{"id":157774,"date":"2022-05-31T19:01:33","date_gmt":"2022-05-31T19:01:33","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/notakey-two-factor-extension\/"},"modified":"2026-08-28T10:41:38","modified_gmt":"2026-08-28T10:41:38","slug":"notakey-two-factor-extension","status":"publish","type":"plugin","link":"https:\/\/nl-be.wordpress.org\/plugins\/notakey-two-factor-extension\/","author":20277024,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.0.1","stable_tag":"2.0.1","tested":"7.1","requires":"4.3","requires_php":"5.6","requires_plugins":null,"header_name":"Notakey Two Factor extension","header_author":"Notakey Latvia","header_description":"Two-Factor Authentication with Notakey Authenticator mobile application using push notifications.","assets_banners_color":"428dcd","last_updated":"2026-08-28 10:41:38","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/github.com\/notakey\/wordpress-two-factor\/","header_author_uri":"https:\/\/github.com\/notakey\/wordpress-two-factor\/graphs\/contributors","rating":5,"author_block_rating":0,"active_installs":0,"downloads":7265,"num_ratings":1,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","changelog"],"tags":{"1.0.10":{"tag":"1.0.10","author":"notakey","date":"2022-05-27 09:14:08","revision":2732452},"1.0.11":{"tag":"1.0.11","author":"notakey","date":"2022-05-31 19:01:00","revision":2735051},"1.0.12":{"tag":"1.0.12","author":"notakey","date":"2022-06-02 06:56:46","revision":2736136},"1.0.13":{"tag":"1.0.13","author":"notakey","date":"2022-06-02 09:34:41","revision":2736227},"1.0.14":{"tag":"1.0.14","author":"notakey","date":"2022-06-02 11:08:07","revision":2736319},"1.0.15":{"tag":"1.0.15","author":"notakey","date":"2022-06-03 08:12:46","revision":2736830},"1.0.16":{"tag":"1.0.16","author":"notakey","date":"2022-06-03 09:11:06","revision":2736850},"1.0.17":{"tag":"1.0.17","author":"notakey","date":"2022-07-20 20:04:11","revision":2759441},"1.0.8":{"tag":"1.0.8","author":"notakey","date":"2022-05-27 08:39:13","revision":2732436},"1.0.9":{"tag":"1.0.9","author":"notakey","date":"2022-05-27 08:43:45","revision":2732438},"2.0.1":{"tag":"2.0.1","author":"notakey","date":"2026-08-28 10:41:38","revision":3670170}},"upgrade_notice":[],"ratings":{"1":0,"2":0,"3":0,"4":0,"5":1},"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":2732452,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":2732452,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":2732452,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":2732452,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.10","1.0.11","1.0.12","1.0.13","1.0.14","1.0.15","1.0.16","1.0.17","1.0.8","1.0.9","2.0.1"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":2732452,"resolution":"1","location":"assets","locale":"","width":2016,"height":1372},"screenshot-2.png":{"filename":"screenshot-2.png","revision":2732452,"resolution":"2","location":"assets","locale":"","width":2018,"height":1348},"screenshot-3.png":{"filename":"screenshot-3.png","revision":2732452,"resolution":"3","location":"assets","locale":"","width":2018,"height":1360},"screenshot-4.png":{"filename":"screenshot-4.png","revision":2732452,"resolution":"4","location":"assets","locale":"","width":998,"height":750}},"screenshots":{"1":"Two-factor authentication security policy settings.","2":"Notakey authentication request options.","3":"Notakey Authentication Server settings.","4":"User authentication while waiting for response from Notakey app."}},"plugin_section":[],"plugin_tags":[710,39814,278031,9217,39820],"plugin_category":[38],"plugin_contributors":[210799],"plugin_business_model":[],"class_list":["post-157774","plugin","type-plugin","status-publish","hentry","plugin_tags-authentication","plugin_tags-mfa","plugin_tags-notakey","plugin_tags-two-factor","plugin_tags-two-step","plugin_category-authentication","plugin_contributors-notakey","plugin_committers-notakey"],"banners":{"banner":"https:\/\/ps.w.org\/notakey-two-factor-extension\/assets\/banner-772x250.png?rev=2732452","banner_2x":"https:\/\/ps.w.org\/notakey-two-factor-extension\/assets\/banner-1544x500.png?rev=2732452","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/notakey-two-factor-extension\/assets\/icon-128x128.png?rev=2732452","icon_2x":"https:\/\/ps.w.org\/notakey-two-factor-extension\/assets\/icon-256x256.png?rev=2732452","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/notakey-two-factor-extension\/assets\/screenshot-1.png?rev=2732452","caption":"Two-factor authentication security policy settings."},{"src":"https:\/\/ps.w.org\/notakey-two-factor-extension\/assets\/screenshot-2.png?rev=2732452","caption":"Notakey authentication request options."},{"src":"https:\/\/ps.w.org\/notakey-two-factor-extension\/assets\/screenshot-3.png?rev=2732452","caption":"Notakey Authentication Server settings."},{"src":"https:\/\/ps.w.org\/notakey-two-factor-extension\/assets\/screenshot-4.png?rev=2732452","caption":"User authentication while waiting for response from Notakey app."}],"raw_content":"<!--section=description-->\n<p>Users with enabled Notakey authentication provider will be sent authentication request to registered mobile device (phone, tablet) after entering a valid username and password.<\/p>\n\n<p>This plugin requires Wordpress <a href=\"https:\/\/wordpress.org\/plugins\/two-factor\/\">Two-Factor<\/a> plugin, that provides base authentication framework. After installing and configuring both plugins, an additional authentication provider will be added to provider list. To register a mobile device for Notakey authentication, use the \"Two-Factor Options\" section under \"Users\" \u2192 \"Your Profile\". Install \"Notakey Authenticator\" and scan provided QR code with Notakey app and enter required details for device registeration.