All skills
automattic avatar

/wp-rest-api

@0253fb3 official
by automatticautomattic/agent-skills211 stars
37

Use when building, extending, or debugging WordPress REST API endpoints/routes: register_rest_route, WP_REST_Controller/controller classes, schema/argument validation, permission_callback/authentication, response shaping, register_rest_field/register_meta, or exposing CPTs/taxonomies via show_in_rest.

Use this Skill: https://skilld.dev/gh/automattic/agent-skills/wp-rest-api

This session only. Nothing lands on disk.

referencesschema.md

≈241 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Schema and Argument Validation (summary)

JSON Schema in WordPress

  • REST API uses JSON Schema (draft 4 subset) for resource and argument definitions.
  • Provide schema via get_item_schema() on controllers or schema callbacks on routes.
  • Schema enables discovery (OPTIONS) and validation.

Validation + sanitization

  • Use rest_validate_value_from_schema( $value, $schema ) then rest_sanitize_value_from_schema( $value, $schema ).
  • If you override sanitize_callback, built-in schema validation will not run; use rest_validate_request_arg to keep it.
  • WP_REST_Controller::get_endpoint_args_for_item_schema() wires validation automatically.

Schema caching

  • Cache the generated schema on the controller instance ($this->schema) to avoid recomputation.

Formats and types

  • Common formats: date-time, uri, email, ip, uuid, hex-color.
  • For array and object types, you must define items or properties schemas.

Source: SKILL.md on GitHub

No alerts17d4 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill provides a set of secure development guidelines and best practices for building and debugging WordPress REST API endpoints. It emphasizes essential security measures such as permission callbacks, nonce validation, and schema-based argument sanitization. No malicious patterns or security risks were identified.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    4/7 files flagged

Signed by skilld at 0253fb3. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 5 months ago.

Dormantupdated 8 months ago
Other metadata
compatibility
Targets WordPress 6.9+ (PHP 7.2.24+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • wordpress
  • rest-api
  • php
  • endpoints
  • authentication
  • schema-validation
  • custom-post-types
  • taxonomies
  • permission-callbacks

README badge

README badge for automattic/agent-skills/wp-rest-api

Registers and debugs WordPress REST API endpoints, routes, and custom fields using register_rest_route, WP_REST_Controller, schema validation, and permission callbacks. Use this when exposing custom post types or taxonomies via REST, adding meta fields to responses, or troubleshooting 401/403/404 errors in WordPress 6.9+.

Generated from the current SKILL.md.

Does this skill work with WordPress versions below 6.9?
The skill targets WordPress 6.9+ (PHP 7.2.24+). If you're on an older version, call out the constraint before proceeding.
What authentication methods does this skill support?
Cookie auth with nonce (for wp-admin/JS), application passwords (basic auth for external clients), or custom auth plugins. The skill guides you to choose the right method based on your use case.
Can I add custom fields to existing REST endpoints without modifying core?
Yes. Use `register_rest_field` for computed fields or `register_meta` with `show_in_rest` for meta. The skill advises against removing core fields; instead, add new ones.
How does this skill handle custom post types and taxonomies?
For built-in endpoints, set `show_in_rest => true` on the post type or taxonomy registration. For full control, provide a custom `rest_controller_class` that extends `WP_REST_Controller`.
What does the skill expect as input before I use it?
You need the repo root and path to your target plugin/theme/mu-plugin, your desired namespace and version (e.g. `my-plugin/v1`), authentication mode, and any WordPress version constraints.

Generated from the current SKILL.md. These answers refresh after source changes.