wp-abilities-api
wordpress/agent-skills
Register and expose WordPress abilities via PHP and REST API for client-side permission checks.
What is wp-abilities-api?
The WordPress Abilities API lets you define granular permissions (abilities) and expose them to JavaScript clients via REST endpoints. Use this skill when registering abilities in PHP, configuring REST exposure, or consuming abilities in client code with @wordpress/abilities.
- Register abilities and ability categories in PHP with stable IDs, labels, descriptions, and metadata
- Expose abilities to clients via REST endpoints under /wp-json/wp-abilities/v1/
- Control visibility and metadata (readonly, show_in_rest) for each ability
- Consume abilities in JavaScript using @wordpress/abilities library
- Diagnose and debug missing or inaccessible abilities in REST or client code
How to install wp-abilities-api
npx skills add https://github.com/wordpress/agent-skills --skill wp-abilities-api- WordPress 6.9+ (PHP 7.2.24+)
- Filesystem access and bash/node environment
- WP-CLI for some diagnostic workflows
- @wordpress/abilities package for JavaScript consumption
How to use wp-abilities-api
- 1.Confirm your WordPress version is 6.9+ and identify whether Abilities API is in core or a plugin
- 2.Search the repo for existing wp_register_ability, wp_register_ability_category, or @wordpress/abilities usage
- 3.Register ability categories early if you need logical grouping using the documented init hooks
- 4.Register abilities in PHP with stable namespaced IDs, labels, descriptions, and set meta.show_in_rest: true for client visibility
- 5.Verify REST endpoints under /wp-json/wp-abilities/v1/ return your abilities and categories
- 6.Consume abilities in JavaScript using @wordpress/abilities APIs and ensure the dependency is bundled in your build
Use cases
- Define custom permissions for a plugin and expose them to a React admin interface
- Create ability categories to organize related permissions logically
- Check client-side permissions before rendering UI elements using @wordpress/abilities
- Verify REST endpoints return expected abilities after registration
- Troubleshoot abilities not appearing in REST responses or JavaScript consumers
- WordPress plugin developers
- Theme developers using Abilities API for permission gating
- Full-stack developers building admin interfaces with REST-backed permissions
- WordPress core contributors working on capability systems
wp-abilities-api FAQ
WordPress 6.9+ includes the Abilities API in core. For earlier versions, you may need to use the Abilities API plugin or package as a dependency.
Verify that meta.show_in_rest is set to true in your ability registration, the registration code is running on the correct init hook, and the ability ID is not conflicting with existing registrations.
Register ability categories using wp_register_ability_category() early in your initialization, then assign abilities to those categories via the category parameter.
Yes, you can register abilities in plugins, themes, or mu-plugins. Ensure the registration code runs on the appropriate WordPress init hooks.
Use the @wordpress/abilities library in your JavaScript code. Ensure it's included as a dependency in your build tooling and that your build pipeline bundles it correctly.
Full instructions (SKILL.md)
Source of truth, from wordpress/agent-skills.
name: wp-abilities-api description: "Use when working with the WordPress Abilities API (wp_register_ability, wp_register_ability_category, /wp-json/wp-abilities/v1/*, @wordpress/abilities) including defining abilities, categories, meta, REST exposure, and permissions checks for clients." compatibility: "Targets WordPress 6.9+ (PHP 7.2.24+). Filesystem-based agent with bash + node. Some workflows require WP-CLI."
WP Abilities API
When to use
Use this skill when the task involves:
- registering abilities or ability categories in PHP,
- exposing abilities to clients via REST (
wp-abilities/v1), - consuming abilities in JS (notably
@wordpress/abilities), - diagnosing “ability doesn’t show up” / “client can’t see ability” / “REST returns empty”.
Inputs required
- Repo root (run
wp-project-triagefirst if you haven’t). - Target WordPress version(s) and whether this is WP core or a plugin/theme.
- Where the change should live (plugin vs theme vs mu-plugin).
Procedure
1) Confirm availability and version constraints
- If this is WP core work, check
signals.isWpCoreCheckoutandversions.wordpress.core. - If the project targets WP < 6.9, you may need the Abilities API plugin/package rather than relying on core.
2) Find existing Abilities usage
Search for these in the repo:
wp_register_ability(wp_register_ability_category(wp_abilities_api_initwp_abilities_api_categories_initwp-abilities/v1@wordpress/abilities
If none exist, decide whether you’re introducing Abilities API fresh (new registrations + client consumption) or only consuming.
3) Register categories (optional)
If you need a logical grouping, register an ability category early (see references/php-registration.md).
4) Register abilities (PHP)
Implement the ability in PHP registration with:
- stable
id(namespaced), label/description,category,meta:- add
readonly: truewhen the ability is informational, - set
show_in_rest: truefor abilities you want visible to clients.
- add
Use the documented init hooks for Abilities API registration so they load at the right time (see references/php-registration.md).
5) Confirm REST exposure
- Verify the REST endpoints exist and return expected results (see
references/rest-api.md). - If the client still can’t see the ability, confirm
meta.show_in_restis enabled and you’re querying the right endpoint.
6) Consume from JS (if needed)
- Prefer
@wordpress/abilitiesAPIs for client-side access and checks. - Ensure build tooling includes the dependency and the project’s build pipeline bundles it.
Verification
wp-project-triageindicatessignals.usesAbilitiesApi: trueafter your change (if applicable).- REST check (in a WP environment): endpoints under
wp-abilities/v1return your ability and category when expected. - If the repo has tests, add/update coverage near:
- PHP: ability registration and meta exposure
- JS: ability consumption and UI gating
Failure modes / debugging
- Ability never appears:
- registration code not running (wrong hook / file not loaded),
- missing
meta.show_in_rest, - incorrect category/ID mismatch.
- REST shows ability but JS doesn’t:
- wrong REST base/namespace,
- JS dependency not bundled,
- caching (object/page caches) masking changes.
Escalation
- If you’re uncertain about version support, confirm target WP core versions and whether Abilities API is expected from core or as a plugin.
- For canonical details, consult:
references/rest-api.mdreferences/php-registration.md
Related skills
More from wordpress/agent-skills and the wider catalog.

wp-block-development
Develop WordPress Gutenberg blocks with block.json, registration, rendering, and deprecation workflows.

wp-block-themes
Develop WordPress block themes with theme.json, templates, patterns, and Site Editor debugging.

wp-interactivity-api
Build and debug WordPress Interactivity API features with directives, store state, and hydration.

wp-performance
Diagnose and optimize WordPress performance using WP-CLI profiling, Query Monitor, and targeted fixes.

wp-phpstan
Configure and fix PHPStan static analysis in WordPress projects with proper typing and baseline management.

wp-playground
Spin up fast, disposable WordPress instances locally or in-browser for testing, debugging, and CI workflows.