{"id":358175,"date":"2026-08-25T07:17:53","date_gmt":"2026-08-25T07:17:53","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/zapqr-login\/"},"modified":"2026-08-30T14:34:25","modified_gmt":"2026-08-30T14:34:25","slug":"zapqr-login","status":"publish","type":"plugin","link":"https:\/\/kaa.wordpress.org\/plugins\/zapqr-login\/","author":23455871,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.1.0","stable_tag":"1.1.0","tested":"7.0.4","requires":"5.5","requires_php":"7.4","requires_plugins":null,"header_name":"ZapQR Login","header_author":"DaSecure","header_description":"Passwordless login for WordPress using ZapQR - scan a QR code with your phone to sign in instantly.","assets_banners_color":"2d1c50","last_updated":"2026-08-30 14:34:25","external_support_url":"","external_repository_url":"","donate_link":"https:\/\/zapqr.ai","header_plugin_uri":"https:\/\/zapqr.ai","header_author_uri":"https:\/\/dasecure.com","rating":0,"author_block_rating":0,"active_installs":0,"downloads":68,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"dasecure","date":"2026-08-25 07:17:19","revision":3664783},"1.1.0":{"tag":"1.1.0","author":"dasecure","date":"2026-08-30 14:34:25","revision":3672681}},"upgrade_notice":{"1.1.0":"<p>Adds &quot;Sign in with ZapQR&quot; single sign-on (passkeys, no passwords). The QR widget script is now bundled locally.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3664783,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3664783,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3664783,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3664783,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0","1.1.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3664783,"resolution":"1","location":"assets","locale":"","width":1280,"height":1180},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3664783,"resolution":"2","location":"assets","locale":"","width":1280,"height":800}},"screenshots":{"1":"Login page with \"Sign in with ZapQR\" and the QR widget","2":"Settings page: SSO configuration with the URIs to register","3":"ZapQR sign-in ceremony (passkey prompt)"}},"plugin_section":[],"plugin_tags":[710,602,218738,9223,2469],"plugin_category":[38,54],"plugin_contributors":[277360],"plugin_business_model":[],"class_list":["post-358175","plugin","type-plugin","status-publish","hentry","plugin_tags-authentication","plugin_tags-login","plugin_tags-passkey","plugin_tags-passwordless","plugin_tags-sso","plugin_category-authentication","plugin_category-security-and-spam-protection","plugin_contributors-dasecure","plugin_committers-dasecure"],"banners":{"banner":"https:\/\/ps.w.org\/zapqr-login\/assets\/banner-772x250.png?rev=3664783","banner_2x":"https:\/\/ps.w.org\/zapqr-login\/assets\/banner-1544x500.png?rev=3664783","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/zapqr-login\/assets\/icon-128x128.png?rev=3664783","icon_2x":"https:\/\/ps.w.org\/zapqr-login\/assets\/icon-256x256.png?rev=3664783","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/zapqr-login\/assets\/screenshot-1.png?rev=3664783","caption":"Login page with \"Sign in with ZapQR\" and the QR widget"},{"src":"https:\/\/ps.w.org\/zapqr-login\/assets\/screenshot-2.png?rev=3664783","caption":"Settings page: SSO configuration with the URIs to register"}],"raw_content":"<!--section=description-->\n<p>ZapQR Login gives your WordPress site passwordless sign-in, two ways:<\/p>\n\n<h4>Sign in with ZapQR (SSO) \u2014 recommended<\/h4>\n\n<p>A \"Sign in with ZapQR\" button on your login page. Visitors sign in with their ZapQR account \u2014 passkey-first (Face ID \/ Touch ID \/ security key), with an email link as fallback \u2014 via standards-based OpenID Connect single sign-on. One ZapQR account works across every site that offers it.<\/p>\n\n<ul>\n<li>Passkey-first: phishing-resistant WebAuthn sign-in, no passwords anywhere<\/li>\n<li>Standards-based: OAuth 2.0 authorization-code flow with PKCE; ID tokens verified in the plugin (RS256, JWKS)<\/li>\n<li>Links existing WordPress users by their verified email \u2014 admins keep their role<\/li>\n<li>New visitors are created with a low-privilege role you choose (Subscriber by default)<\/li>\n<li>Single logout: logging out of WordPress also ends the ZapQR session<\/li>\n<li>No external code: the whole flow is server-side redirects and server-to-server calls<\/li>\n<\/ul>\n\n<h4>QR credential fill (classic)<\/h4>\n\n<p>Users save their WordPress credentials in the ZapQR app; on the login page they scan a QR code and the login form fills and submits itself. Credentials travel phone \u2192 browser over an encrypted WebSocket relay and are never stored on external servers.<\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin talks to the following services. No data is sent anywhere until a site administrator enables the relevant mode.