Title: ZapQR Login
Author: dasecure
Published: <strong>August 25, 2026</strong>
Last modified: August 31, 2026

---

Search plugins

![](https://ps.w.org/zapqr-login/assets/banner-772x250.png?rev=3674421)

![](https://ps.w.org/zapqr-login/assets/icon-256x256.png?rev=3674421)

# ZapQR Login

 By [dasecure](https://profiles.wordpress.org/dasecure/)

[Download](https://downloads.wordpress.org/plugin/zapqr-login.1.1.1.zip)

 * [Details](https://test.wordpress.org/plugins/zapqr-login/#description)
 * [Reviews](https://test.wordpress.org/plugins/zapqr-login/#reviews)
 *  [Installation](https://test.wordpress.org/plugins/zapqr-login/#installation)
 * [Development](https://test.wordpress.org/plugins/zapqr-login/#developers)

 [Support](https://wordpress.org/support/plugin/zapqr-login/)

## Description

ZapQR Login gives your WordPress site passwordless sign-in, two ways:

#### Sign in with ZapQR (SSO) — recommended

A “Sign in with ZapQR” button on your login page. Visitors sign in with their ZapQR
account — passkey-first (Face ID / Touch ID / security key), with an email link 
as fallback — via standards-based OpenID Connect single sign-on. One ZapQR account
works across every site that offers it.

 * Passkey-first: phishing-resistant WebAuthn sign-in, no passwords anywhere
 * Standards-based: OAuth 2.0 authorization-code flow with PKCE; ID tokens verified
   in the plugin (RS256, JWKS)
 * Links existing WordPress users by their verified email — admins keep their role
 * New visitors are created with a low-privilege role you choose (Subscriber by 
   default)
 * Single logout: logging out of WordPress also ends the ZapQR session
 * No external code: the whole flow is server-side redirects and server-to-server
   calls

#### QR credential fill (classic)

Users save their WordPress credentials in the ZapQR app; on the login page they 
scan a QR code and the login form fills and submits itself. Credentials travel phone
browser over an encrypted WebSocket relay and are never stored on external servers.

### External services

This plugin talks to the following services. No data is sent anywhere until a site
administrator enables the relevant mode.

**ZapQR identity provider** (SSO mode) — `auth.zapqr.ai` by default, or a self-hosted
issuer the admin configures. When a visitor clicks “Sign in with ZapQR” their browser
is redirected there to authenticate; your server then exchanges an authorization
code (server-to-server) and receives the visitor’s email address and its verified
status — nothing else. Provider: DaSecure ([zapqr.ai](https://zapqr.ai), terms and
privacy linked there).

**ZapQR relay** (QR mode) — `wss://relay.zapqr.ai`, a WebSocket relay that pairs
the login page with the visitor’s phone using a random session identifier. Credentials
pass through end-to-end encrypted and are not stored. Provider: DaSecure ([zapqr.ai](https://zapqr.ai)).

**QR image service** (QR mode) — `api.qrserver.com` renders the QR image. It receives
only the random session identifier and your site’s hostname — never credentials.
Provider: [goqr.me](https://goqr.me/) ([privacy](https://www.qrserver.com/en/privacy/)).

## Screenshots

[⌊The WordPress login page: "Sign in with ZapQR" above the classic QR widget⌉⌊The
WordPress login page: "Sign in with ZapQR" above the classic QR widget⌉[

The WordPress login page: “Sign in with ZapQR” above the classic QR widget

[⌊Settings > ZapQR Login: SSO configuration, with the exact URIs to register⌉⌊Settings
> ZapQR Login: SSO configuration, with the exact URIs to register⌉[

Settings > ZapQR Login: SSO configuration, with the exact URIs to register

[⌊Signing in from a TV, kiosk or car - scan the code, approve on your phone⌉⌊Signing
in from a TV, kiosk or car - scan the code, approve on your phone⌉[

Signing in from a TV, kiosk or car – scan the code, approve on your phone

[⌊Single logout: signing out of WordPress ends the ZapQR session too⌉⌊Single logout:
signing out of WordPress ends the ZapQR session too⌉[

Single logout: signing out of WordPress ends the ZapQR session too

## Installation

 1. Install and activate the plugin.
 2. **For SSO:** go to Settings > ZapQR Login, copy the Redirect URI and Post-logout
    URI shown there, register your site at the ZapQR identity provider to get a Client
    ID and Secret, paste them in, tick Enable, save.
 3. **For QR fill:** nothing to configure — the widget appears on wp-login.php. Customize
    theme and accent color in Settings > ZapQR Login.

## FAQ

### What does the site receive about the visitor in SSO mode?

Only a verified email address and a stable account identifier, delivered in a cryptographically
signed token that the plugin verifies against the provider’s published keys. No 
passwords, no passkeys, no profile data.

### Can someone take over an existing account?

No. Linking to an existing WordPress user happens only when the ZapQR identity provider
asserts the email is verified; unverified emails are rejected outright. You can 
also disable linking entirely, and new users always get the low-privilege role you
configure.

### Where do passkeys live?

With the visitor and the ZapQR identity provider — never on your WordPress site.
Your site only consumes the signed sign-in assertion.

### Does the QR credential mode still work?

Yes, unchanged. It is a separate, coexisting mode: the ZapQR app stores per-site
WordPress credentials locally on the phone (Face ID / Touch ID protected) and relays
them to the browser at login.

### Does this work with multisite?

Yes.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“ZapQR Login” is open source software. The following people have contributed to 
this plugin.

Contributors

 *   [ dasecure ](https://profiles.wordpress.org/dasecure/)

[Translate “ZapQR Login” into your language.](https://translate.wordpress.org/projects/wp-plugins/zapqr-login)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/zapqr-login/), check
out the [SVN repository](https://plugins.svn.wordpress.org/zapqr-login/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/zapqr-login/) by
[RSS](https://plugins.trac.wordpress.org/log/zapqr-login/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.1.1

 * Fixed: the QR widget showed a stale, unscannable code after a login was delivered(
   e.g. after logging out and back in). It now refreshes its session automatically
   after every successful fill.
 * New: `window.ZapQR.refresh()` lets themes/plugins request a fresh QR programmatically.

#### 1.1.0

 * New: “Sign in with ZapQR” single sign-on (OpenID Connect, authorization-code 
   + PKCE, RS256 ID-token verification via JWKS)
 * New: link existing users by verified email; configurable default role for new
   users; optional single logout through the identity provider
 * Changed: the QR widget script is now bundled with the plugin instead of loaded
   from zapqr.ai
 * Hardened: explicit sanitization on all settings

#### 1.0.0

 * Initial release: QR code credential fill on wp-login.php, theme and accent customization

## Meta

 *  Version **1.1.1**
 *  Last updated **2 weeks ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.5 or higher **
 *  Tested up to **7.0.4**
 *  PHP version ** 7.4 or higher **
 *  Language
 * [English (US)](https://wordpress.org/plugins/zapqr-login/)
 * Tags
 * [authentication](https://test.wordpress.org/plugins/tags/authentication/)[login](https://test.wordpress.org/plugins/tags/login/)
   [passkey](https://test.wordpress.org/plugins/tags/passkey/)[passwordless](https://test.wordpress.org/plugins/tags/passwordless/)
   [sso](https://test.wordpress.org/plugins/tags/sso/)
 *  [Advanced View](https://test.wordpress.org/plugins/zapqr-login/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/zapqr-login/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/zapqr-login/reviews/)

## Contributors

 *   [ dasecure ](https://profiles.wordpress.org/dasecure/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/zapqr-login/)

## Donate

Would you like to support the advancement of this plugin?

 [ Donate to this plugin ](https://zapqr.ai)