WPBridge Studio WordPress Security and Permissions
Use dedicated identities
A WordPress application password authorizes the service to act as its associated WordPress user. The user’s capabilities determine which native REST endpoints can be read or changed. An administrator account gives broad rights, so choose the smallest suitable role for the workflow.
Hosted Studio account sign-in, AI-client OAuth authorization and WordPress site access are separate security boundaries. The product does not need your main WordPress login password. Hosted site credentials belong only in the authenticated Studio dashboard’s connection flow, never in a general support form or chat message.
Separate customer workspaces
Workspaces use independent OAuth resources and authorization state. A token from one workspace cannot authorize another workspace. The site list returned to ChatGPT contains site IDs and URLs, not application passwords.
OAuth uses PKCE, browser-bound consent and rotating refresh tokens. Consent and authorization codes are saved before the server responds. The browser redirect policy includes only the configured callback origins, allowing the return to the registered client without permitting arbitrary callbacks.
Read-only controls and native checks
Read-only is the default in the WordPress companion and workspace. Writing is a separate opt-in. Even when writes are enabled, the underlying WordPress REST permission callback still decides whether the user can perform the requested action.
Changes are real. Publishing and deleting content deserve explicit instructions, careful review and backups. Permission-aware integration is useful protection, but it does not make every instruction or every installed plugin safe.
Storage and payment boundaries
OAuth and commerce state are encrypted with authenticated encryption and stored outside the public web root. Account passwords are stored as salted scrypt hashes. Session cookies are Secure, HttpOnly and SameSite=Lax. State files must live on persistent storage with restricted operator access.
Stripe-hosted Checkout handles payment details. Entitlements come from verified paid webhook events; the application does not unlock access merely because a browser opens a success URL. Daily allowance consumption is serialized to prevent concurrent calls from exceeding the limit.
Know the operational limits
The file-backed release supports processes that share the same persistent filesystem. Separate hosts need a shared transactional store before horizontal scaling. Customer site connections are handled through the authenticated Studio dashboard and must pass verification. Do not treat a submitted URL alone as proof that the customer owns or can administer a site.
Production operators must maintain staging tests, backups, applicable tax and privacy compliance, and verified Stripe webhook processing. To remove access, revoke the WordPress application password and disconnect the connector. Contact support if you need operator-side suspension.
Security controls by layer
Short answer: A secure WordPress AI workflow needs more than a successful connection. Client authorization, WordPress identity, REST permissions and a deliberate decision to enable writes should each be checked independently.
| Layer | What it controls | Safe check |
|---|---|---|
| AI client consent | Which connector receives access | Approve only the intended client and redirect destination |
| Studio customer account | Which verified hosted sites belong to the workspace | Confirm the returned site IDs and URLs |
| WordPress identity | The native capabilities available to REST operations | Read /wp/v2/users/me and check the expected role |
| Read-only controls | Whether content mutations are permitted | Keep writes disabled during first verification |
| Endpoint authorization | Whether a particular WordPress REST operation is allowed | Inspect the target route and respect permission denials |
Credential management and access revocation
- Use a dedicated WordPress user for the connector where practical. Avoid broad administrator access for routine content reviews.
- For hosted mode, create a distinct WordPress Application Password for the selected account and enter it only through the authenticated dashboard.
- Keep OAuth tokens, WordPress credentials and customer billing information out of support tickets and general AI chat messages.
- If a connection is no longer required, revoke its WordPress Application Password and disconnect the AI client’s grant. These are separate revocation actions.
- For impactful edits, maintain backups or revisions and run the first changes against staging content.
Read the Application Password guide for credential rotation and the diagnostic guide for 401, 403 and OAuth errors.
How to verify security boundaries before granting write access
Start with authenticated site identity and a known read, then inspect the exact WordPress user and REST route permissions. Our published connector test provides example result types and separates confirmed REST operations from client features not tested. The demo does not replace a penetration test or a permissions review of your own WordPress installation.
Remote MCP security: current authorization requirements
The July 2026 MCP authorization specification documents protected-resource metadata, authorization-server discovery, token audience validation and OAuth security requirements for supported HTTP-based transports. These safeguards are separate from the WordPress user’s permission to read or edit a given REST endpoint.
Evaluation checklist: verify HTTPS and the exact authorized site, inspect the client-specific OAuth grant, do not log tokens or WordPress passwords, test permission denials with read-only mode, and confirm revocation works. A successful WordPress REST identity request does not independently certify compliance with the entire latest MCP specification. Use the MCP tools reference to identify the operations you can actually test.
WordPress connector security FAQs
Does an OAuth connection make the AI an administrator?
No. The authenticated WordPress user and each endpoint’s permission checks remain authoritative.
Can a read-only connection publish posts?
Not through the connector’s disabled write operations. When writing is enabled, the WordPress user must still have the needed capabilities.
Is Stripe authorization the same as WordPress authorization?
No. Stripe payment verification activates the purchased Studio entitlement; WordPress permissions govern actual site operations. Learn about billing controls.
Practical production security controls
The WordPress MCP security checklist covers 12 controls for production deployment, including authentication, scoped permissions, backup planning and verifiable reads and writes. For authentication failures, see the REST API status-code guide.