Login and registration with Google and Microsoft (personal accounts: Hotmail, Outlook.com, Live) for WooCommerce stores, via OAuth 2.0 / OpenID Connect — self-contained, with no third-party plugins or intermediary services. Customer credentials never pass through the store: authentication happens at Google/Microsoft and the plugin only cryptographically validates the result.
customer) with a strong random password.id_token validation — signature against the provider’s JWKS (with cache), iss, aud, exp, nonce, and per-provider email_verified policy.state + nonce in a transient with an HttpOnly/SameSite=Lax cookie.wp-config.php take priority and lock the admin field.aria-label; light/dark themes.firebase/php-jwt (vendored in the repo — the plugin installs by copy, with no composer install).The customer authenticates at the provider (the store never sees the password); the plugin verifies the signed id_token (JWKS), validates the claims (iss / aud / exp / nonce / email), and resolves the account:
sub known) immediate loginThis plugin is an interface to the sign-in services of Google and Microsoft. It contacts them only when you, the site administrator, enable and configure a provider, and only while a visitor is actively signing in with that provider. There is no telemetry, no analytics, and no data is ever sent to PixelHunter or to any other third party.
accounts.google.com — the visitor’s browser is redirected here to sign in. The request carries the Client ID you configured, the redirect URI of your site, the requested scopes (openid email profile), and a single-use state/nonce. The visitor enters their credentials at Google; the store never sees them.oauth2.googleapis.com — server-to-server exchange of the authorization code for an id_token. Sends the Client ID, the Client Secret, the authorization code, and the redirect URI.www.googleapis.com — fetches Google’s public signing keys (JWKS) to verify the id_token signature. No site or visitor data is sent; the response is cached.Data received back from Google and stored on your site: the account identifier (sub), email address, name, and the email_verified flag. The sub is stored as user meta so the account can be recognised on the next sign-in.
Google terms of service: https://policies.google.com/terms — Google privacy policy: https://policies.google.com/privacy
login.microsoftonline.com — the same three roles as above (visitor sign-in redirect, code-for-token exchange, and JWKS key fetch), against the consumers tenant for personal Microsoft accounts.Data received back from Microsoft and stored on your site: the account identifier (sub), email address, and name.
Microsoft services agreement: https://www.microsoft.com/servicesagreement — Microsoft privacy statement: https://privacy.microsoft.com/privacystatement