mahak-authenticate-bridge
Authenticate WordPress user via json web token from Laravel Application.
Features
- Create user if not exists
- Login via JWT token
- Admin settings page
- Custom invalid token page
- Optional debug mode with full exception details and stack traces
- Configurable role for users created through Mahak authentication
Debug mode is disabled by default. An administrator can enable it from Settings > Mahak Authentication while troubleshooting. The debug page includes server clock/timezone data, safe JWT timing claims, and a Copy Markdown report. JWT contents, secrets, request parameters, and stack-trace arguments are omitted. Because diagnostic pages still expose server paths and other technical details to visitors of the login URL, disable it again after diagnosing the problem.
Updates
Administrators can check for and install published releases from Settings > Mahak Authentication. Updates also appear in WordPress's standard Plugins and Updates screens.
The New user role setting defaults to WordPress Default, using the site's current global new-user role without changing it. Administrators can select a different role only for accounts created by this plugin; existing users keep their current roles.
To publish an update, change the plugin Version header and MAHAK_AUTHENTICATE_BRIDGE_VERSION constant to the same version, commit the change, and push a matching tag such as v2.4.0 to Mahgit. The Gitea Actions workflow builds and attaches the ZIP required by the WordPress updater.
Usage
Send users to: https://your-wp-site.com/mahak/login/?token=TOKEN
With required data encoded in the token.
Payload JWT:
{
"iat" : 1752671371,
"jti" : "---qwe---",
"iss" : "https://api.test",
"exp" : 1763039371,
"aud" : "https://api.test",
"data" : {
"id" : 1,
"name" : "Test User",
"mobile" : "9123456789",
"email" : "user@gmail.com",
"username" : "test-user"
}
}