A WordPress application password authorizes the service to act as its associated WordPress user. The user’s capabilities determine which native REST endpoints can be read or changed. An administrator account gives broad rights, so choose the smallest suitable role for the workflow.
Website login, workspace owner authorization and WordPress site access are separate identities. The product does not need your main WordPress login password. Credentials should be supplied through the operator’s secure onboarding channel, never a general support form.
Workspaces use independent OAuth resources and authorization state. A token from one workspace cannot authorize another workspace. The site list returned to ChatGPT contains site IDs and URLs, not application passwords.
OAuth uses PKCE, browser-bound consent and rotating refresh tokens. Consent and authorization codes are saved before the server responds. The browser redirect policy includes only the configured callback origins, allowing the return to the registered client without permitting arbitrary callbacks.
Read-only is the default in the WordPress companion and workspace. Writing is a separate opt-in. Even when writes are enabled, the underlying WordPress REST permission callback still decides whether the user can perform the requested action.
Changes are real. Publishing and deleting content deserve explicit instructions, careful review and backups. Permission-aware integration is useful protection, but it does not make every instruction or every installed plugin safe.
OAuth and commerce state are encrypted with authenticated encryption and stored outside the public web root. Account passwords are stored as salted scrypt hashes. Session cookies are Secure, HttpOnly and SameSite=Lax. State files must live on persistent storage with restricted operator access.
Stripe-hosted Checkout handles payment details. Entitlements come from verified paid webhook events; the application does not unlock access merely because a browser opens a success URL. Daily allowance consumption is serialized to prevent concurrent calls from exceeding the limit.
The file-backed release supports processes that share the same persistent filesystem. Separate hosts need a shared transactional store before horizontal scaling. Customer site onboarding remains operator-assisted; arbitrary public URL onboarding is not exposed.
Before launch, the operator must validate staging behavior, backups, tax handling, privacy terms and the Stripe webhook setup. To remove access, revoke the WordPress application password and disconnect the connector. Contact support if you need operator-side suspension.