{"id":350324,"date":"2026-08-11T16:05:19","date_gmt":"2026-08-11T16:05:19","guid":{"rendered":"https:\/\/ja.wordpress.org\/plugins\/rapls-passkey\/"},"modified":"2026-09-14T13:10:39","modified_gmt":"2026-09-14T13:10:39","slug":"rapls-passkey","status":"publish","type":"plugin","link":"https:\/\/sw.wordpress.org\/plugins\/rapls-passkey\/","author":23425763,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.13.77","stable_tag":"0.13.77","tested":"7.1.1","requires":"6.0","requires_php":"8.2","requires_plugins":null,"header_name":"Rapls Passkey \u2013 Passwordless Login with WebAuthn","header_author":"Rapls","header_description":"Passwordless authentication for WordPress using passkeys (WebAuthn \/ FIDO2).","assets_banners_color":"0146d8","last_updated":"2026-09-14 13:10:39","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/raplsworks.com\/plugins\/rapls-passkey\/","header_author_uri":"https:\/\/raplsworks.com\/","rating":5,"author_block_rating":0,"active_installs":0,"downloads":441,"num_ratings":2,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.13.68":{"tag":"0.13.68","author":"rapls","date":"2026-08-11 16:04:53","revision":3642252},"0.13.69":{"tag":"0.13.69","author":"rapls","date":"2026-08-12 02:25:57","revision":3642716},"0.13.70":{"tag":"0.13.70","author":"rapls","date":"2026-08-12 07:45:47","revision":3642988},"0.13.71":{"tag":"0.13.71","author":"rapls","date":"2026-08-18 10:58:17","revision":3652597},"0.13.73":{"tag":"0.13.73","author":"rapls","date":"2026-08-20 06:13:48","revision":3655940},"0.13.74":{"tag":"0.13.74","author":"rapls","date":"2026-08-20 07:37:08","revision":3656135},"0.13.75":{"tag":"0.13.75","author":"rapls","date":"2026-08-25 07:44:27","revision":3664811},"0.13.76":{"tag":"0.13.76","author":"rapls","date":"2026-09-06 14:52:14","revision":3683560},"0.13.77":{"tag":"0.13.77","author":"rapls","date":"2026-09-14 13:10:39","revision":3695280}},"upgrade_notice":{"0.13.70":"<p>On PHP older than 8.2 the previous release took the whole site down, front end included. The plugin now steps aside with an admin notice instead.<\/p>","0.13.66":"<p>Administrator enrolment is on by default instead of being unlocked by the Pro add-on. Translations now come from translate.wordpress.org rather than a bundled catalogue.<\/p>","0.13.63":"<p>Every file in the previous package failed the WordPress Plugin Check direct-access test: the guard was rewritten by the build into a form the tool does not recognise. Fixed, along with the code-standard findings that were hidden behind misplaced exemptions.<\/p>","0.13.53":"<p>Fixes CSV injection in the audit-log export: a formula preceded by whitespace was not neutralised. Update if you export audit logs.<\/p>","0.13.28":"<p>Security (multisite): a user marked as spam on the network could still sign in with a passkey, a QR approval, a magic link or a recovery code. Update immediately on multisite.<\/p>"},"ratings":{"1":0,"2":0,"3":0,"4":0,"5":2},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3642248,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3642248,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3642248,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3642248,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":{"rapls-passkey\/login":{"name":"rapls-passkey\/login","title":"Sign in with a passkey"},"rapls-passkey\/register":{"name":"rapls-passkey\/register","title":"Manage passkeys"}},"tagged_versions":["0.13.68","0.13.69","0.13.70","0.13.71","0.13.73","0.13.74","0.13.75","0.13.76","0.13.77"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3642248,"resolution":"1","location":"assets","locale":"","width":1002,"height":1132},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3642248,"resolution":"2","location":"assets","locale":"","width":876,"height":1288},"screenshot-3.png":{"filename":"screenshot-3.png","revision":3642248,"resolution":"3","location":"assets","locale":"","width":1770,"height":600},"screenshot-4.png":{"filename":"screenshot-4.png","revision":3642248,"resolution":"4","location":"assets","locale":"","width