DirectRelay Automation Bridge for n8n turns any WordPress site into a first-class REST API target that n8n workflows, Make scenarios, Zapier zaps, custom AI agents and your own scripts can talk to — with the keys, scopes and security model that production automation actually demands.
It is the only free WordPress automation plugin that ships all four at once: a scoped REST API surface (32 endpoints under /wp-json/directrelay-automation-bridge-for-n8n/v1/), HMAC-signed outgoing webhooks with retry, native reads of Rank Math and Yoast SEO fields, and a self-describing OpenAPI 3.0 spec that lets the n8n HTTP Request node auto-fill every request shape. No purchase code. No license key. No trial period. No feature lock. Every feature listed on this page is fully functional in the free build and always will be.
/wp-json/directrelay-automation-bridge-for-n8n/v1/openapi.json — paste it into n8n’s HTTP Request node and every field, scope and response shape fills itself. No manual mapping.GET /posts/{id}/seo returns focus keyword, SEO title, meta description, canonical URL and OpenGraph fields from whichever SEO plugin you have active. The community n8n-nodes-wordpress node can’t do this.REST API endpoints (32 routes)
* Posts — list, get, publish, bulk publish (single call writes post + featured image + SEO + categories + tags).
* Pages — list and get.
* Media — list, sideload from URL, get.
* Taxonomies — categories and tags.
* Custom meta — list all, get/delete by key (works with ACF, Pods, custom fields).
* SEO read — GET /{type}/{id}/seo returns Rank Math or Yoast fields automatically.
* Discovery — /discovery/fields and /discovery/post-types for schema reflection.
* Webhooks — CRUD + test + delivery log + usage stats + ready-made presets.
* API keys — list, rotate, revoke.
* System — /status, /ping, /cron-health, /blocked-ips.
* Fleet — /fleet/health and /fleet/keys/provision for multi-site monitoring.
* OpenAPI — /openapi.json and /openapi for self-describing discovery.
Security and production hardening
* Scoped API keys with 16+ scope types (posts:read, posts:write, posts:publish, posts:delete, media:write, webhooks:write, etc.).
* Five preset roles (readonly, writer, editor, publisher, full_access) plus custom scope bundles.
* Per-key IP allowlist (single IP or CIDR ranges).
* Per-key expiration date (auto-revoke after).
* Automatic key rotation policy (configurable days; n8n-friendly grace period).
* Keys are stored as salted hashes — the database leak cannot expose live keys.
* Timing-safe comparison (hash_equals) — immune to timing side channels.
* Sliding-window rate limiter — configurable per-IP + per-key, prevents burst abuse.
* Brute-force protection with escalating IP block (5 min 30 min 2 hr 24 hr).
* HMAC-SHA256 signed outgoing webhooks with X-DirectRelay-Signature header and replay protection via timestamp window.
Outgoing webhooks
* Dispatch signed JSON to any HTTP endpoint — n8n webhook, Make hook, Zapier catch hook, custom AI agent.
* Event filtering by post type, status transition, taxonomy.
* Automatic retry with exponential backoff.
* Last 50 deliveries per webhook (status code, response time, request body).
* Built-in “Send test event” button from the admin UI.
* Ready-made presets for post.published, post.updated, post.deleted, page.published.
AI and SEO integrations
* Rank Math field reads: focus keyword, SEO title, description, canonical URL, pillar content flag, robots flags.
* Yoast SEO field reads: focus keyword, SEO title, meta description, canonical URL, OpenGraph title and description.
* IndexNow auto-ping on every publish/update — instant indexing on Bing, Yandex, Naver and Seznam. No cron job needed.
* OpenAI-compatible response shape — all endpoints return JSON that the n8n OpenAI/HTTP nodes parse without transformation.
Operations
* Activity log — last 100 API calls and webhook deliveries, plain text, filterable by event type.
* Email notifications — admin gets pinged on every webhook failure with the failed payload attached.
