wp-rest-api

bởi wordpress

Đăng ký, xác thực và gỡ lỗi các endpoint WordPress REST API với kiểm soát lược đồ và quyền hạn. Bao gồm đăng ký route qua register_rest_route() và các lớp con WP_REST_Controller, hiển thị trường tùy chỉnh qua register_rest_field và đăng ký meta, cùng với hiển thị REST của CPT/taxonomy qua show_in_rest. Thực thi xác thực lược đồ, làm sạch đối số và callback quyền hạn; hỗ trợ cookie + nonce, mật khẩu ứng dụng và plugin xác thực tùy chỉnh. Bao gồm quy trình phân loại để...

npx skills add https://github.com/wordpress/agent-skills --skill wp-rest-api

WP REST API

When to use

Use this skill when you need to:

  • create or update REST routes/endpoints
  • debug 401/403/404 errors or permission/nonce issues
  • add custom fields/meta to REST responses
  • expose custom post types or taxonomies via REST
  • implement schema + argument validation
  • adjust response links/embedding/pagination

Inputs required

  • Repo root + target plugin/theme/mu-plugin (path to entrypoint).
  • Desired namespace + version (e.g. my-plugin/v1) and routes.
  • Authentication mode (cookie + nonce vs application passwords vs auth plugin).
  • Target WordPress version constraints (if below 7.0, call out).

Procedure

0) Triage and locate REST usage

  1. Run triage:
    • node skills/wp-project-triage/scripts/detect_wp_project.mjs
  2. Search for existing REST usage:
    • register_rest_route
    • WP_REST_Controller
    • rest_api_init
    • show_in_rest, rest_base, rest_controller_class

If this is a full site repo, pick the specific plugin/theme before changing code.

1) Choose the right approach

  • Expose CPT/taxonomy in wp/v2:
    • Use show_in_rest => true + rest_base if needed.
    • Optionally provide rest_controller_class.
    • Read references/custom-content-types.md.
  • Custom endpoints:
    • Use register_rest_route() on rest_api_init.
    • Prefer a controller class (WP_REST_Controller subclass) for anything non-trivial.
    • Read references/routes-and-endpoints.md and references/schema.md.

2) Register routes safely (namespaces, methods, permissions)

  • Use a unique namespace vendor/v1; avoid wp/* unless core.
  • Always provide permission_callback (use __return_true for public endpoints).
  • Use WP_REST_Server::READABLE/CREATABLE/EDITABLE/DELETABLE constants.
  • Return data via rest_ensure_response() or WP_REST_Response.
  • Return errors via WP_Error with an explicit status.

Read references/routes-and-endpoints.md.

3) Validate/sanitize request args

  • Define args with type, default, required, validate_callback, sanitize_callback.
  • Prefer JSON Schema validation with rest_validate_value_from_schema then rest_sanitize_value_from_schema.
  • Never read $_GET/$_POST directly inside endpoints; use WP_REST_Request.

Read references/schema.md.

4) Responses, fields, and links

  • Do not remove core fields from default endpoints; add fields instead.
  • Use register_rest_field for computed fields; register_meta with show_in_rest for meta.
  • For object/array meta, define schema in show_in_rest.schema.
  • If you need unfiltered post content (e.g., ToC plugins injecting HTML), request ?context=edit to access content.raw (auth required). Pair with _fields=content.raw to keep responses small.
  • Add related resource links via WP_REST_Response::add_link().

Read references/responses-and-fields.md.

5) Authentication and authorization

  • For wp-admin/JS: cookie auth + X-WP-Nonce (action wp_rest).
  • For external clients: application passwords (basic auth) or an auth plugin.
  • Use capability checks in permission_callback (authorization), not just “logged in”.

Read references/authentication.md.

6) Client-facing behavior (discovery, pagination, embeds)

  • Ensure discovery works (Link header or <link rel="https://api.w.org/">).
  • Support _fields, _embed, _method, _envelope, pagination headers.
  • Remember per_page is capped at 100.

Read references/discovery-and-params.md.

Verification

  • /wp-json/ index includes your namespace.
  • OPTIONS on your route returns schema (when provided).
  • Endpoint returns expected data; permission failures return 401/403 as appropriate.
  • CPT/taxonomy routes appear under wp/v2 when show_in_rest is true.
  • Run repo lint/tests and any PHP/JS build steps.

