getting started

Connect WordPress

Username + Application Password. Native auth, no plugins.

Quibo connects to WordPress using Application Passwords, a native feature in WordPress 5.6+. No plugin, no OAuth dance, no custom endpoint. You generate a one-purpose password from your admin profile and paste it into Quibo.

What you'll need

  • A WordPress user with the Administrator or Editor role on the site.
  • Your WordPress username (the login name, not the display name).
  • An Application Password generated for Quibo.
  • The site served over HTTPS and reachable from the public internet.

Generate the Application Password

  1. Sign into your WordPress admin.
  2. Go to Users, then Profile (or Edit Profile from the top-right avatar if you're editing your own user).
  3. Scroll to the Application Passwords section near the bottom.
  4. In New Application Password Name type Quibo and click Add New Application Password.
  5. Copy the 24-character password that appears (format xxxx xxxx xxxx xxxx xxxx xxxx). It's only shown once. You can leave the spaces: WordPress strips them when checking.

Plug it into Quibo

From Sites, then Connect a site pick WordPress and fill in:

  • Site name (e.g. Acme Blog)
  • Site URL, the public address of your WordPress site (e.g. https://example.com)
  • Output language, the language the articles are written in
  • WordPress username
  • Application Password

Click Connect site. Quibo first verifies the credentials against WordPress: if the check fails, nothing is stored and the error is shown in the wizard. When it passes, Quibo encrypts the credentials, starts learning your brand voice and probes the REST API (see below). Test connection on the site page stays available to re-check them later.

Auto-discovery

After connecting, Quibo probes the WordPress REST API to discover:

  • Post fields, from OPTIONS /wp-json/wp/v2/posts. Used to know which fields your install accepts.
  • Post types, from GET /wp-json/wp/v2/types. Listed for reference only: Quibo always publishes to the standard post type.
  • Editorial users, from GET /wp-json/wp/v2/users?context=edit (up to 100). They power the Default author dropdown so you can pick which user appears as the byline on Quibo-generated posts.

Open Sites, then your site, scroll to Brand profile, pick the Default author and click Save brand profile. Every article Quibo publishes will be attributed to that user. If none is saved, WordPress attributes the post to the user that owns the Application Password.

Discovery runs again once a day, or whenever you click Re-crawl brand on the site page.

What if Application Passwords are disabled?

Some hosts (or security plugins such as iThemes Security) disable Application Passwords by default. Symptoms:

  • Test connection answers Authentication failed. Check user + Application Password.
  • The Application Passwords section doesn't appear in your Profile.

Ask your host or admin to re-enable Application Passwords. Most hosts have a one-line fix in functions.php:

add_filter( 'wp_is_application_passwords_available', '__return_true' );

...or via a small must-use plugin. Once enabled, generate a new password, then open the site page in Quibo, use Update credentials in the Credentials card, and the new values are verified against your CMS before they replace the old ones.

If your site is behind aggressive bot protection (Cloudflare Bot Fight Mode, custom WAF rules), make sure requests to /wp-json/wp/v2/* from external services are allowed.

What we publish

When an article ships to your WordPress, we send one POST /wp-json/wp/v2/posts with:

  • Title, slug and excerpt (the meta description)
  • Content rendered as native Gutenberg blocks, with the article's JSON-LD (Article and FAQPage structured data) appended in a custom HTML block so search engines see it on the page
  • The cover image, uploaded to your media library first with its alt text and set as the featured image. The file carries an XMP marking that identifies it as AI-generated, as required by the EU AI Act.
  • Yoast SEO meta title and description (in meta._yoast_wpseo_title and meta._yoast_wpseo_metadesc)
  • The chosen Default author (numeric author field)
  • status: publish, so the post goes live immediately

When Quibo refreshes an article later, it edits the same post (POST /wp-json/wp/v2/posts/{id}): the slug and the original publish date are kept, the content and the featured image are replaced.

We never delete or modify other posts. We don't touch user accounts. We don't write to site options.

Test the connection

After connecting, go to Sites, then your site and click Test connection. Quibo calls GET /wp-json/wp/v2/users/me?context=edit with your credentials (context=edit requires a user with edit capabilities, so an Author role or higher): a 401 or 403 means the username or the Application Password is wrong or has been revoked.

Security

  • The Application Password is encrypted at rest (AES-256-GCM).
  • It's never returned to the browser, never logged, never sent to a third party.
  • Revoke any time from Users, Profile, Application Passwords, Revoke. Publishing stops immediately.
  • Application Passwords cannot create users, install plugins, or change site settings: they're scoped to the user's existing capabilities.