WPBridge Studio
WPBridge Studio

WordPress Application Passwords for AI Connections

By WPBridge Studio · Product documentation

Create, store and revoke dedicated WordPress Application Passwords for Studio without sharing your main WordPress login.

Which password should you use?

Use a generated Application Password for WordPress API authentication. Your Studio account password signs you into the website; the main WordPress password signs you into wp-admin. Enter the generated Application Password only into Studio’s authenticated connection form.

Why is the password only shown once?

WordPress displays a generated Application Password once. Its later list shows metadata rather than the original password. If it was not saved, create a replacement and update the Studio connection. Revoke obsolete entries after confirming the replacement works.

How can you remove access?

Disconnect the site in Studio and revoke the specific Application Password in WordPress. Disconnecting an AI app removes that client’s grant; revoking WordPress credentials removes access to the site independently. Never put these passwords in a support ticket or an AI conversation.

Set up your connection

Explore WPBridge Studio, follow the installation guide, then compare packages. Start free and confirm site identity before making changes.

How to create a WordPress Application Password for an AI connector

Answer: In WordPress, sign in as the user who should authorize the API, open that user’s profile, find Application Passwords, name the integration and generate the new credential. For hosted WPBridge Studio, enter that generated password only in the authenticated site connection form, not in ChatGPT messages or support tickets.

  1. Choose a dedicated WordPress account with permissions appropriate to the task; an Editor may be sufficient for editorial workflows.
  2. Open WordPress administration → Users → Profile (or edit the selected user if you have permission).
  3. Find the Application Passwords section. Give the credential a recognizable name, such as “WPBridge Studio hosted connection.”
  4. Generate and securely copy the credential immediately. WordPress does not display the original plaintext again after creation.
  5. In the hosted Studio dashboard, supply the site’s HTTPS address, matching WordPress username and newly generated Application Password.
  6. Verify the connection and request /wp/v2/users/me through Studio to confirm the intended WordPress user ID.

Do not use this process as an instruction to send the credential through an ordinary chatbot conversation. For direct WordPress mode, follow the on-site OAuth instructions instead.

Security: what Application Passwords do and do not do

PropertyPractical meaning
Separate credentialThe integration does not need the user’s primary wp-admin password.
User-bound capabilitiesThe credential acts as the associated WordPress user; it does not grant permissions above that role.
Individually revocableYou can revoke the connector’s credential without resetting the main login.
REST use over HTTPSUse TLS to protect the credential in transit; never place it in a public URL or support message.
One-time displayIf the credential is lost, generate a replacement rather than expecting WordPress to reveal it again.

An Application Password is not an OAuth token and does not replace a separate AI-client consent flow. For the underlying WordPress behavior, consult the official administration guide.

Troubleshoot Application Password authentication

Why is the Application Passwords section missing?

Check HTTPS and site configuration, the user’s permissions, and whether a security plugin or hosting policy has disabled the feature. Do not weaken site security merely to make an API connection work.

Why does the correct-looking password return 401?

Verify the username, confirm that the credential belongs to that user, check HTTPS and the Authorization header, and confirm the credential has not been revoked. A proxy or firewall can interfere before WordPress sees the request.

Can I revoke access without deleting the user?

Yes. Revoke that named Application Password in the WordPress user profile, then disconnect any related hosted site or client grant as appropriate.

Should I use the same credential across multiple integrations?

Prefer separate, named credentials where possible. That makes review and selective revocation easier.

For next steps, review the hosted installation guide and connection error explanations.