Failure modes / debugging

  • 404: rest_api_init not firing, route typo, or permalinks off (use ?rest_route=).
  • 401/403: missing nonce/auth, or permission_callback too strict.
  • _doing_it_wrong for missing permission_callback: add it (use __return_true if public).
  • Invalid params: missing/incorrect args schema or validation callbacks.
  • Fields missing: show_in_rest false, meta not registered, or CPT lacks custom-fields support.

Escalation

If version support or behavior is unclear, consult the REST API Handbook and core docs before inventing patterns.

Thêm skills từ wordpress

blueprint
wordpress
Sử dụng khi tạo, chỉnh sửa hoặc xem xét các tệp JSON blueprint của WordPress Playground. Kích hoạt khi đề cập đến blueprint, cấu hình playground hoặc các yêu cầu…
official
wordpress-router
wordpress
Phân loại mã nguồn WordPress và định tuyến đến quy trình làm việc chính xác cho plugin, theme, block và core checkouts. Chạy phân loại dự án tự động để xác định loại kho lưu trữ (plugin, theme, block theme, Gutenberg blocks, WP core) và công cụ có sẵn. Xuất kết quả phân loại và sơ đồ quyết định định tuyến đến các kỹ năng theo miền cụ thể dựa trên ý định người dùng và loại dự án. Yêu cầu quyền truy cập thư mục gốc kho lưu trữ và thao tác hệ thống tệp bash/Node; một số quy trình làm việc cần WP-CLI. Nhắm mục tiêu WordPress 6.9+ với PHP 7.2.24+;...
official
wp-abilities-api
wordpress
Đăng ký API Abilities của WordPress, hiển thị qua REST và tiêu thụ phía client cho WordPress 6.9+. Đăng ký abilities và categories trong PHP bằng wp_register_ability() và wp_register_ability_category() với ID ổn định, nhãn và siêu dữ liệu. Hiển thị abilities cho client qua các endpoint REST /wp-json/wp-abilities/v1/ bằng cách đặt meta.show_in_rest: true. Tiêu thụ abilities trong JavaScript bằng gói @wordpress/abilities để truy cập phía client và kiểm tra quyền. Yêu cầu WordPress 6.9+...
official
wp-abilities-audit
wordpress
Kiểm tra bề mặt REST của plugin WordPress và tạo ra một tài liệu kiểm tra chuẩn hóa đề xuất các đăng ký Abilities API. Tạo ra một tài liệu markdown với YAML…
official
wp-abilities-verify
wordpress
Xác minh đăng ký API Abilities của plugin WordPress: liệt kê các ability, kiểm tra rằng hành vi callback khớp với tuyên bố của từng chú thích (đối nghịch…
official
wp-block-development
wordpress
Phát triển block WordPress cho Gutenberg: siêu dữ liệu, đăng ký, hiển thị và quy trình xây dựng. Bao gồm tạo block, cấu hình block.json, hiển thị tĩnh so với động, và đăng ký PHP phía máy chủ với register_block_type_from_metadata(). Áp dụng apiVersion: 3 để tương thích với WordPress 6.9+, bao gồm hỗ trợ trình soạn thảo iframe và cách ly kiểu dáng. Xử lý tuần tự hóa thuộc tính, loại bỏ/di chuyển để ngăn lỗi "Invalid block", và kết hợp block bên trong. Bao gồm...
official
wp-block-themes
wordpress
Phát triển theme block WordPress: theme.json, templates, patterns, và khắc phục sự cố Site Editor. Bao gồm chỉnh sửa theme.json (presets, settings, kiểu dáng theo từng block), templates và template parts, patterns, và các biến thể kiểu dáng trên WordPress 6.9+. Có các script phân loại để phát hiện thư mục gốc theme và cấu trúc theme block, cùng quy trình hướng dẫn tạo theme mới hoặc chuyển đổi theme cổ điển. Cung cấp quy trình gỡ lỗi cho các vấn đề về thứ bậc kiểu dáng, ghi đè tùy chỉnh của người dùng, và Site...
official
wp-interactivity-api
wordpress
Sử dụng khi xây dựng hoặc gỡ lỗi các tính năng của WordPress Interactivity API (chỉ thị data-wp-*, store/state/actions của @wordpress/interactivity, block viewScriptModule…
official