API Bearer Auth
Access and refresh tokens based authentication plugin for the REST API.
API Bearer Auth ranks #11,063 among WordPress.org plugins with 300+ active installations, is #276 of 1,580 in the Authentication category, a 5/5 rating from 6 reviews, and was last updated Dec 8, 2025. Data from WordPress.org, refreshed twice daily — see methodology.
Next Milestone 400
Unlock Exact Install Count
See the precise estimated active installs for this plugin, calculated from real-time ranking data.
- Exact install estimates within tiers
- Track install growth over time
- Milestone progress predictions
Rank Changes
Downloads Growth
Upgrade to Pro
Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.
Upgrade NowReviews & Ratings
Security History
Source: WPVulnerability2 known vulnerabilities on record · 0 in the last 24 months · checked 1 month ago
-
API Bearer Auth [api-bearer-auth] < 20181230
Fixed in v20181230
-
API Bearer Auth [api-bearer-auth] < 20190908
CVE-2019-16332 · Fixed in v20190908
Track This Plugin
Get detailed analytics, keyword tracking, and position alerts delivered to your inbox.
Start Tracking FreePlugin Details
- Version
- trunk
- Last Updated
- Dec 08, 2025
- Requires WP
- 4.6+
- Tested Up To
- 6.9
- PHP Version
- 5.4.0 or higher
- Author
- michielve
Support & Rating
- Rating
- ★ ★ ★ ★ ★ 5
- Reviews
- 6
- Support Threads
- 0
- Resolved
- 0%
Keywords
Upgrade to Pro
Unlock keyword rankings, search positions, and detailed analytics with a Pro subscription.
Upgrade NowSimilar Plugins
TL;DR
AI summary of the plugin's readmeThis plugin is for WordPress site owners who need to secure their REST API with token-based authentication. It solves the problem of unauthenticated REST API access by requiring JWT-based access and refresh tokens for requests, with the ability to revoke issued tokens.
- JWT access token support
- Refresh token endpoint
- Login endpoint
- Token revocation from users admin screen
- Bulk revoke API tokens action
- Configurable unauthenticated URL whitelist
- Users table token expiry column
- Bearer token authorization header
Frequently Asked Questions
Common questions about API Bearer Auth