If your PHP website only needs to recognize someone who is already signed in to phpBB, it can read phpBB session and user state—but the commonly cited integration example is for phpBB 3.0 and must not be assumed to work unchanged on newer releases. If you need forum and website logins and logouts to act as one, reading the forum session is not enough; that requires a coordinated authentication design.
First decide what “integrate users” means
There are two different goals that are easy to confuse:
- Recognize a phpBB login: Your website checks whether the visitor has an active phpBB session and, if so, reads relevant forum user data.
- Coordinate authentication: Logging in or out of either the forum or website updates the other application’s authentication state as well.
The first is session recognition. It does not automatically provide the second. A phpBB Knowledge Base article about cross-site sessions, published in 2008 for phpBB 3.0, explicitly says its approach does not log a user into the separate website when they log into phpBB. Treat that article as historical implementation context, not current security guidance: phpBB: Using phpBB3 sessions across multiple sites.
Check your phpBB version before choosing an approach
The session-inclusion example commonly cited for a PHP page is documented for phpBB 3.0. The relevant phpBB 3.3 user and developer documentation describes authentication plugins and extension-based providers, which address a different need. Identify the installed phpBB release and use documentation and APIs for that release rather than copying old code into a newer installation.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
The phpBB 3.3 user guide lists PHP 7.2.0 or later among that release’s requirements. That is a version-specific requirement from the 3.3 guide, not confirmation that your host, PHP version, database, or a newer phpBB release is compatible. Check the requirements for the exact version you run: phpBB 3.3 User Guide.
Option 1: Let a PHP page read phpBB session state
This route is intended for a website page that can access the phpBB installation and needs to know whether the visitor has an existing forum session. The phpBB 3.0 Knowledge Base example follows this sequence:
Rank #2
- Include phpBB’s
common.phpfrom the PHP page. - Start the forum session with
session_begin(). - Initialize access-control data using the user data.
- Run user setup before reading user information.
In that historical example, the page checks whether user_id equals ANONYMOUS and reads username_clean for a logged-in user. The ordering matters: do not treat those values as ready before the session, access-control list (ACL), and user setup steps. The source is explicitly for phpBB 3.0, so use it to understand the integration pattern—not as verified code for another release: phpBB: Add a new phpBB3 page to your website as a PHP file.
When this approach fits
- The website and forum run in a PHP environment where the website page can load the appropriate phpBB files.
- The website needs to recognize the existing forum session, rather than create a separate login experience.
- You can verify the required APIs and deployment assumptions against your installed phpBB version.
What it does not provide
Reading phpBB state does not, by itself, authenticate the user to your website, create a website account, or coordinate login and logout between both applications. Those behaviors need explicit design and implementation.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Option 2: Make phpBB authenticate through a provider
If the intended direction is for phpBB itself to authenticate against an external identity source or custom provider, use phpBB’s authentication-provider extension mechanism for the installed version. The phpBB 3.3 developer tutorial describes a provider class, YAML service registration with the auth.provider tag, and enabling the provider in the Administration Control Panel (ACP). It also states that only one provider may currently be active at a time, selected in the ACP: phpBB 3.3 Authentication Provider documentation.
This is not a shortcut for a website page to inspect an existing forum session. It changes how phpBB authenticates users and entails extension development and maintenance. The 3.3 provider API documents concepts including session validation, logout, and linking or unlinking external accounts, but those API concepts alone are not a complete implementation for a particular website: phpBB 3.3 Authentication Provider API.
Rank #4
Choose based on the direction of authentication
| Approach | What it is for | What it does not establish | Evidence and version |
|---|---|---|---|
| Website reads phpBB session state | A PHP website page recognizes a visitor whose session is managed by phpBB. | Automatic website login, coordinated logout, or current-release compatibility from the legacy example alone. | phpBB 3.0 Knowledge Base session example: session integration article. |
| phpBB authentication provider | phpBB authenticates using a provider such as a custom or external identity source. | A ready-made integration with the website or support for multiple active providers; phpBB 3.3’s tutorial says only one provider may be active at a time. | phpBB 3.3 developer documentation: provider tutorial. |
Plan a coordinated login only after defining the trust boundary
If users must sign in once and access both applications, first decide which system is authoritative for identity and which application is responsible for establishing and ending each session. Specify how account identifiers map between the forum and website, what happens when a user logs out, and how each application validates authentication. A custom phpBB provider may be relevant when phpBB must use an external identity source, but the provider documentation is not a complete single-sign-on recipe for an unspecified website.
Do not treat matching cookie settings as proof of single sign-on. The 2008 cross-site Knowledge Base article discusses cookie settings for its historical same-domain setup, but that dated guidance does not establish a safe or suitable configuration for current deployments. Cookie scope alone does not make one application’s login automatically create or invalidate the other application’s session.
Recommended Free Tools
Quick Recap
Practical checklist before implementation
- Record the exact phpBB and PHP versions, and check the corresponding phpBB requirements and developer documentation.
- Confirm whether the site only needs to identify a logged-in forum user or needs coordinated login and logout.
- For session recognition, verify that the website can load the correct phpBB installation and that the documented API matches its version.
- For external authentication in phpBB, confirm the provider extension supports the installed release and account for the one-active-provider constraint documented for phpBB 3.3.
- Test anonymous visitors, authenticated visitors, expired sessions, logout behavior, and account mapping in a non-production environment before relying on the integration.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