":876,"height":672},"screenshot-5.png":{"filename":"screenshot-5.png","revision":3642248,"resolution":"5","location":"assets","locale":"","width":1000,"height":690},"screenshot-6.png":{"filename":"screenshot-6.png","revision":3642248,"resolution":"6","location":"assets","locale":"","width":886,"height":870},"screenshot-7.png":{"filename":"screenshot-7.png","revision":3642248,"resolution":"7","location":"assets","locale":"","width":1842,"height":838},"screenshot-8.png":{"filename":"screenshot-8.png","revision":3642248,"resolution":"8","location":"assets","locale":"","width":2350,"height":1336}},"screenshots":{"1":"Sign in with a passkey from the normal WordPress login screen.","2":"The browser offers the passkeys saved for this site.","3":"Your registered passkeys: rename, suspend or delete each one.","4":"Registering a passkey from your profile screen.","5":"Touch ID confirms before the passkey is saved.","6":"Choose where the passkey is stored.","7":"The first-run check: HTTPS, the relying-party ID, and the WebAuthn library.","8":"Every registration, sign-in and removal, exportable as CSV."}},"plugin_section":[262246],"plugin_tags":[602,218738,9223,9217,183349],"plugin_category":[38],"plugin_contributors":[253146],"plugin_business_model":[],"class_list":["post-350324","plugin","type-plugin","status-publish","hentry","plugin_section-dashboard-widgets","plugin_tags-login","plugin_tags-passkey","plugin_tags-passwordless","plugin_tags-two-factor","plugin_tags-webauthn","plugin_category-authentication","plugin_contributors-rapls","plugin_committers-rapls"],"banners":{"banner":"https:\/\/ps.w.org\/rapls-passkey\/assets\/banner-772x250.png?rev=3642248","banner_2x":"https:\/\/ps.w.org\/rapls-passkey\/assets\/banner-1544x500.png?rev=3642248","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/rapls-passkey\/assets\/icon-128x128.png?rev=3642248","icon_2x":"https:\/\/ps.w.org\/rapls-passkey\/assets\/icon-256x256.png?rev=3642248","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/rapls-passkey\/assets\/screenshot-1.png?rev=3642248","caption":"Sign in with a passkey from the normal WordPress login screen."},{"src":"https:\/\/ps.w.org\/rapls-passkey\/assets\/screenshot-2.png?rev=3642248","caption":"The browser offers the passkeys saved for this site."},{"src":"https:\/\/ps.w.org\/rapls-passkey\/assets\/screenshot-3.png?rev=3642248","caption":"Your registered passkeys: rename, suspend or delete each one."},{"src":"https:\/\/ps.w.org\/rapls-passkey\/assets\/screenshot-4.png?rev=3642248","caption":"Registering a passkey from your profile screen."},{"src":"https:\/\/ps.w.org\/rapls-passkey\/assets\/screenshot-5.png?rev=3642248","caption":"Touch ID confirms before the passkey is saved."},{"src":"https:\/\/ps.w.org\/rapls-passkey\/assets\/screenshot-6.png?rev=3642248","caption":"Choose where the passkey is stored."},{"src":"https:\/\/ps.w.org\/rapls-passkey\/assets\/screenshot-7.png?rev=3642248","caption":"The first-run check: HTTPS, the relying-party ID, and the WebAuthn library."},{"src":"https:\/\/ps.w.org\/rapls-passkey\/assets\/screenshot-8.png?rev=3642248","caption":"Every registration, sign-in and removal, exportable as CSV."}],"raw_content":"<!--section=description-->\n<p>Rapls Passkey adds passkey sign-in to WordPress. Touch ID, Windows Hello, Face\nID or a security key takes the place of the password, and your server never\nholds a shared secret \u2014 only a public key, which is useless to anyone who\nsteals it.<\/p>\n\n<p>A video walkthrough (in Japanese):<\/p>\n\n<p>https:\/\/www.youtube.com\/watch?v=6qeKYlZrh1M<\/p>\n\n<p>It is built to run where most WordPress sites actually run:<\/p>\n\n<ul>\n<li><strong>No PHP extension to install.<\/strong> Nothing beyond what WordPress itself already needs. In particular <code>gmp<\/code> is not required, so there is nothing to ask your shared host for and nothing that stops working when the server's PHP is upgraded.<\/li>\n<li><strong>Nothing leaves your site.<\/strong> The passkey ceremony happens between the browser and your own server. No account, no API key, no third-party service in the login path.