WPBridge Studio

WPBridge Studio

How to Connect WordPress to ChatGPT Safely

By WPBridge Studio · Product documentation

Separate the three credentials

A reliable setup starts by separating your website login, the workspace owner password and the WordPress application password. Your website login manages the purchase and usage dashboard. Hosted Studio OAuth uses your signed-in Studio website account. The application password lets the service use the dedicated WordPress user.

Mixing them makes troubleshooting harder. If the owner form says the password is wrong, changing a WordPress application password does not repair that owner login. If WordPress rejects a site request, a successful owner login does not prove that the site credentials or user permissions are correct.

Start with a dedicated WordPress user

Choose a role that matches the intended task. A draft-review workflow needs different rights from site settings administration. Create an application password in the dedicated user’s profile, retain it through the operator’s secure onboarding process and keep the main login password separate.

Install the companion on staging and leave read-only enabled. Confirm the exact site URL and user identity before connecting additional sites with similar names.

Complete OAuth once

Use the workspace MCP URL supplied by the operator. Follow the current custom connector flow in your ChatGPT account and select OAuth. The server validates the callback, resource, requested scopes and PKCE challenge before presenting its consent form.

Submit the form once and allow the browser to return to ChatGPT. A request becomes consumed after approval. Submitting the same old form again can produce an expired-or-used message even when the first password submission was accepted. Start from the existing connector to create a fresh request when needed.

Verify actual read-only results

Ask for list_sites, site_status and wordpress_read /wp/v2/users/me. Check the HTTP result and WordPress identity. This establishes more than a generic claim that the plugin is installed: it demonstrates that the authenticated request can reach the intended endpoint as the intended user.

For a denied request, inspect the native endpoint permission requirements before increasing privileges. For a missing route, discover the installed REST routes instead of assuming a plugin implements an API.

Enable changes gradually

Enable writing in both the workspace and the companion only after read verification succeeds. Test one disposable draft on staging, read it back and inspect the result. Be precise about the post, requested fields and status; “improve my site” is not a useful scope for an irreversible deletion.

Keep the setup documentation and security explanation available to the team members responsible for the sites.