Category: Guide

  • 3. The digital key: silent sign-in

    The “digital key” is a small must-use plugin, woof-key, on top of the login plugin.

    • A signed-out visitor opens a post in the Members category.
    • WordPress sends the browser to WoofID with prompt=none. That means: don’t show anything, just say whether this person is already signed in and has approved this site.
    • If yes, WoofID sends them straight back, signed in, to the same post. No click, no form.
    • If not, WoofID answers login_required or consent_required. woof-key catches that before the login plugin can retry, sets a 10-minute cookie so it doesn’t ask again, and shows the “Unlock with WoofID” door.

    Bots, link previews and non-GET requests never trigger the silent check. Signing out also sets the cookie, so you aren’t logged straight back in.

  • 4. What WoofID shares, tier by tier

    The scope you request decides what WoofID shares. Your own copy is on Your WoofID key.

    ScopeTierYou get
    openidfreeWoofID user ID, how and when they signed in
    emailfreeEmail and whether it is verified (left out entirely if the account has no email)
    profilefreeName, username, avatar
    custombasicSign-up source, role, whether a password or passwordless login is set
    walletbasicWallet type, whether the account can sign Totochain transactions, and the wallet addresses (see Gotchas)

    WoofID does not share identity verification levels or attestations over OpenID Connect today.

  • 5. Gotchas we hit

    • Wallet addresses are blank for most people. WoofID only shares wallet addresses when that session was signed in with the wallet itself. That’s a deliberate WoofID security rule.
    • The login plugin retries login_required. Without woof-key intercepting the callback first, a failed silent check would bounce the visitor onto the full WoofID login page.
    • No return trip after sign-out. Self-service WoofID apps can’t register a page to come back to after sign-out, so sign-out ends on WoofID’s own page.
    • No PKCE needed. The plugin doesn’t support PKCE, and WoofID doesn’t require it from apps that have a client secret.
    • Wallet-only accounts have no email. WordPress needs one, so woof-key fills in a placeholder at users.woofid.invalid.
    • Break-glass admin. The password form is hidden. Maintainers reach it at /wp-login.php?woof-local=1.
  • 1. Register your site as a WoofID app

    WordPress signs people in with WoofID through OpenID Connect. First, WoofID needs to know about the site.

    1. Sign in at https://idattestor.totochain.net and open Developer → Register app.
    2. Name: Woof Key Club. Redirect URI: https://wordpress.totochain.net/wp-admin/admin-ajax.php?action=openid-connect-authorize (the OpenID Connect plugin’s callback).
    3. Request the basic tier. It adds wallet information and sign-in details on top of name, email and avatar.
    4. A WoofID admin approves the app. You then get a client ID and a client secret. Keep the secret on the server only.

    WoofID shows a one-time consent screen the first time each person signs in, because this is a third-party app. After they approve, WoofID remembers it.

  • 2. Configure the OpenID Connect plugin

    We reuse OpenID Connect Generic Client instead of writing a login from scratch. The settings that matter:

    Login typeOpenID Connect button on login form
    Scopeopenid email profile custom wallet
    EndpointsCopied from https://idattestor.totochain.net/.well-known/openid-configuration
    Identity keysub: the stable WoofID user ID, never the email
    Display name{name}
    Link existing usersOff, so nobody can claim an existing WordPress account just by having the same email
    Create user if missingOn
    State time limit1800 seconds, so a WoofID magic link still works when the email is slow to arrive

    On this site setup.sh writes all of these with WP-CLI, so the whole site can be rebuilt from scratch with one command.