* Compatibility checker — verifies permalinks, REST API, SSL, Rank Math / Yoast presence, PHP version, WP-Cron health.
* Cron health monitor — alerts if WP-Cron is more than 15 min behind.
* n8n starter template — one copy-paste workflow that proves the connection in under 60 seconds.
* Side-load media from URL — POST /media/sideload with an image URL and DirectRelay downloads, attaches and returns the WP media ID.
* Custom Post Type support — auto-discovered, no extra config.
* GDPR-friendly — zero outbound traffic by default. Every external service is an explicit opt-in.
POST /posts with title, content, Rank Math SEO and a featured image URL in a single request IndexNow auto-pings Bing webhook back to n8n notifies your Slack./fleet/health on 20 WordPress sites every 5 min. If any return cron_degraded, n8n opens a PagerDuty incident.GET /posts?per_page=100&status=publish, renders the site. Writers use the regular WP admin to edit.POST /posts with a draft pre-filled with the lead’s company name editorial team gets a Slack notification with a one-click approve link.Rank Math / Yoast SEO field reads
* DirectRelay: Yes, both (Rank Math + Yoast auto-detected)
* WP REST + Application Password: No
* n8n-nodes-wordpress (community): No
* WP Webhooks: No
Per-route API scopes
* DirectRelay: Yes, 16+ scopes (posts:read, posts:write, media:write, etc.)
* WP REST + Application Password: No (always full account access)
* n8n-nodes-wordpress (community): No
* WP Webhooks: No
HMAC-signed outgoing webhooks
* DirectRelay: Yes (HMAC-SHA256, replay-protection timestamp)
* WP REST + Application Password: No
* n8n-nodes-wordpress (community): No
* WP Webhooks: Yes (basic)
OpenAPI 3.0 auto-discovery
* DirectRelay: Yes (/openapi.json so the n8n HTTP Request node auto-fills request shapes)
* WP REST + Application Password: No
* n8n-nodes-wordpress (community): No
* WP Webhooks: No
Outgoing webhooks with retry
* DirectRelay: Yes (exponential backoff, delivery log, test event)
* WP REST + Application Password: No
* n8n-nodes-wordpress (community): No
* WP Webhooks: Yes
Per-credential IP allowlist
* DirectRelay: Yes (single IP or CIDR)
* WP REST + Application Password: No
* n8n-nodes-wordpress (community): No
* WP Webhooks: No
Pricing model
* DirectRelay: 100% free, GPL, no upsell, no trial
* WP REST + Application Password: 100% free (core WordPress)
* n8n-nodes-wordpress (community): 100% free (community node)
* WP Webhooks: Freemium (paid add-ons)
DirectRelay is free software released under the GPL-2.0+ licence. You can use it, study it, modify it and redistribute it under the same terms.
The free plugin distributed on WordPress.org does not perform purchase-code validation, license-server activation, or any third-party license check. There is no purchase code, license key or activation token collected, stored, transmitted or required to use any feature of the free plugin. License management for the optional add-on is provided by the separate DirectRelay Pro add-on plugin distributed from directrelay.wikiofautomation.com/directrelay-pro — Pro is never distributed via WordPress.org and is never required.
The following features are provided by the DirectRelay Pro add-on plugin, distributed from https://directrelay.wikiofautomation.com/directrelay-pro. None of this code ships in the WordPress.org zip.
This plugin supports optional integrations with external services. The services and their data handling policies are outlined below. All transmissions are initiated by the plugin only when the administrator has explicitly enabled the relevant feature; no data is sent silently or by default.
The free plugin distributed on WordPress.org does NOT use the following services: Envato/CodeCanyon purchase-code validation, license-server activation, or any third-party license check. There is no purchase code, license key, or activation token collected, stored, transmitted, or required to use any feature of the free plugin. (License management is provided by the separate DirectRelay Pro add-on plugin distributed from directrelay.wikiofautomation.com/directrelay-pro.)