BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
HeadlessKey – JWT Auth icon
Maintained Tested up to 6.9.9

HeadlessKey – JWT Auth

A complete authentication solution for Headless WordPress applications using JWT, supporting Registration, SSO, RBAC, and advanced Security features.

Active installs<10New
Downloads · 30d69▲ +50% vs prev. 30d
Rating—0 reviews
Health score36/100At risk
All-time downloads498Since Feb 2026
Support resolved—No recent threads
RequiresWP 6.0PHP 8.0+
Downloads · 7d19▲ +46.2% week over week
Our verdict

Consider an alternative

HeadlessKey – JWT Auth shows warning signs in 2026 — compare the alternatives below before installing. Was last updated 8 months ago, and scores 36/100 on our health check.

  • Small user base (<10 active installs)
  • Very few reviews so far
  • Only tested up to WordPress 6.9 (latest is 7.1)

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

134Jul 6Aug 19Oct 3
Yesterday0
Daily average (1y)2
Peak day31Feb 8, 2026
Last 12 months507

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where HeadlessKey – JWT Auth stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
authentication >100 4,350 Best authentication plugins →
headless >100 473 Best headless plugins →
jwt #25 284 Best jwt plugins →
rest-api >100 7,538 Best rest-api plugins →
security >100 10,000 Best security plugins →

About HeadlessKey – JWT Auth

From the official readme · v1.0.0

Description

HeadlessKey – JWT Auth extends the REST API to provide a robust and secure authentication system using JSON Web Tokens (JWT). Designed for Headless WordPress, it enables seamless user authentication, registration, and session management via standard REST endpoints.

Key Features

  • Standard JWT Authentication: Secure user authentication using industry-standard RFC 7519 tokens.
  • Multiple Algorithms: Support for HS256, RS256, and ES256 signing algorithms.
  • Comprehensive Endpoints: Ready-to-use endpoints for Login, Register, Token Refresh, and Password Management.
  • Single Sign-On (SSO): Connect multiple sites with a secure, headers-based SSO exchange mechanism.
  • Role-Based Access Control (RBAC): Configure public or authenticated access for every endpoint.
  • Brute Force Protection: Protects against attacks by locking users/IPs after failed attempts.
  • Activity Logs: Detailed audit trail of all authentication events, including IP and device data.
  • Security Webhooks: Real-time JSON events sent to your external services for monitoring key actions.
  • Device Limits: Restrict the number of active devices/sessions per user.
  • Developer Friendly: Extensive hooks and filters for deep customization.

Configuration

Secret Key

The plugin uses a secret key to sign tokens. By default, a secure random key is generated. For better security and consistency across environments, define your key in wp-config.php:

define('headlesskey_SECRET_KEY', 'your-long-random-secure-string');

You can generate a strong salt here: WordPress Salt Generator

CORS Support

Cross-Origin Resource Sharing (CORS) is enabled by default to allow frontend applications to connect. To disable or customize it via constant:

define('headlesskey_CORS', true); // or false to disable

REST API Namespace

By default, endpoints are under wp-json/wpauthapi/v1. You can customize this namespace:

define('headlesskey_REST_NAMESPACE', 'my-custom-auth');
define('headlesskey_REST_VERSION', 'v2');<h3>Endpoints</h3>

The plugin adds the following endpoints under the /wp-json/headlesskey/v1 namespace:

Endpoint
HTTP Verb
Description

/token
POST
Login: Exchange username/password for a JWT.

/token/validate
POST
Validate: Check if a token validity.

/token/refresh
POST
Refresh: Exchange a valid token for a new one (rotation).

/token/revoke
POST
Logout: Invalidate a specific token.

/register
POST
Register: Create a new user account.

/login
POST
Profile: Login and get full user profile data in one request.

/forgot-password
POST
Recover: Request a password reset via Link or OTP.

/reset-password
POST
Reset: Set a new password using a token or OTP.

/change-password
POST
Update: Change password for authenticated user.

/sso/exchange
POST
SSO: Exchange a remote site token for a local session.

1. Login (Generate Token)

Endpoint: POST /wp-json/headlesskey/v1/token
Description: Authenticate a user and generate a JWT token.

