Skip to main content
In this guide, you build a small WordPress plugin that connects to your Mighty Network through the Mighty API. When you finish, your WordPress site can:
  • Connect to your Network once, from a WordPress settings page, through OAuth 2.0
  • Show upcoming events with a [mighty_events] shortcode
  • Show recent posts from a Space with a [mighty_posts] shortcode
  • Refresh its cache when a webhook reports new content on the Network
The plugin is a backend web app. WordPress runs on a server you control, so it registers as a Confidential client and keeps every token on the server. Visitors to your site never see a Mighty token.

Before you begin

You need:
  • A Mighty Network on the Scale plan or above, and a host account on it. OAuth applications are only available on these plans.
  • A WordPress site served over https, where you can edit wp-config.php and add plugins.
  • PHP 8.0 or later.
  • Pretty permalinks turned on (Settings > Permalinks, any option except Plain). The OAuth callback is a WordPress REST route, and the redirect URI you register must match it exactly.
The examples use my-community as the Network subdomain and https://example.com as the WordPress site. Replace both with your own values.

Choose the account that connects

Every Mighty API token acts as a signed-in user and sees exactly what that user sees in the Network. The plugin shows what its token can read to anyone who visits your WordPress site, so the account you connect decides what becomes public.
If a host connects the plugin, the token can read every Space in the Network, including private and paid Spaces. A shortcode without a space attribute then publishes content from all of them on your public site.
For a public website, create a dedicated member account (for example, website@example.com), add it only to the Spaces you want to publish, and connect the plugin with that account. The plugin only requests the read:network scope, so the token can’t use Host scopes, and the plugin itself only ever sends read queries. It can still read everything the connected account can see, which for a host is every Space.

Step 1: Create an OAuth application

1

Open OAuth Applications

Sign in to your Network as a host. Go to Network Admin > Integrations > OAuth Applications, then click New OAuth Application.
2

Configure the application

  • Name: Something the connecting account recognizes, such as Example.com website.
  • Client type: Confidential.
  • Redirect URI: https://example.com/wp-json/mighty/v1/oauth/callback
  • Member scopes: read:network.
  • Host scopes: Leave empty.
3

Copy your credentials

Save the application and copy the Client ID and Client Secret. You add them to WordPress in the next step.
See OAuth Applications for more on each setting.

Step 2: Add your credentials to wp-config.php

Keep secrets in wp-config.php, not in the WordPress database or in the plugin’s code. Generate an encryption key for the stored tokens and a secret for webhook deliveries:
Add these lines to wp-config.php, above /* That's all, stop editing! */:
wp-config.php

Step 3: Create the plugin

Create the file wp-content/plugins/mighty-networks-connect/mighty-networks-connect.php. Each code block labeled mighty-networks-connect.php in this guide goes into this file, in order. Start with the plugin header and a few helpers:
mighty-networks-connect.php

Store tokens encrypted

The plugin encrypts tokens with libsodium before it writes them to the options table, so a database backup or a leaked export doesn’t expose them:
mighty-networks-connect.php

Add a settings page with a Connect button

The settings page appears under Settings > Mighty Networks and only WordPress administrators can see it:
mighty-networks-connect.php

Start the authorization request

When an administrator clicks Connect, the plugin generates a single-use state value and a PKCE code_verifier on the server. It keeps both in a short-lived transient, binds state to the administrator’s browser with an HttpOnly cookie, and redirects to the Network’s authorization endpoint:
mighty-networks-connect.php
The account that approves the request on the Network’s consent screen is the account the plugin acts as. Before you click Connect, sign in to the Network in that browser with the account you chose in Choose the account that connects.

Handle the callback

The Network redirects back to the REST route you registered as the redirect URI. The callback accepts the request only when the returned state matches both the transient and the cookie, and when iss matches the Network. Then it exchanges the code for tokens on the server:
mighty-networks-connect.php
iss names the host that showed the consent screen, which is https://my-community.mn.co only until your Network’s custom domain gets a live SSL certificate — from then on, /oauth/authorize redirects there first, so iss becomes https://your-custom-domain. Set MIGHTY_NETWORK_CUSTOM_DOMAIN to that URL once it does. /.well-known/oauth-authorization-server isn’t redirected, so its issuer value only matches iss when you fetch it from the same host that redirected you — fetching it from the subdomain won’t tell you what iss becomes once your custom domain is live.