<\/p>\n\n<p><strong>ZapQR identity provider<\/strong> (SSO mode) \u2014 <code>auth.zapqr.ai<\/code> by default, or a self-hosted issuer the admin configures. When a visitor clicks \"Sign in with ZapQR\" their browser is redirected there to authenticate; your server then exchanges an authorization code (server-to-server) and receives the visitor's email address and its verified status \u2014 nothing else. Provider: DaSecure (<a href=\"https:\/\/zapqr.ai\">zapqr.ai<\/a>, terms and privacy linked there).<\/p>\n\n<p><strong>ZapQR relay<\/strong> (QR mode) \u2014 <code>wss:\/\/relay.zapqr.ai<\/code>, a WebSocket relay that pairs the login page with the visitor's phone using a random session identifier. Credentials pass through end-to-end encrypted and are not stored. Provider: DaSecure (<a href=\"https:\/\/zapqr.ai\">zapqr.ai<\/a>).<\/p>\n\n<p><strong>QR image service<\/strong> (QR mode) \u2014 <code>api.qrserver.com<\/code> renders the QR image. It receives only the random session identifier and your site's hostname \u2014 never credentials. Provider: <a href=\"https:\/\/goqr.me\/\">goqr.me<\/a> (<a href=\"https:\/\/www.qrserver.com\/en\/privacy\/\">privacy<\/a>).<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate the plugin.<\/li>\n<li><strong>For SSO:<\/strong> go to Settings &gt; ZapQR Login, copy the Redirect URI and Post-logout URI shown there, register your site at the ZapQR identity provider to get a Client ID and Secret, paste them in, tick Enable, save.<\/li>\n<li><strong>For QR fill:<\/strong> nothing to configure \u2014 the widget appears on wp-login.php. Customize theme and accent color in Settings &gt; ZapQR Login.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"what%20does%20the%20site%20receive%20about%20the%20visitor%20in%20sso%20mode%3F\"><h3>What does the site receive about the visitor in SSO mode?<\/h3><\/dt>\n<dd><p>Only a verified email address and a stable account identifier, delivered in a cryptographically signed token that the plugin verifies against the provider's published keys. No passwords, no passkeys, no profile data.<\/p><\/dd>\n<dt id=\"can%20someone%20take%20over%20an%20existing%20account%3F\"><h3>Can someone take over an existing account?<\/h3><\/dt>\n<dd><p>No. Linking to an existing WordPress user happens only when the ZapQR identity provider asserts the email is verified; unverified emails are rejected outright. You can also disable linking entirely, and new users always get the low-privilege role you configure.<\/p><\/dd>\n<dt id=\"where%20do%20passkeys%20live%3F\"><h3>Where do passkeys live?<\/h3><\/dt>\n<dd><p>With the visitor and the ZapQR identity provider \u2014 never on your WordPress site. Your site only consumes the signed sign-in assertion.<\/p><\/dd>\n<dt id=\"does%20the%20qr%20credential%20mode%20still%20work%3F\"><h3>Does the QR credential mode still work?<\/h3><\/dt>\n<dd><p>Yes, unchanged. It is a separate, coexisting mode: the ZapQR app stores per-site WordPress credentials locally on the phone (Face ID \/ Touch ID protected) and relays them to the browser at login.<\/p><\/dd>\n<dt id=\"does%20this%20work%20with%20multisite%3F\"><h3>Does this work with multisite?<\/h3><\/dt>\n<dd><p>Yes.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.1.0<\/h4>\n\n<ul>\n<li>New: \"Sign in with ZapQR\" single sign-on (OpenID Connect, authorization-code + PKCE, RS256 ID-token verification via JWKS)<\/li>\n<li>New: link existing users by verified email; configurable default role for new users; optional single logout through the identity provider<\/li>\n<li>Changed: the QR widget script is now bundled with the plugin instead of loaded from zapqr.ai<\/li>\n<li>Hardened: explicit sanitization on all settings<\/li>\n<\/ul>\n\n<h4>1.0.0<\/h4>\n\n<ul>\n<li>Initial release: QR code credential fill on wp-login.php, theme and accent customization<\/li>\n<\/ul>","raw_excerpt":"Passwordless login for WordPress \u2014 &quot;Sign in with ZapQR&quot; single sign-on with passkeys, or scan a QR code with your phone.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/358175","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=358175"}],"author":[{"embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/dasecure"}],"wp:attachment":[{"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=358175"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=358175"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=358175"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=358175"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=358175"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/kaa.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=358175"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}