OpenID Connect Server
Use OpenID Connect to log in to other webservices using your own WordPress.
Solid choice
OpenID Connect Server is a solid plugin choice in 2026, with a few things worth checking first. It runs on 100+ sites and was last updated 2 weeks ago, and scores 68/100 on our health check.
- Actively developed — last update 2 weeks ago
- Tested with the latest WordPress (7.1)
- Small user base (100+ active installs)
- Very few reviews so far
How does it stack up?
Side-by-side on installs, updates, ratings & supportDaily downloads
Download spikes usually follow a new release — each site that auto-updates counts as a download.
Rankings
Where OpenID Connect Server stands todayWordPress.org search rankings
Live position in the plugin search, top 100| Keyword | Position |
|---|---|
| oauth | >100 |
| oauth server | #18 |
| oidc | #11 |
| OpenID | #6 |
| openid connect | #5 |
Version adoption
Share of active sites per release.
About OpenID Connect Server
From the official readme · v2.0.3Description
With this plugin you can use your own WordPress install to authenticate with a webservice that provides OpenID Connect to implement Single-Sign On (SSO) for your users.
The plugin is currently only configured using constants and hooks as follows:
Define the RSA keys
If you don’t have keys that you want to use yet, generate them using these commands:
openssl genrsa -out oidc.key 4096
openssl rsa -in oidc.key -pubout -out public.key
And make them available to the plugin as follows (this needs to be added before WordPress loads):
define( 'OIDC_PUBLIC_KEY', <<<OIDC_PUBLIC_KEY
-----BEGIN PUBLIC KEY-----
...
-----END PUBLIC KEY-----
OIDC_PUBLIC_KEY
);
define( 'OIDC_PRIVATE_KEY', <<<OIDC_PRIVATE_KEY
-----BEGIN PRIVATE KEY-----
...
-----END PRIVATE KEY-----
OIDC_PRIVATE_KEY
);
Alternatively, you can also put them outside the webroot and load them from the files like this:
define( 'OIDC_PRIVATE_KEY', file_get_contents( '/web-inaccessible/oidc.key' ) );
define( 'OIDC_PUBLIC_KEY', file_get_contents( '/web-inaccessible/public.key' ) );
Define the clients
Define your clients by adding a filter to oidc_registered_clients in a separate plugin file or functions.php of your theme or in a MU-plugin like:
add_filter( 'oidc_registered_clients', 'my_oidc_clients' );
function my_oidc_clients() {
return array(
'client_id_random_string' => array(
'name' => 'The name of the Client',
'secret' => 'a secret string',
'redirect_uri' => 'https://example.com/redirect.uri',
'grant_types' => array( 'authorization_code' ),
'scope' => 'openid profile',
),
);
}
Exclude URL from caching
example.com/wp-json/openid-connect/userinfo: We implement caching exclusion measures for this endpoint by settingCache-Control: 'no-cache'headers and defining theDONOTCACHEPAGEconstant. If you have a unique caching configuration, please ensure that you manually exclude this URL from caching.
Github Repo
You can report any issues you encounter directly on Github repo: Automattic/wp-openid-connect-server
Changelog
2.0.3
- Align plugin version metadata with the published release version. No code changes since 2.0.2.
2.0.2
- No code changes since 2.0.1.
2.0.1
- Reject invalid JWT algorithm values in access tokens #136.
- Handle a null return from
wp_parse_url()#130. - Update the documentation and WordPress compatibility information #123, #125.
- Fix the WordPress.org deployment workflow’s SVN installation #121 and pin third-party GitHub Actions #133.
2.0.0
- [Breaking] Add a configuration option to support clients that don’t require consent #118 props @lart2150
- Make client_id and client_secret optional for the token endpoint #116 props @lart2150
- Update expected args specs for token endpoint as per OIDC spec #117
1.3.4
- Add the autoloader to the uninstall script #111 props @MariaMozgunova
1.3.3
- Fix failing login when Authorize form is non-English [#108]
- Improvements in site health tests for key detection [#104][#105]
1.3.2
- Prevent userinfo endpoint from being cached [#99]
1.3.0
- Return
display_nameas thenameproperty [#87] - Change text domain to
openid-connect-server, instead ofwp-openid-connect-server[#88]
1.2.1
- No user facing changes
1.2.0
- Add
oidc_user_claimsfilter [#82]
For developers
Is this your plugin? Show off the numbers.
Add a live badge to your site, docs or GitHub README. It updates on its own — no account needed.
Best OpenID Connect Server alternatives
All oauth plugins →FAQ
OpenID Connect Server: quick answers
Straight answers, pulled from live WordPress.org data.
Live data from WordPress.org · checked Sep 28, 2026
Is OpenID Connect Server free?
Yes. OpenID Connect Server is free to download and use from the official WordPress.org plugin directory.
Is OpenID Connect Server safe to use in 2026?
OpenID Connect Server is a solid plugin choice in 2026, with a few things worth checking first. It runs on 100+ sites and was last updated 2 weeks ago, and scores 68/100 on our health check.
How many websites use OpenID Connect Server?
OpenID Connect Server is active on 100+ WordPress websites and has been downloaded 10,318 times since it launched in October 2022. It was downloaded 470 times in the last 30 days.
Does OpenID Connect Server work with WordPress 7.1?
Yes. The developer has tested OpenID Connect Server up to WordPress 7.1.2, the latest release. It requires WordPress 6.0 or newer.
What PHP version does OpenID Connect Server need?
OpenID Connect Server requires PHP 7.4 or higher. Most hosts run PHP 8.x today, so it works on any modern WordPress hosting.
When was OpenID Connect Server last updated?
The latest version, 2.0.3, was released on September 17, 2026 (2 weeks ago).
Who makes OpenID Connect Server?
OpenID Connect Server is developed and maintained by Automattic.
What are the best alternatives to OpenID Connect Server?
The most popular alternatives to OpenID Connect Server are JWT Authentication for WP R… (60K+ installs), Gmail SMTP (10K+ installs) and Login for Google Apps (10K+ installs).
Powered by PageForge
Want thousands of pages that rank like these? Build them in an afternoon.
This directory runs on the same engine as PageForge. Turn any spreadsheet, CSV or API into thousands of fast, SEO-ready WordPress pages — with schema, internal links and AI-written copy baked in.
- CSV, Google Sheets & API data sources
- AI content, schema & internal links per page
- Works with Elementor, Gutenberg, Yoast & Rank Math
- Free on WordPress.org — no credit card