- Connect to your Network once, from a WordPress settings page, through OAuth 2.0
- Show upcoming events with a
[mighty_events]shortcode - Show recent posts from a Space with a
[mighty_posts]shortcode - Refresh its cache when a webhook reports new content on the Network
Before you begin
You need:- A Mighty Network on the Scale plan or above, and a host account on it. OAuth applications are only available on these plans.
- A WordPress site served over
https, where you can editwp-config.phpand add plugins. - PHP 8.0 or later.
- Pretty permalinks turned on (Settings > Permalinks, any option except Plain). The OAuth callback is a WordPress REST route, and the redirect URI you register must match it exactly.
my-community as the Network subdomain and https://example.com as the WordPress site. Replace both with your own values.
Choose the account that connects
Every Mighty API token acts as a signed-in user and sees exactly what that user sees in the Network. The plugin shows what its token can read to anyone who visits your WordPress site, so the account you connect decides what becomes public. For a public website, create a dedicated member account (for example,website@example.com), add it only to the Spaces you want to publish, and connect the plugin with that account. The plugin only requests the read:network scope, so the token can’t use Host scopes, and the plugin itself only ever sends read queries. It can still read everything the connected account can see, which for a host is every Space.
Step 1: Create an OAuth application
1
Open OAuth Applications
Sign in to your Network as a host. Go to Network Admin > Integrations > OAuth Applications, then click New OAuth Application.
2
Configure the application
- Name: Something the connecting account recognizes, such as
Example.com website. - Client type: Confidential.
- Redirect URI:
https://example.com/wp-json/mighty/v1/oauth/callback - Member scopes:
read:network. - Host scopes: Leave empty.
3
Copy your credentials
Save the application and copy the Client ID and Client Secret. You add them to WordPress in the next step.
Step 2: Add your credentials to wp-config.php
Keep secrets inwp-config.php, not in the WordPress database or in the plugin’s code. Generate an encryption key for the stored tokens and a secret for webhook deliveries:
wp-config.php, above /* That's all, stop editing! */:
wp-config.php
Step 3: Create the plugin
Create the filewp-content/plugins/mighty-networks-connect/mighty-networks-connect.php. Each code block labeled mighty-networks-connect.php in this guide goes into this file, in order.
Start with the plugin header and a few helpers:
mighty-networks-connect.php
Store tokens encrypted
The plugin encrypts tokens with libsodium before it writes them to the options table, so a database backup or a leaked export doesn’t expose them:mighty-networks-connect.php
Add a settings page with a Connect button
The settings page appears under Settings > Mighty Networks and only WordPress administrators can see it:mighty-networks-connect.php
Start the authorization request
When an administrator clicks Connect, the plugin generates a single-usestate value and a PKCE code_verifier on the server. It keeps both in a short-lived transient, binds state to the administrator’s browser with an HttpOnly cookie, and redirects to the Network’s authorization endpoint:
mighty-networks-connect.php
Handle the callback
The Network redirects back to the REST route you registered as the redirect URI. The callback accepts the request only when the returnedstate matches both the transient and the cookie, and when iss matches the Network. Then it exchanges the code for tokens on the server:
mighty-networks-connect.php
iss names the host that showed the consent screen, which is https://my-community.mn.co only until your Network’s custom domain gets a live SSL certificate — from then on, /oauth/authorize redirects there first, so iss becomes https://your-custom-domain. Set MIGHTY_NETWORK_CUSTOM_DOMAIN to that URL once it does. /.well-known/oauth-authorization-server isn’t redirected, so its issuer value only matches iss when you fetch it from the same host that redirected you — fetching it from the subdomain won’t tell you what iss becomes once your custom domain is live.Refresh expired access tokens
Access tokens expire after one hour. The plugin refreshes the token shortly before it expires. The refresh token may rotate on every refresh, so the plugin takes an atomic database lock to allow only one refresh at a time. Two page loads that refresh at the same moment would otherwise race, and the loser would send a refresh token that’s no longer valid.mighty-networks-connect.php
invalid_grant when the connection was revoked. That happens when the connected account disconnects the app or changes its password, or when a host deletes the OAuth application. The settings page then shows Not connected until an administrator clicks Connect again.
