You’ve been editing WordPress by hand — copying code, opening the block editor, uploading files — even though you have an AI right in front of you that could do all of that while you focus on something else. The problem isn’t the AI: it’s that you haven’t given it access to your site.
This guide explains three ways to connect any AI agent — Claude Code, ChatGPT, Gemini, Cursor, whichever you use — to your WordPress installation. We cover everything from the fastest, most universal method to the workflow we use ourselves to manage brandgrowth.es with Claude Code directly from the terminal.
Why connecting your AI to WordPress changes how you work
Once your agent has access to the site it can do things that would normally take you minutes or even hours:
- Draft and publish posts without touching the WordPress editor
- Create pages, WooCommerce products or entire custom post types
- Edit the theme directly — PHP, CSS, JS — and upload the changes to the server
- Find and replace content across the site
- Create temporary diagnostic scripts to debug production errors
The key is giving the agent the right level of access for what you need to do. There are three methods, and each has its use case.
Method 1 — Application Password: the fastest (works with any AI)
This is the method that appears in most tutorials and the one you need to know if you use agents like ChatGPT, Gemini, Claude.ai, Cursor or any internet-connected tool. It relies on the WordPress REST API with Application Password authentication — no need to touch server files.
What is an Application Password
WordPress (since version 5.6) lets you generate specific passwords for external applications. They are independent from your dashboard login password: if one is ever compromised, you revoke it without affecting anything else. The WordPress REST API is active by default in any modern installation and lets you read and write practically any site content.
Step 1 — Generate the password in your WordPress
- Log in to your WordPress dashboard (
yourdomain.com/wp-admin). - Go to Users → Your Profile (or the user you want to use).
- Scroll down to the Application Passwords section.
- Type a descriptive name: Claude Code, ChatGPT, Cursor — whatever helps you identify it.
- Click Add New Application Password.
- WordPress generates a password in the format
XXXX XXXX XXXX XXXX XXXX XXXX. Copy it now — it won’t be shown again.
Security note: use a user with the minimum role needed. For publishing posts only, an Editor is enough. You only need Administrator if you’re installing plugins or changing site settings.
Step 2 — Tell your AI to connect
Open the chat with your agent and write something like this:
Connect to my WordPress site.
URL: https://yourdomain.com
WordPress username: your_username
Application Password: XXXX XXXX XXXX XXXX XXXX XXXX
Confirm you have access before making any changes.
The agent should make a GET request to https://yourdomain.com/wp-json/wp/v2/users/me to verify the connection. If it responds with your username and permissions, you’re in.
If you’re using Claude Code (the CLI), the flow is identical: pass those credentials in the message and the agent calls the REST API with fetch or curl as needed.
Step 3 — Start operating from the chat
Once connected, the natural-language commands you can give are:
- «Draft a post titled [X] in category [Y] and leave it as a draft»
- «Create a new page with the slug /summer-landing/ and this content: […]»
- «Give me a list of the last 10 published posts with their URL and date»
- «Update the excerpt of post ID 42 to this text: […]»
- «Create these 5 WooCommerce products with these prices: […]»
The agent translates each instruction into REST calls (POST /wp/v2/posts, PUT /wp/v2/posts/42, etc.) and confirms the result. You don’t need to touch the dashboard.
Method 2 — Claude Code with direct server access (FTP / SSH)
The previous method works perfectly for managing content. But if you need to edit theme code — PHP templates, CSS, JS — you need direct access to the server’s files. This is what we do at Brandgrowth with Claude Code.
The workflow is: you edit files locally, Claude Code applies the changes, and a script automatically uploads the modified file to the server via FTP.
When to use this method
Use it when you need to:
- Modify theme PHP templates (
page.php,single.php,functions.php, etc.) - Update global theme CSS or JS
- Upload a custom plugin
- Run temporary PHP diagnostic scripts in production
- Work with files the REST API doesn’t handle
FTP access with Python (no external dependencies)
Python includes ftplib in its standard library — no installation needed. This is the base script we use to upload a modified file to the Hostinger server:
from ftplib import FTP
ftp = FTP()
ftp.connect('SERVER_IP', 21, timeout=60)
ftp.login('your_ftp_user', 'your_ftp_password')
ftp.encoding = 'utf-8'
local_path = r'C:/local/path/to/file.php'
remote_path = '/domains/yourdomain.com/public_html/wp-content/themes/your-theme/file.php'
with open(local_path, 'rb') as f:
ftp.storbinary(f'STOR {remote_path}', f)
ftp.quit()
print('Uploaded successfully.')
You tell Claude Code: «Edit the theme’s page.php to add this JSON-LD schema block and then upload it to the server with the FTP script.» The agent edits the local file, runs the script and confirms the upload completed.
Common pitfall with Hostinger and other shared hosts: the FTP root is not the WordPress root. You connect via FTP and see a public_html/ folder — but WordPress may be at /domains/yourdomain.com/public_html/. Always verify the correct path by navigating the FTP before writing it into scripts.
SSH access (when the host supports it)
SSH is the most powerful method: you give Claude Code access to a terminal session on the server and it can run any command — wp-cli, composer, database operations, anything.