<\/li>\n<li><strong>Passwords keep working.<\/strong> Password login is never switched off in the free plugin. Nobody gets locked out while a site moves across.<\/li>\n<li><strong>Japanese UI included.<\/strong> Fully translated, alongside the English source.<\/li>\n<\/ul>\n\n<h4>What the free plugin does<\/h4>\n\n<ul>\n<li>Passwordless, phishing-resistant sign-in (WebAuthn \/ FIDO2)<\/li>\n<li>Same-device passkeys (Touch ID \/ Windows Hello \/ Face ID)<\/li>\n<li>Cross-device sign-in using the browser's native passkey flow when the browser offers it (scan with your phone). A custom QR approval flow is available in Pro.<\/li>\n<li>Shortcodes and Gutenberg blocks (login \/ passkey management) you can embed on any page<\/li>\n<li>Rename, suspend and resume individual passkeys \u2014 a device that is temporarily out of reach can be cut off without destroying the credential<\/li>\n<li>A site-wide passkey list for administrators (Users -&gt; Passkeys), searchable by owner or name<\/li>\n<li>Works with two-factor plugins (Wordfence Login Security, Two-Factor, ...): a passkey counts as the second factor, while weaker alternative logins must still pass the site's 2FA<\/li>\n<li>An audit log of registrations, sign-ins and removals, exportable as CSV<\/li>\n<li>WP-CLI commands, a first-run configuration check, and an emergency bypass constant<\/li>\n<li>Fully translatable UI (English source; translations come from translate.wordpress.org)<\/li>\n<\/ul>\n\n<h4>Shortcodes<\/h4>\n\n<p>Embed them in any page, post, or widget. In the block editor they are also available as the \"Sign in with a passkey\" and \"Manage passkeys\" blocks.<\/p>\n\n<ul>\n<li><code>[rapls_passkey_login]<\/code> \u2014 a passkey sign-in button for logged-out visitors. Supports the <code>redirect<\/code> (URL to go to after success) and <code>label<\/code> (button text) attributes.<\/li>\n<li><code>[rapls_passkey_register]<\/code> \u2014 a management UI where logged-in users can register and remove their own passkeys.<\/li>\n<\/ul>\n\n<h4>Requirements<\/h4>\n\n<ul>\n<li>WordPress 6.0 or later<\/li>\n<li>PHP 8.2 or later<\/li>\n<li>HTTPS, except on localhost \u2014 browsers refuse WebAuthn without it<\/li>\n<\/ul>\n\n<p>No PHP extension beyond WordPress's own requirements.<\/p>\n\n<h4>Rapls Passkey Pro<\/h4>\n\n<p>Everything above is free, and stays free. Pro is a separate add-on for the part\nthat comes after the first passkey: moving a whole site across, and keeping a\nway in when a device goes missing.<\/p>\n\n<ul>\n<li><strong>Sign in from another device<\/strong> \u2014 approve a login on your computer from your phone, with a QR code and a four-digit confirmation code so a relayed code cannot be used elsewhere<\/li>\n<li><strong>A way back in that is not a password<\/strong> \u2014 one-time recovery codes and email magic-link sign-in<\/li>\n<li><strong>Roll out by role<\/strong> \u2014 require passkeys for the roles you choose, with a grace period, then turn password login off once everyone is across<\/li>\n<li><strong>Adaptive step-up<\/strong> \u2014 ask for a passkey again after a password sign-in from somewhere unfamiliar<\/li>\n<li><strong>Authenticator policy<\/strong> \u2014 FIDO Metadata Service checks, AAGUID allow and deny lists, trusted-device management<\/li>\n<li><strong>Operations<\/strong> \u2014 security webhooks, adoption reports, multisite network settings, WP-CLI<\/li>\n<\/ul>\n\n<p>One-time purchase, no subscription, with a year of updates and a 14-day refund.