Description
Casdoor is an open-source identity and access management (IAM) and single sign-on (SSO) platform. With this plugin your users log in to WordPress with their Casdoor account, over OAuth 2.0 and OpenID Connect, the same way they log in to the other applications of your organization.
Behind Casdoor they can use passwords, MFA, passkeys, social logins (Google, GitHub, WeChat, Microsoft and many more), LDAP, SAML or any other provider Casdoor supports, without another plugin in WordPress.
Features
- Replaces the WordPress login page with Casdoor, or adds a “Log in with Casdoor” button to it.
- Creates the WordPress user on the first login, or only lets existing users in.
- Links WordPress users to Casdoor users by the Casdoor user ID or a verified email, never by the user name alone.
- Only lets in the users of one Casdoor organization, if you want.
- Logs out of Casdoor together with WordPress.
- Optional automatic login for visitors that are not logged in.
- The
[casdoor_login_button]shortcode for a login link anywhere. - Protects the login with the OAuth
state, verifies TLS and asks Casdoor for the user, so a login can not be forged.
Users that only exist in WordPress, such as the first admin, can still use the WordPress login form at /wp-login.php?use_native_login=1.
Casdoor
- Website: casdoor.ai
- Source code of Casdoor: github.com/casdoor/casdoor
- Source code of this plugin: github.com/casdoor/wordpress-casdoor-plugin
External services
This plugin connects to the Casdoor server that you set in Settings > Casdoor SSO. It is your own Casdoor (self-hosted or a Casdoor cloud instance), the plugin does not connect to any other service.
- When a user logs in, the browser is sent to the login page of your Casdoor server.
- After the login, the plugin sends the authorization code with the client ID and client secret of your Casdoor application to the server, and gets the access token and the user’s account (name, display name, email, organization) from it.
- When a user logs out and “Log out of Casdoor too” is enabled, the browser is sent to the logout page of your Casdoor server with the user’s token.
Casdoor is open-source software under the Apache-2.0 license. The terms and privacy policy are those of whoever runs your Casdoor server; for Casdoor cloud they are at casdoor.com/terms and casdoor.com/privacy.
Screenshots

Installation
- Install and activate the plugin.
- In Casdoor, create an application (or use an existing one) and add
https://your-site/?auth=casdoorto its “Redirect URLs”. To log out of Casdoor together with WordPress, addhttps://your-site/too. - In WordPress, go to Settings > Casdoor SSO, enter the URL of your Casdoor server and the client ID and client secret of the application, and check “Activate”.
FAQ
-
Do I need a Casdoor server?
-
Yes. Run your own with Docker (see the Casdoor docs) or use Casdoor cloud.
-
I am locked out after activating the plugin.
-
Use the WordPress login form at
/wp-login.php?use_native_login=1. -
Which WordPress user does a Casdoor user log in as?
-
The WordPress user that is linked to the Casdoor user, the one that logged in with this Casdoor user before, or the one with the same email when Casdoor has verified the email. Otherwise a new WordPress user is created, unless “Existing users only” is checked. The admins of the organization in the “Organization” setting become WordPress administrators.
-
Can I change where users go after logging in?
-
Yes, with the
casdoor_user_redirect_urlfilter. Thecasdoor_user_loginandcasdoor_user_createdactions run after a login and after a new user is created.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Casdoor – SSO, OAuth 2.0 & OIDC Login” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Casdoor – SSO, OAuth 2.0 & OIDC Login” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
See the releases on GitHub.
