wp-rest-api

tarafından wordpress

WordPress REST API uç noktalarını şema zorunluluğu ve izin kontrolleriyle kaydeder, doğrular ve hata ayıklar. register_rest_route() ve WP_REST_Controller alt sınıfları aracılığıyla rota kaydını, register_rest_field ve meta kaydı ile özel alan açığa çıkarmayı ve show_in_rest ile CPT/taksonomi REST açığa çıkarmayı kapsar. Şema doğrulaması, argüman temizleme ve izin geri çağrılarını zorunlu kılar; çerez + nonce, uygulama parolaları ve özel kimlik doğrulama eklentilerini destekler. Sorun giderme iş akışını içerir...

npx skills add https://github.com/wordpress/agent-skills --skill wp-rest-api

WP REST API

When to use

Use this skill when you need to:

  • create or update REST routes/endpoints
  • debug 401/403/404 errors or permission/nonce issues
  • add custom fields/meta to REST responses
  • expose custom post types or taxonomies via REST
  • implement schema + argument validation
  • adjust response links/embedding/pagination

Inputs required

  • Repo root + target plugin/theme/mu-plugin (path to entrypoint).
  • Desired namespace + version (e.g. my-plugin/v1) and routes.
  • Authentication mode (cookie + nonce vs application passwords vs auth plugin).
  • Target WordPress version constraints (if below 7.0, call out).

Procedure

0) Triage and locate REST usage

  1. Run triage:
    • node skills/wp-project-triage/scripts/detect_wp_project.mjs
  2. Search for existing REST usage:
    • register_rest_route
    • WP_REST_Controller
    • rest_api_init
    • show_in_rest, rest_base, rest_controller_class

If this is a full site repo, pick the specific plugin/theme before changing code.

1) Choose the right approach

  • Expose CPT/taxonomy in wp/v2:
    • Use show_in_rest => true + rest_base if needed.
    • Optionally provide rest_controller_class.
    • Read references/custom-content-types.md.
  • Custom endpoints:
    • Use register_rest_route() on rest_api_init.
    • Prefer a controller class (WP_REST_Controller subclass) for anything non-trivial.
    • Read references/routes-and-endpoints.md and references/schema.md.

2) Register routes safely (namespaces, methods, permissions)

  • Use a unique namespace vendor/v1; avoid wp/* unless core.
  • Always provide permission_callback (use __return_true for public endpoints).
  • Use WP_REST_Server::READABLE/CREATABLE/EDITABLE/DELETABLE constants.
  • Return data via rest_ensure_response() or WP_REST_Response.
  • Return errors via WP_Error with an explicit status.

Read references/routes-and-endpoints.md.

3) Validate/sanitize request args

  • Define args with type, default, required, validate_callback, sanitize_callback.
  • Prefer JSON Schema validation with rest_validate_value_from_schema then rest_sanitize_value_from_schema.
  • Never read $_GET/$_POST directly inside endpoints; use WP_REST_Request.

Read references/schema.md.

4) Responses, fields, and links

  • Do not remove core fields from default endpoints; add fields instead.
  • Use register_rest_field for computed fields; register_meta with show_in_rest for meta.
  • For object/array meta, define schema in show_in_rest.schema.
  • If you need unfiltered post content (e.g., ToC plugins injecting HTML), request ?context=edit to access content.raw (auth required). Pair with _fields=content.raw to keep responses small.
  • Add related resource links via WP_REST_Response::add_link().

Read references/responses-and-fields.md.

5) Authentication and authorization

  • For wp-admin/JS: cookie auth + X-WP-Nonce (action wp_rest).
  • For external clients: application passwords (basic auth) or an auth plugin.
  • Use capability checks in permission_callback (authorization), not just “logged in”.

Read references/authentication.md.

6) Client-facing behavior (discovery, pagination, embeds)

  • Ensure discovery works (Link header or <link rel="https://api.w.org/">).
  • Support _fields, _embed, _method, _envelope, pagination headers.
  • Remember per_page is capped at 100.

Read references/discovery-and-params.md.

Verification

  • /wp-json/ index includes your namespace.
  • OPTIONS on your route returns schema (when provided).
  • Endpoint returns expected data; permission failures return 401/403 as appropriate.
  • CPT/taxonomy routes appear under wp/v2 when show_in_rest is true.
  • Run repo lint/tests and any PHP/JS build steps.

Failure modes / debugging

  • 404: rest_api_init not firing, route typo, or permalinks off (use ?rest_route=).
  • 401/403: missing nonce/auth, or permission_callback too strict.
  • _doing_it_wrong for missing permission_callback: add it (use __return_true if public).
  • Invalid params: missing/incorrect args schema or validation callbacks.
  • Fields missing: show_in_rest false, meta not registered, or CPT lacks custom-fields support.

Escalation

If version support or behavior is unclear, consult the REST API Handbook and core docs before inventing patterns.

wordpress tarafından daha fazla skill

blueprint
wordpress
WordPress Playground blueprint JSON dosyalarını oluştururken, düzenlerken veya incelerken kullanılır. Blueprint'lerden, playground yapılandırmasından veya taleplerden bahsedildiğinde tetiklenir…
official
wordpress-router
wordpress
WordPress kod tabanlarını sınıflandırır ve eklentiler, temalar, bloklar ile çekirdek kontrolleri için doğru iş akışına yönlendirir. Depo türünü (eklenti, tema, blok teması, Gutenberg blokları, WP çekirdeği) ve mevcut araçları belirlemek için otomatik proje triyajı çalıştırır. Kullanıcı niyeti ve proje türüne göre sınıflandırma sonuçları ile karar ağacı yönlendirmesini alana özel becerilere çıktı olarak verir. Depo kök erişimi ve bash/Node dosya sistemi işlemleri gerektirir; bazı iş akışları WP-CLI'ye ihtiyaç duyar. WordPress 6.9+ ve PHP
official
wp-abilities-api
wordpress
WordPress Abilities API kaydı, REST sunumu ve WordPress 6.9+ için istemci tarafı tüketimi. wp_register_ability() ve wp_register_ability_category() kullanarak PHP'de kararlı kimlikler, etiketler ve meta verilerle yetenekler ve kategoriler kaydedin. meta.show_in_rest: true ayarını yaparak yetenekleri /wp-json/wp-abilities/v1/ REST uç noktaları aracılığıyla istemcilere sunun. @wordpress/abilities paketini kullanarak JavaScript'te istemci tarafı erişim ve izin kontrolleri için yetenekleri tüketin. WordPress 6.9+ gerektirir...
official
wp-abilities-audit
wordpress
WordPress eklentisinin REST yüzeyini denetleyin ve Abilities API kayıtları öneren standart bir denetim belgesi oluşturun. YAML içeren bir markdown belgesi üretir…
official
wp-abilities-verify
wordpress
WordPress eklentisinin Abilities API kayıtlarını doğrulayın: yetenekleri numaralandırın, geri çağırma davranışının her açıklamanın iddiasıyla eşleşip eşleşmediğini kontrol edin (saldırgan…
official
wp-block-development
wordpress
WordPress blok geliştirme (Gutenberg için): meta veri, kayıt, oluşturma ve derleme iş akışları. Blok oluşturma, block.json yapılandırması, statik ve dinamik oluşturma ile register_block_type_from_metadata() kullanarak sunucu tarafı PHP kaydını kapsar. WordPress 6.9+ uyumluluğu için apiVersion: 3'ü zorunlu kılar; iframe düzenleyici desteği ve stil izolasyonunu içerir. "Geçersiz blok" hatalarını önlemek için nitelik serileştirme, eski sürümler/geçişler ve iç blok kompozisyonunu yönetir. Şunları içerir...
official
wp-block-themes
wordpress
WordPress blok tema geliştirme: theme.json, şablonlar, desenler ve Site Düzenleyici sorun giderme. theme.json düzenleme (ön ayarlar, ayarlar, blok başına stiller), şablonlar ve şablon parçaları, desenler ve WordPress 6.9+ üzerinde stil varyasyonlarını kapsar. Tema köklerini ve blok tema yapısını tespit etmek için triyaj betikleri ile yeni temalar oluşturma veya klasik temaları dönüştürme için rehberli prosedürler içerir. Stil hiyerarşisi sorunları, kullanıcı özelleştirme geçersiz kılmaları ve Site... için hata ayıklama iş akışları sağlar.
official
wp-interactivity-api
wordpress
WordPress Interactivity API özellikleri (data-wp-* yönergeleri, @wordpress/interactivity store/state/actions, block viewScriptModule…) oluştururken veya hata ayıklarken kullanın.
official