We reuse OpenID Connect Generic Client instead of writing a login from scratch. The settings that matter:
| Login type | OpenID Connect button on login form |
| Scope | openid email profile custom wallet |
| Endpoints | Copied from https://idattestor.totochain.net/.well-known/openid-configuration |
| Identity key | sub: the stable WoofID user ID, never the email |
| Display name | {name} |
| Link existing users | Off, so nobody can claim an existing WordPress account just by having the same email |
| Create user if missing | On |
| State time limit | 1800 seconds, so a WoofID magic link still works when the email is slow to arrive |
On this site setup.sh writes all of these with WP-CLI, so the whole site can be rebuilt from scratch with one command.