콘텐츠로 바로가기
WordPress.org

한국어

  • 테마
  • 플러그인
  • 소식
    • 문서
    • 포럼
  • About
    • WordPress 6.9
    • 워드프레스 6.8
    • 워드프레스와 40% 웹을 위한 여정
    • 워드프레스 번역 핸드북
  • 워드프레스 한국팀
  • 워드프레스 받기
워드프레스 받기
WordPress.org

Plugin Directory

ZapQR Login

  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인
  • 플러그인 제출하기
  • 내 즐겨찾기
  • 로그인

ZapQR Login

작성자: dasecure
다운로드
  • 세부사항
  • 평가
  • 설치
  • 개발
지원

설명

ZapQR Login gives your WordPress site passwordless sign-in, two ways:

Sign in with ZapQR (SSO) — recommended

A “Sign in with ZapQR” button on your login page. Visitors sign in with their ZapQR account — passkey-first (Face ID / Touch ID / security key), with an email link as fallback — via standards-based OpenID Connect single sign-on. One ZapQR account works across every site that offers it.

  • Passkey-first: phishing-resistant WebAuthn sign-in, no passwords anywhere
  • Standards-based: OAuth 2.0 authorization-code flow with PKCE; ID tokens verified in the plugin (RS256, JWKS)
  • Links existing WordPress users by their verified email — admins keep their role
  • New visitors are created with a low-privilege role you choose (Subscriber by default)
  • Single logout: logging out of WordPress also ends the ZapQR session
  • No external code: the whole flow is server-side redirects and server-to-server calls

QR credential fill (classic)

Users save their WordPress credentials in the ZapQR app; on the login page they scan a QR code and the login form fills and submits itself. Credentials travel phone → browser over an encrypted WebSocket relay and are never stored on external servers.

External services

This plugin talks to the following services. No data is sent anywhere until a site administrator enables the relevant mode.

ZapQR identity provider (SSO mode) — auth.zapqr.ai by default, or a self-hosted issuer the admin configures. When a visitor clicks “Sign in with ZapQR” their browser is redirected there to authenticate; your server then exchanges an authorization code (server-to-server) and receives the visitor’s email address and its verified status — nothing else. Provider: DaSecure (zapqr.ai, terms and privacy linked there).

ZapQR relay (QR mode) — wss://relay.zapqr.ai, a WebSocket relay that pairs the login page with the visitor’s phone using a random session identifier. Credentials pass through end-to-end encrypted and are not stored. Provider: DaSecure (zapqr.ai).

QR image service (QR mode) — api.qrserver.com renders the QR image. It receives only the random session identifier and your site’s hostname — never credentials. Provider: goqr.me (privacy).

스크린샷

The WordPress login page: "Sign in with ZapQR" above the classic QR widget
The WordPress login page: “Sign in with ZapQR” above the classic QR widget
Settings > ZapQR Login: SSO configuration, with the exact URIs to register
Settings > ZapQR Login: SSO configuration, with the exact URIs to register
Signing in from a TV, kiosk or car - scan the code, approve on your phone
Signing in from a TV, kiosk or car – scan the code, approve on your phone
Single logout: signing out of WordPress ends the ZapQR session too
Single logout: signing out of WordPress ends the ZapQR session too

설치

  1. Install and activate the plugin.
  2. For SSO: go to Settings > ZapQR Login, copy the Redirect URI and Post-logout URI shown there, register your site at the ZapQR identity provider to get a Client ID and Secret, paste them in, tick Enable, save.
  3. For QR fill: nothing to configure — the widget appears on wp-login.php. Customize theme and accent color in Settings > ZapQR Login.

FAQ

What does the site receive about the visitor in SSO mode?

Only a verified email address and a stable account identifier, delivered in a cryptographically signed token that the plugin verifies against the provider’s published keys. No passwords, no passkeys, no profile data.

Can someone take over an existing account?

No. Linking to an existing WordPress user happens only when the ZapQR identity provider asserts the email is verified; unverified emails are rejected outright. You can also disable linking entirely, and new users always get the low-privilege role you configure.

