Simple JWT Login – Allows you to use JWT on REST endpoints.
View on WordPress.orgScores higher than 69% of indexed plugins
About
Enhance the WordPress REST API with JWT authentication for secure access by mobile apps, external sites, and third-party services.
Security History
What It Does
Simple JWT Login extends the WordPress REST API with JSON Web Token authentication, letting external clients such as mobile apps, decoupled frontends, and third-party services verify users and access protected endpoints without relying on cookie-based sessions. It also bundles endpoints for auto-login and user registration, so you can issue tokens and create accounts from outside the wp-admin. In practice it acts as a thin authentication layer that sits on top of core WordPress user accounts.
Who It's For
This plugin is a good fit for developers building headless WordPress sites, native mobile apps, or backend integrations that need to authenticate WordPress users programmatically. It also suits shops or agencies that want a quick way to expose login, registration, and authenticated REST endpoints to a separate client without writing custom auth code. Teams comfortable managing JWT secrets and configuring endpoints by hand will get the most out of it.
Who Should Skip It
If you only need cookie-based logins inside a normal WordPress site, this plugin adds unnecessary surface area and risk. Hobby bloggers, content-only sites, and anyone who is not actively building an external client should skip it and use the default WordPress login flow instead.
The Bottom Line
Simple JWT Login is a well-maintained, broadly compatible JWT plugin that earns a 78.63/100 overall score, dragged down mostly by its small install base and a complete absence of public support threads. It is a sensible pick for developers who want login, registration, and auto-login endpoints in one package, but larger teams may prefer the more battle-tested JWT Authentication for WP REST API. Treat the perfect 100/100 rating with mild skepticism given only 47 reviewers.
Related Plugins
Pick this instead if you want a more widely deployed solution with 60,000 installs and a larger community, though it focuses only on auth and lacks built-in auto-login and registration endpoints.
Choose this instead if your goal is the opposite: locking down the REST API entirely rather than extending it with JWT auth.
Pick this instead only if your real priority is transactional email delivery with a REST-based send hook, not JWT authentication.
Choose this if you need WordPress to consume external REST APIs from the server side rather than authenticate external clients calling your endpoints.
Pick this if your bottleneck is REST response speed rather than authentication, since it caches endpoint output without addressing JWT at all.