsxtuP6Xv1Bmrw99s7wHmd8+nUmFQNepL7Ul/qe3fUd8vi9m1pkxqwbz59nLh04fPhKr1y0etG4ufc9MHHWjPNuuGeVGss9Omv443UyYNxYs0Bp5w+/cYAuVsL64bcvmu5stPIelVZrqzs2XbROZnzwtUXTpHzitxd9zytt1qjSOfsqn3jnxDsfmnXRdBlwydj1pTLw8XE3npC7XxS5+4Re/5uvLTp/gr1OfSpZdJ+zpSwa+7V9avtXNg2xDkC5e97EVSJ3PidyiYx9YNYF1pGqff7lxRM3bsq096PXqCdV8e3hV++z9mLWd/CVaaL/J22fl6qveePhd2bdbS+yDsqp78p98soqc+xrnjd947w77nnguRvGnq+PQ5ZNiLjvuJj6Ul/qe3bX985VctcimfCinLjaHLaNrfCdd7FcdJfcstIaq37bp2rinfioDFwvV0TLXP2o797jvfXqTFWsH97ue/Sb052Nfhge4X7PO224ZJbLc5uk/P5psnpA2zWqvs6+yu+/1bvoDu9D4+S6BN+qVTLwa6qyva+bKL4rY/RRPrDMN2GCve6uh+W6e0NbyjSZ+0F0+TdbnKM2F/3k9ofs+uoRrnWkap83XXKxrLrZ3o9eoxJ5w8NSWm7txRr73vC2fHel3k2b5zW83Lqhx77WLfugnPo+uv4nYwdY9TXPm67v93y/ubrFe88yp76h++e/SH2pL/Wlvsq83uK7Ou2BC+UnZn3vunLWrLF3yEUV0jLOquVAHarr3pk1a9FFcsP3bh6iH7X+bfWD+XOqWOvVBOqN052NysP1VVtdKc0nJsy6RMpVtH54c9s1unT2vsrV/MWXL5bmv8jcVePufUUGqiq9skw2PfqNV8z/HNwrcssEe13CvLTVPwxtKQNumHXJfXp7+wD0fMDKTR+ciKivdaQD1aTC8Blyyw32fuz6XnlTaC9WfR96XG6cZj7ByOc1vNy6oetr3bIPyqmvTPzWKru+5nnT9R0oMVeKrL7LqW/o/q011PcfW9/Lrj/DB2bNbHO3d/xg68aD77a9f7LJI6gvzqi+F4pc7X0gTUdE1/dhc91FmTLtntA8raqvPeV5380f/MSO0wSzvt9QP/9PD28kEbO78+TFh2t870j511R9V7Vdo+dY7X3p1Su/Jd558vhdmevGycAvqwH5Ohn48Cu3mPW9UeS5CfY6ueMCPSC2t3x00TQ1mNTb2wegpkSuWJagRrjrw/U1j1Tv894h8pv19n6c+paG9mLP+16x7kZzP22el6rvw868r3XLPqhQfVdfMsOur3nedH0HyIVXqImQi2WeT9ZNiLjPzEOX1XdFfPy1r8WE7j771XaPqNc9nf9eR3vsFx//yW1tfzVp9IMd1jdmSs3p6/uVBdQXZzTz8KIMVDMP++QWs77XXdIiFS12RVZ/16mv76KBkrZM1Hf2RP162Xcf9956iTnzsFJuun96eCPN2Wqe3PG2fOP+iPqG16jSOfsK1/ei3rI6VN+EK/7iM4/yygpZPcFeJ8seWC+hLQc+LBXvmPW1D0Bk7ljx3XizjtxzV8s3vu0cabi+1n70Gj3zsFqk1NqLXd+bH7Dy2OZ5DS+3biQ84Hwm+6CG3GrXd8aLcsr6Lpohd0fWt83Y9z5+D7wz65vja1342qfWt2P94r8fXfJU0mk+p1Pba56V09d38JZp1Benr+83lbvtV90mbFp9kfXT/I3D5z1kV6RlwqYZVn3lvnH3XnJC5l15580nveo27vaJ08Mbac5W8+S+KzatnhdR3/AaVTpnX+H6fuuK21eG6it3rLIO8zfjxo2bYK8T+UCNap0tS+9dtH6TWV/7AJTvDX98/c3q5b5Nd18i0a+Mc151C9XX2o9eo55U3Z3D37nA2otd3/L7rf9DtXle6lU368bd4+62b1kH9eJ5dn31EZyqvhdccfvDkfW15n3Nkz9dJgzkG7Qz6yvywsdqcPvIzOcT5evx8fEH7Nuy4KU3J/86WaaqZbV65iF348zbGkOL7fqKbDwmv1sx8/oaKZu6Zs8CPfNgP1CemHptiV3bjZeF7/d5a8tteyVhy371+vXBYM3hKfFTeotcfw31xRmfPTX9sO/OL9Rh+xbVdLC07l5fl37WfefxDfNPXd/SjS9J5s69NZU7a8yxr3N7wZRcOfaaNfZV9U1Y+FK/9w4OcxY79f3+zt81TWns98QjUhb/rjnv6zywZMrsQY/Y9b1qtoTuR/WpqNwySd44JvL16+WF67PkbfWg197osf2IXfL7J3+sLwuqXvv7v+0azHdiJ9R33f3Dx9V8kY562vCVHSwdeMXbXfpZV/+lhm+Yf+p53/iPp8neX6vbB0rM+jq3F/xKpPWRUH0btqgXDi5f4yy2533j4xf4Fryq/ss/taosPtqsr/PAjUdFGuz6qtq2uX/4qPR90icfvydf/dh6Q7AnLu+p/eh76HCwdcqP1a38rVUjbjvAdyI/OYD6mmPftAY1MF2jO6rGrrq+zu0FXxeZvTBU36QV6uO7C5zFoZkHkefNDTLKpopZX+eBkwv0I6zaXtskofv9f60mM1TCr80YtHmw9F5w7ZbX1E9na17rqf249G8JauAfH5SmQ2qypc+hQXwrUl9QX2ved+/z8lV75Hm5qq9z+6T6NmxRv5tzeE0H9b3+MvOeU1/ngRvVA9+266sf4tyf8lGV7yVV33efeeKwXuedMyUptJOeWN//UP8UHJoj7/9N3Rh8qJJvReoL6mvVN3pqYNoU9TLZpDhZo2Zfndt2Zis+mWbN+67YK1lT53dQ31HbysTXGKqv88DLbuvtW2DX96i65sG5P3WQ1ExV9a2auq1VzUWMluRtAYneUtVT+9FwaK9U5B9KtTIsvz/KtyL1BfW16itP7JGhG2du21gvZTvVNQ/2bSezr9nXPHxfXcoQkA7qK42TD04+EKqv80B5YtuKJ+z6BrcMCd0vvmrPswdUfWXPTjXj8BU1DfG6SM6entuPqP879PtLD3mc+r7PtyL1BfXtPsfebb/spWPh25NTenI/ygYPO5TizDwU8q1IfUF9/6F2bKk/e/ox/slmKTukrvwIxHONEPUF9f2HWjNl71nSjydakw6oaV+RJfk7RvzHeL4TqS+oL7qlH2sPPfV/5oUOo9VvW4yP4fxQX1Bf0A/OHkB96Qc4e6C+oB+cPYD60g/OHkB9QT84ewD1pR+cPYD6gn5w9gDqSz84ewD1pR/g7IH6gn5w9gDqSz/A2QP1Bf3g7AHUl35w9gDqC/rB2QOo7xff9qGcg89t6HbOAagvPqe67efg89pezTcQqC8AgPoCAPUFAFBfAKC+AADqCwDUFwCoLwCA+gIA9QUAUF8AoL4AAOoLANQXAEB9AYD6AgCoLwBQXwCgvgAA6gsA1BcAQH0BgPoCAKgvAFBfAAD1BQDqCwDUFwBAfQGA+gIAqC8AUF8AAPUFAOoLAKC+AEB9AYD6Ul8AoL4AQH0BANQXAKgvAID6AgD1BQBQXwCgvgAA6gsA1BcAqC8AgPoCAPUFAFBfAKC+AADqCwDUFwBAfQGA+gIA9aW+AEB9AYD6AgCoLwBQXwAA9QUA6gsAoL4AQH0BANQXAKgvAFBfAAD1BQDqC3yR9M5KDBQbOUWBjEmZnA1QX6BbeOsLjAiNYxI4J6C+QFeLnu83TpIzhtMC6gt0reBIowN5zD+A+gJdaWgouEX9E5sCHudeKsNfUF+g6zTYsc1ITrMWJAwdlWotGsbZAfUFukiKNc2bUhq5MLrVym8u5wfUF+gSQbOynjrnrs++UWXOBRcz9wvqC3SyEZOa1SyDebFDbLSzsLbGuVVh5reA8wTqC3SuMcbI/ZJtjnzTQgtby0I3+5mTv0M5UaC+QKcapNpqXWoWDC+snB2+vdu8DIITBeoLdKrdzpVlieFlaW2mGvrqtVWcKVBfQDr99TYlObws2TAiHhHDzC+oL9DpKkK/ZBGb5VzpMKnNNITM1mt7c6pAfYFOFB3xW8VJ9kUP6jLfEdJmKGwYWZwqUF+gM4XjO8f5VQv1W8YZEjkNrDRwpkB9gc5UbLfXHxc5HE6KfEiRfrcdzhSoL9CZrLfTSe/bLG0ug/BGPKSX/iVkzhSoL9CZzPdTL+wXsWT+yfO8w/QCzhSoL9CZAupNJPf75OTYpia3ff8zxr6gvkCnmmMETrqaLMZ814ecYJuZBw9nCtQX6EyJ9e0WecdE6Xc2G+3cz+bXLUB9ge6RpaaDR1Zbt336fSACnBNQX6DT1TQ2n7xoWsDwV5i3qk56GwiA+gKdIq0h3VjafvGQVk9vZ+LBqOM0gfoC0vmX/CZ1tKJ3rfrd40zeZQfUF+gS5p9vqz/V2li9tpazBOoLdLYh5hVmMR2vnGT+LlwpZwnUF+h0fcx3mGzuaFWNGd/5nCNQX6Dz1eWcKr/9+KuaoL5A18kyR7iV/dotLzEnJXhrdVBfoGskWm8zmdJm