Where do passkeys live?

With the visitor and the ZapQR identity provider — never on your WordPress site. Your site only consumes the signed sign-in assertion.

Does the QR credential mode still work?

Yes, unchanged. It is a separate, coexisting mode: the ZapQR app stores per-site WordPress credentials locally on the phone (Face ID / Touch ID protected) and relays them to the browser at login.

Does this work with multisite?

Yes.

후기

이 플러그인에 대한 평가가 없습니다.

기여자 & 개발자

“ZapQR Login”(은)는 오픈 소스 소프트웨어입니다. 다음의 사람들이 이 플러그인에 기여하였습니다.

기여자
  • dasecure

자국어로 “ZapQR Login”(을)를 번역하세요.

개발에 관심이 있으십니까?

코드 탐색하기는, SVN 저장소를 확인하시거나, 개발 기록을 RSS로 구독하세요.

변경이력

1.2.0

  • New: back-channel logout. Register the URI shown in Settings at ZapQR and signing out of ZapQR (or an Emergency sign-out) ends the WordPress session too — only the session that ZapQR session created.
  • Fixed: single logout remembered one ID token per user, so after logging out on one device the next device’s logout skipped ZapQR entirely. Each WordPress session now carries its own.
  • Fixed: when ZapQR could not be reached at logout, the WordPress-only logout was silent; it is now logged.
  • Fixed: Chrome could autofill the WordPress admin’s saved username and password into Client ID and Client secret. The fields no longer look like a login form, and a Client ID that doesn’t start with “zq_” gets a warning on save.

1.1.1

  • Fixed: the QR widget showed a stale, unscannable code after a login was delivered (e.g. after logging out and back in). It now refreshes its session automatically after every successful fill.
  • New: window.ZapQR.refresh() lets themes/plugins request a fresh QR programmatically.

1.1.0

  • New: “Sign in with ZapQR” single sign-on (OpenID Connect, authorization-code + PKCE, RS256 ID-token verification via JWKS)
  • New: link existing users by verified email; configurable default role for new users; optional single logout through the identity provider
  • Changed: the QR widget script is now bundled with the plugin instead of loaded from zapqr.ai
  • Hardened: explicit sanitization on all settings

1.0.0

  • Initial release: QR code credential fill on wp-login.php, theme and accent customization

기초

  • 버전 1.2.0
  • 최근 업데이트: 5일 전
  • 활성화된 설치 10보다 적음
  • 워드프레스 버전 5.5 또는 그 이상
  • 다음까지 시험됨: 7.0.6
  • PHP 버전 7.4 또는 그 이상
  • 언어
    English (US)
  • 태그:
    authenticationloginpasskeypasswordlesssso
  • 고급 보기

평점

아직 제출된 리뷰가 없습니다.

Your review

모든 리뷰 보기

기여자

  • dasecure

지원

할 말 있으신가요? 도움이 필요하신가요?

지원 포럼 보기

기부

이 플러그인이 발전하도록 도우시겠습니까?

이 플러그인에 기부하기

  • 소개
  • 뉴스
  • 호스팅
  • 개인정보
  • 쇼케이스
  • 테마
  • 플러그인
  • 패턴
  • 배우기
  • 지원
  • 개발자 도구
  • WordPress.tv ↗
  • 참여하기
  • 이벤트
  • 기부하기 ↗
  • Swag ↗
  • WordPress.com ↗
  • Matt ↗
  • bbPress ↗
  • BuddyPress ↗
WordPress.org
WordPress.org

한국어

  • X(이전 트위터) 계정 방문하기
  • 블루스카이 계정 방문하기
  • 마스토돈 계정 방문하기
  • 스레드 계정 방문하기
  • 페이스북 페이지 방문하기
  • 인스타그램 계정 방문하기
  • LinkedIn 계정 방문하기
  • 틱톡 계정 방문하기
  • 유튜브 채널 방문하기
  • 텀블러 계정 방문하기
코드는 詩다
The WordPress® trademark is the intellectual property of the WordPress Foundation.