JSON API User
Extends the JSON API Plugin to allow RESTful user registration, authentication & many other User Meta, BP functions. A Pro version is also available.
Safe pick
Yes — JSON API User is a safe, well-maintained plugin to use in 2026. It runs on 1K+ sites, is rated 3.9/5 and was last updated 4 weeks ago, and scores 82/100 on our health check.
- Actively developed — last update 4 weeks ago
- Tested with the latest WordPress (7.1)
- Momentum — downloads up 84.4% vs the previous 30 days
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where JSON API User stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| authentication | >100 |
| json api | #3 |
| RESTful Facebook Login | #1 |
| RESTful User Meta and BuddyPress xProfile | #1 |
| RESTful user registration | #1 |
Version adoption
Share of active sites per release.
Rating breakdown
★★★★★★★★★★ 3.9 from 21 reviews
About JSON API User
From the official readme · v4.1.4Description
Important: use RESTful JSON API for new integrations
JSON API User is retained for existing sites that still depend on the original JSON API plugin and its cookie-authentication workflow. For a new mobile app, headless site, external service, or AI-assisted integration, install RESTful JSON API instead.
RESTful JSON API provides plugin-issued JWT bearer authentication, requires HTTPS by default for requests that handle passwords or tokens, and includes a broader set of endpoints organized into Core, Posts, User, Respond, and Widgets controllers. Its User controller covers signup, JWT login, token validation, profiles, avatars, password-reset requests, safe user meta, and authenticated comments. The Posts controller also provides post, custom post type, taxonomy, term, media, attachment, and comment discovery endpoints.
Existing JSON API User integrations can continue using this plugin. Because the authentication format and endpoint paths differ, test your client migration before deactivating the legacy JSON API stack.
JSON API User extends the JSON API Plugin with a new Controller to allow RESTful user registration, authentication, password reset, RESTful Facebook Login, RESTful User Meta and BuddyPress xProfile get and update methods. This plugin is for WordPress/Mobile app developers who want to use WordPress as mobile app data backend.
JSON API Plugin, that is required, was closed on August 7, 2019 from WordPress repository. You can download JSON API Plugin from https://github.com/PI-Media/json-api until it is republished and available on WordPress.
Features include:
- Generate Auth Cookie for user authentication
- Validate Auth Cookie
- RESTful User Registration
- RESTful Facebook Login/Registration with valid access_token
- RESTful BuddyPress xProfile fields update
- Get User Meta and xProfile fields
- Update User Meta and xProfile fields
- Delete User Meta
- Password Reset
- Get Avatar
- Get User Info
- Post Comment
The plugin was created for mobile apps integration with the web app using WordPress as backend for all the data. WordPress helped in putting together the web app quickly and then Mobile iOS and Android apps were integrated via this plugin. There were some app specific customized methods which are not included but rest have been made generic for community usage.
My other JSON API Auth plugin has also been integrated with this plugin from version 1.1 because most endpoints required user authentication via cookie for data update.
Pro Version – JSON API User Plus
A pro version of this plugin, JSON API User Plus, is available here http://www.parorrey.com/solutions/json-api-user-plus/ that supports BuddyPress Messages component, BuddyPress avatar upload, BuddyPress Extended Profile, BuddyPress Groups, BuddyPress Friends, BuddyPress Activity, BuddyPress Notifications, BuddyPres Settings and other BuddyPress related functions to integrate BuddyPress features in your mobile app via REST api.
JSON API User Plus includes API key which protects and restricts the endpoint calls. This key can be updated from Settings > User Plus options page. Your app must include this key with every call to get the data from REST API. Please see documentation for calling endpoints examples for ‘JSON API User Plus’.
