API Bearer Auth
The API Bearer Auth plugin enables authentication for the REST API by using JWT access an refresh tokens. After the user logs in, the access and refresh tokens are returned and can be used for the next requests. Issued tokens can be revoked from within the users admin screen. See below for the endpoints. Note that after activating this plugin, all REST API endpoints will need to be authenticated, unless the endpoint is whitelisted in the api_bearer_auth_unauthenticated_urls filter (see FAQ for how to use this filter). JWT Access tokens can be formatted as JWT tokens. For this to work, you first have to create a secret and add it to the wp-config.php file. If you don’t do this, access tokens will work also, but are just random strings. To create a random secret key, you can do for example: base64_encode(openssl_random_pseudo_bytes(64)); And then add the result to wp-config: define('API_BEARER_JWT_SECRET', 'mysecretkey'); If you have problems, you can verify your JWT tokens at: https://jwt.io/ Revoke tokens This plugin adds a column to the users table in de admin where you can see when a token expires. You can also revoke tokens by selection the “Revoke API tokens” from the bulk actions select box. API endpoints Note that all endpoints expect JSON in the POST body. Login Endpoint: POST /api-bearer-auth/v1/login Request body: Note: client_name is optional. But if you use it, make sure to use it as well for the refresh call! {"username": "my_username", "password": "my_password", "client_name": "my_app"} Response: { "wp_user": { "data": { "ID": 1, "user_login": "your_user_login", // other default WordPress user fields } }, "access_token": "your_access_token", "expires_in": 86400, // number of seconds "refresh_token": "your_refresh_token" } Make sure to save the access and refresh token! Refresh access token Endpoint: POST /api-bearer-auth/v1/tokens/refresh Request body: Note: client_name is optional. But if you did use it for the login call, make sure to use it here as well! {"token": "your_refresh_token", "client_name": "my_app"} Response success: { "access_token": "your_new_access_token", "expires_in": 86400 } Response when sending a wrong refresh token is a 401: { "code": "api_api_bearer_auth_error_invalid_token", "message": "Invalid token.", "data": { "status": 401 } } Do a request After you have the access token, you can make requests to authenticated endpoints with an Authorization header like this: Authorization: Bearer Note that Apache sometimes strips out the Authorization header. If this is the case, make sure to add this to the .htaccess file: RewriteCond %{HTTP:Authorization} ^(.*) # Don't know why, but some need the line below instead of the RewriteRule line # SetEnvIf Authorization .+ HTTP_AUTHORIZATION=$0 RewriteRule ^(.*) - [E=HTTP_AUTHORIZATION:%1] If you are not logged in or you send an invalid access token, you get a 401 response: { "code": "api_bearer_auth_not_logged_in", "message": "You are not logged in.", "data": { "status": 401 } } Important update Update immediately if you’re using a version below 20200807. Before this version all access tokens were updated when calling the refresh callback. If you are affected by this the fastest solution is to execute this query: update wp_user_tokens set access_token_valid = NOW(); This will invalidate all access tokens. This means that all users need to refresh their access token and will get a new access token and a unique one this time. A big thank to @harchvertelol for reporting this and suggesting the fix as well!
Top keywords
- token19×3.23%
- access17×2.89%
- tokens14×2.38%
- refresh12×2.04%
- access token10×1.70%
- api9×1.53%
- authorization7×1.19%
- bearer6×1.02%
- jwt6×1.02%
- user6×1.02%
- endpoints5×0.85%
- login5×0.85%
Store-IT – Contact
The Store-IT Contact plugin allows you to create and manage contact forms that automatically sync submissions with the Store-IT API. The plugin provides a complete form builder with styling options, field management, and multi-language support. Features Form Builder: Create unlimited contact forms with customizable fields Store-IT API Integration: Automatic submission synchronization with Store-IT services Multi-language Support: Available in English, Dutch, German, Spanish, Finnish, French, and Italian Customizable Styling: Full control over form appearance including colors, fonts, and spacing Field Management: Configure field visibility, requirements, labels, and validation reCAPTCHA Support: Built-in Google reCAPTCHA integration for spam protection Responsive Design: Mobile-friendly forms that adapt to any screen size Admin Dashboard: Complete management interface for forms and submissions Supported Form Fields Location (dropdown of available facilities) Request Type (dropdown of available request categories) Title (optional title field with predefined options) First Name (text input) Surname (text input) Phone Number (telephone input with validation) Email (email input with validation – required) Message (textarea for message content) reCAPTCHA (Google reCAPTCHA verification) Submit Button (form submission button) Multi-language Support The plugin includes translations for: * English (en) * Dutch (nl) * German (de) * Spanish (es) * Finnish (fi) * French (fr) * Italian (it) Configuration API Settings Navigate to Store-IT Contact > Global Settings Configure your API credentials: Base URL: Your Store-IT API endpoint Username: Your Store-IT API username Password: Your Store-IT API password Grant Type: Authentication method (default: password) Client ID: Your Store-IT API client ID reCAPTCHA Setup (Optional) Go to Store-IT Contact > Global Settings > reCAPTCHA Enter your Google reCAPTCHA credentials: Site Key: Your reCAPTCHA site key Secret Key: Your reCAPTCHA secret key Usage Creating a Contact Form Navigate to Store-IT Contact > Add New Form Configure the form settings (name, title, language, request types, locations) Customize styling in the Styling tab Configure fields in the Fields tab Set up notifications in the Notifications tab Displaying Forms Use the shortcode to display your form: [store_it_contact_form id=”your_form_id”] Requirements WordPress 5.0 or higher PHP 7.4 or higher Store-IT API access credentials cURL support for API communication External services This plugin relies on external services to provide its functionality: Store-IT API Integration The plugin connects to the Store-IT API to synchronize form submissions and create customer records. * Service Provider: Store-IT (https://store-it.eu/) * API Endpoints: – https://api.store-it365.eu (main API endpoint) – https://token.store-it365.eu/auth (authentication endpoint) * Data Sent: Form submission data including contact information (name, email, phone, address), request type, location, and message content * When Data is Sent: Every time a contact form is submitted on your website * Purpose: To create customer records and tasks in the Store-IT system for business management * Terms of Service: https://store-it.atlassian.net/wiki/x/EgDS5g * Privacy Policy: https://store-it.atlassian.net/wiki/x/EgDS5g Google reCAPTCHA (Optional) When enabled, the plugin uses Google reCAPTCHA to prevent spam submissions. * Service Provider: Google LLC * Service Endpoint: https://www.google.com/recaptcha/api.js * Data Sent: User interaction data and IP address for verification purposes * When Data is Sent: When users interact with the reCAPTCHA widget on the contact form * Purpose: Spam protection and bot detection * Terms of Service: https://policies.google.com/terms * Privacy Policy: https://policies.google.com/privacy Support For support and documentation, visit: * Store-IT Website: https://store-it.eu/ * Store-IT Software: https://store-it.eu/store356-de-software/ License This plugin is licensed under the GPL v2 or later. This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA