OAuth Single Sign On – SSO (OAuth Client)
View on WordPress.orgScores higher than 73% of indexed plugins
About
WordPress OAuth SSO (Single Sign On) with Azure, Okta, Cognito, Keycloak, OAuth & OpenID Providers. Free Unlimited SSO Authentication [24/7 Support]
Security History
What It Does
This plugin enables WordPress single sign-on (SSO) by connecting your site as an OAuth or OpenID Connect client against a wide range of identity providers, including Azure, Azure B2C, AWS Cognito, Okta, ClassLink, Discord, Clever, Keycloak, and any generic OAuth 2.0 server. In practice, it lets you replace or supplement the default WordPress login form so users authenticate through an external identity provider instead of a local password. It is built primarily for enterprise, education, and gaming-community sites that already manage users in an external directory.
Who It's For
This plugin is best suited for organizations, schools, enterprises, or community sites that already run an external identity provider and want WordPress to act as a relying party for SSO. It fits IT administrators who need to federate Azure AD, Okta, ClassLink, Keycloak, or similar providers with a WordPress site. It is also a fit for EVE Online community sites, Discord-driven communities, and any team that wants centralized user provisioning and de-provisioning rather than managing local WordPress accounts.
Who Should Skip It
Small personal blogs, brochure sites, and small businesses that only need a simple login form should skip this plugin, as the configuration overhead is far higher than the value delivered. Anyone looking for a general security plugin, login customizer, or brute-force protection tool should also look elsewhere, because this plugin does only SSO and nothing else.
The Bottom Line
MiniOrange OAuth Single Sign On is a focused, well-maintained, and highly rated enterprise SSO bridge for WordPress, scoring 79.12 out of 100 on PluginCheck. Its only meaningful weakness is the lack of visible public support threads, which is worth confirming with the vendor if you depend on SLA-style help. For its narrow audience it is a strong pick, but it is overkill for anyone who does not already use an external identity provider.
Related Plugins
Pick WPS Hide Login instead if all you need is to change the wp-login URL for lightweight obscurity against bots, not real SSO.
Pick Loginizer instead if your goal is brute-force protection, login attempt limiting, and password hardening rather than federated identity.
Pick this security suite instead if you need a broad firewall, malware scanning, and hardening toolkit rather than an identity provider bridge.
Pick SiteGround Security Optimizer instead if you want all-in-one hardening plus login tweaks, and you are not trying to federate with an external IdP.
Pick LoginPress instead if your priority is redesigning the wp-login page and adding branding, not adding external identity providers.