WP SAML Auth
View on WordPress.orgScores higher than 66% of indexed plugins
About
SAML authentication for WordPress.
What It Does
WP SAML Auth enables WordPress to accept logins through a SAML 2.0 identity provider, letting users sign in with corporate or institutional SSO credentials instead of a local WordPress password. It bridges WordPress with existing identity systems such as Okta, Azure AD, OneLogin, or Shibboleth so that user provisioning and authentication are handled centrally. Role mapping and attribute-based permissions are configurable through the plugin's settings.
Who It's For
This plugin is built for organizations that already run an enterprise identity provider and need WordPress to sit inside that same login ecosystem, such as universities, healthcare networks, government agencies, and corporate intranets. It suits administrators comfortable editing PHP configuration files or constants, since several settings are exposed through wp-config rather than the admin UI. Sites with fewer than a handful of SSO users will find the setup overhead disproportionate.
Who Should Skip It
If you only need two-factor protection on standard WordPress logins, or your team is small with no central IdP, this plugin adds complexity without real benefit. Blog owners, small business sites, and anyone relying on social login or basic password authentication should look at lighter plugins like Two Factor or Google Authenticator instead.
The Bottom Line
WP SAML Auth delivers a focused, well-maintained SAML 2.0 integration that earns its 78.48 overall score through strong compatibility and a clean code trail. Its limited install base and thin support footprint mean you should be comfortable troubleshooting IdP integration with limited community backup. For organizations that need WordPress to honour an existing SSO, it is a sensible choice; for everyone else, a simpler auth plugin will do the job with less friction.
Related Plugins
Pick this if you only need a second login factor on standard WordPress accounts and do not run a SAML identity provider.
Choose this when your goal is gating site content behind registrations rather than federating with an external IdP.
Pick this if you want a more GUI-driven SAML setup with premium support tiers, though it has a similar install count and slightly lower quality score.
Choose this for a lightweight TOTP second factor when SAML is overkill for your use case.
Pick this for brute-force protection on standard WordPress logins rather than enterprise SSO.