WP OAuth Server (OAuth Authentication)
View on WordPress.orgScores higher than 37% of indexed plugins
About
Adds Authentication through OAuth 2. Provides the ability for Single Sign On for websites & Mobile Applications.
Security History
What It Does
WP OAuth Server turns a WordPress site into a functioning OAuth 2.0 provider, letting external clients such as mobile apps, single page applications, and third party services authenticate users against WordPress user accounts. It handles the standard OAuth 2.0 flows including authorization code, implicit, client credentials, and password grants, issuing access tokens that other systems can validate. In practice this means you can use WordPress as the identity backbone for a broader application ecosystem without building a separate auth service.
Who It's For
This plugin fits developers and technical teams who need WordPress to act as the central identity provider for a multi-platform product, whether that is a mobile app, a SaaS offering, or a network of connected sites. It is best suited to shops comfortable working with token lifetimes, scopes, and client credentials at the code level. Small business owners running a brochure site or basic blog will get no value from it.
Who Should Skip It
If you only need to log into WordPress using an external identity provider like Google or Azure AD, you want a client plugin such as OpenID Connect Generic, not this server plugin. Anyone without development resources to configure clients, test grant flows, and handle token storage on the consumer side should also look elsewhere.
The Bottom Line
WP OAuth Server delivers a focused, actively maintained OAuth 2.0 server capability for WordPress, and it scores 74.47 out of 100 on PluginCheck with full marks for maintenance and compatibility. The weak spots are the small install base and the absence of any resolved public support threads, so plan to handle integration testing on your own. If you genuinely need WordPress to be the OAuth provider for an external app or service, it is a solid choice; if not, you are probably looking for the wrong category entirely.
Related Plugins
Pick this instead if you just need stateless token auth for your own REST API consumers rather than a full OAuth 2.0 provider for third parties.
Choose this if you want WordPress to consume logins from an external OAuth or OIDC provider, the opposite direction of what WP OAuth Server does.
Pick Authorizer when your goal is restricting dashboard or content access through external identity providers rather than issuing tokens to external apps.
This is not a competing auth plugin and only appears in the same category due to tag overlap, so treat it as a non-relevant match.
Consider this miniOrange variant if you want similar OAuth 2.0 server functionality bundled with premium support and add-ons.