Refresh expired access tokens

Access tokens expire after one hour. The plugin refreshes the token shortly before it expires. The refresh token may rotate on every refresh, so the plugin takes an atomic database lock to allow only one refresh at a time. Two page loads that refresh at the same moment would otherwise race, and the loser would send a refresh token that’s no longer valid.
mighty-networks-connect.php
A refresh returns invalid_grant when the connection was revoked. That happens when the connected account disconnects the app or changes its password, or when a host deletes the OAuth application. The settings page then shows Not connected until an administrator clicks Connect again.

Disconnect

Disconnect revokes the token pair at the Network and deletes it from WordPress:
mighty-networks-connect.php

Step 4: Query the Mighty API

Every GraphQL request is a POST to the Network’s endpoint on api.mn.co. Requests need a non-empty User-Agent header. GraphQL returns HTTP 200 for most errors, so the client checks the errors array on every response:
mighty-networks-connect.php

Cache responses

Calling the Mighty API on every page view is slow, and it spends your Network’s API quota. The plugin caches each result in a transient for 15 minutes. The cache key includes a version number, so a single update_option call makes every cached result stale at once. You use that version number in Step 6. The plugin also keeps the last successful result in a separate, non-expiring copy, and serves it if the API call that would replace an expired cache fails, so an outage empties nothing that was already showing.
mighty-networks-connect.php

Step 5: Add shortcodes

Upcoming events

network.events returns one row for each occurrence, so a recurring event appears once for each upcoming date. spaceId limits the results to one Space.
mighty-networks-connect.php

Recent posts

network.posts returns posts, events, and polls as a union. Filter it with postTypes, and select fields on the Post type with an inline fragment. By default, the connection returns only published posts.
mighty-networks-connect.php
The shortcodes render bodyText, the plain-text body, and escape every value. If you switch to bodyHtml to keep formatting, pass it through wp_kses_post() before you output it.

Find a Space ID

The space attribute takes a Space’s GraphQL id. To list the Spaces the connected account can see, open the hosted GraphiQL explorer at https://my-community.mn.co/admin/headless-api/explorer and run:
The explorer runs as your host account, so it lists every Space in the Network. The plugin only sees Spaces that the connected account belongs to.

Activate and test

  1. In WordPress, go to Plugins and activate Mighty Networks Connect.
  2. Go to Settings > Mighty Networks, click Connect to Mighty Networks, sign in with the account you chose, and approve access.
  3. Add the shortcodes to any page or post:

Step 6: Refresh the cache with a webhook

Without a webhook, new content shows up on your site within 15 minutes, when the cache expires. With a webhook, the Network notifies WordPress when content changes, and the plugin clears its cache right away. Add a REST route that accepts deliveries. The Network sends the API key you set on the webhook as a Bearer token in the Authorization header, so the route compares that header with MIGHTY_WEBHOOK_SECRET:
mighty-networks-connect.php
Then register the webhook on your Network:
  • Network Admin: Go to Network Admin > Integrations > Webhooks. Set the URL to https://example.com/wp-json/mighty/v1/webhook and the API key to your MIGHTY_WEBHOOK_SECRET value.
  • Mighty API: A host can run the createWebhookCallback mutation in the same GraphiQL explorer used in Find a Space ID. It requires the host:write:network_integrations scope, which the WordPress application doesn’t have — but the explorer doesn’t run as any OAuth application you create; it always runs with every scope a host can hold, so no separate application is needed.
The route returns 204 right away and doesn’t depend on the payload, so retried or duplicate deliveries are harmless. If your endpoint fails intermittently, delivery backs off and retries on its own — see the circuit breaker for details. But if it fails for 5 consecutive attempts spanning at least 3 days, the Network disables the webhook outright, and nothing retries it after that: go to Network Admin > Integrations > Webhooks and save the webhook again (or run updateWebhookCallback) to turn it back on.
Webhooks follow your Network’s plan. If Webhooks doesn’t appear under Integrations, the 15-minute cache still keeps your site up to date.

Troubleshooting

Check your PHP error log for Mighty API errors lines. A NOT_FOUND or empty result usually means the connected account doesn’t belong to the Space. An UNAUTHENTICATED error means the connection was revoked, so click Connect again.
api.mn.co blocks requests without a User-Agent header. The plugin sets one on every request. If you changed the HTTP code, restore the header.

Next steps

Browse the schema

Find more fields to show on your site, such as event images, courses, or member counts.

Authentication

Read the complete OAuth flow, token lifecycle, and error reference.

OAuth Client Architectures

Check the plugin’s design against the security review checklist.

Changelog

Track schema changes before you update the plugin.