If your host supports it (most VPS and some shared hosting plans do), the command is:
# Connect with username and password
ssh user@SERVER_IP -p PORT
# Connect with private key (more secure)
ssh -i ~/.ssh/your_key user@SERVER_IP -p PORT
Once connected via SSH, Claude Code can run WP-CLI commands directly:
# Examples of what you can ask Claude Code via SSH + WP-CLI
wp post create --post_title="My article" --post_status=draft --post_type=post
wp plugin activate plugin-name
wp search-replace 'old-text' 'new-text' --all-tables
wp cache flush
Important note: some shared hosts block password-based SSH from external scripts for security reasons. If this happens, use FTP as an alternative or configure public key authentication.
The complete workflow: local → server
This is the workflow we use at Brandgrowth so Claude Code can manage the WordPress theme without dashboard access:
- Edit locally: Claude Code modifies the file in the local repository (
wp-content/themes/brandgrowth/file.php). - Version bump: if the change affects CSS or JS, the version in
style.cssis incremented so WordPress invalidates the browser cache. - Upload to server: the Python FTP script runs and transfers only the modified file.
- Verify in production: we open the site in the browser to confirm the change is live.
The local repository acts as the source of truth. The server always reflects the latest version of those files. Claude Code understands the entire project structure and can track which files need modifying for each task. Our AI web design service is built entirely on this workflow.
Method 3 — VSCode + SFTP extension (auto-deploy on save)
If you work in VSCode and want files to be uploaded to the server automatically every time you save, the SFTP extension (Natizyskunk / Liximomo) does exactly that.
- Install the SFTP extension from the VSCode Marketplace.
- Open the command palette (
Ctrl+Shift+P) and run SFTP: Config. - Configure the
.vscode/sftp.jsonfile it generates:
{
"name": "Production server",
"host": "SERVER_IP",
"protocol": "ftp",
"port": 21,
"username": "your_ftp_user",
"password": "your_ftp_password",
"remotePath": "/domains/yourdomain.com/public_html/wp-content/themes/your-theme/",
"uploadOnSave": true,
"ignore": [".vscode", ".git", "node_modules", "*.md"]
}
With "uploadOnSave": true, every time you save a file in VSCode it is automatically uploaded to the server. Claude Code (inside VSCode) edits the file, you save, and the change is live in seconds.
Caution: add this file to .gitignore if your repository is public — it contains server credentials in plain text. For team projects, use environment variables or a secrets manager.
What you can do once your AI has access
The combination of REST API + FTP/SSH access covers virtually everything you need to manage a WordPress site. For social media content, Claude can also generate Canva carousels in minutes.
- Content: publish posts and pages, create drafts, update meta descriptions, edit excerpts, manage categories and tags.
- WooCommerce: create products, update prices, manage inventory, modify product categories.
- Theme: edit PHP templates, update CSS and JS, create new page templates, add shortcodes in
functions.php. - SEO: update titles and meta descriptions via plugin (Yoast, RankMath expose their fields in the REST API), add JSON-LD schema in templates — part of our AI SEO strategy.
- Diagnostics: upload temporary PHP scripts to the server, run them and delete them — useful for debugging errors or migrating data.
- Database: via WP-CLI over SSH — find and replace, export tables, migrate content between environments.
Security best practices
Giving an AI access to your production site requires basic precautions you should never skip:
- Use a specific Application Password — never share your main WordPress password with any external application.
- Assign the minimum necessary role — if the agent only needs to publish posts, create an Editor user, not an Administrator.
- Revoke credentials when you’re done — in WordPress you can delete Application Passwords individually from the user profile at any time.
- Don’t store FTP credentials in the repository — put them in environment variables or a local file outside version control.
- Temporary PHP scripts: always delete them — a diagnostic script accessible at
yourdomain.com/script.phpis a vulnerability. Run it and delete it in the same session. - Review what the agent proposes before executing — especially for destructive operations (deleting posts, modifying database tables, changes to
functions.php).
Frequently asked questions
-
The REST API with Application Password works on any modern WordPress (5.6+) regardless of the host. FTP access works on almost all shared hosts. SSH depends on the plan — VPS always has it; shared hosting plans vary.
-
Yes, just as a human developer can. Modern agents propose changes before executing them — review them. For critical operations, keep a recent backup and don’t run changes in production without testing locally or on a staging environment first.
-
For Method 1 (Application Password) you need no technical knowledge — it’s copy and paste. For Methods 2 and 3 you need a basic level: knowing how to open a terminal, install Python and edit a JSON configuration file. The agent writes the code for you; you decide what to run.
-
The REST API manages content (posts, pages, products, taxonomies) and uses WordPress’s internal functions — it is the safe, «official» way. Editing files directly (FTP/SSH) modifies theme or plugin code and requires knowing the project structure. For most content tasks, the REST API is sufficient and safer.
-
Yes. WooCommerce exposes its own REST API (
/wp-json/wc/v3/) with which you can manage products, orders, customers, categories and inventory. The authentication is the same: Application Password or, for the WooCommerce API, the specific WooCommerce API Keys from WooCommerce → Settings → Advanced → REST API.