Agent skill

Wp REST API

by gambitph in gambitph/Stackable

A skill your agent uses when building, extending, or debugging WordPress REST API endpoints/routes: registerrestroute, WPRESTController/controller classes, schema/argument validation…

GPL-3.0Auto-check passedBackend & APIs

Install Wp REST API

skills CLI
$ npx skills add gambitph/Stackable --skill wp-rest-api -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install gambitph/Stackable wp-rest-api --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/wp-rest-api .claude/skills/wp-rest-api && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wp-rest-api
GitHub stars
350
Used in
2 other repos
Token cost
~1.2k tokens
SKILL.md length
470 words
Files
7 (incl. references)
Skills in repo
18
Repo updated
First seen
Licence
GPL-3.0

At a glance

A skill your agent uses when building, extending, or debugging WordPress REST API endpoints/routes: registerrestroute, WPRESTController/controller classes, schema/argument validation…

  • Works in 7 steps: Triage and locate REST usage → Choose the right approach → Register routes safely (namespaces,… → …
  • Debugging WordPress REST API endpoints/routes: registerrestroute
  • SKILL.md covers When to use, Inputs required, Procedure and Verification, plus 2 more sections
  • Calls node; reaches api.w.org

What it does

Wp REST API is an agent skill from gambitph/Stackable. Use when building, extending, or debugging WordPress REST API endpoints/routes: registerrestroute, WPRESTController/controller classes, schema/argument validation, permissioncallback/authentication, response shaping, registerrestfield/registermeta, or exposing CPTs/taxonomies via showinrest.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/authentication.md`, `references/custom-content-types.md` and `references/discovery-and-params.md`). Compatibility notes: Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.

It sits in Backend & APIs, covering REST APIs and Authentication. It works with WordPress. The repository describes itself as: Page Builder Blocks for WordPress. An Amazing Block Library for the new WordPress Block Editor (Gutenberg). The licence is GPL-3.0.

When your agent uses it

  • Debugging WordPress REST API endpoints/routes: registerrestroute
  • WPRESTController/controller classes
  • Schema/argument validation
  • Permissioncallback/authentication

Example prompts

  • “/wp-rest-api”

Requirements

  • Compatibility (from SKILL.md): Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Triage and locate REST usage
  2. Choose the right approach
  3. Register routes safely (namespaces, methods, permissions)
  4. Validate/sanitize request args
  5. Responses, fields, and links
  6. Authentication and authorization
  7. Client-facing behavior (discovery, pagination, embeds)

What it can do on your machine

Read from SKILL.md and the folder at commit 5c13d80. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.w.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.

    From compatibility in the SKILL.md frontmatter.

Context cost

Wp REST API loads about 1.2k tokens when it runs, and up to ~2.6k if it reads all its reference files. Until then it costs about 79 tokens; SKILL.md has 470 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from gambitph/Stackable at commit 5c13d80, republished under its GPL-3.0 licence (© gambitph). 470 words, ~1,218 tokens.

Download SKILL.mdSave it as .claude/skills/wp-rest-api/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
wp-rest-api
description
Use when building, extending, or debugging WordPress REST API endpoints/routes: register_rest_route, WP_REST_Controller/controller classes, schema/argument validation, permission_callback/authentication, response shaping, register_rest_field/register_meta, or exposing CPTs/taxonomies via show_in_rest.
compatibility
Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.

WP REST API

When to use

Use this skill when you need to:

  • create or update REST routes/endpoints
  • debug 401/403/404 errors or permission/nonce issues
  • add custom fields/meta to REST responses
  • expose custom post types or taxonomies via REST
  • implement schema + argument validation
  • adjust response links/embedding/pagination

Inputs required

  • Repo root + target plugin/theme/mu-plugin (path to entrypoint).
  • Desired namespace + version (e.g. my-plugin/v1) and routes.
  • Authentication mode (cookie + nonce vs application passwords vs auth plugin).
  • Target WordPress version constraints (if below 7.0, call out).

Procedure

0) Triage and locate REST usage
  1. Run triage:
    • node skills/wp-project-triage/scripts/detect_wp_project.mjs
  2. Search for existing REST usage:
    • register_rest_route
    • WP_REST_Controller
    • rest_api_init
    • show_in_rest, rest_base, rest_controller_class

If this is a full site repo, pick the specific plugin/theme before changing code.

