BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
DIESIS JWT Auth for Cloudflare Access icon
Actively maintained Tested with WP 7.1 #69 in access

DIESIS JWT Auth for Cloudflare Access

Validates Cloudflare Access JWTs at the WordPress origin so protected paths stay closed to requests that bypass Cloudflare.

Active installs<10New
Downloads · 30d283• 0% vs prev. 30d
Rating—0 reviews
Health score64/100Good
All-time downloads273Since Sep 2026
Support resolved—No recent threads
RequiresWP 6.8PHP 8.1+
Downloads · 7d74▼ -24.5% week over week
Our verdict

Solid choice

DIESIS JWT Auth for Cloudflare… is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 5 days ago, and scores 64/100 on our health check.

  • Actively developed — last update 5 days ago
  • Tested with the latest WordPress (7.1)
  • Small user base (<10 active installs)
  • Very few reviews so far
  • Needs PHP 8.1 or newer

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

102132Sep 17Sep 25Oct 4
Yesterday0
Daily average (1y)16
Peak day43Sep 30, 2026
Last 12 months283

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where DIESIS JWT Auth for Cloudfl… stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
access >100 10,000 Best access plugins →
authentication >100 4,356 Best authentication plugins →
cloudflare >100 1,842 Best cloudflare plugins →
jwt #41 285 Best jwt plugins →
security >100 10,000 Best security plugins →

About DIESIS JWT Auth for Cloudflare Access

From the official readme · v1.4.3

Description

Cloudflare Access can put a login in front of /wp-admin and /wp-login.php. It only helps if every request really passes through Cloudflare. Without Cloudflare Tunnel, anyone who knows the origin’s address can reach WordPress directly and skip Access entirely.

DIESIS JWT Auth for Cloudflare Access closes that gap. For the paths you choose, WordPress itself checks the Cf-Access-Jwt-Assertion header that Cloudflare Access adds to authenticated requests. A request without a valid token is answered with HTTP 403 before WordPress does anything else.

What it does

  • Verifies the Access JWT signature (RS256) against the signing keys of your Cloudflare Access team.
  • Checks expiry, issuer and the application audience of your Access application.
  • Optionally restricts access to a list of email addresses as a second check at the origin.
  • Protects the paths you configure, with prefix matching and explicit exclusions.
  • Caches signing keys for 12 hours and refreshes them when Cloudflare rotates keys.

What it does not do

  • It does not replace the WordPress login and does not create or log in users. Visitors pass Cloudflare Access first and then sign in to WordPress as usual.
  • It does not accept Cloudflare Access service tokens. Those carry no email claim and are always denied. Keep machine-to-machine paths such as cron, XML-RPC or the REST API out of the protected paths, or leave them public in both WordPress and the matching Access destination.

Safe defaults

Enforcement only runs when the settings are complete and the issuer is an HTTPS cloudflareaccess.com URL. Incomplete or invalid settings disable enforcement instead of locking you out. If Cloudflare’s key endpoint is temporarily unreachable, a previously cached key set keeps working.

Third-party service

To verify tokens the plugin downloads the public signing keys of your Cloudflare Access team from the issuer you configure, for example https://your-team.cloudflareaccess.com/cdn-cgi/access/certs. No site data is sent; the request is a plain download of public keys, repeated at most every 12 hours or after a key rotation. Cloudflare’s terms and privacy policy apply to that endpoint: Terms, Privacy policy.

Source code, issues and support: github.com/DiesisMedia/diesis-jwt-auth

Installation

  1. Create a self-hosted application in Cloudflare Zero Trust that covers your WordPress login and admin paths, and note the team domain (the issuer) and the application audience tag.
  2. Install the plugin from the WordPress plugin directory or upload the ZIP under Plugins > Add New Plugin > Upload Plugin, then activate it.
  3. Open Settings > DIESIS JWT Auth.
  4. Enter the issuer, for example https://your-team.cloudflareaccess.com, and the application audience. Save with enforcement still disabled.
  5. Check that the protected paths match the paths your Access application covers. Use the copyable defaults below, adjusting the prefix if WordPress is installed in a subdirectory.
  6. Enable enforcement and save.
  7. Test twice: once through your Cloudflare URL, which should work, and once directly against the origin, which should return 403.

