Found Image http://plugins.svn.wordpress.org/json-api-auth/assets/icon-256x256.png JSON API Auth | Plugin Review Network Skip to Content

Plugin Review Network

Plugin Review Network

an eye on the best wordpress plugins
Show Sidebar Hide Sidebar
[+] Sidebar [-] Sidebar
Plugin:
Rated:
94%
4.7 Stars (11 votes)

Home

WP.Org

ReadMe

Support
  • Author:
    Ali Qureshi
Version: 2.4.0
Requires: WP 3.0.1
Last Updated:2417 days ago
Downloads:38938
Installations: 5,000+
Tags:
    api, authenticate user, json-api, wordpress user authentication
Download Plugin Package

JSON API Auth

Released on December 17, 2013.
Download Plugin Package

Version: 2.4.0

Requires PHP: 7.4 Extends the JSON API Plugin for RESTful user authentication

  • Description
  • FAQ
  • Changelog
  • Installation
  • Screenshots


Important: use RESTful JSON API for new integrations

JSON API Auth is retained for existing sites that still depend on the original JSON API plugin and its cookie-authentication workflow. For a new mobile app, headless site, external service, or AI-assisted integration, install RESTful JSON API instead.

RESTful JSON API provides plugin-issued JWT bearer authentication, requires HTTPS by default for requests that handle passwords or tokens, and includes a broader set of endpoints organized into Core, Posts, User, Respond, and Widgets controllers. Its User controller includes signup, JWT login, token validation, profiles, avatars, password-reset requests, safe user meta, and authenticated comments, while the other controllers expose content, custom post type, taxonomy, media, menu, search, comment, and widget workflows.

Existing JSON API Auth integrations can continue using this plugin. Because JWT bearer tokens replace the legacy cookie format and endpoint paths differ, test your client migration before deactivating the legacy JSON API stack.

JSON API Auth extends the JSON API Plugin to allow RESTful user authentication.

JSON API Plugin, that is required, was closed on August 7, 2019 from WordPress repository. You can download JSON API Plugin from https://github.com/PI-Media/json-api until it is republished and available on WordPress.

Features include:

  • Generate Auth Cookie for user authentication

  • Validate Auth Cookie

  • Get Current User Info

For documentation: See 'Other Notes' tab above for usage examples.

Credits: http://www.parorrey.com/solutions/json-api-auth/

Thanks to 'mattberg' who wrote the auth controller (https://github.com/mattberg/wp-json-api-auth) initially. I have added few methods and authored it as a WordPress plugin so that it could easily be searched and installed vis WordPress.

  • There are following methods available: validate_auth_cookie, generate_auth_cookie, clear_auth_cookie, get_currentuserinfo

  • nonce can be created by calling http://localhost/api/get_nonce/?controller=auth&method=generate_auth_cookie

  • You can then use 'nonce' value to generate cookie. http://localhost/api/auth/generate_auth_cookie/?nonce=f4320f4a67&username=Catherine&password=password-here

  • Use cookie like this with your other controller calls: http://localhost/api/contoller-name/method-name/?cookie=Catherine|1392018917|3ad7b9f1c5c2cccb569c8a82119ca4fd

For instance, you have a new controller 'events' and want to allow users to post new 'event' using 'add_event' method. This is how you will call the end point with cookie and post the event with user info:

http://localhost/api/events/add_event/?cookie=Catherine|1392018917|3ad7b9f1c5c2cccb569c8a82119ca4fd

If you want sample code how it can be done, check 'JSON API User' plugin https://wordpress.org/plugins/json-api-user/. This Auth plugin is part of JSON API User plugin.

Method: validate_auth_cookie

It needs 'cookie' var.

http://localhost/api/auth/validate_auth_cookie/?cookie=Catherine|1392018917|3ad7b9f1c5c2cccb569c8a82119ca4fd

Method: generate_auth_cookie

It needs username, password vars. seconds is optional.

Then generate cookie: http://localhost/api/auth/generate_auth_cookie/?username=john&password=PASSWORD-HERE

Optional 'seconds' var. It provided, generated cookie will be valid for that many seconds, otherwise default is for 14 days.

generate cookie for 1 minute: http://localhost/api/auth/generate_auth_cookie/?username=john&password=PASSWORD-HERE&seconds=60

60 means 1 minute.

Method: get_currentuserinfo

It needs 'cookie' var.

http://localhost/api/auth/get_currentuserinfo/?cookie=Catherine|1392018917|3ad7b9f1c5c2cccb569c8a82119ca4fd

3.1.1

  • Added a migration notice recommending the newer RESTful JSON API plugin for new projects.
  • Documented its JWT bearer authentication, HTTPS-by-default protection, and broader controller-based endpoint set.
  • Added secure WordPress.org and donation links.

3.1.0

  • Tested and confirmed working with WordPress 7.0
  • Bumped minimum PHP requirement to 7.4
  • Replaced deprecated wp_capabilities user meta key with $user->roles for reliable role retrieval
  • Switched avatar retrieval to get_avatar_url() (WP 4.2+) with regex fallback, fixing broken avatar URLs in modern WordPress
  • Added sanitize_text_field() to POST parameter handling for improved input security
  • Fixed isset() check on json_api->query->cookie in cookie auth hook to avoid PHP notices

3.0.0

  • Updated for WordPress version 6.8

2.9.1

  • Fixed a bug for generate_auth_cookie, get_currentuserinfo endpoints for avatar
  • Updated for WordPress version 6.4.1

2.9.0

  • Updated for WordPress version 6.1.1

2.8.0

  • Updated for WordPress version 6.0.1

2.7.1

  • Updated for WordPress version 5.9

2.7.0

  • Updated for wordpress version 5.8

2.6.0

  • Updated for wordpress version 5.7

2.5.0

  • Updated for wordpress version 5.5.3

2.4.0

  • Fixed bug in the generate_auth_cookie endpoint.

2.3.0

  • Updated for JSON API Plugin diretory check error and updated action links.

2.2.0

  • Updated for GitHub and settings action links.

2.1.0

  • Updated for WordPress version & added JSON API plugin GitHub link due its closing down on WordPress repository.

2.0.0

  • Updated for wordpress version


First you have to install the JSON API for WordPress Plugin (http://wordpress.org/extend/plugins/json-api/installation/). or You can download JSON API Plugin from https://github.com/PI-Media/json-api

To install JSON API Auth just follow these steps:

  • upload the folder "json-api-auth" to your WordPress plugin folder (/wp-content/plugins)

  • activate the plugin through the 'Plugins' menu in WordPress or by using the link provided by the plugin installer

  • activate the controller through the JSON API menu found in the WordPress admin center (Settings -> JSON API)


Call to generate_auth_cookie endpoint using Postman
Screenshot 1


Call to get_currentuserinfo endpoint using Postman
Screenshot 2


Call to validate_auth_cookie endpoint using Postman
Screenshot 3



 

Click here to cancel reply.

Click here to cancel reply.


*

*


Please copy the string NhMuVB to the field below:

Home | Sitemap | Contact
Network Skin Theme for BioShip by WordQuest
Password Reset
Please enter your e-mail address. You will receive a new password via e-mail.