4egMayl/0RjUF+gqKVZoPSmZ9oLorDz7nX+XcnZAfYEuUxv6+26jMhITsz3O3ZHJnBtQX6ALBZOMDhTGcGZAfYGuVeY5ub1F9ZwVUF+g6yVnFEe0N3YHZwTUF+gmcfNbC9Wrb9kpO/j9NlBfAAD1BQDqCwCgvgBAfQGA+gIAqC8AUF8AAPUFAOoLAKC+AEB9AQDUFwCoLwBQX+oLANQXAKgvAID6AgD1BQBQXwCgvgAA6gsA1BcAQH0BgPoCAPUFAFBf9CSjjID+UGaMPsMNEowRzs3COWf2OC2vz+c8wLJ6vkigvuiR9TWCX+j6xmbzRQL1RU+sr8cTS30B6ovur2+Zsdupb1lliWe2117TJ0/9U5yeJtJaqG7tLkgdOSrarOrSgtRAjFnf5D6phUGJ3NLb5CmprHXqG13gqYiob2m2P7UgWd+tKsrJTtbLfJOSSqIyhlgPKjITnWxUiVQE1ENrRJIMpZWvE6gvel59fZUFdn1HGBlZKTnOIHV/iVdqjHSVZn+DyCAjUD/CU+RTVfUEBtV6PCq1hZ6opUOjitMit2xNTamabUyy6ltaWVQaMfZN83iWDgqkB3Vg+wyqjfKrZYk58+NylyZbDxpj6Ki3+n1SkRO1tL4xtbcEi2Jzc0fzdQL1Rc+rr9Srsaaub9rIJrUgzrBT2M/Ilf1RsQ0y2ogTr1+/OFeRXq+qWmjeGqPqWzxY1Nr6iC2DRpa61ZCToOvb2xObEDnzMKlEx7VAjanzVPCl2lDLYiPHtWk5iSrbJSkic0aqLX1Rs5l5APVFz62vJCWZ9Q2q3Crpifaq4kTJnp1SIEvTE+yqSkGGqqq5PklVs9C8XCInJWLL+YbXnDvIlWajyd8nTSLrG9AzzDIs3SfpKfpWlFrWlNoQDB9Nkxr2TtID4FSdc2mIor6gvujB9d1h1Ov6DjJq9BJ/f3tVdqyk1icbCaPUQDXLsOSp+taaNW10XnVT8xLhLZuK9Y06o0zPUBjBtq+6FWVb0wsVg61X5GLNeV+/kbQ/2n5UnTFIPKPUfLH96dKpL6gvenB9paBS1zdZzTCol83SG+xVS9OTjWhvSZUaA6sJ4NpcrZ+qqrk+qjWivuEthxl6uJur7jcbI3rlBNuOffV8gySqh4THvkp0vTlxYQoEcs195fQyP10u9QX1RU+ub66Rp+obXdJL3a5Xw0/LECNPTfEG8vS0gtfTGrqSTG8x2hgTUd/wlnHGUD2BkB6j66teggtG1rfB6K1uVRZFzvtazY11HpZlxOrdS2tlWqjHfJFAfdFT6yuxhr7moTZ9ae4Of15oXbHRV71UZuiLziQuvXFEbllAzyiMbMrNTTKveXDqG7Fl9siq3BF6aKuvefC1piZH1DfBU5Cb25Q+TU8MN6h9jFTD2tgmdclD+jDnU/r8xnz9MabYMz8uq7961a2heIe+5sHI4GsF6oueV9+gEbret8kbWjfH2KEvfWg07wRjRxpRDRWqqpNGGc71vk59w1t6+6rrfZc61/v6RpUkd3i9746i9JzaJDXh0DfWnxo7Jnw8TenWNWoxczxGcS/12OgMv77el/qC+gKdJCZ9RLtlPg+/WQHqC3SZBDXxEBc7svmkxdG5TcYQzg6oL9BV0gKG4R9Vd/LiZKOojJMD6gsA1BcAQH0BgPoCAKgvAFBfAAD1BQDqCwCgvgBAfQGA+gIAqC8AUF8AAPUFAOoLAKC+AEB9cVYoGCNxfvWXKD/vn+eJNv/qcOfL8px+/6f5vH/X8+lIjFHadkFUPd84oL5ob1jSZ3jwmCD1pb6gvuj++v69taK+oL7UF23r60vxpAYq1F9sbyr271e9GD1npJHTzypXjOQa6u+hpQZPnnkYGkj1NKi/8540u7GgMKj+XHuf7Ngo/ZfTkgtKKlVzMpsqUwNBHcemvEJrX/VFqdnqr8WnNXlyRg3WW+Yl1cvSopKCftLmOJqyRzVWmruKTdV/7d3eo9ak7saqo5gfCC1Wn8BfrP7ifGj/o/NSPZMk9FHXty4qxdre2qNzbPbzaW6qNJy/gZxSUFI4VG+U0uiJ6T0qx9/gsxuuFziHntbXY/iDEt2/2J/RbD+T0uzUonpdX/sZeftaZxOgvjhVfVP8uaW9/AnSEBvMbEivlzn9K6TOGjAWlkliZask5/hOru/S3IS4qKWqPJ4Y2ZEaI01GslSMjJPqkrLBu/3qY21F7wa/V7KMFGcM2ic4unG2SP9AMLOpQG+ZKVLmiRtcVhzT5jiajFypyMmUYHrKYJkW2qNW5ZHmHE+1BPaHFmelZ2cmexpC+x9c3FQaN3JS6KOqb3CkHUFnj/ax2c9nadEQX7T9X4DEftFlJTVqo0CaeKOaKmryGuyjVwtCh56dlOzLrJbG2OohhX3sZ1KQVxFMUvV1nlGiJzkzO536gvri1PX1q3GmVwVKF86XWi+tgdBfBG7oLwVZOZKS3eGrbpN0eYbpSI+QpoB++Bxp6qV3PMp6QE5QsnJ8Tn3VaLM+SUoNlSpvao0kzVdLi9RAUwK1bY6jSe1WkrKkv7WXyD02G73jAhlLvSqQzuKs9AQ1EveH9j9Gz0Tsjwp9jDZqRybbB2zv0Tk2+/mM8CS3OS19Jtk703tIzgkfvXPoFdbfpq821Hnqp3480M+kWn2UOFVf5xn5VXibqS+oL05TX0PHp2C+TwdGPPXSO+BJbU0wV+32N6d6K2sal7arb32g2DD0CHaM7lWiNOnlk2Ilz9CSJDojKd0w4kLTstb8q9pDsvkAo0qSdKasO30jj8Pqqvp0jdao2dmjWFdeNMyvz84dGV6c5deDWiO0/5Q8dT+uJPQx2vCE/oNh79E5Nvv5pPVKSo8dHZp5MIwGa2cp1sElhI7eOfRphvlY80OaOmv6mUxLVXcqVH2dZ+ScTYD64nRjX58e+6pUpJmjNV9yVKK5Ki19frY0DUuvPrm+MUZWha9W11f/ZO5RY189uZsxR/r3tWdoA/0SJKeD+lZYOROrvp6q8OE4x+HUt7/1qZw9WjMDrUnB6NTE1vDirHQ181rvD+3fHPPWRoU+RhtDkpz82nt0ji38fEZnF5hrBvmTYyTbrm9Zob/cIRgAAALsSURBVLR97c459Aqj2hr7qmVD9Nh3qL6jpnx3q3+cZxQ+mwD1Rcf1TSxMkBHmvG+zpKhexDXL4AJ7tjavuFaqiv3trvfNVCFKS9L1LR40uCFHzfump0QPLYmToJr7lcygZKgq13c09pXsUdHi2+G16ltbpELWr6LNcTj1DZaowfC00B5NycVq2FtYrDrtLM5KT5TmgobQ/kuL62Vw5aTQx2gjM6Fgjtfc2t6jc2z280nOVC845lkjehXcuhJ7ZwmeYT5pjou4csI59D6j0kTN+8ZmiK81YP93pKBJvAFVX+cZJRakqdFzvUQ3VPCdBuqLk+pr/pBcG77mISd9kidOElMNIzvN/klcTXE2G73a/7bFMH/jHPO1s/lJhnnNQ/85hkfPQgQbc/yxWdI7qiDQ4O+ovt5ET2phtl1fGZpUUpk3uu01D/an01c16Gse7D2avCVz1DGYKbQXZ3kmpVvXPNj77+Cah4SCgJVfa4/OsdnPZ5DfMIqqrUPoU5nXq49dXylt9ecUJEbU1zl0de2Dec1Da7G/V4Jd39LsyqgUPQC2n5G3r6dotpp5yDSS+U4D9cWn8pZUf7YNrIbayQRAffHZlapX8htihfoC1Bfdqi7dyBkVQ30B6gsA1BcAQH0BgPoCAKgvAFBfAAD1BQDqCwDUFwBAfQGA+gIAqC8AUF8AAPUFAOoLAKC+AEB9AYD6AgCoLwBQXwAA9QUA6gsAoL4AQH0BANQXAKgvAID6AgD1BQDqCwCgvgBAfQEA1BcAqC8AgPoCAPUFAFBfAKC+AEB9AQDUFwCoLwCA+gIA9QUAUF8AoL4AAOoLANQXAEB9AYD6AgD1BQBQXwCgvgAA6gsA1BcAQH0BgPoCAKgvAFBfAKC+AADqCwDUFwBAfQGgh9S3JY3TAADdK63FJTNKOQ8A0L1KZ7gks4bzAADdqybTJTJ3LicCALqT6q5Lf6gpZe4XALpJWmmNGvTq+krmjJYvAQC6RcuMTBH5/2w2nz9LHTwoAAAAAElFTkSuQmCC) Every outgoing webhook request is logged. View the log under **Settings → Simple JWT Login → Webhooks → Logs**. Each log entry shows: * The webhook URL that was called * The HTTP method used * The event that triggered it * The response status code * The timestamp tip Webhook logs help you debug delivery failures. If a webhook is not