1) Choose the right approach
  • Expose CPT/taxonomy in wp/v2:
    • Use show_in_rest => true + rest_base if needed.
    • Optionally provide rest_controller_class.
    • Read references/custom-content-types.md.
  • Custom endpoints:
    • Use register_rest_route() on rest_api_init.
    • Prefer a controller class (WP_REST_Controller subclass) for anything non-trivial.
    • Read references/routes-and-endpoints.md and references/schema.md.
2) Register routes safely (namespaces, methods, permissions)
  • Use a unique namespace vendor/v1; avoid wp/* unless core.
  • Always provide permission_callback (use __return_true for public endpoints).
  • Use WP_REST_Server::READABLE/CREATABLE/EDITABLE/DELETABLE constants.
  • Return data via rest_ensure_response() or WP_REST_Response.
  • Return errors via WP_Error with an explicit status.

Read references/routes-and-endpoints.md.

3) Validate/sanitize request args
  • Define args with type, default, required, validate_callback, sanitize_callback.
  • Prefer JSON Schema validation with rest_validate_value_from_schema then rest_sanitize_value_from_schema.
  • Never read $_GET/$_POST directly inside endpoints; use WP_REST_Request.

Read references/schema.md.

  • Do not remove core fields from default endpoints; add fields instead.
  • Use register_rest_field for computed fields; register_meta with show_in_rest for meta.
  • For object/array meta, define schema in show_in_rest.schema.
  • If you need unfiltered post content (e.g., ToC plugins injecting HTML), request ?context=edit to access content.raw (auth required). Pair with _fields=content.raw to keep responses small.
  • Add related resource links via WP_REST_Response::add_link().

Read references/responses-and-fields.md.

Show full SKILL.md (174 more words)Show less
5) Authentication and authorization
  • For wp-admin/JS: cookie auth + X-WP-Nonce (action wp_rest).
  • For external clients: application passwords (basic auth) or an auth plugin.
  • Use capability checks in permission_callback (authorization), not just “logged in”.

Read references/authentication.md.

6) Client-facing behavior (discovery, pagination, embeds)
  • Ensure discovery works (Link header or <link rel="https://api.w.org/">).
  • Support _fields, _embed, _method, _envelope, pagination headers.
  • Remember per_page is capped at 100.

Read references/discovery-and-params.md.

Verification

  • /wp-json/ index includes your namespace.
  • OPTIONS on your route returns schema (when provided).
  • Endpoint returns expected data; permission failures return 401/403 as appropriate.
  • CPT/taxonomy routes appear under wp/v2 when show_in_rest is true.
  • Run repo lint/tests and any PHP/JS build steps.

Failure modes / debugging

  • 404: rest_api_init not firing, route typo, or permalinks off (use ?rest_route=).
  • 401/403: missing nonce/auth, or permission_callback too strict.
  • _doing_it_wrong for missing permission_callback: add it (use __return_true if public).
  • Invalid params: missing/incorrect args schema or validation callbacks.
  • Fields missing: show_in_rest false, meta not registered, or CPT lacks custom-fields support.

Escalation

If version support or behavior is unclear, consult the REST API Handbook and core docs before inventing patterns.

© gambitph, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in .cursor/skills/wp-rest-api of gambitph/Stackable.

  • SKILL.md
  • references/authentication.md
  • references/custom-content-types.md
  • references/discovery-and-params.md
  • references/responses-and-fields.md
  • references/routes-and-endpoints.md
  • references/schema.md

Open the folder on GitHubat commit 5c13d80

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in gambitph/Stackable, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Wp REST API next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wp REST API compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wp REST API this skillgambitph/Stackable3502 repos~1.2kAutomated safety check: PassGPL-3.0
WooCommerce Store API Routeswoocommerce/woocommerce11k—~932Automated safety check: PassCustom licence
Laravel SpecialistJeffallan/claude-skills12k1 repos~2.1kAutomated safety check: PassMIT
API Patternsdilolabs/nosia2131 repos~2.5kAutomated safety check: PassMIT
Verify Authendpointsmadeyoga/AuthEndpoints121—~2.6kAutomated safety check: PassMIT
Nodejs Express Serverever-works/ever-works158—~965Automated safety check: PassAGPL-3.0

Similar skills

  • WooCommerce Store API Routes

    woocommerce/woocommerce

    Guidelines for adding or changing routes in the WooCommerce Store API under /wc/store/v1, covering authentication, REST design, schemas and variations.

    11k GitHub stars~932 tokensUpdated today
    Backend & APIsAuto-check passed
  • Laravel Specialist

    Jeffallan/claude-skills

    Builds Laravel 10+ applications with Eloquent models, Sanctum authentication, Horizon queues, API resources and Livewire components, tested with Pest or PHPUnit.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    Backend & APIsAuto-check passed
  • API Patterns

    dilolabs/nosia

    Builds REST APIs using respondto blocks with Jbuilder templates following the 37signals same-controllers-different-formats philosophy.

    213 GitHub starsUsed in 1 repo~2.5k tokens
    Backend & APIsAuto-check passed
  • Verify Authendpoints

    madeyoga/AuthEndpoints

    Drive the AuthEndpoints HTTP API via the in-repo test host (cookie sessions, Identity bearer, Simple JWT, CSRF, ReAuth).

