WordPress plugin profile

MemberAuth – Login & Content Access for Join It

Protect WordPress content using your Join It membership. Members log in with Join It and access content based on membership type and status.

Version1.7.0
Active installsNew
Rating0.0 / 5
Tested toWP 7.1

About this plugin

MemberAuth – Login & Content Access for Join It makes it easy for organizations using Join It to create member-only areas in WordPress. The full name above is the product name. The WordPress admin sidebar uses the shorter MemberAuth label, and Member Access is the feature inside that menu for protecting content and managing access rules. Connect your Join It organization, choose the WordPress Pages or Posts to protect, and decide which membership types and statuses can view them. Join It remains the source of truth, so there is no need to maintain WordPress roles manually for membership access. Administrators can: Let members log in with Join It. Protect supported WordPress Page and Post content. Choose access by Join It membership type and status. Create a dedicated Member Login page. Place the reusable [memberauth_login] shortcode on another Page or Post. Customize member login screens and access messages. Synchronize Join It membership types. Control messages for expired, pending, prospective, canceled, or mismatched memberships. Review access activity and use built-in troubleshooting tools. MemberAuth reads the membership information needed for access decisions. Protected content fails closed when no allowed result is available. MemberAuth protects supported WordPress Page and Post content responses using server-side access checks. Direct media file URLs, third-party APIs, custom page-builder data outside the standard content response, custom metadata or SEO fields, and copies previously stored by a CDN or proxy may require separate controls. A Join It organization on an eligible plan with API access is required. Use HTTPS in production and exclude protected pages and the OAuth callback from full-page or CDN caching. External Services MemberAuth – Login & Content Access for Join It depends on Join It and requires a Join It organization with suitable API access. app.joinit.com is used in the member’s browser for Join It authorization and login. It is also the destination for the Join It Developer Tools and App Keys setup links. app.joinitapi.com is used by the WordPress server for: OAuth authorization-code exchange using the Client ID and Client Secret; authenticated user information using the temporary member OAuth access token; organization details, membership types, and matching membership records using the configured Access Token (AppToken). During login, the member’s browser is redirected to Join It. MemberAuth does not collect the member’s Join It password. Join It returns authenticated identity information, and the member email is used to locate the relevant membership in the connected organization. The temporary member OAuth access token is used for user information and then discarded. The AppToken is stored server-side and used for read-only organization and membership requests. OAuth member login and organization API access are separate. Client ID and Client Secret cannot replace the AppToken, and the AppToken is not used as a member OAuth token. Use of Join It is subject to its Terms of Service and Privacy Policy . MemberAuth sends no analytics or marketing data to the plugin author. Privacy MemberAuth may store a local WordPress user and Join It identity association, short-lived normalized membership checks, access activity, and limited diagnostics. When entered in WordPress, the App key, Client Secret, and AppToken are stored locally using authenticated encryption. Members authenticate on Join It. MemberAuth does not collect or store Join It passwords. The temporary member OAuth access token is used for authenticated user information and then discarded. Raw Client Secrets and AppTokens are never written to activity logs, diagnostics, privacy exports, or support reports. Site owners control applicable membership-check and activity-retention settings and can clear saved checks, activity, and diagnostics. Uninstall always removes stored credentials and identity-associated or ephemeral security data. Reusable configuration follows the saved uninstall preference; WordPress users and content are not deleted. The plugin registers WordPress personal-data exporter and eraser callbacks and suggested Privacy Policy text. Review that text for the site’s hosting, backups, cache/CDN, other plugins, and Join It arrangements.