Title: wp_connectors_sanitize_application_password_credentials
Published: August 20, 2026

---

# wp_connectors_sanitize_application_password_credentials( mixed $value, string $option = '' ): array{username:

## In this article

 * [Description](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#description)
 * [Parameters](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#parameters)
 * [Return](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#return)
 * [Source](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#source)
 * [Related](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#related)
 * [Changelog](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#changelog)

[ Back to top](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#wp--skip-link--target)

This function’s access is marked private. This means it is not intended for use 
by plugin or theme developers, only by core. It is listed here for completeness.

Sanitizes stored application-password credentials for a connector.

## 󠀁[Description](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#description)󠁿

Credential fields that are missing or not strings keep their currently stored values,
so partial updates cannot silently clear a stored secret.
A password matching the
mask that `_wp_connectors_rest_settings_dispatch()` places in REST responses also
keeps the stored password, so a masked settings response can be submitted back to
the endpoint unchanged.Pass an empty string to clear a field.If the sanitized username
is empty, both fields are discarded so partial credentials cannot leave an orphaned
secret.

## 󠀁[Parameters](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#parameters)󠁿

 `$value`mixedrequired

The submitted setting value.

`$option`stringoptional

The option name being sanitized. Passed explicitly by the registered sanitize callback;
falls back to the current `sanitize_option_{$option}` filter name when omitted.

Default:`''`

## 󠀁[Return](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#return)󠁿

 array{username: string, password: string} Sanitized credentials.

## 󠀁[Source](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#source)󠁿

    ```php
    function wp_connectors_sanitize_application_password_credentials( $value, string $option = '' ): array {
    	if ( ! is_array( $value ) ) {
    		$value = array();
    	}

    	if ( '' === $option ) {
    		$option = str_replace( 'sanitize_option_', '', (string) current_filter() );
    	}

    	$stored = get_option( $option );
    	if ( ! is_array( $stored ) ) {
    		$stored = array();
    	}

    	$credentials = array();
    	foreach ( array( 'username', 'password' ) as $field ) {
    		if ( isset( $value[ $field ] ) && is_string( $value[ $field ] ) ) {
    			$credentials[ $field ] = sanitize_text_field( $value[ $field ] );
    		} else {
    			$credentials[ $field ] = isset( $stored[ $field ] ) && is_string( $stored[ $field ] ) ? $stored[ $field ] : '';
    		}
    	}

    	// A masked password means a client resubmitted a masked REST response.
    	if ( str_repeat( "\u{2022}", 16 ) === $credentials['password'] ) {
    		$credentials['password'] = isset( $stored['password'] ) && is_string( $stored['password'] ) ? $stored['password'] : '';
    	}

    	if ( '' === $credentials['username'] ) {
    		return array(
    			'username' => '',
    			'password' => '',
    		);
    	}

    	return $credentials;
    }
    ```

[View all references](https://developer.wordpress.org/reference/files/wp-includes/connectors.php/)
[View on Trac](https://core.trac.wordpress.org/browser/tags/7.1/src/wp-includes/connectors.php#L641)
[View on GitHub](https://github.com/WordPress/wordpress-develop/blob/7.1/src/wp-includes/connectors.php#L641-L677)

## 󠀁[Related](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#related)󠁿

| Uses | Description | 
| [current_filter()](https://developer.wordpress.org/reference/functions/current_filter/)`wp-includes/plugin.php` |

Retrieves the name of the current filter hook.

  | 
| [sanitize_text_field()](https://developer.wordpress.org/reference/functions/sanitize_text_field/)`wp-includes/formatting.php` |

Sanitizes a string from user input or from the database.

  | 
| [get_option()](https://developer.wordpress.org/reference/functions/get_option/)`wp-includes/option.php` |

Retrieves an option value based on an option name.

  |

[Show 1 more](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#)
[Show less](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#)

| Used by | Description | 
| [_wp_register_default_connector_settings()](https://developer.wordpress.org/reference/functions/_wp_register_default_connector_settings/)`wp-includes/connectors.php` |

Registers default connector settings.

  |

## 󠀁[Changelog](https://developer.wordpress.org/reference/functions/wp_connectors_sanitize_application_password_credentials/?output_format=md#changelog)󠁿

| Version | Description | 
| [7.1.0](https://developer.wordpress.org/reference/since/7.1.0/) | Introduced. |

## User Contributed Notes

You must [log in](https://login.wordpress.org/?redirect_to=https%3A%2F%2Fdeveloper.wordpress.org%2Freference%2Ffunctions%2Fwp_connectors_sanitize_application_password_credentials%2F)
before being able to contribute a note or feedback.