BLACK FRIDAY
Save 59% on PageForge Annual $191/year $485/year
Claim 59% Off →
JSON API User icon
Actively maintained Tested with WP 7.1 #26 in authentication

JSON API User

Extends the JSON API Plugin to allow RESTful user registration, authentication & many other User Meta, BP functions. A Pro version is also available.

Active installs1K+1K+ tier
Downloads · 30d1.1K▲ +84.4% vs prev. 30d
Rating3.9/521 reviews
Health score82/100Excellent
All-time downloads125.2KSince Dec 2013
Support resolved—No recent threads
RequiresWP 3.0.1PHP 7.4+
Downloads · 7d205▼ -1.9% week over week
Our verdict

Safe pick

Yes — JSON API User is a safe, well-maintained plugin to use in 2026. It runs on 1K+ sites, is rated 3.9/5 and was last updated 4 weeks ago, and scores 82/100 on our health check.

  • Actively developed — last update 4 weeks ago
  • Tested with the latest WordPress (7.1)
  • Momentum — downloads up 84.4% vs the previous 30 days

How does it stack up?

Side-by-side on installs, updates, ratings & support

Daily downloads

60120180Jul 6Aug 19Oct 3
Yesterday32
Daily average (1y)17
Peak day241Sep 8, 2026
Last 12 months6.1K

Download spikes usually follow a new release — each site that auto-updates counts as a download.

Rankings

Where JSON API User stands today

WordPress.org search rankings

Live position in the plugin search, top 100
KeywordPositionCompeting pluginsCategory
authentication >100 4,351 Best authentication plugins →
json api #3 4,941 Best json api plugins →
RESTful Facebook Login #1 4 Best RESTful Facebook Login plugins →
RESTful User Meta and BuddyPress xProfile #1 1 Best RESTful User Meta and BuddyPress xProfile plugins →
RESTful user registration #1 14 Best RESTful user registration plugins →

Version adoption

Share of active sites per release.

  • 4.140.8%
  • 3.920.6%
  • 2.88.1%
  • 4.07.8%
  • 3.86.0%
  • Other16.7%

Rating breakdown

★★★★★★★★★★ 3.9 from 21 reviews

  • 5★66.7%
  • 4★4.8%
  • 3★4.8%
  • 2★0.00%
  • 1★23.8%

About JSON API User

From the official readme · v4.1.4

Description

Important: use RESTful JSON API for new integrations

JSON API User is retained for existing sites that still depend on the original JSON API plugin and its cookie-authentication workflow. For a new mobile app, headless site, external service, or AI-assisted integration, install RESTful JSON API instead.

RESTful JSON API provides plugin-issued JWT bearer authentication, requires HTTPS by default for requests that handle passwords or tokens, and includes a broader set of endpoints organized into Core, Posts, User, Respond, and Widgets controllers. Its User controller covers signup, JWT login, token validation, profiles, avatars, password-reset requests, safe user meta, and authenticated comments. The Posts controller also provides post, custom post type, taxonomy, term, media, attachment, and comment discovery endpoints.

Existing JSON API User integrations can continue using this plugin. Because the authentication format and endpoint paths differ, test your client migration before deactivating the legacy JSON API stack.

JSON API User extends the JSON API Plugin with a new Controller to allow RESTful user registration, authentication, password reset, RESTful Facebook Login, RESTful User Meta and BuddyPress xProfile get and update methods. This plugin is for WordPress/Mobile app developers who want to use WordPress as mobile app data backend.

JSON API Plugin, that is required, was closed on August 7, 2019 from WordPress repository. You can download JSON API Plugin from https://github.com/PI-Media/json-api until it is republished and available on WordPress.

Features include:

  • Generate Auth Cookie for user authentication
  • Validate Auth Cookie
  • RESTful User Registration
  • RESTful Facebook Login/Registration with valid access_token
  • RESTful BuddyPress xProfile fields update
  • Get User Meta and xProfile fields
  • Update User Meta and xProfile fields
  • Delete User Meta
  • Password Reset
  • Get Avatar
  • Get User Info
  • Post Comment

The plugin was created for mobile apps integration with the web app using WordPress as backend for all the data. WordPress helped in putting together the web app quickly and then Mobile iOS and Android apps were integrated via this plugin. There were some app specific customized methods which are not included but rest have been made generic for community usage.