<\/p>\n\n<p>Notakey authentication can be combined with other second factor authentication means: TOTP, email, backup codes and others.<\/p>\n\n<p>This plugin adds also some basic security policy options for Wordpress site admins:<\/p>\n\n<ul>\n<li><p>Enable Notakey 2FA provider for all users - enables Notakey authentication for all users (in case your users have devices already registered on other services).<\/p><\/li>\n<li><p>Allow users to provide onboarding details - lets users enter their mobile number, if SMS code verification onboarding is used.<\/p><\/li>\n<li><p>Reject user login without 2FA verification - blocks user login without any second factor authentication.<\/p><\/li>\n<\/ul>\n\n<p>Other configuration options include:<\/p>\n\n<ul>\n<li><p>Various options to customize authentication request.<\/p><\/li>\n<li><p>Configuration for Notakey Authentication Server.<\/p><\/li>\n<\/ul>\n\n<p>To adjust policy or configure this plugin, navigate to \"Settings\" \u2192 \"Notakey MFA\".<\/p>\n\n<p>Plugin requires a hosted or on-premise version of Notakey Authentication Server (yes, there is a free version) with configured service, onboarding requirements and API client credentials.<\/p>\n\n<p>See our <a href=\"https:\/\/documentation.notakey.com\/\">documentation site<\/a> for detailed instructions how to set up Notakey Authentication Server.<\/p>\n\n<h4>API client setup<\/h4>\n\n<p>The plugin talks to Notakey Authentication Server (NtkAS) over its REST API and authenticates with OAuth 2.0 client credentials. Register an API client (client ID and secret) using the Notakey Authentication Appliance configuration shell, then copy the values into \"Settings\" \u2192 \"Notakey MFA\" \u2192 \"Authentication Server\".<\/p>\n\n<p>The API client must be provisioned with at least the following scopes:<\/p>\n\n<ul>\n<li><code>urn:notakey:auth<\/code> - create and query authentication requests.<\/li>\n<li><code>urn:notakey:user<\/code> - look up service users and their registered devices.<\/li>\n<li><code>urn:notakey:usermanager<\/code> - create, update and delete service users during device registration.<\/li>\n<\/ul>\n\n<p>Additionally, <code>urn:notakey:devicemanager<\/code> is required if you want the plugin to be able to remove registered devices from a user account.<\/p>\n\n<p>Values required in the \"Authentication Server\" settings section:<\/p>\n\n<ul>\n<li>Service URL - address of your NtkAS instance, e.g. <code>https:\/\/mfa.example.com<\/code>.<\/li>\n<li>Client ID and Client Secret - API client credentials, found in the authentication server dashboard, \"Access credentials\" page.<\/li>\n<li>Service ID (Access ID) - service identifier from the authentication server dashboard service settings.<\/li>\n<li>Service Domain - domain announced to users, requires a DNS SRV record in that zone.<\/li>\n<\/ul>\n\n<p>The plugin requests a bearer token from <code>POST \/api\/token<\/code> with <code>grant_type=client_credentials<\/code> and only the scopes needed for each call. You can verify credentials manually:<\/p>\n\n<pre><code>curl -X POST https:\/\/mfa.example.com\/api\/token \\\n  -d 'grant_type=client_credentials&amp;client_id=&lt;client_id&gt;&amp;client_secret=&lt;client_secret&gt;&amp;scope=urn:notakey:auth urn:notakey:user urn:notakey:usermanager'\n<\/code><\/pre>\n\n<p>A successful response contains an <code>access_token<\/code> value. If the client is not provisioned with the requested scopes, the token request fails and the plugin will not be able to send authentication requests.<\/p>\n\n<h3>Get Involved<\/h3>\n\n<p>Development happens <a href=\"https:\/\/github.com\/notakey\/wordpress-two-factor\/\">on GitHub<\/a>.<\/p>\n\n<p>Here is how to get started:<\/p>\n\n<pre><code>git clone https:\/\/github.com\/notakey\/wordpress-two-factor.git\n<\/code><\/pre>\n\n<p>Start development by starting a <a href=\"https:\/\/code.visualstudio.com\/docs\/remote\/containers\">devcontainer<\/a>.<\/p>\n\n<p>Then open <a href=\"https:\/\/help.github.com\/articles\/creating-a-pull-request-from-a-fork\/\">a pull request<\/a> with the suggested changes.<\/p>\n\n<!--section=changelog-->\n<p>See the <a href=\"https:\/\/github.com\/notakey\/wordpress-two-factor\/releases\">release history<\/a>.<\/p>","raw_excerpt":"Reduce friction and improve security of Two-Factor Authentication using push-based Notakey Authenticator mobile application.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/nl-be.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/157774","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nl-be.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/nl-be.wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/nl-be.wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=157774"}],"author":[{"embeddable":true,"href":"https:\/\/nl-be.wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/notakey"}],"wp:attachment":[{"href":"https:\/\/nl-be.wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=157774"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/nl-be.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=157774"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/nl-be.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=157774"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/nl-be.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=157774"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/nl-be.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=157774"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/nl-be.wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=157774"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}