Open Access SSO
by idgold 1 (0 reviews)

Open Access SSO

Free, privacy-first SAML 2.0 single sign-on for WordPress. Role mapping, access control, multi-IdP. No premium tier, no tracking.

Open Access SSO ranks #35,259 among WordPress.org plugins with 1+ active installations, is #1,034 of 1,586 in the Authentication category, a 1/5 rating from 0 reviews, and was last updated Jun 21, 2026. Data from WordPress.org, refreshed twice daily — see methodology.

Tested up to WP 7 (Current: 7.1.1)
v2.2.0 Current Version v2.2.0
Updated 2 months ago Last Update on 21 Jun, 2026
Refreshed 18 hours ago Last Refreshed on
#1,034 of 1,586 in Authentication Downloads +76.8% this week
View on WordPress.org
Rank
#35,259
No change
Active Installs
1+
-50%
KW Avg Position
53.5
No change
Downloads
872
+14 today
Support Resolved
0%
No change
Rating
20%
Review 1 out of 5
1 (0 reviews)

Next Milestone 10

Total Progress 50%
0+ 10+
34,552
Ranks to Climb
-
Growth Needed
8,000,000
Active Installs
Pro

Unlock Exact Install Count

See the precise estimated active installs for this plugin, calculated from real-time ranking data.

  • Exact install estimates within tiers
  • Track install growth over time
  • Milestone progress predictions
Upgrade to Pro
Need 5 more installs to reach 10+

Rank Changes

34,134 36,571 39,009 41,446 43,883 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026
33,552 37,250 40,948 44,646 48,344 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026
Current #35,259
Change
Best #

Upgrade to Pro

Unlock 30-day and 90-day rank history charts with a Pro subscription.

Upgrade Now

Active Installs Growth

Active Installs 0,000,000+
Growth +0.0%
Peak 0,000,000

Downloads Growth

0 10 20 30 40 50 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026
0 10 20 30 40 50 04-09-2026 05-09-2026 06-09-2026 07-09-2026 08-09-2026 09-09-2026 10-09-2026 11-09-2026 12-09-2026 13-09-2026 14-09-2026 15-09-2026 16-09-2026 17-09-2026 18-09-2026 19-09-2026
Downloads
Growth
Peak

Upgrade to Pro

Unlock 30-day, 90-day, and yearly download history charts with a Pro subscription.

Upgrade Now

Reviews & Ratings

1.0
0 reviews
Overall 20%
5
0 (0%)
4
0 (0%)
3
0 (0%)
2
0 (0%)
1
0 (0%)

Frequently Asked Questions

Common questions about Open Access SSO

Yes — completely. There is no premium tier, no license key, and nothing to unlock. Every feature you read about ships in the GPLv2-or-later codebase: role mapping, multi-IdP, access control, the audit log, WooCommerce integration, all of it. The full source is on Codeberg, so you can see exactly what you're installing.
Almost certainly. Open Access SSO speaks standard SAML 2.0, so it works with any standards-compliant identity provider — Microsoft Entra ID (Azure AD), Okta, OneLogin, Keycloak, ADFS, Shibboleth, and NetIQ Access Manager (now OpenText), among others. There's no built-in or default IdP; you bring your own, and you point the plugin at it. The identity-provider setup guide (see Documentation) walks through the common providers step by step.
No. Setup is point-and-click in the WordPress admin. You add your identity provider one of three easy ways — upload its metadata XML file, paste a metadata URL, or type the details in by hand — then copy the SP metadata the plugin generates and register your site with your IdP. No code required for normal use. (If you are a developer, there's a documented, stable hook API waiting for you.)
Yes, and no tracking whatsoever. The plugin has no telemetry, no analytics, no "phone home," and no external CDN. The only time it ever reaches out to the network is when you ask it to fetch your IdP's metadata from a URL — plus an optional, off-by-default certificate-rotation check that re-fetches that same address you entered. It never contacts the plugin author or any third party, and every setting stays in your own site's database. Sign-ins are validated end to end before anyone is let in, and your SP private keys are encrypted at rest. For the full details, see the security & hardening guide in Documentation.
You have a built-in emergency way back in. You can either add define( 'OASSO_BYPASS', true ); to wp-config.php to switch off forced SSO entirely, or set a Bypass Secret Key on the dashboard ahead of time and visit /wp-admin/?oasso_bypass_key=YOUR_KEY to get back in without touching any files. The key route is rate-limited per IP address to frustrate brute-force guessing. The troubleshooting guide (see Documentation) covers recovery in detail.
Yes. Configure as many IdPs as you need under Tools → Open Access SSO → Identity Providers. Your users pick the right one with a button on the login page or via a simple ?idp=slug link.
Yes — that's one of the headline features. Map WordPress roles from the groups or attributes your IdP sends, using exact, contains, or regex matching, with per-IdP rule sets, a default-role fallback, and an option to deny anyone who doesn't match a rule. For safety, SSO won't grant admin-level roles unless you explicitly turn that on, and existing administrator accounts are never auto-linked to an SSO login.
Yes, out of the box — including the modern encryption that some providers (such as NetIQ Access Manager) turn on by default and that stock PHP can't unwrap on its own. The plugin bundles a small MIT-licensed library to handle exactly that, so encrypted sign-in just works where a plain PHP setup would fall short. Encrypted user identifiers are supported too.
Yes. NetIQ Access Manager (now part of OpenText) is a standard SAML 2.0 identity provider and is fully supported, including its default encrypted assertions. One clarification: NetIQ Identity Manager (sometimes called "IDM") is a separate user-provisioning product, not a SAML IdP — it's Access Manager that acts as the identity provider here.
Yes. The plugin tracks each IdP's signing-certificate expiry and can warn you before it changes, detecting rotation on a daily or weekly check with your choice of manual, auto-trust, grace-period, or require-approval handling — and you can pin a specific certificate if you want strict change control. A searchable, database-backed audit log records who signed in and when, with CSV export and a retention period you set.

Sign In / Register

You need to sign in or register to use this feature.