Request:
json
{
"username": "admin",
"password": "secret-password"
}

Response:
json
{
"token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9...",
"expiration": "2023-10-27T10:00:00+00:00",
"expires_in": 3600,
"user": {
"ID": 1,
"user_login": "admin",
"user_email": "admin@example.com",
"display_name": "Administrator",
"roles": ["administrator"]
},
"refreshable": true,
"jti": "545086b9-450f-488b-a70d-3047d14d1101"
}

2. Validate Token

Endpoint: POST /wp-json/headlesskey/v1/token/validate
Description: Validate if an existing token is valid.

Request:
json
{
"token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9..."
}

Response:
json
{
"valid": true,
"data": {
"iss": "https://example.com",
"iat": 1698393600,
"exp": 1698397200,
"data": {
"ID": 1,
"user_login": "admin"
}
}
}

3. Refresh Token

Endpoint: POST /wp-json/headlesskey/v1/token/refresh
Description: Rotate an expiring token for a fresh one.

Request:
json
{
"token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9..."
}

Response:
json
{
"token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.new...",
"expiration": "2023-10-27T11:00:00+00:00",
"user": {
"ID": 1,
"user_login": "admin"
},
"jti": "new-uuid-v4"
}

4. Revoke Token (Logout)

Endpoint: POST /wp-json/headlesskey/v1/token/revoke
Description: Invalidate a token immediately.

Request:
json
{
"token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9..."
}

Response:
json
{
"message": "Token revoked successfully."
}

5. Register User

Endpoint: POST /wp-json/headlesskey/v1/register
Description: Create a new user account.

Request:
json
{
"username": "johndoe",
"email": "john@example.com",
"password": "secure-password",
"name": "John Doe"
}

Response:
json
{
"user_id": 45,
"user": {
"ID": 45,
"user_login": "johndoe",
"user_email": "john@example.com",
"display_name": "John Doe",
"roles": ["subscriber"]
},
"token_response": {
"token": "eyJ0eXAiOiJKV1QiLCJhbGciOi...",
"expiration": "2023-10-27T10:00:00+00:00"
}
}

6. User Profile (Login Extended)

Endpoint: POST /wp-json/headlesskey/v1/login
Description: Alternative login endpoint that returns cleaner profile structure.

Request:
json
{
"username": "admin",
"password": "secret-password"
}

Response:
json
{
"token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9...",
"expiration": "2023-10-27T10:00:00+00:00",
"user": {
"ID": 1,
"user_login": "admin",
"user_email": "admin@example.com",
"display_name": "Administrator",
"roles": ["administrator"]
}
}

7. Forgot Password

Endpoint: POST /wp-json/headlesskey/v1/forgot-password
Description: Initiate password recovery. Note: delivery can be link or otp.

Request:
json
{
"login": "admin@example.com",
"delivery": "link"
}

Response:
json
{
"message": "Password reset email sent."
}

8. Reset Password

Endpoint: POST /wp-json/headlesskey/v1/reset-password
Description: Reset password using the token sent via email or OTP.

Request (Link method):
json
{
"login": "admin@example.com",
"password": "new-secure-password",
"token": "generated-reset-key"
}

Response:
json
{
"message": "Password updated successfully."
}

9. Change Password

Endpoint: POST /wp-json/headlesskey/v1/change-password
Description: Change password for currently authenticated user. Requires Authorization header.

Headers:
Authorization: Bearer

Request:
json
{
"current_password": "old-password",
"new_password": "new-secure-password"
}

Response:
json
{
"message": "Password changed successfully. Please login again."
}

10. SSO Token Exchange

Endpoint: POST /wp-json/headlesskey/v1/sso/exchange
Description: Securely exchange a token from a connected remote site for a local authentication session. This powers the distributed Single Sign-On network.

Request:
json
{
"site_key": "remote-site-id",
"token": "remote-jwt-token",
"signature": "hmac-sha256-signature"
}

Response:
Returns a standard Login response (Token + User Data) if the signature is valid.

Frequently asked questions

How do I generate a JWT Secret?

The plugin automatically generates a strong secret key upon activation. You can find it in the plugin settings. For better security, you can define headlesskey_SECRET_KEY in your wp-config.php file.

Can I use this with Next.js or other frontend frameworks?

Yes! The plugin sends correct CORS headers and returns standard JSON responses, making it compatible with any frontend framework or language that supports HTTP requests.

Does it support Public/Private keys?

Yes, you can configure RS256 or ES256 algorithms in the settings and provide your PEM formatted keys for asymmetric signing.

