WordPress Application Password Setup

A WordPress application password is a secure, revocable credential that lets apps publish to your site through the WordPress REST API without your real login. This guide shows exactly where to create one, builds your REST API URL from your site address, and explains how tools like nativeWP use it to auto-publish.

Key takeaways

What is a WordPress application password?

Introduced in WordPress 5.6, an application password is a long, unique token you generate per app. It authenticates REST API requests, can be revoked any time without changing your main password, and never exposes your account login. It is the standard, safe way to connect a third-party publishing tool.

How do I create an application password?

In WordPress admin, go to Users → Profile, scroll to Application Passwords, type a name (for example, nativeWP), and click Add New Application Password. Copy the generated password immediately — WordPress shows it only once. Use the field above to build the exact REST API URL for your site.

Why use an application password instead of my login?

nativeWP is an AI content automation platform for WordPress that bulk-generates SEO articles with your own OpenRouter API key and auto-publishes or schedules them to WordPress and Shopify. It connects to your site with a URL and an application password in under a minute.

How to create a WordPress application password

  1. Open your profile. In WordPress admin, go to Users → Profile.
  2. Find Application Passwords. Scroll to the Application Passwords section near the bottom.
  3. Name the application. Enter a name such as nativeWP so you can identify it later.
  4. Generate and copy. Click Add New Application Password and copy the token — it is shown only once.
  5. Connect your tool. Paste your site URL and the application password into the tool to start publishing.

Frequently asked questions

Are application passwords safe?
Yes. Each one is scoped to a single app and can be revoked independently, so it is far safer than sharing your main WordPress password.
Why can't I see the Application Passwords section?
It requires WordPress 5.6+ and an SSL (https) site. Some hosts or security plugins disable it; enabling SSL or the feature usually restores it.
What is my WordPress REST API URL?
It is your site address followed by /wp-json/wp/v2. The builder above generates the exact URL from your domain.

nativeWP is an AI content automation platform for WordPress that bulk-generates SEO articles with your own OpenRouter API key and auto-publishes or schedules them to WordPress and Shopify.