Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A WordPress nonce is a time-limited token that helps protect a request from cross-site request forgery (CSRF). Despite the name, it is not a one-time-use token: it can be accepted repeatedly while valid. A nonce also does not prove a user has permission to perform an action, so code that processes a request must check both the nonce and the user’s capability.

What a WordPress nonce does

CSRF occurs when a site is induced to send a request that a user did not intend—for example, an action submitted through the browser while the user is signed in. A WordPress nonce gives the request handler a way to check that the request includes a token associated with the intended action. This helps defend against forged requests, but it is not a complete security system.

WordPress’s use of “nonce” differs from the strict cryptographic meaning of a number used once. A WordPress nonce can be reused during its validity period; it is not checked for one-time use and does not prevent replay attacks. The WordPress Common APIs Handbook explains both the CSRF purpose and this limitation.

What a nonce does not do

Nonce verification is not authentication, authorization, or access control. It does not identify a user or establish that the user may carry out the requested operation. After validating the nonce, check the relevant capability, usually with current_user_can(), before making the change. WordPress explicitly advises that nonces should not be relied on for authentication, authorization, or access control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

For example, a request to delete a post should validate a nonce tied to that deletion and the relevant post, then independently confirm that the current user can delete that post. A valid token alone is not permission to delete it.

How long a WordPress nonce lasts

The default nonce life is a 24-hour interval, but that does not mean every nonce is valid for exactly 24 hours. WordPress divides the interval into two ticks and accepts the current tick and the previous one. With the default interval, a nonce’s usable window is just over 12 hours at its shortest and up to 24 hours, depending on when it was created relative to a tick boundary.

Rank #2
Sale
PETER PAUPER PRESS Old World Internet Address & Password Logbook (removable cover band for security)
  • Time- and headache-saving little volume is organized with tabbed A to Z pages, with space on each page to write down websites, usernames, passwords, and notes.

wp_verify_nonce() returns 1 when the nonce matches the current tick, 2 when it matches the previous tick, and false when it is invalid or expired. The nonce_life filter can change the interval; changing it affects security-relevant behavior and should be done deliberately. See the WordPress nonce documentation and the WordPress Developer Blog’s explanation of nonce ticks.

Creating and checking a nonce for a form

Add the hidden field

Use wp_nonce_field() to print a hidden input containing a nonce. Give it an action string that describes the operation; where useful, include the target object so tokens for different objects are not interchangeable.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
wp_nonce_field( 'delete_post_' . $post_id, 'delete_post_nonce' );

By default, the function also prints a referrer field. The action and field name are choices your code makes; use the same action when validating the submitted value. Details are in the Common APIs Handbook and the wp_nonce_field() reference.

Validate before processing

For an admin form or URL, check_admin_referer() checks the nonce and referrer and terminates with a forbidden response on failure by default. Then check the user’s capability before carrying out the operation.

if ( ! current_user_can( 'delete_post', $post_id ) ) {
    wp_die( 'You are not allowed to delete this post.' );
}

check_admin_referer( 'delete_post_' . $post_id, 'delete_post_nonce' );

// Perform the authorized operation.

Keep request validation and authorization distinct: the nonce checks the request token; the capability check checks whether the user may act.

Choosing the right helper for the request

Request context Nonce helper What it checks or returns
Admin form or URL check_admin_referer() Checks the nonce and referrer; terminates on failure by default.
AJAX request check_ajax_referer() Checks the nonce, not the referrer; terminates on failure by default.
Custom request or validation flow wp_verify_nonce() Returns 1, 2, or false; your code must stop processing when validation fails.
Nonce in a URL wp_nonce_url() Adds a nonce for the specified action to a URL.
Custom transport or context wp_create_nonce() Returns a nonce for the specified action.

Use an action string that identifies the operation, and validate against that same string. Consult the nonce handbook for function behavior and arguments. Whichever helper fits the request, a separate capability check is still required for protected operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Nonces in AJAX and REST API requests

AJAX

For AJAX handlers, send a nonce with the request and validate it with check_ajax_referer(). That helper does not check the referrer. If validation fails, it terminates by default; the handler must still check whether the current user is allowed to perform the requested action.

REST API cookie authentication

For REST API requests authenticated with WordPress cookies, WordPress uses the action wp_rest to mitigate CSRF. Without the nonce, the request is treated as unauthenticated even if the user is logged in. The REST API authentication handbook recommends using the built-in JavaScript API, which handles transmitting the nonce.

Logged-out visitors and guest nonces

By default, WordPress uses user ID 0 when generating nonces for logged-out users. As a result, guests share the same default identity for nonce generation; the default does not give each visitor a unique guest nonce. Sites that need guest-specific behavior must add a guest-session mechanism rather than assuming the built-in default distinguishes visitors. For logged-in users, a nonce is tied to the user context, but it still does not replace permission checks.

Handle submitted nonce values carefully

When reading a nonce from request input, follow WordPress guidance to unslash and sanitize the value before verification. The verification function is pluggable, so do not treat raw request input as inherently trustworthy. See the Common APIs Handbook for nonce validation guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common nonce mistakes

  • Calling it one-time-use: WordPress accepts a nonce repeatedly while it remains valid.
  • Assuming every nonce lasts exactly 24 hours: the default acceptance window varies with the two-tick boundary.
  • Treating verification as authorization: check the user’s capability separately before performing the action.
  • Assuming guests have unique default nonces: logged-out users share user ID 0 unless the site adds a guest-session mechanism.
  • Assuming REST cookie authentication works without a nonce: without the wp_rest nonce, WordPress treats the request as unauthenticated.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.