All skills
wordpress avatar

/wp-rest-api

@20324d2 official
by wordpresswordpress/agent-skills2.2k stars
327

Use when building, extending, or debugging WordPress REST API endpoints/routes: register_rest_route, WP_REST_Controller/controller classes, schema/argument validation, permission_callback/authentication, response shaping, register_rest_field/register_meta, or exposing CPTs/taxonomies via show_in_rest.

Use this Skill: https://skilld.dev/gh/wordpress/agent-skills/wp-rest-api

This session only. Nothing lands on disk.

referencesresponses-and-fields.md

≈273 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Responses and Fields (summary)

Do not remove core fields

  • Removing or changing core fields breaks clients (including wp-admin).
  • Prefer adding new fields or using _fields to limit response size.

register_rest_field

  • Use for computed or custom fields.
  • Provide get_callback, optional update_callback, and schema.
  • Register on rest_api_init.

Raw vs rendered content

  • For posts, content.rendered reflects filters (plugins like ToC inject HTML).
  • Use ?context=edit (authenticated) to access content.raw.
  • Combine with _fields=content.raw when you only need the editable body.

register_meta / register_post_meta / register_term_meta

  • Use when the data is stored as meta.
  • Set show_in_rest => true to expose under .meta.
  • For object or array types, provide a JSON schema in show_in_rest.schema.

Links and embedding

  • Add links with WP_REST_Response::add_link( $rel, $href, $attrs ).
  • Use embeddable => true to allow _embed.
  • Use IANA rels or a custom URI relation; CURIEs can be registered via rest_response_link_curies.

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is safe and provides comprehensive guidance on building secure WordPress REST APIs, following best practices like mandatory permission callbacks and input validation. A low-severity risk of indirect prompt injection is present because the skill processes external source code as its primary function.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    7/7 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 20324d2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 3 months ago
Other metadata
compatibility
Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • wordpress
  • rest-api
  • php
  • endpoints
  • authentication
  • schema-validation
  • custom-post-types
  • taxonomies
  • permissions

README badge

README badge for wordpress/agent-skills/wp-rest-api

Registers and debugs WordPress REST API endpoints, custom routes, and field exposure using register_rest_route, WP_REST_Controller classes, schema validation, and permission callbacks. Use this when building custom endpoints, exposing custom post types or taxonomies via REST, or troubleshooting authentication and response formatting issues in WordPress 6.9+.

Generated from the current SKILL.md.

Does this skill work with WordPress versions below 6.9?
The skill targets WordPress 6.9+ (PHP 7.2.24+). If your site runs an older version, you should call that out before proceeding, as some workflows may not apply.
What authentication methods does this skill support?
The skill covers cookie auth with nonce for wp-admin/JS clients, application passwords (basic auth) for external clients, and integration with auth plugins. Choose based on your client type.
Can I expose custom post types and taxonomies via REST?
Yes. Use `show_in_rest => true` plus optional `rest_base` and `rest_controller_class` arguments on post type/taxonomy registration to expose them under the `wp/v2` namespace.
How do I add custom fields or metadata to REST responses?
Use `register_rest_field` for computed fields or `register_meta` with `show_in_rest` for stored metadata. For object/array meta, define the schema in `show_in_rest.schema`.
What should I do if I get a 404 error on my endpoint?
Check that `rest_api_init` is firing, verify the route path is correct, and ensure permalinks are enabled (or use `?rest_route=` as a fallback). Also confirm the namespace is registered via `/wp-json/`.

Generated from the current SKILL.md. These answers refresh after source changes.