people sitting down near table with assorted laptop computers

The WordPress Abilities API: Letting AI Agents Call Your Site

This blog runs on WordPress, which makes the new WordPress Abilities API, shipped in version 6.9, worth understanding for exactly the same reason WP Probe was worth covering last week: it’s aimed directly at the platform this site is built on, and it’s explicitly framed by WordPress core as the groundwork for letting AI agents interact with a site properly, rather than through workarounds.

What actually shipped in WordPress 6.9

WordPress 6.9 focused on three areas: editor collaboration (block-level notes for team feedback), more capable core blocks (Accordion, Math, visibility controls), and – the part that matters here – developer features preparing WordPress for AI and more complex applications, headlined by a new Abilities API alongside updates to the existing Interactivity API and Block Bindings API.

What the Abilities API actually is

A REST API endpoint answers a request shape you defined in advance. An “ability” is different: it’s a discrete, named, self-describing capability that a site registers – with its own input schema, output schema, and permission check – specifically so that an automated caller (an AI agent, an MCP-connected tool, another plugin) can discover what a site can do and invoke it directly, without a human first reading API documentation and writing bespoke integration code.

add_action( 'abilities_api_init', function() {
	wp_register_ability( 'my-plugin/get-recent-comments', array(
		'label'       => 'Get recent comments',
		'description' => 'Returns the N most recent approved comments.',
		'input_schema'  => array(
			'type'       => 'object',
			'properties' => array( 'limit' => array( 'type' => 'integer', 'default' => 5 ) ),
		),
		'execute_callback'    => 'my_plugin_get_recent_comments',
		'permission_callback' => function() { return current_user_can( 'moderate_comments' ); },
	) );
} );

Why this is different from just adding a REST route

  • A custom REST route is discoverable only if you already know its URL and read the documentation for it
  • An ability is registered into a central, queryable registry – a caller can ask “what abilities does this site expose” and get back names, descriptions and schemas for all of them
  • That discoverability is the entire point: it’s what lets an AI agent (or any MCP-style tool) work out what it’s allowed to do on a site it hasn’t been specifically coded against in advance

Where this plugs into the wider agent-tooling picture

This is the same underlying idea covered elsewhere on this blog for Claude specifically – a defined, discoverable, permission-checked set of actions an agent can call – just implemented as a WordPress-native primitive rather than a bespoke MCP server. A WordPress site with abilities registered is, in effect, exposing a structured menu of safe actions that an MCP bridge (or any other agent-facing layer) can sit in front of, instead of an agent having to guess at REST endpoints or scrape the admin UI.

Getting started on an existing site

  1. Update to WordPress 6.9 or later – the Abilities API isn’t available on earlier versions
  2. Identify one genuinely useful, low-risk capability worth exposing first – reading published post metadata is a safer starting point than anything that writes or deletes content
  3. Register it with a tight permission_callback from the start, the same way you’d scope any other API credential – abilities inherit WordPress’s existing capability system, so this is a normal current_user_can() check, not new security machinery to learn
  4. Only widen scope to write actions once the read-only ability has been tested against whatever agent or tool is actually going to call it

Early days, worth watching

The Abilities API is new enough in WordPress 6.9 that most plugins haven’t adopted it yet – the practical value today is mostly for site owners and plugin developers willing to register their own abilities ahead of the ecosystem catching up. Given how directly it overlaps with the site’s own AI/agent-tooling coverage, it’s a reasonable one to keep an eye on as more plugins start shipping abilities out of the box.


Leave a Reply