    121 GitHub stars~2.6k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Nodejs Express Server

    ever-works/ever-works

    Build production-ready Express.js servers with middleware, authentication, routing, and database integration.

    158 GitHub stars~965 tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • API Debugging

    ownpilot/OwnPilot

    Systematic approach to debugging REST APIs, HTTP errors, authentication issues, and network problems.

    426 GitHub stars~824 tokensUpdated 29 days ago
    Backend & APIsAuto-check passed

More from gambitph/Stackable

All 18 skills in this repo
  • Wp Block Development

    gambitph/Stackable

    A skill your agent uses when developing WordPress (Gutenberg) blocks: block.json metadata, registerblocktype(frommetadata), attributes/serialization, supports, dynamic rendering…

    350 GitHub starsUsed in 3 repos~1.6k tokens
    Auto-check passed
  • Wp Block Themes

    gambitph/Stackable

    A skill your agent uses when developing WordPress block themes: theme.json (global settings/styles), templates and template parts, patterns, style variations, and Site Editor troubleshooting (style…

    350 GitHub starsUsed in 3 repos~985 tokens
    Auto-check passed
  • Wp Performance

    gambitph/Stackable

    A skill your agent uses when investigating or improving WordPress performance (backend-only agent): profiling and measurement (WP-CLI profile/doctor, Server-Timing, Query Monitor via REST headers)…

    350 GitHub starsUsed in 3 repos~1.5k tokens
    Auto-check passed
  • Wp Plugin Development

    gambitph/Stackable

    A skill your agent uses when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security…

    350 GitHub starsUsed in 3 repos~999 tokens
    Auto-check passed
  • Wp Project Triage

    gambitph/Stackable

    A skill your agent uses when you need a deterministic inspection of a WordPress repository (plugin/theme/block theme/WP core/Gutenberg/full site) including tooling/tests/version hints, and a…

    350 GitHub starsUsed in 3 repos~371 tokens
    Auto-check passed
  • A skill your agent uses when reviewing WordPress plugins for GPL compliance, checking license headers or compatibility, evaluating upsell/freemium/trialware patterns, validating plugin naming or…

    350 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed

Works with

Categories

Questions about Wp REST API

What does Wp REST API do?

A skill your agent uses when building, extending, or debugging WordPress REST API endpoints/routes: registerrestroute, WPRESTController/controller classes, schema/argument validation…. Wp REST API is an agent skill from gambitph/Stackable. Use when building, extending, or debugging WordPress REST API endpoints/routes: registerrestroute, WPRESTController/controller classes, schema/argument validation, permissioncallback/authentication, response shaping, registerrestfield/registermeta, or exposing CPTs/taxonomies via showinrest.

When should I use Wp REST API?

Wp REST API fits situations like: debugging WordPress REST API endpoints/routes: registerrestroute; WPRESTController/controller classes; schema/argument validation; permissioncallback/authentication.

How do I install Wp REST API in Claude Code?

Run `npx skills add gambitph/Stackable --skill wp-rest-api -a claude-code`. Or copy the skill folder (.cursor/skills/wp-rest-api in gambitph/Stackable) into .claude/skills/wp-rest-api in your project. Claude Code loads it when a task matches its description.

How do I install Wp REST API in Codex?

Run `npx skills add gambitph/Stackable --skill wp-rest-api -a codex`. Or copy the skill folder (.cursor/skills/wp-rest-api in gambitph/Stackable) into .agents/skills/wp-rest-api in your project. Codex loads it when a task matches its description.

Can I use Wp REST API in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gambitph/Stackable --skill wp-rest-api -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wp-rest-api, .gemini/skills/wp-rest-api, .github/skills/wp-rest-api and .opencode/skills/wp-rest-api in your project.

What does Wp REST API need to run?

Going by SKILL.md and its folder, Wp REST API needs the command-line tools its instructions call (node). Compatibility (from SKILL.md): Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI..

Does Wp REST API access the network?

SKILL.md names 1 domain. In commands or code: api.w.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Wp REST API safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Wp REST API use?

Wp REST API is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wp REST API use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.4k tokens, read only when the agent opens those files.

What are the alternatives to Wp REST API?

Skills that share tags, products or a category with Wp REST API: WooCommerce Store API Routes (woocommerce/woocommerce, 11k stars), Laravel Specialist (Jeffallan/claude-skills, 12k stars), API Patterns (dilolabs/nosia, 213 stars) and Verify Authendpoints (madeyoga/AuthEndpoints, 121 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wp REST API?

gambitph (a GitHub organization) maintains it in gambitph/Stackable, which has 350 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 7, 2026.

Source: gambitph/Stackable on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.