Pickaxe Embed SSO releases
Signs short-lived Pickaxe embed SSO tokens for logged-in WordPress users.
by Pickaxe · github.com/pickaxeproject/pickaxe-embed-sso-wordpress
Install
The author publishes release zips, so WP-CLI can install straight from GitHub:
wp plugin install https://github.com/pickaxeproject/pickaxe-embed-sso-wordpress/releases/download/v0.4.0/pickaxe-embed-sso.zipPickaxe Embed SSO WordPress Plugin
This plugin signs short-lived Pickaxe embed SSO tokens for logged-in WordPress users.
Install
Copy pickaxe-embed-sso into:
wp-content/plugins/pickaxe-embed-sso
Then activate Pickaxe Embed SSO in WordPress admin.
Configure
Open Settings -> Pickaxe Embed SSO and click Generate WordPress SSO Config.
That fills most fields automatically:
- Issuer, from the WordPress site URL
- Audience, usually
pickaxe-embed - Key ID
- ES256 private key PEM
- Embed service origin
- Embed script URL
- Auth provider label
Then set:
- Default deployment ID, for example
deployment-your-id - Default embed mode, either script embed or iframe embed
- For iframe mode, either a default iframe source or a default Pickaxe ID
For production, prefer defining secrets in wp-config.php so the private key is not stored in the
database:
define('PICKAXE_SSO_CUSTOMER_ID', 'acme-nextauth-demo');
define('PICKAXE_SSO_DEFAULT_DEPLOYMENT_ID', 'deployment-your-id');
define('PICKAXE_SSO_ISSUER', 'https://example.com');
define('PICKAXE_SSO_AUDIENCE', 'pickaxe-embed');
define('PICKAXE_SSO_KEY_ID', 'acme-key-2026-04');
define('PICKAXE_SSO_PRIVATE_KEY_PEM', "-----BEGIN PRIVATE KEY-----\n...\n-----END PRIVATE KEY-----");
define('PICKAXE_SSO_EMBED_SERVICE_ORIGIN', 'https://embed.pickaxe.co');
define('PICKAXE_SSO_EMBED_SCRIPT_URL', 'https://embed.pickaxe.co/embed-loader.js');
define('PICKAXE_SSO_EMBED_MODE', 'script');
define('PICKAXE_SSO_DEFAULT_PICKAXE_ID', 'your-pickaxe-id');
define('PICKAXE_SSO_IFRAME_SRC', 'https://studio.pickaxe.co/_embed/your-pickaxe-id?d=deployment-your-id');
Optional constants:
define('PICKAXE_SSO_AUTH_PROVIDER', 'wordpress-native');
define('PICKAXE_SSO_TOKEN_TTL_SECONDS', 60);
Use
Add this shortcode to a page:
[pickaxe_embed]
The shortcode uses the default deployment ID from settings. You can still override it per page:
[pickaxe_embed deployment_id="deployment-your-id"]
Use the same deployment-... ID from the normal Pickaxe embed snippet. The shortcode loads the configured embed script and, for logged-in WordPress users, provides a nonce-authenticated JWT callback. Logged-out visitors do not receive an SSO token.
For raw iframe embeds, use:
[pickaxe_embed mode="iframe" iframe_src="https://studio.pickaxe.co/_embed/your-pickaxe-id?d=deployment-your-id"]
Iframe mode renders the iframe and listens for a pickaxe:sso:request message from the iframe. The plugin responds with a short-lived JWT only to the iframe origin configured by the iframe source. The iframe then exchanges that JWT with Pickaxe using the same SSO contract as the script embed.
Token Endpoint
The plugin exposes:
GET /wp-json/pickaxe-sso/v1/embed-token
The request must be made by a logged-in WordPress user and include a valid X-WP-Nonce header.
The response shape is:
{
"token": "eyJ...",
"expiresInSeconds": 60,
"payloadMapping": []
}
WordPress Field Mapping
WP_User->IDmaps tosubWP_User->IDmaps toexternal_user_idWP_User->user_emailmaps toemailWP_User->display_namemaps toname- native WordPress auth maps to
auth_provider = wordpress-native - configured values supply
customer_id,iss,aud, andkid
The JWT is signed as ES256 using the configured private key.
License
MIT
Releases
8 releases. Each count is every asset in that release; expand a row for the breakdown.