Casdoor – SSO, OAuth 2.0 & OIDC Login Wordpress Plugin - Rating, Reviews, Demo & Download
Plugin Description
Casdoor is an open-source identity and access management (IAM) and single sign-on (SSO) platform. With this plugin your users log in to WordPress with their Casdoor account, over OAuth 2.0 and OpenID Connect, the same way they log in to the other applications of your organization.
Behind Casdoor they can use passwords, MFA, passkeys, social logins (Google, GitHub, WeChat, Microsoft and many more), LDAP, SAML or any other provider Casdoor supports, without another plugin in WordPress.
Features
- Replaces the WordPress login page with Casdoor, or adds a “Log in with Casdoor” button to it.
- Creates the WordPress user on the first login, or only lets existing users in.
- Links WordPress users to Casdoor users by the Casdoor user ID or a verified email, never by the user name alone.
- Only lets in the users of one Casdoor organization, if you want.
- Logs out of Casdoor together with WordPress.
- Optional automatic login for visitors that are not logged in.
- The
[casdoor_login_button]shortcode for a login link anywhere. - Protects the login with the OAuth
state, verifies TLS and asks Casdoor for the user, so a login can not be forged.
Users that only exist in WordPress, such as the first admin, can still use the WordPress login form at /wp-login.php?use_native_login=1.
Casdoor
- Website: casdoor.ai
- Source code of Casdoor: github.com/casdoor/casdoor
- Source code of this plugin: github.com/casdoor/wordpress-casdoor-plugin
External services
This plugin connects to the Casdoor server that you set in Settings > Casdoor SSO. It is your own Casdoor (self-hosted or a Casdoor cloud instance), the plugin does not connect to any other service.
- When a user logs in, the browser is sent to the login page of your Casdoor server.
- After the login, the plugin sends the authorization code with the client ID and client secret of your Casdoor application to the server, and gets the access token and the user’s account (name, display name, email, organization) from it.
- When a user logs out and “Log out of Casdoor too” is enabled, the browser is sent to the logout page of your Casdoor server with the user’s token.
Casdoor is open-source software under the Apache-2.0 license. The terms and privacy policy are those of whoever runs your Casdoor server; for Casdoor cloud they are at casdoor.com/terms and casdoor.com/privacy.
Screenshots
The settings page (Settings > Casdoor SSO): connect your Casdoor application and choose how users log in.