\n<a href=\"https:\/\/raplsworks.com\/rapls-passkey-pro\/\">Details and pricing<\/a><\/p>\n\n<h3>External services<\/h3>\n\n<p>This plugin sends nothing to any external service by default. One optional\nintegration, off unless you turn it on, contacts a third party:<\/p>\n\n<p><strong>Google reCAPTCHA v3<\/strong> \u2014 used only when you enable reCAPTCHA for password\nlogins. When it is on, the visitor's browser loads\n    https:\/\/www.google.com\/recaptcha\/api.js, and the plugin sends the resulting\ntoken together with the request IP address to\n    https:\/\/www.google.com\/recaptcha\/api\/siteverify so that Google can score the\nrequest. Nothing is sent while the option is off. This service is provided by\nGoogle and its use is governed by Google's terms and privacy policy:<\/p>\n\n<ul>\n<li>Terms of Service: https:\/\/policies.google.com\/terms<\/li>\n<li>Privacy Policy: https:\/\/policies.google.com\/privacy<\/li>\n<\/ul>\n\n<p>No other host is contacted. The plugin bundles the public suffix list it needs\n(<code>data\/public_suffix_list.dat<\/code>) rather than fetching it, and passkey ceremonies\nhappen between the browser and your own site.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>Authentication data is stored on your own site.<\/p>\n\n<p>What is stored:<\/p>\n\n<ul>\n<li>Passkey credential records (public key, credential ID, sign counter, a label and timestamps) in a custom database table.<\/li>\n<li>A per-user WebAuthn user handle in user meta, plus one row in the options table recording that the account has one. The handle carries nothing about the person: for accounts created from this version it is derived from the account id and a site secret, and accounts that already had a random handle keep it.<\/li>\n<li>An optional audit log of passkey events (registration, sign-in, removal) with the acting user, IP address and timestamp.<\/li>\n<\/ul>\n\n<p>Retention and removal:<\/p>\n\n<ul>\n<li>Passkey records remain until the user or an administrator deletes them; deleting a user removes their passkey records.<\/li>\n<li>The plugin integrates with WordPress's built-in personal-data export and erase tools, so a user's passkey and audit data are included in export\/erase requests.<\/li>\n<li>Uninstalling the plugin (delete from the Plugins screen) drops its custom table and options.<\/li>\n<\/ul>\n\n<p>This plugin does not use cookies for tracking. It sets only short-lived, functional cookies during a login ceremony (for example the pending second-factor login), which expire within minutes.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Place the plugin in <code>wp-content\/plugins\/rapls-passkey<\/code>.<\/li>\n<li>Activate \"Rapls Passkey\" from the Plugins screen.<\/li>\n<li>Register a passkey from your profile screen.<\/li>\n<\/ol>\n\n<p>Nothing else is required: no account, no API key, no configuration before the\nfirst passkey. The settings screen shows a first-run check (HTTPS, the\nrelying-party ID, the WebAuthn library) so you can see the site is ready.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20need%20any%20php%20extensions%3F\"><h3>Does this need any PHP extensions?<\/h3><\/dt>\n<dd><p>No. It runs on what WordPress itself already requires. Some WebAuthn plugins\nneed <code>gmp<\/code> compiled into PHP, which is not present on every shared host and can\ndisappear when the host upgrades PHP; this plugin does not use it.<\/p><\/dd>\n<dt id=\"does%20it%20work%20on%20shared%20hosting%3F\"><h3>Does it work on shared hosting?<\/h3><\/dt>\n<dd><p>Yes. There is no extension to install, no persistent process, and nothing\nwritten outside the plugin's own table and options.<\/p><\/dd>\n<dt id=\"which%20browsers%20and%20devices%20work%3F\"><h3>Which browsers and devices work?<\/h3><\/dt>\n<dd><p>Any current browser with a built-in authenticator \u2014 Touch ID, Windows Hello,\nFace ID \u2014 or a FIDO2 security key. If the machine in front of you has no\npasskey for the site, the browser's own cross-device flow lets you scan with\nyour phone instead.<\/p><\/dd>\n<dt id=\"is%20the%20free%20version%20limited%3F\"><h3>Is the free version limited?<\/h3><\/dt>\n<dd><p>No. Passkey sign-in, registration, management, the shortcodes and blocks, the\nadministrator's passkey list and the two-factor integrations are all in the free\nplugin, without a cap, a trial period or a licence key. Rapls Passkey Pro is a\nseparate add-on that adds different features \u2014 cross-device QR login, recovery\ncodes, enforcement by role \u2014 and installing it is not required for anything\ndescribed above to work.