Skip to main content
Agency Program Get 2× more leads and save 50% on hosting. Built for agencies ready to grow. Book a call
WordPress REST API Authentication icon

WordPress REST API Authentication

v3.6.2
by miniOrange · 4.4 (67 reviews)

Secure and protect your WP REST API endpoints from unauthorized access with our WordPress API Auth using highly secure authentication methods.

20K+ active installs Updated Jan 10, 2025 Tested to 6.7.2 Requires PHP 5.6
Try Demo Download
Pre-installed Ready in ~10s No card
WordPress REST API Authentication

About WordPress REST API Authentication

The WordPress REST API endpoints are open and unsecured by default, making your site vulnerable to remote attacks. Our WordPress REST API Authentication plugin allows you to secure your APIs using various authentication methods such as API Key, JWT, Basic Authentication, OAuth 2.0, and third-party provider authentication, ensuring that only authorized users can access your site's resources.

Screenshots

WordPress REST API Authentication screenshot
WordPress REST API Authentication screenshot
WordPress REST API Authentication screenshot
WordPress REST API Authentication screenshot
WordPress REST API Authentication screenshot
WordPress REST API Authentication screenshot
WordPress REST API Authentication screenshot
WordPress REST API Authentication screenshot

Frequently asked questions

What does the WordPress REST API Authentication plugin do?
The WordPress REST API Authentication plugin protects WP REST API endpoints from public access and unauthorized users using various authentication methods such as API Key Authentication, JWT Authentication, Basic Authentication, OAuth 2.0 Authentication, and third-party OAuth 2.0/OIDC/Firebase provider's token authentication methods.
How does the plugin secure WordPress login endpoints?
The plugin secures WordPress login endpoints by allowing only authenticated users, who have successfully passed the authentication process, to access the site's resources.
What are the authentication methods supported by the plugin?
The plugin supports Basic Authentication, API Key Authentication, JWT Authentication, OAuth 2.0 Authentication, and Third-Party Provider Authentication methods.
Can the plugin be used to authenticate third-party plugin API endpoints?
Yes, the plugin can be used to authenticate and secure third-party plugin API endpoints such as WooCommerce, Learndash, Buddypress, Gravity forms, and CoCart.
Does the plugin support integration with external identity providers?
Yes, the plugin supports integration with external OAuth/OIDC providers and allows authentication of WordPress REST API endpoints using the access token or JWT token provided by these providers.

Changelog

3.6.2

  • Bug fixes for file includes

3.6.1

  • Bug fixes

3.6.0

  • Code improvments.
  • Compatibility with WP 6.7.*

3.5.4

  • Added analytics logs for logged in user.
  • Added fix for plugin not getting deactivated after clicking Skip button.

3.5.3

  • Minor Bug fix

3.5.2

  • Major bug fix for 401 response on edit, update and delete API requests (Requires saving the “Protected REST APIs” Settings in plugin again for changes to be in effect)
  • Usability improvements for API Access analytics

3.5.1

  • Bug fix for file includes

3.5.0

  • Auditing and analytics for REST API access
  • Bug fixes for Basic Authentication
  • UI Updates

3.4.0

  • Compatibility with WordPress 6.6
  • UI Updates

3.3.1

  • Major Release with UI and UX improvements

3.3.0

  • Major Release with UI and UX improvements

3.2.0

  • Compatibility with WordPress 6.5
  • Fix related to the CORS issue

3.1.0

  • Minor UI Improvements

3.0.0

  • Compatibility with WordPress 6.4

2.9.1

  • Quick fix related to permalinks settings

2.9.0

  • Usability improvements
  • UI updates

2.8.0

  • WordPress 6.3 compatibility
  • Added support for the WordPress.com environment for API authentication
  • UI Improvements

2.7.0

  • WordPress 6.2 compatibility
  • UI Changes

2.6.0

  • Security Fixes
  • UI Improvements & Fixes

2.5.1

  • PHP Warning for incorrect JWT fixed

2.5.0

  • Security Fixes
  • UI Improvements

2.4.2

  • Bug Fixes

2.4.1

  • WordPress 6.1 compatibility
  • Added a JWT token endpoint for the JWT authentication method
  • Security fixes

2.4.0

  • Minor Bug Fixes

2.3.0

  • WordPress 6.0 compatibility
  • Improvised Test Configuration User experience
  • Minor Bug Fixes

2.2.1

  • Bug fixes for Test API Configuration
  • Bug fixes for API key configuration
  • UI fixes

2.2.0

  • UI improvements
  • Introduced feature for Test API Configuration
  • Added the Third-party plugin integration section
  • Bug fixes

2.1.0

  • Major UI updates
  • Usability improvements and bug fixes
  • Compatibility with WordPress 5.9.1
  • Compatibility with PHP 8+

1.6.7

  • Compatibility with WordPress 5.9

1.6.6

  • UI Updates

1.6.5

  • WordPress 5.8.2 compatibility
  • UI Changes

1.6.4

  • Security Improvements

1.6.3

  • WordPress 5.8.1 compatibility
  • Readme Updates

1.6.2

  • WordPress 5.8 compatibility
  • Bug Fixes
  • Usability Improvements
  • UI Updates

1.6.1

  • Bug Fixes
  • Modifications for Custom API auth capabilities

1.6.0

  • Minor fixes
  • UI updates
  • Usability improvements

1.5.2

  • Minor fixes
  • Remove extra code

1.5.1

  • Minor fixes
  • Security fixes

1.5.0

  • Minor fixes
  • Security fixes

1.4.2

  • UI updates

1.4.1

  • UI updates
  • Minor fixes

1.4.0

  • WordPress 5.6 compatibility

1.3.10

  • Allow all REST APIs to authenticate
  • Added postman samples
  • Minor Bugfix

1.3.9

  • Minor Bugfix

1.3.8

  • Added compatibility for WP 5.5

1.3.7

  • Bundle plan release
  • Minor Bugfix

1.3.6

  • Added compatibility for WP 5.4

1.3.5

  • Minor Bugfix

1.3.4

  • Minor Bugfix

1.3.2

  • Minor Bugfix

1.3.1

  • Minor Fixes

1.3.0

  • Added UI Changes
  • Updated plugin licensing
  • Added New features
  • Added compatibility for WP 5.3 & PHP7.4
  • Minor UI & feature fixes

1.2.1

  • Added fixes for undefined getallheaders()

1.2.0

  • Added UI changes for Signing Algorithms and Role-Based Access
  • Added Signature Validation
  • Minor fixes

1.1.2

  • Added JWT Authentication
  • Fixed role-based access to REST APIs
  • Fixed common class conflicts

1.1.1

  • Fixes to Create, Posts, Update Publish Posts

1.1.0

  • Updated UI and features
  • Added compatibility for WordPress version 5.2.2
  • Added support for accessing draft posts as per User’s WordPress Role Capability
  • Allowed Logged In Users to access posts through /wp-admin Dashboard

1.0.2

  • Added Bug fixes

1.0.0

  • Updated UI and features
  • Added compatibility for WordPress version 5.2.2

Try other plugins

Yoast SEO icon

Yoast SEO

4.8 · 10M+ installs

Improve your WordPress SEO: Write better content and have a fully optimized WordPress site using the Yoast SEO…