All skills
automattic avatar

/wp-rest-api

@0253fb3 official
by automatticautomattic/agent-skills211 stars
37

Use when building, extending, or debugging WordPress REST API endpoints/routes: register_rest_route, WP_REST_Controller/controller classes, schema/argument validation, permission_callback/authentication, response shaping, register_rest_field/register_meta, or exposing CPTs/taxonomies via show_in_rest.

Use this Skill: https://skilld.dev/gh/automattic/agent-skills/wp-rest-api

This session only. Nothing lands on disk.

referencesresponses-and-fields.md

≈273 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Responses and Fields (summary)

Do not remove core fields

  • Removing or changing core fields breaks clients (including wp-admin).
  • Prefer adding new fields or using _fields to limit response size.

register_rest_field

  • Use for computed or custom fields.
  • Provide get_callback, optional update_callback, and schema.
  • Register on rest_api_init.

Raw vs rendered content

  • For posts, content.rendered reflects filters (plugins like ToC inject HTML).
  • Use ?context=edit (authenticated) to access content.raw.
  • Combine with _fields=content.raw when you only need the editable body.

register_meta / register_post_meta / register_term_meta

  • Use when the data is stored as meta.
  • Set show_in_rest => true to expose under .meta.
  • For object or array types, provide a JSON schema in show_in_rest.schema.

Links and embedding

  • Add links with WP_REST_Response::add_link( $rel, $href, $attrs ).
  • Use embeddable => true to allow _embed.
  • Use IANA rels or a custom URI relation; CURIEs can be registered via rest_response_link_curies.

Source: SKILL.md on GitHub

No alerts17d4 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill provides a set of secure development guidelines and best practices for building and debugging WordPress REST API endpoints. It emphasizes essential security measures such as permission callbacks, nonce validation, and schema-based argument sanitization. No malicious patterns or security risks were identified.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    4/7 files flagged

Signed by skilld at 0253fb3. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 5 months ago.

Dormantupdated 8 months ago
Other metadata
compatibility
Targets WordPress 6.9+ (PHP 7.2.24+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • wordpress
  • rest-api
  • php
  • endpoints
  • authentication
  • schema-validation
  • custom-post-types
  • taxonomies
  • permission-callbacks

README badge

README badge for automattic/agent-skills/wp-rest-api

Registers and debugs WordPress REST API endpoints, routes, and custom fields using register_rest_route, WP_REST_Controller, schema validation, and permission callbacks. Use this when exposing custom post types or taxonomies via REST, adding meta fields to responses, or troubleshooting 401/403/404 errors in WordPress 6.9+.

Generated from the current SKILL.md.

Does this skill work with WordPress versions below 6.9?
The skill targets WordPress 6.9+ (PHP 7.2.24+). If you're on an older version, call out the constraint before proceeding.
What authentication methods does this skill support?
Cookie auth with nonce (for wp-admin/JS), application passwords (basic auth for external clients), or custom auth plugins. The skill guides you to choose the right method based on your use case.
Can I add custom fields to existing REST endpoints without modifying core?
Yes. Use `register_rest_field` for computed fields or `register_meta` with `show_in_rest` for meta. The skill advises against removing core fields; instead, add new ones.
How does this skill handle custom post types and taxonomies?
For built-in endpoints, set `show_in_rest => true` on the post type or taxonomy registration. For full control, provide a custom `rest_controller_class` that extends `WP_REST_Controller`.
What does the skill expect as input before I use it?
You need the repo root and path to your target plugin/theme/mu-plugin, your desired namespace and version (e.g. `my-plugin/v1`), authentication mode, and any WordPress version constraints.

Generated from the current SKILL.md. These answers refresh after source changes.