Default settings

A fresh installation starts with these values:

  • Enforcement: disabled.
  • Issuer: empty. Enter your own Cloudflare Access team domain, such as https://your-team.cloudflareaccess.com, with no extra path.
  • Application audience: empty. Copy the audience tag of your self-hosted Access application from Cloudflare Zero Trust. This is not the application name or your site URL.
  • Allowed emails: empty. There is no additional email allowlist at the origin. A valid user token with an email claim is still required.
  • Protected paths: the three lines below.
  • Excluded paths: empty. There are no exclusions.

Copy these lines into Protected paths, one per line, for WordPress installed at the domain root:

/wp-login.php*
/wp-admin
/wp-admin/*

If your login and admin URLs start with /wordpress/, use:

/wordpress/wp-login.php*
/wordpress/wp-admin
/wordpress/wp-admin/*

Use the path prefix from your actual login and admin URLs, without the domain. Leaving Protected paths empty restores the default three paths; it does not disable protection.

Issuer and Application audience are specific to your Cloudflare setup and have no shared default. Leave Allowed emails and Excluded paths empty for the default setup. If you add an email allowlist, use your actual permitted addresses, one per line, matching your Access policy.

Frequently asked questions

I excluded a path in WordPress, but Cloudflare still asks me to log in.

Exclusions in this plugin only stop the origin check. Cloudflare Access decides on its own which paths it intercepts. Leave the path public in the Access application as well.

Why does a request get a 403?

Any failed check ends in 403: no Cf-Access-Jwt-Assertion header, a token not signed with RS256, an invalid or expired signature, a wrong issuer or audience, a missing email claim, or an email that is not on the allowed list. With WP_DEBUG enabled the reason is written to the PHP error log.

I locked myself out. How do I get back in?

Make sure you are opening the site through Cloudflare, not through the origin’s own address, and that the Access application covers the same paths as the plugin. If you need to disable the plugin without admin access, rename or delete its folder under wp-content/plugins/ via SFTP or your host’s file manager.

What happens when Cloudflare’s certificate endpoint is down?

A cached key set stays valid for 12 hours and keeps working. Only if there are no cached keys at all and Cloudflare cannot be reached are protected requests denied.

Does the plugin work with Cloudflare Access service tokens?

No. Service tokens carry a common_name instead of an email and are always denied. Keep paths used by machines out of the protected paths.

How do I get rid of the review notice?

Follow the review link: that ends it for your account for good. “Remind me later” brings the notice back after three months, after a year and after two years; the last reminder offers “Don’t show this again” instead and ends it as well. The notice only ever appears on the Dashboard, the Plugins screen and the plugin’s own settings page, and only once enforcement has been running for two weeks.

Does it work on multisite?

Yes. Settings are per site, and uninstalling cleans up every site of the network.

Changelog

Adds a review request in the admin. No settings change needed.

1.4.3

  • Updated the bundled firebase/php-jwt library to 7.2.0.

1.4.2

  • Updated the bundled firebase/php-jwt library to 7.1.1.

1.4.1

  • The plugin asks for a review on WordPress.org and a star on GitHub: a dismissible notice after two weeks of enforcement, a line on the settings page, and two links in the plugin row. Dismissing the notice brings it back after three months, a year and two years, then never again; following the review link ends it straight away. Uninstalling removes everything it stored.

1.4.0

  • The plugin is translatable. It ships catalogs for de_DE, es_ES, it_IT, zh_CN, ja, and pt_BR; further languages can come from translate.wordpress.org.
  • Documented all default settings, with copyable protected paths for root and subdirectory installations.

1.3.0

  • The plugin slug and text domain are now diesis-jwt-auth; the option and cached key names follow it.

1.2.0

  • Renamed to DIESIS JWT Auth for Cloudflare Access; first release in the WordPress plugin directory.
  • The bundled JWT library is now namespaced to this plugin, so another plugin shipping a different version cannot replace it.
  • Fixed the release build appending to an existing ZIP.
  • The settings page and menu entry carry the plugin name.
  • The release package contains only the files the plugin needs; development and agent files stay out.