My other JSON API Auth plugin has also been integrated with this plugin from version 1.1 because most endpoints required user authentication via cookie for data update.

Pro Version – JSON API User Plus

A pro version of this plugin, JSON API User Plus, is available here http://www.parorrey.com/solutions/json-api-user-plus/ that supports BuddyPress Messages component, BuddyPress avatar upload, BuddyPress Extended Profile, BuddyPress Groups, BuddyPress Friends, BuddyPress Activity, BuddyPress Notifications, BuddyPres Settings and other BuddyPress related functions to integrate BuddyPress features in your mobile app via REST api.

JSON API User Plus includes API key which protects and restricts the endpoint calls. This key can be updated from Settings > User Plus options page. Your app must include this key with every call to get the data from REST API. Please see documentation for calling endpoints examples for ‘JSON API User Plus’.

JSON API User Plus features include:

  • Generate Auth Cookie for user authentication
  • Validate Auth Cookie
  • RESTful User Registration
  • RESTful Facebook Login/Registration with valid access_token
  • RESTful BuddyPress xProfile fields update
  • Get User Meta and xProfile fields
  • Update User Meta and xProfile fields
  • Delete User Meta
  • Password Reset
  • Get/Upload Avatar
  • Get User Info
  • Post Comment
  • Add Post, Update Post, Delete Post
  • Add/Edit/Delete Custom Post Type, Custom Fields
  • Search User
  • BuddyPress Activities
  • BuddyPress Members
  • BuddyPress Friends
  • BuddyPress Notifications
  • BuddyPress Settings
  • & many more

Installation

First you have to install the JSON API for WordPress Plugin (https://wordpress.org/extend/plugins/json-api/installation/).

To install JSON API User just follow these steps:

  • Upload the folder “json-api-user” to your WordPress plugin folder (/wp-content/plugins)
  • Activate the plugin through the ‘Plugins’ menu in WordPress or by using the link provided by the plugin installer
  • Activate the controller through the JSON API menu found in the WordPress admin center (Settings -> JSON API)

Frequently asked questions

Method: info

http://localhost/api/user/info/ This returns plugin version.

Method: register

http://localhost/api/user/register/?username=john&email=john@domain.com&nonce=8bdfeb4e16&display_name=John&notify=both To register user & get valid cookie for 100 seconds: http://localhost/api/user/register/?username=john&email=john@domain.com&display_name=John&notify=both&seconds=100 Optional fields: ‘user_pass’, ‘user_nicename’, ‘user_url’, ‘nickname’, ‘first_name’, ‘last_name’, ‘description’, ‘rich_editing’, ‘user_registered’, ‘jabber’, ‘aim’, ‘yim’, ‘comment_shortcuts’, ‘admin_color’, ‘use_ssl’, ‘show_admin_bar_front’. Please make sure you provide valid values that these fields expect in…

Method: fb_connect

It needs valid ‘access_token’ var. http://localhost/api/user/fb_connect/?access_token=CAACEdEose0cBADLKmcHWOZCnW4RGU8emG Provide valid access_token with email extended permission. To generate test access_token, try this tool https://developers.facebook.com/tools/explorer/ and select the app from above drop down that you want to get access_token (You must have joined that app already with email permission to generate access_token) for and then select email from the fields. By default, only ‘id’ and ‘name’ are added but you need to include ’email’ for user identification. You will have to first…

Method: validate_auth_cookie

It needs ‘cookie’ var. http://localhost/api/user/validate_auth_cookie/?cookie=admin|43089754375034fjwfn39u8

Method: generate_auth_cookie

It needs username, password vars. seconds is optional. First get the nonce: http://localhost/api/get_nonce/?controller=user&method=generate_auth_cookie Then generate cookie: http://localhost/api/user/generate_auth_cookie/?username=john&password=PASSWORD-HERE Optional ‘seconds’ var. It provided, generated cookie will be valid for that many seconds, otherwise default is for 14 days. generate cookie for 1 minute: http://localhost/api/user/generate_auth_cookie/?username=john&password=PASSWORD-HERE&seconds=60 60 means 1 minute.

