wp-abilities-api
wordpress/agent-skills
Register and expose WordPress abilities via PHP and REST API for agent and client consumption.
What is wp-abilities-api?
The WordPress Abilities API skill enables you to define, register, and expose capabilities as abilities in WordPress 7.0+. Use it when building ability registrations in PHP, exposing them via REST endpoints, or consuming them in JavaScript clients—particularly for agent-driven workflows and permission checks.
- Register abilities and ability categories using wp_register_ability and wp_register_ability_category hooks
- Expose abilities to clients via REST endpoints under wp-abilities/v1 namespace
- Consume abilities in JavaScript using @wordpress/abilities package
- Configure ability metadata including readonly flags and REST visibility
- Implement permission checks and execute callbacks for ability validation
- Diagnose and debug ability visibility and REST exposure issues
How to install wp-abilities-api
npx skills add https://github.com/wordpress/agent-skills --skill wp-abilities-api- WordPress 7.0+ (PHP 7.4.0+)
- Filesystem access and bash/node environment
- WP-CLI for some diagnostic workflows
- Understanding of WordPress hooks and REST API basics
How to use wp-abilities-api
- 1.Run wp-project-triage to confirm repo root and WordPress version
- 2.Search the codebase for existing wp_register_ability, wp_register_ability_category, or @wordpress/abilities usage
- 3.Read references/domain-vs-projection.md to understand ability registration vs. client exposure
- 4.Register ability categories if needed using wp_abilities_api_categories_init hook
- 5.Register abilities in PHP with stable ID, label, description, category, and appropriate meta flags (readonly, show_in_rest)
- 6.Verify REST endpoints under wp-abilities/v1 return your abilities with correct metadata
- 7.Consume abilities in JavaScript using @wordpress/abilities package and confirm build tooling bundles the dependency
- 8.Add tests for PHP registration and JS consumption near ability definitions
Use cases
- Define a new ability for a custom post type and expose it to a JavaScript client via REST
- Register ability categories to logically group related capabilities in a plugin
- Consume registered abilities in a command-palette or MCP interface to gate operations
- Debug why an ability isn't appearing in REST responses or client-side checks
- Implement shared service patterns where abilities, REST handlers, and CLI commands delegate to common logic
- WordPress plugin developers building agent-driven workflows
- Theme developers integrating capability-based access control
- Full-stack developers exposing WordPress capabilities to JavaScript clients
- WordPress core contributors working on capability systems
wp-abilities-api FAQ
Abilities are a projection layer for capabilities designed for agent and client consumption. Use Abilities API when you need to expose capabilities via REST, gate UI/MCP operations, or provide structured metadata to clients. Traditional capabilities remain the domain layer.
Check that meta.show_in_rest is set to true, the registration code is running on the correct hook (wp_abilities_api_init or wp_abilities_api_categories_init), and the file is being loaded. Verify the endpoint wp-abilities/v1 is accessible and returns expected results.
Read references/grouping-heuristic.md before deciding. Avoid registering one atomic ability per operation; instead, group logically related operations under fewer, well-named abilities to reduce registration drift and maintenance burden.
Follow the shared-core-service pattern: abilities, REST handlers, CLI commands, and UI controllers should be thin adapters over a shared service. This keeps registrations in sync when code paths change and prevents metric/telemetry traps.
WordPress 7.0+ includes the Abilities API in core. For earlier versions, use the Abilities API plugin or package. Always confirm your target version and whether you're working in WP core or a plugin/theme.
Full instructions (SKILL.md)
Source of truth, from wordpress/agent-skills.
name: wp-abilities-api description: "Use when working with the WordPress Abilities API (wp_register_ability, wp_register_ability_category, /wp-json/wp-abilities/v1/*, @wordpress/abilities) including defining abilities, categories, meta, REST exposure, and permissions checks for clients." compatibility: "Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI."
WP Abilities API
When to use
Use this skill when the task involves:
- registering abilities or ability categories in PHP,
- exposing abilities to clients via REST (
wp-abilities/v1), - consuming abilities in JS (notably
@wordpress/abilities), - diagnosing “ability doesn’t show up” / “client can’t see ability” / “REST returns empty”.
Inputs required
- Repo root (run
wp-project-triagefirst if you haven’t). - Target WordPress version(s) and whether this is WP core or a plugin/theme.