Disconnect
Disconnect revokes the token pair at the Network and deletes it from WordPress:mighty-networks-connect.php
Step 4: Query the Mighty API
Every GraphQL request is aPOST to the Network’s endpoint on api.mn.co. Requests need a non-empty User-Agent header. GraphQL returns HTTP 200 for most errors, so the client checks the errors array on every response:
mighty-networks-connect.php
Cache responses
Calling the Mighty API on every page view is slow, and it spends your Network’s API quota. The plugin caches each result in a transient for 15 minutes. The cache key includes a version number, so a singleupdate_option call makes every cached result stale at once. You use that version number in Step 6. The plugin also keeps the last successful result in a separate, non-expiring copy, and serves it if the API call that would replace an expired cache fails, so an outage empties nothing that was already showing.
mighty-networks-connect.php
Step 5: Add shortcodes
Upcoming events
network.events returns one row for each occurrence, so a recurring event appears once for each upcoming date. spaceId limits the results to one Space.
mighty-networks-connect.php
Recent posts
network.posts returns posts, events, and polls as a union. Filter it with postTypes, and select fields on the Post type with an inline fragment. By default, the connection returns only published posts.
mighty-networks-connect.php
Find a Space ID
Thespace attribute takes a Space’s GraphQL id. To list the Spaces the connected account can see, open the hosted GraphiQL explorer at https://my-community.mn.co/admin/headless-api/explorer and run:
Activate and test
- In WordPress, go to Plugins and activate Mighty Networks Connect.
- Go to Settings > Mighty Networks, click Connect to Mighty Networks, sign in with the account you chose, and approve access.
-
Add the shortcodes to any page or post:
Step 6: Refresh the cache with a webhook
Without a webhook, new content shows up on your site within 15 minutes, when the cache expires. With a webhook, the Network notifies WordPress when content changes, and the plugin clears its cache right away. Add a REST route that accepts deliveries. The Network sends the API key you set on the webhook as a Bearer token in theAuthorization header, so the route compares that header with MIGHTY_WEBHOOK_SECRET:
mighty-networks-connect.php
-
Network Admin: Go to Network Admin > Integrations > Webhooks. Set the URL to
https://example.com/wp-json/mighty/v1/webhookand the API key to yourMIGHTY_WEBHOOK_SECRETvalue. -
Mighty API: A host can run the
createWebhookCallbackmutation in the same GraphiQL explorer used in Find a Space ID. It requires thehost:write:network_integrationsscope, which the WordPress application doesn’t have — but the explorer doesn’t run as any OAuth application you create; it always runs with every scope a host can hold, so no separate application is needed.
204 right away and doesn’t depend on the payload, so retried or duplicate deliveries are harmless. If your endpoint fails intermittently, delivery backs off and retries on its own — see the circuit breaker for details. But if it fails for 5 consecutive attempts spanning at least 3 days, the Network disables the webhook outright, and nothing retries it after that: go to Network Admin > Integrations > Webhooks and save the webhook again (or run updateWebhookCallback) to turn it back on.
Webhooks follow your Network’s plan. If Webhooks doesn’t appear under Integrations, the 15-minute cache still keeps your site up to date.
Troubleshooting
redirect_uri_mismatch on the consent screen
redirect_uri_mismatch on the consent screen
The redirect URI the plugin sends must exactly match the one on the OAuth application. Open
https://example.com/wp-json/mighty/v1/oauth/callback in a browser. If WordPress redirects to a different URL (for example, www. or a trailing slash), or if permalinks are set to Plain, register the URL that WordPress actually uses.This sign-in link is invalid or expired
This sign-in link is invalid or expired
The
state check failed. Start again from Settings > Mighty Networks, and finish within 10 minutes in the same browser. Caching plugins or a CDN that strip cookies from /wp-json/ requests also cause this error. Exclude the callback route from caching.Shortcodes show no content
Shortcodes show no content
Check your PHP error log for
Mighty API errors lines. A NOT_FOUND or empty result usually means the connected account doesn’t belong to the Space. An UNAUTHENTICATED error means the connection was revoked, so click Connect again.A 403 response with an HTML page
A 403 response with an HTML page
api.mn.co blocks requests without a User-Agent header. The plugin sets one on every request. If you changed the HTTP code, restore the header.Next steps
Browse the schema
Find more fields to show on your site, such as event images, courses, or member counts.
Authentication
Read the complete OAuth flow, token lifecycle, and error reference.
OAuth Client Architectures
Check the plugin’s design against the security review checklist.
Changelog
Track schema changes before you update the plugin.