All skills
wordpress avatar

/wp-rest-api

@20324d2 official
by wordpresswordpress/agent-skills2.2k stars
327

Use when building, extending, or debugging WordPress REST API endpoints/routes: register_rest_route, WP_REST_Controller/controller classes, schema/argument validation, permission_callback/authentication, response shaping, register_rest_field/register_meta, or exposing CPTs/taxonomies via show_in_rest.

Use this Skill: https://skilld.dev/gh/wordpress/agent-skills/wp-rest-api

This session only. Nothing lands on disk.

SKILL.md

≈79 tokens always: the name and description. ≈1.1k when used: this file. ≈1.4k more on demand in 6 files.

WP REST API

When to use

Use this skill when you need to:

  • create or update REST routes/endpoints
  • debug 401/403/404 errors or permission/nonce issues
  • add custom fields/meta to REST responses
  • expose custom post types or taxonomies via REST
  • implement schema + argument validation
  • adjust response links/embedding/pagination

Inputs required

  • Repo root + target plugin/theme/mu-plugin (path to entrypoint).
  • Desired namespace + version (e.g. my-plugin/v1) and routes.
  • Authentication mode (cookie + nonce vs application passwords vs auth plugin).
  • Target WordPress version constraints (if below 7.0, call out).

Procedure

0) Triage and locate REST usage

  1. Run triage:
    • node skills/wp-project-triage/scripts/detect_wp_project.mjs
  2. Search for existing REST usage:
    • register_rest_route
    • WP_REST_Controller
    • rest_api_init
    • show_in_rest, rest_base, rest_controller_class

If this is a full site repo, pick the specific plugin/theme before changing code.

1) Choose the right approach

  • Expose CPT/taxonomy in wp/v2:
    • Use show_in_rest => true + rest_base if needed.
    • Optionally provide rest_controller_class.
    • Read references/custom-content-types.md.
  • Custom endpoints:
    • Use register_rest_route() on rest_api_init.
    • Prefer a controller class (WP_REST_Controller subclass) for anything non-trivial.
    • Read references/routes-and-endpoints.md and references/schema.md.

2) Register routes safely (namespaces, methods, permissions)

  • Use a unique namespace vendor/v1; avoid wp/* unless core.
  • Always provide permission_callback (use __return_true for public endpoints).
  • Use WP_REST_Server::READABLE/CREATABLE/EDITABLE/DELETABLE constants.
  • Return data via rest_ensure_response() or WP_REST_Response.
  • Return errors via WP_Error with an explicit status.

Read references/routes-and-endpoints.md.

3) Validate/sanitize request args

  • Define args with type, default, required, validate_callback, sanitize_callback.
  • Prefer JSON Schema validation with rest_validate_value_from_schema then rest_sanitize_value_from_schema.
  • Never read $_GET/$_POST directly inside endpoints; use WP_REST_Request.

Read references/schema.md.

4) Responses, fields, and links

  • Do not remove core fields from default endpoints; add fields instead.
  • Use register_rest_field for computed fields; register_meta with show_in_rest for meta.
  • For object/array meta, define schema in show_in_rest.schema.
  • If you need unfiltered post content (e.g., ToC plugins injecting HTML), request ?context=edit to access content.raw (auth required). Pair with _fields=content.raw to keep responses small.
  • Add related resource links via WP_REST_Response::add_link().

Read references/responses-and-fields.md.

5) Authentication and authorization

  • For wp-admin/JS: cookie auth + X-WP-Nonce (action wp_rest).
  • For external clients: application passwords (basic auth) or an auth plugin.
  • Use capability checks in permission_callback (authorization), not just “logged in”.

Read references/authentication.md.

6) Client-facing behavior (discovery, pagination, embeds)

  • Ensure discovery works (Link header or <link rel="https://api.w.org/">).
  • Support _fields, _embed, _method, _envelope, pagination headers.
  • Remember per_page is capped at 100.

Read references/discovery-and-params.md.

Verification

  • /wp-json/ index includes your namespace.
  • OPTIONS on your route returns schema (when provided).
  • Endpoint returns expected data; permission failures return 401/403 as appropriate.
  • CPT/taxonomy routes appear under wp/v2 when show_in_rest is true.
  • Run repo lint/tests and any PHP/JS build steps.

Failure modes / debugging

  • 404: rest_api_init not firing, route typo, or permalinks off (use ?rest_route=).
  • 401/403: missing nonce/auth, or permission_callback too strict.
  • _doing_it_wrong for missing permission_callback: add it (use __return_true if public).
  • Invalid params: missing/incorrect args schema or validation callbacks.
  • Fields missing: show_in_rest false, meta not registered, or CPT lacks custom-fields support.

Escalation

If version support or behavior is unclear, consult the REST API Handbook and core docs before inventing patterns.

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is safe and provides comprehensive guidance on building secure WordPress REST APIs, following best practices like mandatory permission callbacks and input validation. A low-severity risk of indirect prompt injection is present because the skill processes external source code as its primary function.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    7/7 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 20324d2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 3 months ago
Other metadata
compatibility
Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • wordpress
  • rest-api
  • php
  • endpoints
  • authentication
  • schema-validation
  • custom-post-types
  • taxonomies
  • permissions

README badge

README badge for wordpress/agent-skills/wp-rest-api

Registers and debugs WordPress REST API endpoints, custom routes, and field exposure using register_rest_route, WP_REST_Controller classes, schema validation, and permission callbacks. Use this when building custom endpoints, exposing custom post types or taxonomies via REST, or troubleshooting authentication and response formatting issues in WordPress 6.9+.

Generated from the current SKILL.md.

Does this skill work with WordPress versions below 6.9?
The skill targets WordPress 6.9+ (PHP 7.2.24+). If your site runs an older version, you should call that out before proceeding, as some workflows may not apply.
What authentication methods does this skill support?
The skill covers cookie auth with nonce for wp-admin/JS clients, application passwords (basic auth) for external clients, and integration with auth plugins. Choose based on your client type.
Can I expose custom post types and taxonomies via REST?
Yes. Use `show_in_rest => true` plus optional `rest_base` and `rest_controller_class` arguments on post type/taxonomy registration to expose them under the `wp/v2` namespace.
How do I add custom fields or metadata to REST responses?
Use `register_rest_field` for computed fields or `register_meta` with `show_in_rest` for stored metadata. For object/array meta, define the schema in `show_in_rest.schema`.
What should I do if I get a 404 error on my endpoint?
Check that `rest_api_init` is firing, verify the route path is correct, and ensure permalinks are enabled (or use `?rest_route=` as a fallback). Also confirm the namespace is registered via `/wp-json/`.

Generated from the current SKILL.md. These answers refresh after source changes.