WordPress Application Password Setup
A WordPress application password is a secure, revocable credential that lets apps publish to your site through the WordPress REST API without your real login. This guide shows exactly where to create one, builds your REST API URL from your site address, and explains how tools like nativeWP use it to auto-publish.
Key takeaways
- Application passwords authenticate apps via the REST API without your real login.
- Create one under Users → Profile → Application Passwords; it shows only once.
- Your REST API base URL is your site address followed by /wp-json/wp/v2.
What is a WordPress application password?
Introduced in WordPress 5.6, an application password is a long, unique token you generate per app. It authenticates REST API requests, can be revoked any time without changing your main password, and never exposes your account login. It is the standard, safe way to connect a third-party publishing tool.
How do I create an application password?
In WordPress admin, go to Users → Profile, scroll to Application Passwords, type a name (for example, nativeWP), and click Add New Application Password. Copy the generated password immediately — WordPress shows it only once. Use the field above to build the exact REST API URL for your site.
Why use an application password instead of my login?
- Security — revoke access to one app without affecting anything else.
- No password sharing — the tool never sees your real credentials.
- REST API access — it is the supported method for programmatic publishing.
nativeWP is an AI content automation platform for WordPress that bulk-generates SEO articles with your own OpenRouter API key and auto-publishes or schedules them to WordPress and Shopify. It connects to your site with a URL and an application password in under a minute.
How to create a WordPress application password
- Open your profile. In WordPress admin, go to Users → Profile.
- Find Application Passwords. Scroll to the Application Passwords section near the bottom.
- Name the application. Enter a name such as nativeWP so you can identify it later.
- Generate and copy. Click Add New Application Password and copy the token — it is shown only once.
- Connect your tool. Paste your site URL and the application password into the tool to start publishing.
Frequently asked questions
- Are application passwords safe?
- Yes. Each one is scoped to a single app and can be revoked independently, so it is far safer than sharing your main WordPress password.
- Why can't I see the Application Passwords section?
- It requires WordPress 5.6+ and an SSL (https) site. Some hosts or security plugins disable it; enabling SSL or the feature usually restores it.
- What is my WordPress REST API URL?
- It is your site address followed by /wp-json/wp/v2. The builder above generates the exact URL from your domain.
nativeWP is an AI content automation platform for WordPress that bulk-generates SEO articles with your own OpenRouter API key and auto-publishes or schedules them to WordPress and Shopify.