Docs & Support

Learn about all the Formidable features and get support from our amazing customer success team.

Add-onsAutomation
Using Application Passwords for API Authentication

Using Application Passwords for API Authentication

Use a WordPress Application Password to authenticate a Formidable REST API, Abilities API, or remote MCP request. An Application Password belongs to one WordPress user. The request has the same permissions as that user. Learn more about WordPress Application Passwords.

Application Password or Formidable API key? Use an Application Password for Formidable REST API v3, Abilities API, and MCP integrations. The legacy Formidable API key runs requests with administrator access. An Application Password supports a dedicated user with fewer permissions.

Requirements

  • A WordPress site that supports Application Passwords.
  • Formidable Forms Pro and Formidable API Add-On 2.0 installed and activated for REST API v3, Abilities API, or Formidable MCP requests.
  • HTTPS when credentials travel over a network.
  • A dedicated WordPress user with only the permissions required by the integration.

Formidable Forms makes advanced site building simple. Launch forms, directories, dashboards, and custom WordPress apps faster than ever before.

Configure the WordPress user

  1. Create or select a dedicated WordPress user for the integration.
  2. Assign the user to a WordPress role that you reserve for the integration.
  3. Go to Formidable → Global Settings → Permissions.
  4. Under each required Formidable permission, select the integration user's role.
  5. Click Update.

For example, a read-only reporting client can use View Forms List and View Entries from Admin Area. Do not give it entry, form, View, or Application change permissions unless it must change that data.

An Abilities API or MCP user also needs the standard WordPress Read permission to discover the public ability catalog. This permission does not appear on the Formidable Permissions screen. If you created a custom role, confirm this permission with your WordPress role-management tool.

Create an Application Password

  1. Sign in as the dedicated WordPress user.
  2. Go to Users → Profile.
  3. Go to the Application Passwords section.
  4. Enter a clear name in New Application Password Name. Include the client and purpose, such as Codex Formidable staging.

    Enter a name for a WordPress Application Password
  5. Click Add New Application Password.
  6. Copy the password immediately. WordPress shows it only once.

    Copy a new WordPress Application Password
  7. Store the password in the protected credential settings for the client. Do not paste it into an AI chat, prompt, support message, or public file.
Important: An Application Password gives a client the permissions of its WordPress user. Revoke it when the client no longer needs access. If it is exposed, revoke it and create a replacement.

Choose the endpoint

Use the endpoint for the interface that your client supports.

InterfaceEndpointUse it for
REST API v2/wp-json/frm/v2Maintain an existing integration that uses the frozen version 2 routes.
Formidable REST API v3/wp-json/frm/v3Build a new custom REST integration.
WordPress Abilities API/wp-json/wp-abilities/v1Discover and run individual Formidable abilities.
Formidable MCP server/wp-json/mcp/formidable-mcpConnect a compatible remote AI client.
Turn on REST API in Formidable → Global Settings → API before you use a /frm/v3 route. Turn on MCP Server before you use Formidable abilities or the MCP endpoint.

Test a REST API request in Postman

  1. Download and open Postman. Create a new HTTP request.
  2. Select GET.
  3. Enter your site URL followed by /wp-json/frm/v3/entries.
  4. Open the Authorization tab.
  5. Select Basic Auth.
  6. Enter the dedicated WordPress username as the username.
  7. Enter its Application Password as the password.
  8. Click Send.

The same credentials can authenticate supported POST, PATCH, and DELETE requests. The WordPress user must have the permission required for each operation.

Troubleshooting

  • 401 Unauthorized: Confirm the WordPress username and Application Password. Confirm that the client uses Basic Auth and HTTPS.
  • 403 Forbidden: The credentials can be valid while the WordPress user does not have the required Formidable permission. Add only the missing permission.
  • 404 Not Found: Confirm the endpoint and the related Global Settings toggle. Use /frm/v3 for a new Formidable REST integration.
  • MCP client cannot discover Formidable tools: Confirm that MCP Server is on, the Formidable license is active, and the client uses /wp-json/mcp/formidable-mcp.

Revoke an Application Password

Go to Users → Profile → Application Passwords. Find the client name and click Revoke.

Revoke a WordPress Application Password

Limitations

  • An Application Password authenticates a request. It does not bypass the WordPress user's Formidable permissions.
  • A local WP-CLI MCP connection does not use an Application Password.
  • The MCP Connections table records authenticated HTTP MCP activity. It does not record local WP-CLI connections.
Was this article helpful? *

This article may contain affiliate links. Once in a while, we earn commissions from those links. But we only recommend products we like, with or without commissions.

In this article

    We have a small, but amazing team of dedicated people who are committed to helping you achieve your goals and project requirements.


    Copyright © 2026 Strategy11, LLC. Formidable Forms® is a registered trademark Strategy11, LLC.

    Complete your purchase
    Don't forget your purchase!
    Complete Purchase
    Join 400,000+ using Formidable Forms to create form-focused solutions fast. Get Formidable Forms