Hippoo Auth
Hippoo Auth enhances the WooCommerce Store API by adding secure JWT-based authentication endpoints. It supports login and signup via Google, Facebook, Apple, or manually with email and password. Once authenticated…
Use with caution
Hippoo Auth works, but test it on a staging site before relying on it in 2026. Is rated 5/5 and was last updated 4 weeks ago, and scores 59/100 on our health check.
- Actively developed — last update 4 weeks ago
- Small user base (<10 active installs)
- Very few reviews so far
- Only tested up to WordPress 6.8 (latest is 7.1)
Daily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where Hippoo Auth stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| Headless WooCommerce | #73 |
| jwt | #61 |
| rest-api | >100 |
| social login | >100 |
| woocommerce | >100 |
Rating breakdown
★★★★★★★★★★ 5 from 1 reviews
About Hippoo Auth
From the official readme · v1.1.1Description
Hippoo Auth enhances the WooCommerce Store API by adding secure JWT-based authentication endpoints. It supports login and signup via Google, Facebook, Apple, or manually with email and password. Once authenticated, users can retrieve and update their billing/shipping information, view order history, and more — all via API.
Perfect for developers building API-driven themes, custom mobile apps, or headless WooCommerce experiences.
Use it to build:
- Headless WooCommerce themes
- Custom frontend apps (React, Vue, etc.)
- Mobile apps using Flutter, React Native, or Kotlin
- API-based user dashboards
With Hippoo Auth, users can register, login (manually or via Google, Apple, or Facebook), and securely access:
- Order history and details
- Billing and shipping addresses
- JWT-based session tokens with refresh support
🔐 Auth is handled via JWT for secure stateless sessions, ideal for frontend-heavy or decoupled environments.
📘 Developer Docs:
https://hippoo.app/hippoo-auth-web-service-documentation-for-authentication-and-user-management-in-woocommerce/
Features
- REST API login with JWT tokens
- Social login (Google, Facebook, Apple)
- Secure signup and password reset
- Access to orders and addresses via API
- Built-in token refresh and logout endpoint
- Compatible with WooCommerce stores and custom frontends
- No dependency on the Hippoo App
External services
This plugin connects to third-party services for social authentication:
-
Google OAuth API: Used to verify Google login tokens. Sends OAuth access token.
Privacy Policy, Terms of Service -
Facebook Graph API: Used to fetch user info (ID, email, name). Sends OAuth access token.
Privacy Policy, Terms -
Apple ID Authentication API: Used for sign-in via Apple. Sends OAuth access token.
Privacy Policy, Terms
These are required for enabling social login functionality.
Credits
This plugin was built with the Hippoo team — creators of the Hippoo WooCommerce App, a mobile app that helps you manage store orders, products, coupons, and more on the go.
Installation
- Upload the
hippoo-authfolder to the/wp-content/plugins/directory. - Activate the plugin through the ‘Plugins’ menu in WordPress.
- Visit the Hippoo Auth settings page to configure the plugin.
- Use the endpoints immediately, or check the official docs
Changelog
1.1.1
- Improved token signing key handling.
1.1.0
- Stateless REST auth:
hippoo_auth_permission_checkno longer sets WordPress/WooCommerce session cookies on every authenticated call. The permission callback now useswp_set_current_user()for the current request only. Fixes intermittent502 Bad Gatewayresponses on authenticated routes caused by response headers overflowing nginx’s default FastCGI buffer. - JWT token validation (
hippoo_auth_validate_access_token,hippoo_auth_validate_refresh_token) now catches\Throwable(not just\Exception) soTypeError/Errorfrom the JWT library surface as clean 401 responses instead of PHP fatals. Addeduser_idandWP_Userguards to eliminate a latent “property of non-object” notice. - Fixed Apple social-login JWT decode:
hippoo_auth_verify_apple_tokennow wraps the parsed public key innew Key( $pem, 'RS256' )as required by firebase/php-jwt v6+ (was using the v5 signature and throwing an uncaughtTypeError).
1.0.4
- Fix
Invalid argument supplied for foreach()warning in autoload — capture prefixes via closureuse()instead of relying onglobal(the array sits in plugin-file scope, not global scope).
1.0.3
- Maintenance Release
1.0.1
- Minor bug fix.
1.0.0
- Initial release.
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
FAQ
Hippoo Auth: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 4, 2026
Is Hippoo Auth free?
Yes. Hippoo Auth is free to download and use from the official WordPress.org plugin directory.
Is Hippoo Auth safe to use in 2026?
Hippoo Auth works, but test it on a staging site before relying on it in 2026. Is rated 5/5 and was last updated 4 weeks ago, and scores 59/100 on our health check.
How many websites use Hippoo Auth?
Hippoo Auth is active on <10 WordPress websites and has been downloaded 935 times since it launched in June 2025. It was downloaded 164 times in the last 30 days.
Does Hippoo Auth work with WordPress 7.1?
Hippoo Auth is officially tested up to WordPress 6.8.10, while the latest release is 7.1.2. It may still work, but try it on a staging site first.
What PHP version does Hippoo Auth need?
Hippoo Auth requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was Hippoo Auth last updated?
The latest version, 1.1.1, was released on September 5, 2026 (4 weeks ago).
Who makes Hippoo Auth?
Hippoo Auth is developed and maintained by hippoosupport.
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card