Use when building, extending, or debugging WordPress REST API endpoints/routes: register_rest_route, WP_REST_Controller/controller classes, schema/argument validation, permission_callback/authentication, response shaping, register_rest_field/register_meta, or exposing CPTs/taxonomies via show_in_rest.
Installation
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Use when building, extending, or debugging WordPress REST API endpoints/routes: register_rest_route, WP_REST_Controller/controller classes, schema/argument validation, permission_callback/authentication, response shaping, register_rest_field/register_meta, or exposing CPTs/taxonomies via show_in_rest.
WP REST API
Compatibility: Targets WordPress 6.9+ (PHP 7.2.24+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
When to use
Use this skill when you need to:
create or update REST routes/endpoints
debug 401/403/404 errors or permission/nonce issues
add custom fields/meta to REST responses
expose custom post types or taxonomies via REST
implement schema + argument validation
adjust response links/embedding/pagination
Inputs required
Repo root + target plugin/theme/mu-plugin (path to entrypoint).
Desired namespace + version (e.g. my-plugin/v1) and routes.
Authentication mode (cookie + nonce vs application passwords vs auth plugin).
Target WordPress version constraints (if below 6.9, call out).
Use a unique namespace vendor/v1; avoid wp/* unless core.
Always provide permission_callback (use __return_true for public endpoints).
Use WP_REST_Server::READABLE/CREATABLE/EDITABLE/DELETABLE constants.
Return data via rest_ensure_response() or WP_REST_Response.
Return errors via WP_Error with an explicit status.
Read references/routes-and-endpoints.md.
3) Validate/sanitize request args
Define args with type, default, required, validate_callback, sanitize_callback.
Prefer JSON Schema validation with rest_validate_value_from_schema then rest_sanitize_value_from_schema.
Never read $_GET/$_POST directly inside endpoints; use WP_REST_Request.
Read references/schema.md.
4) Responses, fields, and links
Do not remove core fields from default endpoints; add fields instead.
Use register_rest_field for computed fields; register_meta with show_in_rest for meta.
For object/array meta, define schema in show_in_rest.schema.
If you need unfiltered post content (e.g., ToC plugins injecting HTML), request ?context=edit to access content.raw (auth required). Pair with _fields=content.raw to keep responses small.
Add related resource links via WP_REST_Response::add_link().
Read references/responses-and-fields.md.
5) Authentication and authorization
For wp-admin/JS: cookie auth + X-WP-Nonce (action wp_rest).
For external clients: application passwords (basic auth) or an auth plugin.
Use capability checks in permission_callback (authorization), not just “logged in”.