- Where the change should live (plugin vs theme vs mu-plugin).
Procedure
Before deciding what to register, read references/domain-vs-projection.md — abilities live at the domain capability layer; MCP / Command Palette / REST exposure is a projection. Registration shape and exposure shape are different decisions, and conflating them forces re-registration every time a consumer's constraints change.
1) Confirm availability and version constraints
- If this is WP core work, check
signals.isWpCoreCheckoutandversions.wordpress.core. - If the project targets WP < 6.9, you may need the Abilities API plugin/package rather than relying on core.
2) Find existing Abilities usage
Search for these in the repo:
wp_register_ability(wp_register_ability_category(wp_abilities_api_initwp_abilities_api_categories_initwp-abilities/v1@wordpress/abilities
If none exist, decide whether you’re introducing Abilities API fresh (new registrations + client consumption) or only consuming.
3) Register categories (optional)
If you need a logical grouping, register an ability category early (see references/php-registration.md).
4) Register abilities (PHP)
For grouping decisions (how many abilities to register, and where to put filters vs. new ability names), read references/grouping-heuristic.md first — it keeps you from shipping one atomic ability per REST operation.
To avoid drift between the ability and the existing UI / REST code path, see references/shared-core-service.md — abilities, REST handlers, CLI commands, and UI controllers should be thin adapters over a shared service. The reference also covers the metric trap (REST handlers that emit usage telemetry) and the AGENTS.md rule for keeping registrations in sync when underlying code paths change.
For shared helper patterns when multiple execute callbacks delegate to existing REST controllers, see references/plugin-family-patterns.md (identify the shared-API-client vs zero-arg-controllers shape) and references/delegate-helper-pattern.md (one helper shape that works, and when not to use it).
For standardized WP_Error codes that let agents reason about retry vs. escalation, see references/error-code-vocabulary.md.
Implement the ability in PHP registration with:
- stable
id(namespaced), label/description,category,meta:- add
readonly: truewhen the ability is informational, - set
show_in_rest: truefor abilities you want visible to clients.
- add
Use the documented init hooks for Abilities API registration so they load at the right time (see references/php-registration.md).
5) Confirm REST exposure
- Verify the REST endpoints exist and return expected results (see
references/rest-api.md). - If the client still can’t see the ability, confirm
meta.show_in_restis enabled and you’re querying the right endpoint.
6) Consume from JS (if needed)
- Prefer
@wordpress/abilitiesAPIs for client-side access and checks. - Ensure build tooling includes the dependency and the project’s build pipeline bundles it.
Verification
wp-project-triageindicatessignals.usesAbilitiesApi: trueafter your change (if applicable).- REST check (in a WP environment): endpoints under
wp-abilities/v1return your ability and category when expected. - If the repo has tests, add/update coverage near:
- PHP: ability registration and meta exposure
- JS: ability consumption and UI gating
Failure modes / debugging
- Ability never appears:
- registration code not running (wrong hook / file not loaded),
- missing
meta.show_in_rest, - incorrect category/ID mismatch.
- REST shows ability but JS doesn’t:
- wrong REST base/namespace,
- JS dependency not bundled,
- caching (object/page caches) masking changes.
- Execute callback returns unexpected errors or silently ignores input:
input_schemadefaults aren't being applied, pagination key drift between the ability and the backing, orempty()-based ID validation — seereferences/input-schema-gotchas.md.
Escalation
- If you’re uncertain about version support, confirm target WP core versions and whether Abilities API is expected from core or as a plugin.
- For canonical details, consult:
references/rest-api.mdreferences/php-registration.md
Related skills
More from wordpress/agent-skills and the wider catalog.

wp-abilities-audit
Audit WordPress plugin REST surfaces and propose Abilities API registrations in standardized markdown documents.

wp-abilities-verify
Verify WordPress plugin Abilities API registrations for correctness, permissions, and schema compliance.

wp-block-development
Develop WordPress Gutenberg blocks with block.json, registration, rendering, and deprecation workflows.

wp-block-themes
Develop WordPress block themes: theme.json, templates, patterns, and Site Editor debugging.

wp-interactivity-api
Build and debug WordPress Interactivity API features with data-wp-* directives, store management, and hydration.

wp-patterns
Create and manage WordPress block patterns for starter pages, templates, and layouts with design tokens and accessibility.