JSON API User Plus features include:
- Generate Auth Cookie for user authentication
- Validate Auth Cookie
- RESTful User Registration
- RESTful Facebook Login/Registration with valid access_token
- RESTful BuddyPress xProfile fields update
- Get User Meta and xProfile fields
- Update User Meta and xProfile fields
- Delete User Meta
- Password Reset
- Get/Upload Avatar
- Get User Info
- Post Comment
- Add Post, Update Post, Delete Post
- Add/Edit/Delete Custom Post Type, Custom Fields
- Search User
- BuddyPress Activities
- BuddyPress Members
- BuddyPress Friends
- BuddyPress Notifications
- BuddyPress Settings
- & many more
Installation
First you have to install the JSON API for WordPress Plugin (https://wordpress.org/extend/plugins/json-api/installation/).
To install JSON API User just follow these steps:
- Upload the folder “json-api-user” to your WordPress plugin folder (/wp-content/plugins)
- Activate the plugin through the ‘Plugins’ menu in WordPress or by using the link provided by the plugin installer
- Activate the controller through the JSON API menu found in the WordPress admin center (Settings -> JSON API)
Frequently asked questions
Method: info
http://localhost/api/user/info/ This returns plugin version.
Method: register
http://localhost/api/user/register/?username=john&email=john@domain.com&nonce=8bdfeb4e16&display_name=John¬ify=both To register user & get valid cookie for 100 seconds: http://localhost/api/user/register/?username=john&email=john@domain.com&display_name=John¬ify=both&seconds=100 Optional fields: ‘user_pass’, ‘user_nicename’, ‘user_url’, ‘nickname’, ‘first_name’, ‘last_name’, ‘description’, ‘rich_editing’, ‘user_registered’, ‘jabber’, ‘aim’, ‘yim’, ‘comment_shortcuts’, ‘admin_color’, ‘use_ssl’, ‘show_admin_bar_front’. Please make sure you provide valid values that these fields expect in…
Method: fb_connect
It needs valid ‘access_token’ var. http://localhost/api/user/fb_connect/?access_token=CAACEdEose0cBADLKmcHWOZCnW4RGU8emG Provide valid access_token with email extended permission. To generate test access_token, try this tool https://developers.facebook.com/tools/explorer/ and select the app from above drop down that you want to get access_token (You must have joined that app already with email permission to generate access_token) for and then select email from the fields. By default, only ‘id’ and ‘name’ are added but you need to include ’email’ for user identification. You will have to first…
Method: validate_auth_cookie
It needs ‘cookie’ var. http://localhost/api/user/validate_auth_cookie/?cookie=admin|43089754375034fjwfn39u8
Method: generate_auth_cookie
It needs username, password vars. seconds is optional. First get the nonce: http://localhost/api/get_nonce/?controller=user&method=generate_auth_cookie Then generate cookie: http://localhost/api/user/generate_auth_cookie/?username=john&password=PASSWORD-HERE Optional ‘seconds’ var. It provided, generated cookie will be valid for that many seconds, otherwise default is for 14 days. generate cookie for 1 minute: http://localhost/api/user/generate_auth_cookie/?username=john&password=PASSWORD-HERE&seconds=60 60 means 1 minute.
Method: delete_user_meta
It needs ‘cookie’ and ‘meta_key’ var and ‘meta_value’ to delete. http://localhost/api/user/delete_user_meta/?cookie=COOKIE-HERE&meta_key=KEY-HERE&meta_value=VALUE-HERE
Method: update_user_meta
It needs ‘cookie’ and ‘meta_key’ var and ‘meta_value’ to update. You must include a ‘meta_value’ var in your request. If you have multiple values for any meta_key, you must send it as an array meta_value[] in POST method. http://localhost/api/user/update_user_meta/?cookie=COOKIE-HERE&meta_key=KEY-HERE&meta_value=VALUE-HERE
Method: update_user_meta_vars
It needs ‘cookie’ and any user meta variables. This endpoint allows you cut http requests if you have to add/update more than one user_meta field at a time. http://localhost/api/user/update_user_meta_vars/ In the above endpoint use custom_fields[‘website’]=domain.com, custom_fields[‘city’]=NYC, custom_fields[‘country’]=USA as meta_key for WordPress user_meta values using POST method. If you have multiple values for any variable, you must send it as an array i.e. variable_name[] in POST method. For instance, you have skills variable with multiple values, you will send a…
Method: get_user_meta
It needs ‘user_id’. ‘meta_key’ var is optional. http://localhost/api/user/get_user_meta/?cookie=COOKIE-HERE&meta_key=KEY-HERE
Method: xprofile
It needs ‘user_id’ and any profile ‘field’ var. http://localhost/api/user/xprofile/?user_id=USERID-HERE&field=FIELD-LABEL-HERE
Method: xprofile_update
It needs ‘cookie’ and any profile ‘field’ var and ‘value’. http://localhost/api/user/xprofile_update/?cookie=COOKIE-HERE&exact-xprofile-field-label=value http://localhost/api/user/xprofile_update/?cookie=COOKIE-HERE&field=value&field2=value&multi-value-field=value1,value2,value3 Please make sure you provide ending comma for all those fields which have multiple values. e.g. If ‘skills’ xProfile field has multiple values, pass them like http://localhost/api/user/xprofile_update/?cookie=COOKIE-HERE&skills=PHP,MySQL, or &skills=PHP, make sure you always pass ending comma for multi-select fields…
Method: retrieve_password
It needs user_login var. http://localhost/api/user/retrieve_password/?user_login=john
Method: get_avatar
It needs user_id var. http://localhost/api/user/get_avatar/?user_id=1
Method: get_userinfo
It needs user_id var. http://localhost/api/user/get_userinfo/?user_id=1
Method: post_comment
It needs ‘cookie’, ‘post_id’, ‘content’ vars. ‘comment_status’ is optional. http://localhost/api/user/post_comment/?cookie=COOKIE-HERE&post_id=ID&content=Comment contents here&comment_status=1 Comment content is sanitized with wp_filter_post_kses() before being saved, and the comment is inserted via wp_new_comment() so normal WordPress comment moderation, flood checks, and spam filtering (e.g. Akismet) still apply. ‘comment_status=1’ only auto-approves the comment if the authenticated user has the ‘moderate_comments’ capability (e.g. Editor/Administrator); otherwise the comment falls back to…
Changelog
4.1.4
- Tested and confirmed compatible with WordPress 7.1.
- Confirmed the secure Parorrey donation link.
4.1.3
- Added a migration notice recommending the newer RESTful JSON API plugin for new projects.
- Documented its JWT bearer authentication, HTTPS-by-default protection, and broader controller-based endpoint set.
- Added secure WordPress.org and donation links.
4.1.2
- Updated for WP, php version
4.1.1
- Security fix: fixed a security vulnerability.
4.1.0
- For new version of WordPress 6.8
4.0.0
- bug fix for array, for new version of WordPress 6.6.2
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best JSON API User alternatives
All authentication plugins →FAQ
JSON API User: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Oct 4, 2026
Is JSON API User free?
Yes. JSON API User is free to download and use from the official WordPress.org plugin directory.
Is JSON API User safe to use in 2026?
Yes — JSON API User is a safe, well-maintained plugin to use in 2026. It runs on 1K+ sites, is rated 3.9/5 and was last updated 4 weeks ago, and scores 82/100 on our health check.
How many websites use JSON API User?
JSON API User is active on 1K+ WordPress websites and has been downloaded 125,196 times since it launched in December 2013. It was downloaded 1,143 times in the last 30 days.
Does JSON API User work with WordPress 7.1?
Yes. The developer has tested JSON API User up to WordPress 7.1.2, the latest release. It requires WordPress 3.0.1 or newer.
What PHP version does JSON API User need?
JSON API User requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was JSON API User last updated?
The latest version, 4.1.4, was released on September 7, 2026 (4 weeks ago).
Who makes JSON API User?
JSON API User is developed and maintained by Ali Qureshi.
What are the best alternatives to JSON API User?
The most popular alternatives to JSON API User are Limit Login Attempts (300K+ installs), WPS Limit Login (100K+ installs) and Two Factor (100K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card