Full changelog on WordPress.org →

Screenshots

The settings page: enforcement toggle, issuer, application audience, optional allowed emails, protected and excluded paths.
The settings page: enforcement toggle, issuer, application audience, optional allowed…

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best DIESIS JWT Auth for Cloudflar… alternatives

All access plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Loginizer Loginizer Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks. by Softaculous 1M+ ★★★★★★★★★★ 4.8 (1K) 7 days ago 90
2 User Role Editor User Role Editor User Role Editor WordPress plugin makes user roles and capabilities changing easy… by Vladimir Garagulya 700K+ ★★★★★★★★★★ 4.5 (288) 1 week ago 89
3 Members – Membership & User Role Editor Plugin Members – Membership & User Role Editor Plugin The best WordPress membership and user role editor plugin. User Roles & Capabilities editor… by Blair Williams 300K+ ★★★★★★★★★★ 4.9 (1.3K) 1 month ago 93
4 Remove Dashboard Access Remove Dashboard Access Disable Dashboard access for users of a specific role or capability. Disallowed users are… by TrustedLogin 30K+ ★★★★★★★★★★ 4.6 (78) 5 months ago 74
5 User Access Manager User Access Manager With the "User Access Manager"-plugin you can manage the access to your posts, pages and… by gm_alex 10K+ ★★★★★★★★★★ 4.4 (112) 4 weeks ago 91
6 Groups – Memberships and Access Control Groups – Memberships and Access Control Turn your site into a powerful membership solution. Manage members, teams and access to… by itthinx 10K+ ★★★★★★★★★★ 4.8 (382) 2 weeks ago 93
7 Controlled Admin Access Controlled Admin Access Give a temporarily limited admin access to themes designers, plugins developers and support… by Waseem Senjer 10K+ ★★★★★★★★★★ 4.8 (45) 2 months ago 85
8 Simple Membership Form Shortcode Simple Membership Form Shortcode Simple Membership Addon to generate registration form shortcode for specific membership… by wp.insider 2K+ ★★★★★★★★★★ 5 (2) 1 month ago 74
9 Authenticator Authenticator This plugin allows you to make your WordPress site accessible to logged in users only. by Syde GmbH (formerly Inpsyde) 1K+ ★★★★★★★★★★ 5 (8) 9 months ago 54
10 Groups 404 Redirect Groups 404 Redirect Redirect 404's when a visitor tries to access a page protected by Groups. by itthinx 1K+ ★★★★★★★★★★ 4.6 (10) 1 week ago 80

FAQ

DIESIS JWT Auth for Cloudflare Acce…: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 5, 2026

Is DIESIS JWT Auth for Cloudflare… free?

Yes. DIESIS JWT Auth for Cloudflare… is free to download and use from the official WordPress.org plugin directory.

Is DIESIS JWT Auth for Cloudflare… safe to use in 2026?

DIESIS JWT Auth for Cloudflare… is a solid plugin choice in 2026, with a few things worth checking first. Was last updated 5 days ago, and scores 64/100 on our health check.

How many websites use DIESIS JWT Auth for Cloudflare…?

DIESIS JWT Auth for Cloudflare… is active on <10 WordPress websites and has been downloaded 273 times since it launched in September 2026. It was downloaded 283 times in the last 30 days.

Does DIESIS JWT Auth for Cloudflare… work with WordPress 7.1?

Yes. The developer has tested DIESIS JWT Auth for Cloudflare… up to WordPress 7.1.2, the latest release. It requires WordPress 6.8 or newer.

What PHP version does DIESIS JWT Auth for Cloudflare… need?

DIESIS JWT Auth for Cloudflare… requires PHP 8.1 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was DIESIS JWT Auth for Cloudflare… last updated?

The latest version, 1.4.3, was released on September 30, 2026 (5 days ago).

Who makes DIESIS JWT Auth for Cloudflare…?

DIESIS JWT Auth for Cloudflare… is developed and maintained by DIESIS Media.

What are the best alternatives to DIESIS JWT Auth for Cloudflare…?

The most popular alternatives to DIESIS JWT Auth for Cloudflare… are Loginizer (1M+ installs), User Role Editor (700K+ installs) and Members (300K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.