AH JWT Auth
This plugin allows sign in to WordPress using a JSON Web Token (JWT) contained in a HTTP Header.
Use with caution
AH JWT Auth works, but test it on a staging site before relying on it in 2026. It runs on 20+ sites and was last updated 3 months ago, and scores 58/100 on our health check.
- Small user base (20+ active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where AH JWT Auth stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| auth | #39 |
| authentication | >100 |
| jwt | #12 |
| login | >100 |
| sso | #75 |
Version adoption
Share of active sites per release.
About AH JWT Auth
From the official readme · v2.4.0Description
This plugin allows sign in to WordPress using a JSON Web Token (JWT) contained
in a HTTP Header that is added by a reverse proxy that sits in front of your
WordPress deployment.
Authentication and optionally role assignment is handled by claims contained in
the JWT.
If configured, the plugin also validates the JWT aud and iss claims against
the expected application audience and JWT issuer values.
Verification of the JWT is handled by either:
- a shared secret for HS256 (as per RFC 7518 this must be at least 256-bits in
size) - a PEM encoded public key for RS256
- retrieving a JSON Web Key Set (JWKS) from a configured URL (also for RS256)
During the login process if the user does not exist an account will be created
with a matching role from the JWT, unless automatic user creation has been
disabled in the plugin settings.
If the JWT did not contain a role claim then user is created with the role set
in the plugin settings (by default this is the subscriber role).
Automatic user creation is enabled by default for backwards compatibility. It
can be disabled when user provisioning should remain manual.
Frequently asked questions
What header is the JWT retrieved from?
By default the plugin looks for the JWT in the Authorization header as follows: Authorization: Bearer However the token may be retrieved from a configurable HTTP header, for example to integrate with Cloudflare Access, which was the original target for this plugin, you would configure the use of the Cf-Access-Jwt-Assertion header.
What claims should the JWT contain?
The JWT must contain at least an email claim and may also contain a role claim: { "iss": "example.com", "aud": "example-audience-id", "email": "admin@example.com", "iat": 1356999524, "nbf": 1357000000, "role": "admin" } The aud and iss claims are only required when a JWT Audience and/or Issuer value has been configured in the plugin settings, however as they are standard JWT claims it is recommended to set these options to verify those claims exist and are valid.
What signature algorithms are supported to verify the JWT?
Currently only the HS256 and RS256 algorithms are supported.
Changelog
Initial public release
2.4.0
- Fix fatal error with JWKS caching
2.3.0
- Replace JWKS caching process
2.2.0
- Spelling fixes and hardening
- Add option to enforce JWT auth (ie “fail-closed”) rather than falling
through to WordPress authentication.
2.1.0
- Add option to verify JWT issuer
2.0.0
- Breaking Change: Any secrets that are less than 256-bits (32-characters)
in length will fail JWT HS256 verification
1.6.0
- Added option to verify JWT Audience (AUD)
- Added option to disable automatic user creation
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best AH JWT Auth alternatives
All auth plugins →FAQ
AH JWT Auth: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 4, 2026
Is AH JWT Auth free?
Yes. AH JWT Auth is free to download and use from the official WordPress.org plugin directory.
Is AH JWT Auth safe to use in 2026?
AH JWT Auth works, but test it on a staging site before relying on it in 2026. It runs on 20+ sites and was last updated 3 months ago, and scores 58/100 on our health check.
How many websites use AH JWT Auth?
AH JWT Auth is active on 20+ WordPress websites and has been downloaded 3,235 times since it launched in April 2021. It was downloaded 88 times in the last 30 days.
Does AH JWT Auth work with WordPress 7.1?
AH JWT Auth is officially tested up to WordPress 7.0.0, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does AH JWT Auth need?
AH JWT Auth requires PHP 8.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was AH JWT Auth last updated?
The latest version, 2.4.0, was released on July 17, 2026 (3 months ago).
Who makes AH JWT Auth?
AH JWT Auth is developed and maintained by andrewheberle.
What are the best alternatives to AH JWT Auth?
The most popular alternatives to AH JWT Auth are authLdap (4K+ installs), WP BASIC Auth (3K+ installs) and WP Cron HTTP Auth (1K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card
