# mahak-authenticate-bridge Authenticate WordPress user via json web token from Laravel Application. ## Features - Create user if not exists - Login via JWT token - Admin settings page - Custom invalid token page - Optional debug mode with full exception details and stack traces Debug mode is disabled by default. An administrator can enable it from **Settings > Mahak Authentication** while troubleshooting. The debug page includes server clock/timezone data, safe JWT timing claims, and a Copy Markdown report. JWT contents, secrets, request parameters, and stack-trace arguments are omitted. Because diagnostic pages still expose server paths and other technical details to visitors of the login URL, disable it again after diagnosing the problem. ## Updates Administrators can check for and install published releases from **Settings > Mahak Authentication**. Updates also appear in WordPress's standard **Plugins** and **Updates** screens. To publish an update, change the plugin `Version` header and `MAHAK_AUTHENTICATE_BRIDGE_VERSION` constant to the same version, commit the change, and push a matching tag such as `v2.3.0` to Mahgit. The Gitea Actions workflow builds and attaches the ZIP required by the WordPress updater. ## Usage Send users to: https://your-wp-site.com/mahak/login/?token=TOKEN With required data encoded in the token. Payload JWT: ```json { "iat" : 1752671371, "jti" : "---qwe---", "iss" : "https://api.test", "exp" : 1763039371, "aud" : "https://api.test", "data" : { "id" : 1, "name" : "Test User", "mobile" : "9123456789", "email" : "user@gmail.com", "username" : "test-user" } } ```