Method: delete_user_meta

It needs ‘cookie’ and ‘meta_key’ var and ‘meta_value’ to delete. http://localhost/api/user/delete_user_meta/?cookie=COOKIE-HERE&meta_key=KEY-HERE&meta_value=VALUE-HERE

Method: update_user_meta

It needs ‘cookie’ and ‘meta_key’ var and ‘meta_value’ to update. You must include a ‘meta_value’ var in your request. If you have multiple values for any meta_key, you must send it as an array meta_value[] in POST method. http://localhost/api/user/update_user_meta/?cookie=COOKIE-HERE&meta_key=KEY-HERE&meta_value=VALUE-HERE

Method: update_user_meta_vars

It needs ‘cookie’ and any user meta variables. This endpoint allows you cut http requests if you have to add/update more than one user_meta field at a time. http://localhost/api/user/update_user_meta_vars/ In the above endpoint use custom_fields[‘website’]=domain.com, custom_fields[‘city’]=NYC, custom_fields[‘country’]=USA as meta_key for WordPress user_meta values using POST method. If you have multiple values for any variable, you must send it as an array i.e. variable_name[] in POST method. For instance, you have skills variable with multiple values, you will send a…

Method: get_user_meta

It needs ‘user_id’. ‘meta_key’ var is optional. http://localhost/api/user/get_user_meta/?cookie=COOKIE-HERE&meta_key=KEY-HERE

Method: xprofile

It needs ‘user_id’ and any profile ‘field’ var. http://localhost/api/user/xprofile/?user_id=USERID-HERE&field=FIELD-LABEL-HERE

Method: xprofile_update

It needs ‘cookie’ and any profile ‘field’ var and ‘value’. http://localhost/api/user/xprofile_update/?cookie=COOKIE-HERE&exact-xprofile-field-label=value http://localhost/api/user/xprofile_update/?cookie=COOKIE-HERE&field=value&field2=value&multi-value-field=value1,value2,value3 Please make sure you provide ending comma for all those fields which have multiple values. e.g. If ‘skills’ xProfile field has multiple values, pass them like http://localhost/api/user/xprofile_update/?cookie=COOKIE-HERE&skills=PHP,MySQL, or &skills=PHP, make sure you always pass ending comma for multi-select fields…

Method: retrieve_password

It needs user_login var. http://localhost/api/user/retrieve_password/?user_login=john

Method: get_avatar

It needs user_id var. http://localhost/api/user/get_avatar/?user_id=1

Method: get_userinfo

It needs user_id var. http://localhost/api/user/get_userinfo/?user_id=1

Method: post_comment

It needs ‘cookie’, ‘post_id’, ‘content’ vars. ‘comment_status’ is optional. http://localhost/api/user/post_comment/?cookie=COOKIE-HERE&post_id=ID&content=Comment contents here&comment_status=1 Comment content is sanitized with wp_filter_post_kses() before being saved, and the comment is inserted via wp_new_comment() so normal WordPress comment moderation, flood checks, and spam filtering (e.g. Akismet) still apply. ‘comment_status=1’ only auto-approves the comment if the authenticated user has the ‘moderate_comments’ capability (e.g. Editor/Administrator); otherwise the comment falls back to…

Changelog

4.1.4

  • Tested and confirmed compatible with WordPress 7.1.
  • Confirmed the secure Parorrey donation link.

4.1.3

  • Added a migration notice recommending the newer RESTful JSON API plugin for new projects.
  • Documented its JWT bearer authentication, HTTPS-by-default protection, and broader controller-based endpoint set.
  • Added secure WordPress.org and donation links.

4.1.2

  • Updated for WP, php version

4.1.1

  • Security fix: fixed a security vulnerability.

4.1.0

  • For new version of WordPress 6.8

4.0.0

  • bug fix for array, for new version of WordPress 6.6.2

Full changelog on WordPress.org →

Screenshots

Call to generate_auth_cookie endpoint using Postman
Call to generate_auth_cookie endpoint using Postman
Call to get_currentuserinfo endpoint using Postman
Call to get_currentuserinfo endpoint using Postman
Call to validate_auth_cookie endpoint using Postman
Call to validate_auth_cookie endpoint using Postman

For developers

Is this your plugin? Show off the numbers.

Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.