Changelog

Initial release. Secure your Headless WordPress with JWT today!

1.0.0

  • Initial Release: Complete authentication suite with JWT, RBAC, SSO, and Security features.
  • Security: Added Brute Force protection, Device Limits, and Security Webhooks.
  • API: Full set of endpoints for Login, Register, Password Reset, and Token Management.

Full changelog on WordPress.org →

Screenshots

General Settings - Configure Token Expiration and Security Policy.
General Settings - Configure Token Expiration and Security Policy.
Algorithms - Choose between HS256, RS256, and ES256.
Algorithms - Choose between HS256, RS256, and ES256.
Logs - View recent authentication activity.
Logs - View recent authentication activity.

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best HeadlessKey – JWT Auth alternatives

All authentication plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Limit Login Attempts Limit Login Attempts Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable. by Automattic 300K+ ★★★★★★★★★★ 4.6 (202) 4 years ago 48
2 WPS Limit Login WPS Limit Login WPS Limit login limit connection attempts by IP address by NicolasKulka 100K+ ★★★★★★★★★★ 4.9 (83) 2 weeks ago 81
3 Two Factor Two Factor Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email… by WordPress.org 100K+ ★★★★★★★★★★ 4.8 (208) 6 days ago 86
4 WP-Members Membership Plugin WP-Members Membership Plugin The original WordPress membership plugin with content restriction, user login, custom… by Chad Butler 50K+ ★★★★★★★★★★ 4.6 (273) 4 weeks ago 78
5 Google Authenticator Google Authenticator Google Authenticator for your WordPress blog. by Ivan 20K+ ★★★★★★★★★★ 4.3 (135) 1 month ago 83
6 miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) miniOrange 2FA Free 2FA plugin for unlimited users with Passkey, Google Authenticator, Email/SMS OTP, Push… by miniOrange 10K+ ★★★★★★★★★★ 4.5 (385) 3 days ago 88
7 WP Limit Login Attempts WP Limit Login Attempts Limit rate of login attempts and block IP temporarily. Brute force attack protection. GDPR… by Arshid 10K+ ★★★★★★★★★★ 4.6 (300) 3 weeks ago 88
8 Login for Google Apps by WPAuth Login for Google Apps by WPAuth Simple secure login and user management through your Google Workspace for WordPress (using… by Syed Balkhi 10K+ ★★★★★★★★★★ 4.6 (64) 5 days ago 88
9 Login by Auth0 Login by Auth0 Login by Auth0 provides improved username/password login, Passwordless login, Social login… by Auth0 10K+ ★★★★★★★★★★ 3.1 (18) 2 years ago 34
10 Two Factor (2FA) Authentication via Email Two Factor (2FA) Authentication via Email Enable one-click login with this WordPress Two-Factor Authentication (2FA) plugin… by Sully 9K+ ★★★★★★★★★★ 5 (4) 3 weeks ago 83

FAQ

HeadlessKey – JWT Auth: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 4, 2026

Is HeadlessKey – JWT Auth free?

Yes. HeadlessKey – JWT Auth is free to download and use from the official WordPress.org plugin directory.

Is HeadlessKey – JWT Auth safe to use in 2026?

HeadlessKey – JWT Auth shows warning signs in 2026 — compare the alternatives below before installing. Was last updated 8 months ago, and scores 36/100 on our health check.

How many websites use HeadlessKey – JWT Auth?

HeadlessKey – JWT Auth is active on <10 WordPress websites and has been downloaded 498 times since it launched in February 2026. It was downloaded 69 times in the last 30 days.

Does HeadlessKey – JWT Auth work with WordPress 7.1?

HeadlessKey – JWT Auth is officially tested up to WordPress 6.9.9, while the latest release is 7.1.2. It may still work, but try it on a staging site first.

What PHP version does HeadlessKey – JWT Auth need?

HeadlessKey – JWT Auth requires PHP 8.0 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was HeadlessKey – JWT Auth last updated?

The latest version, 1.0.0, was released on February 8, 2026 (8 months ago).

Who makes HeadlessKey – JWT Auth?

HeadlessKey – JWT Auth is developed and maintained by Hidayat Mahetar.

What are the best alternatives to HeadlessKey – JWT Auth?

The most popular alternatives to HeadlessKey – JWT Auth are Limit Login Attempts (300K+ installs), WPS Limit Login (100K+ installs) and Two Factor (100K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.