All skills
automattic avatar

/wp-rest-api

@0253fb3 official
by automatticautomattic/agent-skills211 stars
37

Use when building, extending, or debugging WordPress REST API endpoints/routes: register_rest_route, WP_REST_Controller/controller classes, schema/argument validation, permission_callback/authentication, response shaping, register_rest_field/register_meta, or exposing CPTs/taxonomies via show_in_rest.

Use this Skill: https://skilld.dev/gh/automattic/agent-skills/wp-rest-api

This session only. Nothing lands on disk.

referencesdiscovery-and-params.md

≈183 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Discovery and Global Parameters (summary)

API discovery

  • REST API root is discovered via the Link header: rel="https://api.w.org/".
  • HTML pages also include a <link rel="https://api.w.org/" href="..."> element.
  • For non-pretty permalinks, use ?rest_route=/.

Global parameters

  • _fields limits response fields (supports nested meta keys).
  • _embed includes linked resources in _embedded.
  • _method or X-HTTP-Method-Override allows POST to simulate PUT/DELETE.
  • _envelope puts headers/status in the response body.
  • _jsonp enables JSONP for legacy clients.

Pagination

  • Collections accept page, per_page (1-100), and offset.
  • Pagination headers: X-WP-Total and X-WP-TotalPages.

Source: SKILL.md on GitHub

No alerts17d4 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill provides a set of secure development guidelines and best practices for building and debugging WordPress REST API endpoints. It emphasizes essential security measures such as permission callbacks, nonce validation, and schema-based argument sanitization. No malicious patterns or security risks were identified.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    4/7 files flagged

Signed by skilld at 0253fb3. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 5 months ago.

Dormantupdated 8 months ago
Other metadata
compatibility
Targets WordPress 6.9+ (PHP 7.2.24+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • wordpress
  • rest-api
  • php
  • endpoints
  • authentication
  • schema-validation
  • custom-post-types
  • taxonomies
  • permission-callbacks

README badge

README badge for automattic/agent-skills/wp-rest-api

Registers and debugs WordPress REST API endpoints, routes, and custom fields using register_rest_route, WP_REST_Controller, schema validation, and permission callbacks. Use this when exposing custom post types or taxonomies via REST, adding meta fields to responses, or troubleshooting 401/403/404 errors in WordPress 6.9+.

Generated from the current SKILL.md.

Does this skill work with WordPress versions below 6.9?
The skill targets WordPress 6.9+ (PHP 7.2.24+). If you're on an older version, call out the constraint before proceeding.
What authentication methods does this skill support?
Cookie auth with nonce (for wp-admin/JS), application passwords (basic auth for external clients), or custom auth plugins. The skill guides you to choose the right method based on your use case.
Can I add custom fields to existing REST endpoints without modifying core?
Yes. Use `register_rest_field` for computed fields or `register_meta` with `show_in_rest` for meta. The skill advises against removing core fields; instead, add new ones.
How does this skill handle custom post types and taxonomies?
For built-in endpoints, set `show_in_rest => true` on the post type or taxonomy registration. For full control, provide a custom `rest_controller_class` that extends `WP_REST_Controller`.
What does the skill expect as input before I use it?
You need the repo root and path to your target plugin/theme/mu-plugin, your desired namespace and version (e.g. `my-plugin/v1`), authentication mode, and any WordPress version constraints.

Generated from the current SKILL.md. These answers refresh after source changes.