API Bearer Auth
The API Bearer Auth plugin enables authentication for the REST API by using JWT access an refresh tokens. After the user logs in, the access and refresh tokens are returned and can be used for the next requests. Issued tokens can be revoked from within the users admin screen. See below for the endpoints. Note that after activating this plugin, all REST API endpoints will need to be authenticated, unless the endpoint is whitelisted in the api_bearer_auth_unauthenticated_urls filter (see FAQ for how to use this filter). JWT Access tokens can be formatted as JWT tokens. For this to work, you first have to create a secret and add it to the wp-config.php file. If you don’t do this, access tokens will work also, but are just random strings. To create a random secret key, you can do for example: base64_encode(openssl_random_pseudo_bytes(64)); And then add the result to wp-config: define('API_BEARER_JWT_SECRET', 'mysecretkey'); If you have problems, you can verify your JWT tokens at: https://jwt.io/ Revoke tokens This plugin adds a column to the users table in de admin where you can see when a token expires. You can also revoke tokens by selection the “Revoke API tokens” from the bulk actions select box. API endpoints Note that all endpoints expect JSON in the POST body. Login Endpoint: POST /api-bearer-auth/v1/login Request body: Note: client_name is optional. But if you use it, make sure to use it as well for the refresh call! {"username": "my_username", "password": "my_password", "client_name": "my_app"} Response: { "wp_user": { "data": { "ID": 1, "user_login": "your_user_login", // other default WordPress user fields } }, "access_token": "your_access_token", "expires_in": 86400, // number of seconds "refresh_token": "your_refresh_token" } Make sure to save the access and refresh token! Refresh access token Endpoint: POST /api-bearer-auth/v1/tokens/refresh Request body: Note: client_name is optional. But if you did use it for the login call, make sure to use it here as well! {"token": "your_refresh_token", "client_name": "my_app"} Response success: { "access_token": "your_new_access_token", "expires_in": 86400 } Response when sending a wrong refresh token is a 401: { "code": "api_api_bearer_auth_error_invalid_token", "message": "Invalid token.", "data": { "status": 401 } } Do a request After you have the access token, you can make requests to authenticated endpoints with an Authorization header like this: Authorization: Bearer Note that Apache sometimes strips out the Authorization header. If this is the case, make sure to add this to the .htaccess file: RewriteCond %{HTTP:Authorization} ^(.*) # Don't know why, but some need the line below instead of the RewriteRule line # SetEnvIf Authorization .+ HTTP_AUTHORIZATION=$0 RewriteRule ^(.*) - [E=HTTP_AUTHORIZATION:%1] If you are not logged in or you send an invalid access token, you get a 401 response: { "code": "api_bearer_auth_not_logged_in", "message": "You are not logged in.", "data": { "status": 401 } } Important update Update immediately if you’re using a version below 20200807. Before this version all access tokens were updated when calling the refresh callback. If you are affected by this the fastest solution is to execute this query: update wp_user_tokens set access_token_valid = NOW(); This will invalidate all access tokens. This means that all users need to refresh their access token and will get a new access token and a unique one this time. A big thank to @harchvertelol for reporting this and suggesting the fix as well!
Top keywords
- token19×3.23%
- access17×2.89%
- tokens14×2.38%
- refresh12×2.04%
- access token10×1.70%
- api9×1.53%
- authorization7×1.19%
- bearer6×1.02%
- jwt6×1.02%
- user6×1.02%
- endpoints5×0.85%
- login5×0.85%
Simpler Checkout
The Simpler Checkout button lets your customers complete their purchases in seconds. Customers using Simpler for the first time will fill in a simple form once. For all the next purchases, they can complete their orders with one click, regardless of device or browser, and without a password. Simpler checkout is designed based on conversion best practices, reducing friction and increasing sales. 1.4.11 Fix(compat): Apply custom order numbers to emails and Simpler 1.4.10 Feat(compat): Custom Order Numbers for WooCommerce 1.4.9 Feat: Accept regulatory_code (e.g. DNI) on order submission Feat: Billing address handling 1.4.8 Fix: persist voucher meta on order creation for v3.3 1.4.7 Fix: Set woocommerce taxes when creating order shipping line item manually 1.4.6 Fix(sequra): Save payment type meta on order creation; fix empty payment gateway ID fallback; sync shipment status 1.4.5 Compat: BOPO Bundle Builder Premium Compat: WooCommerce Order Attribution 10.x 1.4.4 Compat: BOPO Bundle Builder 1.4.3 Feat(compat): TranslatePress – Multilingual 1.4.2 Fix(compat): BOX NOW Delivery 3.2.1 1.4.1 Fix: Cart request URL 1.4.0 Breaking: Drop support for PHP versions <7.4 Fix: SLM phone field, collect package rates before calculating quotes Fix(submit): Add shipping item only if not exists Fix(hook): Pass shipping method on COD hook 1.3.5 Feat: use /v1/cart-requests to create carts for takeover 1.3.4 Fix: compatibility with woocommerce 10.4+ 1.3.3 Fix(takeover): use determine_locale with extra filter for language resolution 1.3.2 Feat: handle grouped products Fix: normalize option keys in product feed Fix: handle stock status in product feed Compat: Skroutz Lockers 1.3.1 Fix: normalize product feed and product details request responses 1.3.0 Feat: introduce product feed route 1.2.7 Fix(coupons): Check if coupon already exists in session cart before applying it 1.2.6 Fix(compat): Set order status to complete for digital vouchers from WooCommerce PDF Vouchers 1.2.5 Fix: Pass shipping as order item for WC 10.3.0 1.2.4 Fix: Should render button for WooCommerce PDF Vouchers 1.2.3 Feat: Default support for woo attribution to true Fix: Support extra keys for order attribution meta Compat: WooCommerce PDF Vouchers 1.2.2 Fix: Payment method title 1.2.1 Feat: Clean output buffers before writing api json responses 1.2.0 Feat: Check verification token before auto-login on order success 1.1.13 Compat: EU VAT Compliance Premium 1.1.12 Fix(compat): WC Pickup Store 1.1.11 Fix(multi-currency): Full support of multi-currency Feat(settings): Disable force login 1.1.10 Chore: strict time frame 1.1.9 Compat: WPML Multicurrency Compat: Pre-Orders for WooCommerce 1.1.8 Fix: Bank transfer email on order submit (default status: on-hold) Fix: Order notes 1.1.7 Compat: PW WooCommerce Gift Cards 1.1.6 Compat: Gift Wrapping for WooCommerce Feat: Link stub payment gateway settings screen to plugin settings for configuration Fix: WooCommerce order attribution hooks race condition Fix: Ignore shipping address when quote is for virtual cart Fix(COD): include restrictions 1.1.5 Fix/Compat: WC Smart COD / availability to set 0 fees 1.1.4 Fix/Compat: WC Smart COD / include tax 1.1.3 Feat: Bank transfer payment method Fix/Compat: WC Smart COD 1.1.2 Compat: WPC Product Bundles for WooCommerce Compat: WPC Frequently Bought Together for WooCommerce 1.1.1 Compat: Asana WooCommerce Dynamic Pricing and Discounts 1.1.0 Feat(hook): custom cod cost hook 1.0.9 Fix(takeover-checkout): prevent redirection if cart has no products Compat: BoxNow ‘Pay on the Go’ payment method as COD 1.0.8 Feat: takeover checkout (Replace native checkout with Simpler) 1.0.7 Compat: WC Smart COD 1.0.6 Fix: increase http timeout for integration status call Compat: Rightpress Dynamic Discounts 1.0.5 fix(payment): enable payment gateway and hide it from checkout 1.0.4 Compat: BOGO 1.0.3 Feat: handle bundle discounted products 1.0.2 Feat: simplerwc_customer_properties filter Compat: WC Pickup Store 1.0.1 Hotfix: default to production environment when no explicit setting 1.0.0 Feat: new simplerwc_order_created action on successful submission Feat: run woocommerce_checkout_order_created action on successful submission Feat: remove sandbox option as Simpler production environment now supports Test Stores 0.7.11 Compat: WordPress 6.5 0.7.10 Feat: Experimental support for WooCommerce Order Attribution Tracking 0.7.9 Compat: Pay for Payment for WooCommerce 0.7.8 Fix: omit coupon from button payload if empty 0.7.7 Feat: introduce simplerwc_should_render_product_button and simplerwc_should_render_cart_button filters for granular control of rendering logic Feat: introduce simplerwc_button_get_product_attibutes and simplerwc_get_cart_item_data filters for managing cart item attributes Compat: iThemeland Free Gifts 0.7.6 Fix: COD filters invocation 0.7.5 Feat: Parse company invoicing details in order request Fix: do not set payment method title when payment method is not simpler 0.7.4 Feat: Support COD payment method Compat: Smart COD plugin support 0.7.3 Compat: BoxNow v2 plugin support 0.7.2 Feat: Allow switching to sandbox environment from single distributable 0.7.1 Fix: Correct auth cookie argument in login before order confirmation redirect 0.7.0 Feat: Login user before redirecting to order confirmation 0.6.2 Feat: Add Minicart placement setting Fix: remove excessive free gifts returned in products response when FGF plugin is active 0.6.1 Compat: BoxNow support 0.6.0 Compat: WooCommerce Local Pickup Plus support Fix: Apply coupons before collecting shipping rates to account for free shipping coupons Fix: Set chosen shipping method on retrieved package keys instead of defaulting to 0 0.5.8 Fix: WooCommerce Product Bundles correct quantity payload when bundle is in cart 0.5.7 Fix: Free Gifts for Woocommerce support for cart checkout with gift 0.5.6 Free Gifts for Woocommerce support 0.5.5 Support Product Bundles created with WooCommerce Product Bundles plugin 0.5.4 Calculate discounted tax when simpler discount present Fix : check data validity when invoking simplerwc_should_render_button function 0.5.3 Optionally include customer email during quotation to handle coupon usage limits Fix : Refactor submission flow to ensure shipping tax calculation works as intended 0.5.2 Fix: Cost reporting in order confirmation email Remove deprecated order submission functionality Remove deprecated Offers tab from Settings 0.5.1 Hotfix: Include customer name & phone in order shipping address 0.5.0 Support custom fees during cart fees calculation Breakdown products cost during quotation Excluded specific user roles from viewing the button Fix: Price rounding Fix: Include tax in coupons 0.4.0 Breaking : Drop support for legacy SDK Add configuration option to hide the product page button if cart contains at least one item Include amount in refund request to account for partial refunds Introduce programmatic filter to modify shipping rates during quotation Fix : Include tax amount in shipping costs during quotation Fix : Respect prices when input excluding tax 0.3.3 Introduce products route to speed up product details retrieval Introduce /v2/order route to include cart calculation hooks in order submission flow 0.3.2 Fix critical issue preventing the plugin from running on PHP 7.2 Render translated asset texts based on store locale 0.3.1 Add product attributes to simpler integration for variable products. 0.3.0 Extract browser assets to external file, hosted at https://cdn.simpler.so. This behavior can be toggled off by the “use legacy SDK” checkbox in the plugin settings, but is not encouraged. Use a Web Component to render the simpler-checkout button Add separate option to control if checkout button gets rendered in the cart view Accepted cards notice is now controlled by a single option for all positions to enhance consistency