IndieAuth
by IndieWeb 5 (4 reviews)

IndieAuth

IndieAuth is a way to allow users to use their own domain to sign into other websites and services.

IndieAuth ranks #9,431 among WordPress.org plugins with 400+ active installations, is #252 of 1,580 in the Authentication category, a 5/5 rating from 4 reviews, and was last updated Aug 31, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Compatible with WP 7.1
v4.7.2 Current Version v4.7.2
Updated 2 weeks ago Last Update on 31 Aug, 2026
Refreshed 16 hours ago Last Refreshed on
#252 of 1,580 in Authentication Top 25% by installs Downloads -7.1% this week Actively maintained
View on WordPress.org
Rank
#9,431
No change
Active Installs
400+
-16.3%
KW Avg Position
10.3
No change
Downloads
30.3K
+8 today
Support Resolved
0%
No change
Rating
100%
Review 5 out of 5
5 (4 reviews)

Next Milestone 500

Total Progress 81%
400+ 500+
198
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 19 more installs to reach 500+

Rank Changes

9,350 9,396 9,443 9,489 9,535 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
9,350 9,396 9,443 9,489 9,535 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
Current #9,431
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 100 200 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
0 100 200 02-09-2026 03-09-2026 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

5.0
4 reviews
Overall 100%
5
4 (100%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Security History

Source: WPVulnerability

1 known vulnerability on record · 1 in the last 24 months · checked 1 month ago

  1. IndieAuth [indieauth] < 4.5.5

    CVE-2025-12028 · Fixed in v4.5.5

TL;DR

AI summary of the plugin's readme

This plugin is for WordPress site owners who want to let users sign in with their own domain. It turns WordPress into an IndieAuth endpoint, providing an authentication mechanism for WordPress, its REST API, and other sites.

  • IndieAuth endpoint for WordPress
  • Authentication for WordPress REST API
  • Identity mechanism for other sites
  • Uses profile page URL
  • Uses author URL
  • Web sign-in using your domain

Frequently Asked Questions

Common questions about IndieAuth

IndieAuth is a way for doing Web sign-in, where you use your own homepage or author post URL( usually /author/authorname ) to sign in to other places. It is built on top of OAuth 2.0, which is used by many websites.
IndieAuth is an extension to OAuth. If you are a developer, you have probably used OAuth to get access to APIs. As a user, if you have given an application access to your account on a service, you probably used OAuth. One advantage of IndieAuth is how easily it allows everyone's website to be their own OAuth Server without needing applications to register with each site.
IndieAuth was built on top of OAuth 2.0 and differs in that users and clients are represented by URLs. Clients can verify the identity of a user and obtain an OAuth 2.0 Bearer token that can be used to access user resources. You can read the specification for implementation details.
The goals of OpenID and Web Sign In are similar. Both encourage you to sign in to a website using your own domain name. However, OpenID has failed to gain wide adoption. Web sign-in prompts a user to enter a URL to sign on. Upon submission, it tries to discover the URL's authorization endpoint, and authenticate to that. If none is found, it falls back on other options. This plugin only supports searching an external site for an authorization endpoint, allowing you to log into one site with the credentials of another site if that site is listed as the website URL in your user profile.
Indieauth.com is the reference implementation of the IndieAuth Protocol. If you activate this plugin you do not need to use this site. IndieAuth.com uses rel-me links on your website to determine your identity for authentication, but this is not required to use this plugin which uses your WordPress login to verify your identity.
As of version 3.2, the endpoints return the display name, avatar, and URL from your user profile.
No. When you provide the URL of the WordPress site and authenticate to WordPress, it will return the URL of your author profile as your unique URL. Only one user may use the URL of the site itself. This setting is set in the plugin settings page, or if there is only a single user, it will default to them.
That, as mentioned, depends on the server. By default, the built-in IndieAuth server uses the WordPress login. By adding Indieauth support, you can log into sites simply by providing your URL.
We recommend your site uses HTTPS to ensure your credentials are not sent in cleartext. As of Version 4.5.5, this plugin requires Proof Key for Code Exchange(PKCE), whether or not the client supports it.
Once you have proven your identity, the token endpoint issues a token, which applications can use to authenticate as you to your site. You can manage and revoke tokens under User->Manage Tokens. You will only see tokens for the currently logged in user.

More plugins by IndieWeb

Sign In / Register

You need to sign in or register to use this feature.