Active installs badge Rating badge Health score badge

Best JSON API User alternatives

All authentication plugins →
Alternatives
Rank Plugin Active installs Rating Updated Health
1 Limit Login Attempts Limit Login Attempts Limit rate of login attempts, including by way of cookies, for each IP. Fully customizable. by Automattic 300K+ ★★★★★★★★★★ 4.6 (202) 4 years ago 48
2 WPS Limit Login WPS Limit Login WPS Limit login limit connection attempts by IP address by NicolasKulka 100K+ ★★★★★★★★★★ 4.9 (83) 2 weeks ago 81
3 Two Factor Two Factor Enable Two-Factor Authentication (2FA) using time-based one-time passwords (TOTP), email… by WordPress.org 100K+ ★★★★★★★★★★ 4.8 (208) 6 days ago 86
4 WP-Members Membership Plugin WP-Members Membership Plugin The original WordPress membership plugin with content restriction, user login, custom… by Chad Butler 50K+ ★★★★★★★★★★ 4.6 (272) 4 weeks ago 78
5 Google Authenticator Google Authenticator Google Authenticator for your WordPress blog. by Ivan 20K+ ★★★★★★★★★★ 4.3 (135) 1 month ago 83
6 miniOrange 2FA – Two Factor Authentication for WordPress (OTP, SMS, Email, Google Authenticator) miniOrange 2FA Free 2FA plugin for unlimited users with Passkey, Google Authenticator, Email/SMS OTP, Push… by miniOrange 10K+ ★★★★★★★★★★ 4.5 (385) 3 days ago 88
7 WP Limit Login Attempts WP Limit Login Attempts Limit rate of login attempts and block IP temporarily. Brute force attack protection. GDPR… by Arshid 10K+ ★★★★★★★★★★ 4.6 (300) 3 weeks ago 88
8 Login for Google Apps by WPAuth Login for Google Apps by WPAuth Simple secure login and user management through your Google Workspace for WordPress (using… by Syed Balkhi 10K+ ★★★★★★★★★★ 4.6 (64) 5 days ago 88
9 Login by Auth0 Login by Auth0 Login by Auth0 provides improved username/password login, Passwordless login, Social login… by Auth0 10K+ ★★★★★★★★★★ 3.1 (18) 2 years ago 34
10 Two Factor (2FA) Authentication via Email Two Factor (2FA) Authentication via Email Enable one-click login with this WordPress Two-Factor Authentication (2FA) plugin… by Sully 9K+ ★★★★★★★★★★ 5 (4) 3 weeks ago 83

FAQ

JSON API User: quick answers

Straight answers, pulled from live WordPress.org data.

Live data from WordPress.org · checked Oct 4, 2026

Is JSON API User free?

Yes. JSON API User is free to download and use from the official WordPress.org plugin directory.

Is JSON API User safe to use in 2026?

Yes — JSON API User is a safe, well-maintained plugin to use in 2026. It runs on 1K+ sites, is rated 3.9/5 and was last updated 4 weeks ago, and scores 82/100 on our health check.

How many websites use JSON API User?

JSON API User is active on 1K+ WordPress websites and has been downloaded 125,196 times since it launched in December 2013. It was downloaded 1,143 times in the last 30 days.

Does JSON API User work with WordPress 7.1?

Yes. The developer has tested JSON API User up to WordPress 7.1.2, the latest release. It requires WordPress 3.0.1 or newer.

What PHP version does JSON API User need?

JSON API User requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.

When was JSON API User last updated?

The latest version, 4.1.4, was released on September 7, 2026 (4 weeks ago).

Who makes JSON API User?

JSON API User is developed and maintained by Ali Qureshi.

What are the best alternatives to JSON API User?

The most popular alternatives to JSON API User are Limit Login Attempts (300K+ installs), WPS Limit Login (100K+ installs) and Two Factor (100K+ installs).

Powered by PageForge

Want thousands of pages that rank like these? Build them in an afternoon.

This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.

  • CSV, Google Sheets & API data sources
  • AI content, schema & internal links per page
  • Works with Elementor, Gutenberg, Yoast & Rank Math
  • Free on WordPress.org — no credit card
Sarah is here to help!
Hi there! 👋 Need help finding what you're looking for?
Sarah
Sarah
Online & Ready to Help
Hi there! 👋 Need help finding what you're looking for?

We'll use this to continue our conversation

Just now ✓ Verified

Join 500+ SEO Pros Scaling Their Strategy

Get exclusive programmatic SEO tactics, AI content workflows, and the latest PageForge updates delivered straight to your inbox. Stay ahead of the algorithm.

We care about your data in our privacy policy.