[WordPress] 外掛分享: Keystone OIDC

首頁外掛目錄 › Keystone OIDC
WordPress 外掛 Keystone OIDC 的封面圖片
10+
安裝啟用
尚無評分
24 天前
最後更新
問題解決
WordPress 5.6+ PHP 7.4+ v2.3.4 上架:2026-06-11

內容簡介

Keystone OIDC 將您的 WordPress 安裝轉變為功能完整的 OpenID Connect (OIDC) 身份提供者,允許其他應用程式通過您的 WordPress 用戶資料庫進行用戶身份驗證。

【主要功能】
• 支援 PKCE 的 OIDC 授權碼流程
• RS256 JWT 簽名的訪問令牌和 ID 令牌
• 管理介面可創建和管理多個 OIDC 客戶端
• 安全生成和重置客戶端密鑰
• OIDC 發現端點自動配置客戶端
• 支援長期會話的刷新令牌

外掛標籤

開發者團隊

⬇ 下載最新版 (v2.3.4) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「Keystone OIDC」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

Keystone OIDC transforms your WordPress installation into a fully-featured OpenID Connect (OIDC) identity provider, allowing other applications to authenticate users via your WordPress user database.
Key Features

OIDC Authorization Code Flow with PKCE support
RS256 JWT signed access tokens and ID tokens
Admin UI to create and manage multiple OIDC clients
Client secret management – generate and reset secrets securely (shown only once)
OIDC Discovery endpoint (/wenisch-tech/keystone-oidc/.well-known/openid-configuration) for automatic client configuration
Standard scopes: openid, profile, email
Refresh tokens for long-lived sessions
Zero additional configuration after install – just create a client and you’re ready

Quick Start

Install and activate the plugin
Go to OIDC Provider → Add Client in your WordPress admin
Enter your application name and redirect URI(s)
Copy the generated Client ID and Client Secret (shown once)
Configure your OIDC client application with the discovery URL shown in the settings

Endpoints
All URLs are relative to your WordPress site root.

Discovery: /wenisch-tech/keystone-oidc/.well-known/openid-configuration
Authorization: /wenisch-tech/keystone-oidc/oauth/authorize
Token: /wenisch-tech/keystone-oidc/oauth/token
UserInfo: /wenisch-tech/keystone-oidc/oauth/userinfo
JWKS: /wenisch-tech/keystone-oidc/oauth/jwks

Compatibility aliases are also routed under /wenisch-tech/keystone-oidc/protocol/openid-connect/* for clients that still derive Keycloak-style paths from the custom issuer URI. These aliases are not advertised in discovery.
UserInfo Example
For openid profile email, /wenisch-tech/keystone-oidc/oauth/userinfo returns:
{
"sub": "42",
"name": "Jane Doe",
"given_name": "Jane",
"family_name": "Doe",
"preferred_username": "jane",
"email": "[email protected]",
"email_verified": true
}

sub is the WordPress user ID as a string, `preferred_username` is the WordPress `user_login`, and `email` is the WordPress `user_email`.

Roles are not currently emitted. The plugin does not expose WordPress roles or capabilities in UserInfo or ID tokens.
[2.3.0](https://github.com/wenisch-tech/wordpress-keystone-oidc/compare/v2.2.2…v2.3.0) (2026-06-14)
Features

consent-screen now uses theme default colors if available (24beefe)

Bug Fixes

ensure compability with wordpress v7 (36f0d50)

2.2.2
Released on 2026-06-12.
Bug Fixes

updated release versioning and changelog creation (98cfb30)
updated repository links (f46b2b6)
updatet generation of changelog. (357bded)

Documentation

added “Report a bug” button to plugin page (8281f6c)

1.0.0

Initial release
Authorization Code Flow with PKCE
RS256 JWT tokens
Multi-client admin UI with secret management
OIDC Discovery endpoint
Refresh token support

延伸相關外掛

文章
Filter
Mastodon