Connecting your app to WordPress can be useful to enhance application features by using data from the WordPress database. WP OAuth Server was designed to allow a connection to WordPress easily without having to develop an overly complicated API.
What you will need
- WP OAuth Server installed on a publicly accessible WordPress website.
- Your App
In this article, we assume your app is a native mobile application or desktop app not using any HTML / Hybrid technology. Your app will require internet access as well.
Create and configure the client
Create a client in WP OAuth Server. When you are creating the client ensure that the grant type “User Credentials.” After saving the client, be sure to copy the Client ID and Client Secret that was generated upon saving the client.
Setup your app to allow your app to connect as a WordPress User
Due to the nature of many programming languages, we are only going to cover how your app should send a request to the WordPress website. You will need to refer to your programming language documentation for specific documentation.
Your app will need to collect the username and password from the user. Connecting the username and password is typically done by using a login form. How you obtain the username and password is up to you.
The request to the server is relatively simple. Form a POST request to your WordPress website.
POST https://yourserver.com?oauth=token basic authorization client_id:client_secret
grant_type=password username=user_input password=user_input
Note: A REFERER is required in the header during the POST request, or the request will fail.
If the user login is valid, your application will be presented with an access token for the specified user. This access token can be used with the WP REST API or OAuth 2.o Resource Server to get information about the user.
If the user login information is not correct, the server will respond with an invalid username message in JSON.
Request the user information using the access token
After you get the access token, you will need to know who the user is. To request the user information from the OAuth 2.0 server, you will need your app to make a GET request.
If the access token is valid, the response will be the user information in JSON format. The response from the server contains general information about the user, but the API can be extended to provide additional information. Extending the API is helpful if you need to have information from bbpress, WooCommerce or custom fields returned.
See Extending Endpoints for an example of extending the resource endpoints.
Current Version: 3.7.3
Any documentation and or published articles may not reflect the latest WP OAuth Server plugin version. It is always best to stay updated for security.
How To ArticlesBelow is a list of "How To" documentation articles.
- Connect your App to WordPress Users
- WP REST API Bearer Token Authentication
- Enabling WooCommerce API
- Enable User Consent Dialog
- OAuth 2.0 Token Introspection
- Disable Plugin Updates
- Extending the OpenID Discovery API
- OpenID Authentication for WP REST API
- Using a Bearer Token with WP REST API
- How to Authenticate with WP REST API
- Using POSTMAN and WP REST API
- Setup WP OAuth Server for Single Sign On with WordPress
- Extending Endpoints
- Setting up Moodle and WordPress for Single Sign On
- Rocket.Chat OAuth Setup
- Never Expiring Access Token
OAuth Server 3.7.3
WP OAuth Server Pro allows for Unlimited clients and multiple grant types.BUY NOW