<\/p><\/dd>\n<dt id=\"does%20it%20work%20with%20my%20security%20plugin%3F\"><h3>Does it work with my security plugin?<\/h3><\/dt>\n<dd><p>It is built to sit alongside them rather than replace them. Plugins that change\nthe login URL or add an image CAPTCHA keep doing so; the passkey button appears\non whatever login screen your site actually serves. With Wordfence Login\nSecurity or Two-Factor, a passkey satisfies the second factor, and a weaker\nalternative login still has to pass the site's own 2FA.<\/p><\/dd>\n<dt id=\"is%20the%20plugin%20available%20in%20japanese%3F\"><h3>Is the plugin available in Japanese?<\/h3><\/dt>\n<dd><p>Yes. The Japanese translation is complete, and WordPress.org serves it as a\nlanguage pack \u2014 no bundled catalogue, so it updates independently of the\nplugin.<\/p><\/dd>\n<dt id=\"what%20if%20i%20lose%20my%20passkey%20and%20cannot%20sign%20in%3F\"><h3>What if I lose my passkey and cannot sign in?<\/h3><\/dt>\n<dd><p>Password login still works alongside passkeys, so sign in with your password as usual and then remove or re-register passkeys from your profile screen.<\/p>\n\n<p>You can also manage passkeys from the server with WP-CLI:<\/p>\n\n<pre><code>wp rapls-passkey list --user=admin\nwp rapls-passkey remove &lt;id&gt;\n<\/code><\/pre>\n\n<p>In an emergency, add the following to wp-config.php. It switches off every passkey requirement and second-factor check this plugin applies; remove it once you have recovered:<\/p>\n\n<pre><code>define( 'RAPLS_PASSKEY_BYPASS', true );\n<\/code><\/pre><\/dd>\n<dt id=\"will%20passkeys%20made%20on%20a%20staging%20site%20work%20on%20the%20live%20site%3F\"><h3>Will passkeys made on a staging site work on the live site?<\/h3><\/dt>\n<dd><p>Not by default. A passkey is bound to the domain it was registered on, and that\nbinding is kept inside the authenticator, not in the database \u2014 so moving the\ndatabase to production does not carry it across. A passkey registered on\nstaging.example.com is not offered on example.com.<\/p>\n\n<p>Either register again on the live site and treat staging passkeys as disposable,\nor have both sites use the parent domain before anyone registers:<\/p>\n\n<pre><code>add_filter( 'rapls_passkey_rp_id', function () {\n    return 'example.com';\n} );\n<\/code><\/pre>\n\n<p>With the second, passkeys registered on staging keep working once the database\nmoves to production, including any you did not mean to keep. Passkeys made on\nlocalhost only ever work on localhost. The setup screen shows the relying-party\nID in use, so this can be settled before the first passkey is registered.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.13.77<\/h4>\n\n<ul>\n<li>The short description now leads with what decides whether a site can try this safely: your password still works, so a lost device does not lock you out, and the Japanese interface is fully translated.<\/li>\n<li>New FAQ entry: why passkeys registered on a staging site do not work on the live one, and the two ways to handle it. The lost-passkey entry now says what the emergency constant actually switches off.<\/li>\n<li>A video walkthrough is linked from the description.<\/li>\n<li>The changelog had lost 0.13.46\u20130.13.62. When 0.13.71 trimmed this readme it deleted those entries and pointed to changelog.txt for them, but they were never added there. They are restored from history, and this readme now carries only the latest releases.<\/li>\n<li>No functional change.<\/li>\n<\/ul>\n\n<h4>0.13.76<\/h4>\n\n<ul>\n<li>Packaging fix: in the released package, and only there, every certificate signature check failed. Building this plugin rewrites the bundled libraries into a private namespace so that another plugin carrying the same library cannot collide with ours, and that step rewrites any text shaped like a namespaced class name. One piece of text has that shape without being a class name: <code>ymdHis\\Z<\/code>, the format a certificate's validity dates are written in. Certificates were then rewritten with those dates expanded into something else, the bytes stopped matching what the certificate authority had signed, and every certificate was reported as not verifying. Sign-in and registration verify no certificates, so passkeys themselves were unaffected; the Pro add-on's FIDO metadata refresh does, and it reported \"Certificate chain does not validate to a trusted FIDO root\" while naming trust anchors that had been correct all along.