WPThumbs
Themes Plugins By purpose By industry Best-of lists Fix it guides
Free Plugin by miniOrange v4.6.0

JWT Authentication for WP REST APIs

Secure and protect WordPress REST API from unauthorized access using JWT token, Basic Authentication, API Key, OAuth 2, or external token.

JWT Authentication for WP REST APIs

The facts

Rating
4.4★ from 74
Active installs
20k+
Price
Free
Last updated
4 Aug 2026
Added
May 2019
Requires WP
3.0.1
Tested up to
WP 7.0.4
Requires PHP
5.6
Downloads
533,350

Our analysis

AI-assisted

JWT Authentication for WP REST APIs is a WordPress plugin designed to secure REST API endpoints from unauthorized access. It provides multiple authentication methods, including JWT, Basic, API Key, and OAuth 2.0, enabling you to protect both default and custom REST endpoints.

The plugin is suitable for WordPress sites that require enhanced security for their API interactions, particularly those using third-party plugins like WooCommerce or Gravity Forms. It also includes features for managing token expiry, allowing for a smoother user experience through refresh and revoke token mechanisms.

Best for: This plugin is best for WordPress sites needing secure API access for various integrations.

What it does well

  • Multiple authentication methods available
  • Supports both core and custom REST API endpoints
  • Includes refresh and revoke token mechanisms for user convenience
  • Can disable WP REST APIs to prevent unauthorized access
  • Free to use from the WordPress.org directory

Where it falls short

  • Limited information on specific configurations or advanced features

Verdict

JWT Authentication for WP REST APIs offers essential security features for REST API endpoints, making it a practical choice for developers and site administrators focused on protecting their data.

From the developer

miniOrange's own description of JWT Authentication for WP REST APIs, lightly tidied.

WordPress REST API endpoints are open and unsecured by default which can be used to access your site data. Secure WordPress APIs from unauthorized users with our JWT Authentication for WP REST APIs plugin.

Our plugin offers below authentication methods to Protect WP REST API endpoints:
JWT Authentication
Basic Authentication
API Key Authentication
OAuth 2.0 Authentication
– External Token based Authentication 2.0/OIDC/JWT/Firebase provider’s token authentication methods.

You can authenticate default WordPress endpoints and custom-developed REST endpoints and third-party plugin REST API endpoints like that of Woocommerce, Learndash, Buddypress, Gravity Forms, CoCart, etc.

WP REST API Authentication Methods in our plugin

  • JWT Authentication
    Provides an endpoint where you can pass the user credentials, and it will generate a JWT (JSON Web Token), which you can use to access the WordPress REST APIs accordingly.
    Additionally, to maintain a seamless user experience without frequent logins needed due to token expiry, you can use our Refresh and Revoke token mechanisms feature.
    When the access token expires, instead of forcing the user to log in again, the client can request a new access token using a valid refresh token.
  • API Key Authentication
  • Basic Authentication:
    – 1. Username: Password
    – 2. Client-ID: Client-Secret
  • OAuth 2.0 Authentication
    – 1. Password Grant
    – 2. Client Credentials Grant
  • Third Party Provider Authentication

Following are some of the integrations that are possible with WP REST API Authentication:

  • Learndash API Authentication
  • Custom Built REST API Endpoints Authentication
  • BuddyPress API Authentication
  • WooCommerce API Authentication
  • Gravity Form API Authentication
  • External/Third-party plugin API endpoints integration in WordPress

You can also disable the WP REST APIs with our plugin such that no one can make API calls to your WordPress REST API endpoints.Our plugin also provides Refresh and Revoke Token that can be used to improve the API security.

Benefits of Refresh Token

  • Enhances security by keeping access tokens short-lived.
  • Improves user experience with uninterrupted sessions.
  • Reduces login frequency.

Benefits of Revoke Token

  • Protects against token misuse if a device is lost or compromised.
  • Enables admin-triggered logouts or session control.
  • Useful for complying with stricter session policies.

With this plugin, the user is allowed to access your site’s resources only after successful WP REST API authentication. JWT Authentication for WP REST APIs plugin will make your WordPress endpoints secure from unauthorized access.

Plugin Feature List

Free plan

  • Authenticate only default core WordPress REST API endpoints.
  • Basic Authentication with username and password.
  • JWT Authentication (JSON Web Token Authentication).
  • Enable Selective API protection.
  • Restrict non-logged-in users to access REST API endpoints.
  • Disable WP REST APIs

Read the full description on the official page →

Tagged as

Alternatives

Other plugins for integrating services.

LocoAI

LocoAI

89

LocoAI - Auto Translate For Loco Translate is a powerful tool for developers looking to quickly translate thei...

Free 70k+ installs 4.9★ (637)
Uncanny Automator

The AI + Automation plugin for WordPress. Automate workflows across all your plugins and apps, add an AI agent...

Free 40k+ installs 4.9★ (156)
Open User Map

Create custom interactive maps with free Leaflet-based styles, no Google Maps API key, frontend marker submiss...

Free 10k+ installs 5★ (67)
Activity Log

Monitor every change on your WordPress site — who did what, when, and where it came from — for a complete audi...

Free 200k+ installs 4.3★ (74)
Reviews Feed

No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your si...

Free 100k+ installs 4.4★ (34)
Bit integrations

Contact Form, Google Sheet, MailChimp, Brevo, Webhook, Zoho CRM Automation and Integration plugin that Connect...

Free 20k+ installs 4.9★ (160)