- Wallet addresses are blank for most people. WoofID only shares wallet addresses when that session was signed in with the wallet itself. That’s a deliberate WoofID security rule.
- The login plugin retries
login_required. Withoutwoof-keyintercepting the callback first, a failed silent check would bounce the visitor onto the full WoofID login page. - No return trip after sign-out. Self-service WoofID apps can’t register a page to come back to after sign-out, so sign-out ends on WoofID’s own page.
- No PKCE needed. The plugin doesn’t support PKCE, and WoofID doesn’t require it from apps that have a client secret.
- Wallet-only accounts have no email. WordPress needs one, so
woof-keyfills in a placeholder atusers.woofid.invalid. - Break-glass admin. The password form is hidden. Maintainers reach it at
/wp-login.php?woof-local=1.