<\/li>\n<li>The check that would have caught this was being skipped. Running the suite against the built package excused it as needing the bundled libraries under their original names \u2014 it does not; it reaches them only through the plugin's own code. It runs against the package now, and the packaging step's rewrites are exercised directly as well, so a string it should not touch failing to survive is a test failure rather than a release.<\/li>\n<\/ul>\n\n<h4>0.13.75<\/h4>\n\n<ul>\n<li>Translation only: the Japanese catalogue now follows the WordPress Japanese style guide where it had drifted from it. A half-width number takes no space around it in Japanese, so \"0 \u306f\u7121\u5236\u9650\u3067\u3059\" becomes \"0\u306f\u7121\u5236\u9650\u3067\u3059\"; and the glossary settles \u30d6\u30e9\u30a6\u30b6\u30fc, \u30b5\u30fc\u30d0\u30fc and \u30e6\u30fc\u30b6\u30fc over the shorter forms the \u9577\u97f3 rule would otherwise produce. 293 strings, no code change.<\/li>\n<li>tests\/smoke-ja-style.php now checks both, and one more thing: translate.wordpress.org warns when a translation opens in a different letter case from the original. Japanese word order produces that on its own \u2014 \"Enable reCAPTCHA\" becomes \"reCAPTCHA \u3092\u6709\u52b9\u306b\u3059\u308b\" \u2014 so it is worth catching here rather than at upload time.<\/li>\n<\/ul>\n\n<h4>0.13.74<\/h4>\n\n<ul>\n<li>Passkey sign-in no longer depends on the object cache. A sign-in is two requests \u2014 the browser asks for a challenge, then sends back the answer \u2014 and the challenge was kept in a transient, which WordPress stores in the object cache whenever one is installed. WordPress then assumes the cache will hand the second request what the first one wrote, and that is up to the host, not the plugin: separate PHP-FPM instances and separate servers do not share an APCu segment, and any cache can evict an entry or lose the counter a drop-in namespaces its keys by. Seen on a live site, the challenge was not what came back seconds later, and a correct passkey was refused as expired \u2014 which is why the same passkey worked, then did not, then worked again. Challenges and parked two-factor logins now go straight to the database.<\/li>\n<li>A challenge can no longer be spent twice on such a host. Single use was enforced with an atomic add on the object cache, which decides a winner only among callers the cache actually serializes; where it does not, two requests could both be told they had won. It is now decided by the database.<\/li>\n<li>Site Health reports an object cache that does not return what an earlier request wrote. It affects far more than this plugin, and nothing else says so.<\/li>\n<\/ul>\n\n<p>For the change history of 0.13.72 and earlier releases, see changelog.txt.<\/p>","raw_excerpt":"Touch ID, Windows Hello or a security key signs you in. Your password still works, so a lost device won&#039;t lock you out. Japanese UI fully translated.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/350324","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=350324"}],"author":[{"embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/rapls"}],"wp:attachment":[{"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=350324"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=350324"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=350324"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=350324"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=350324"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/sw.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=350324"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}