reaching your endpoint, check the log for the HTTP status code returned by your server. *** ## Delivery Behavior[​](#delivery-behavior "Direct link to Delivery Behavior") Webhook HTTP calls are dispatched **after the API response is sent to the client** - they never block or delay the response your app receives. The plugin uses PHP's `fastcgi_finish_request()` to flush the response to the client first, then process all queued webhooks in the same PHP process. If that function is unavailable (see table below), webhooks are processed synchronously before the response is returned, which adds latency equal to the total time of all outgoing HTTP calls. | Server environment | Async delivery | | ------------------------------------------ | ------------------------------------------------- | | **nginx + PHP-FPM** (standard nginx setup) | Yes - response flushed before HTTP calls are made | | **Apache + PHP-FPM** (`mod_proxy_fcgi`) | Yes - response flushed before HTTP calls are made | | **Apache + mod\_php** | No - webhooks block the response | | **LiteSpeed / OpenLiteSpeed** | Depends on version - generally no | tip If your site runs on Apache with `mod_php` and you have slow webhook endpoints, consider keeping webhook payloads small and endpoints fast to avoid adding visible latency to your login/register API calls. *** ## Security Recommendations[​](#security-recommendations "Direct link to Security Recommendations") * Use **HTTPS** endpoints only - avoid sending event data over plain HTTP. * Pass a shared secret in a custom header (e.g. `X-Webhook-Secret`) and verify it on the receiving side to ensure the request originated from your site. * Validate the payload on the receiver before acting on it. *** ## Example: Notify Slack on User Registration[​](#example-notify-slack-on-user-registration "Direct link to Example: Notify Slack on User Registration") 1. Create a Slack Incoming Webhook URL in your Slack workspace. 2. In the plugin, add a new webhook with that URL. 3. Set the method to `POST`. 4. Enable the `register` event. 5. Set a custom payload: ``` { "text": "New user registered: {{user_email}}" } ``` Slack will display the message in your chosen channel each time a new user registers. ---