WordPress ChatGPT Connection Troubleshooting
Start with the endpoint and exact error. Quota exhaustion, OAuth validation and a WordPress permission denial require different fixes.
Invalid OAuth authorization request
This means the authorization request failed validation before approval. Check the registered callback, resource URL, requested scopes, client registration and S256 PKCE. Start authorization from the intended personal app rather than opening an authorization endpoint by itself. Keep the WordPress direct app and the older hosted WPBridge app separate.
Authorization expired or already used
Authorization links and codes are short-lived and single-use. Reopening a consumed link does not renew it. Initiate a fresh request from the same app; check persistent server storage if fresh requests fail immediately after a server restart. Do not disable expiry or callback validation.
Daily allowance reached
A quota message is not an authentication failure. Read site_status or your hosted account usage to identify the plan and reset. The free allowance is 20 daily calls; the public free allowance is 20 calls per authorized user per site. One conversation may invoke several tools.
Connected, but an operation is denied
Confirm read_only and the authenticated user ID. Studio retains native endpoint permission checks. A 403 from a target endpoint means that operation is denied; a 404 may indicate a missing REST route. Studio now reports the target error status rather than wrapping it as a successful tool operation.
WordPress connection errors: diagnosis by symptom
| Symptom | Likely layer | First action |
|---|---|---|
| Sign-in page loops or callback mismatch | OAuth client configuration | Confirm the exact callback URI, MCP resource and intended Studio connection; restart authorization once. |
401 Unauthorized | Authentication | Check whether the correct account is authorized and whether the WordPress Application Password is active in hosted mode. |
403 Forbidden | Permissions or access mode | Read the authenticated user ID, WordPress role, route permissions and read-only configuration. |
404 Not Found for an API operation | REST route availability | Discover installed routes and compare the namespace, method and endpoint spelling. |
429 Too Many Requests or allowance error | Rate control or plan usage | Check account usage and the source of the limit; do not assume it is an OAuth failure. |
| Timeout, 502 or 503 | Server, firewall or upstream network | Check endpoint reachability and hosting/WAF logs; retry a safe read after service recovers. |
HTTP status codes are clues rather than complete diagnoses. Record the exact error body and the request time before changing configuration.
A safe step-by-step troubleshooting sequence
- Confirm whether you use direct WordPress or hosted Studio. Their endpoints and account requirements differ.
- For hosted mode, sign in to the same Studio account that owns the connected site and verify its site credentials in the dashboard.
- Restart the authorization flow from your AI client’s connector settings if the previous link expired; do not reuse an already-consumed code.
- Call
list_sitesandsite_statusto check the target URL and site ID. - Read
/wp/v2/users/me. A failure here suggests authentication or routing issues before any content edit is attempted. - Use
discover_routesto check whether the requested plugin endpoint exists, then attempt a read-only operation. - Only after read checks pass, enable writing deliberately and test with a disposable draft in staging.
Frequently asked questions about connection failures
Why does ChatGPT say a connection is available but cannot edit WordPress?
Client authorization, workspace write access, companion-plugin read-only mode and WordPress capabilities are separate controls. A successful OAuth grant does not make a WordPress editor an administrator or activate disabled write tools.
Why does an installed plugin not appear as an editable tool?
Some plugins expose only WordPress dashboard forms. WPBridge Studio discovers registered REST routes; it cannot invent a route for a feature that lacks one. Check the relevant namespace and documented endpoint.
How should I report a problem without sharing secrets?
Send the time of the attempt, site URL or site ID, client name, expected action, HTTP code and a redacted error response. Never include WordPress passwords, application passwords, access tokens, refresh tokens or card details.
Does resetting authorization fix every error?
No. Reauthorization may solve expired consent or mismatched account problems, but not a missing REST route, a WordPress permission denial or an exhausted account allowance.
Next steps
Read the compatibility checklist before changing roles, and use the support page for a redacted diagnostic report. For general WordPress behavior, see the official WordPress REST authentication guide.
Further WordPress API troubleshooting
If the connected site is correct but requests fail, use the 401 versus 403 authentication guide to distinguish credentials from permissions. When the profile does not show the feature, follow the missing Application Password checklist. Confirm identity with a read-only request before changing settings.