Site Connection Errors: What They Mean and How to Fix Them
Connecting a site takes three steps. Your AI gives you a link. The link opens an approval page on your own WordPress site. When you click Approve, WordPress sends you back to WPVibe. Where an error appears tells you which step failed. The basics are in Connect a WordPress Site.
Before you start: get a connection report
If the WPVibe plugin is installed, open WPVibe in WordPress admin and click Check site connectivity, then Copy report to clipboard. Without the plugin, open mcp.wpvibe.ai/account/sites while signed in to WPVibe. The report shows which step fails and what to try next. Send it to us or to your host if you get stuck.
“No credentials found for …” or “No sites registered yet”
Your AI says this when WPVibe has no saved connection for that address on your account. The usual causes:
- The site is connected at a slightly different address on the same domain, for example
/blog. Ask your AI to list your sites and use that exact address. - The connection never finished.
- This AI app is signed in to a different WPVibe account (a different email address) than the one you connected the site with. See Your Plan and Your WPVibe Account.
Not sure the site runs WordPress? Open yoursite.com/?rest_route=/ in your browser. WordPress shows a page of code-like text with "namespaces" in it. A normal web page means the site isn’t WordPress, its REST API is turned off, or WordPress lives at another address. Connect the address shown as WordPress Address under Settings > General.
“Couldn’t reach the WordPress REST API at …”
WPVibe couldn’t get a WordPress answer from your site, so it didn’t give you a link. Try the ?rest_route=/ test above first. If WordPress answers in your browser but not for WPVibe, something is blocking WPVibe’s requests: see Firewalls, Bot Protection, and WPVibe’s IP Address. Otherwise run the connection report and send it to us.
“WordPress Application Passwords are turned off on …”
WPVibe connects with a WordPress Application Password, and something on your site has switched them off. To check, open Users > Profile in wp-admin and scroll down: if there is no Application Passwords section, they are off. Fixes, easiest first:
- Install the free WPVibe plugin, open WPVibe in the wp-admin menu, and click Allow for WPVibe. That allows Application Passwords for WPVibe only; your security plugin still controls everything else. Then ask your AI to connect again.
- Wordfence (the most common cause): go to Wordfence > All Options > Brute Force Protection, untick Disable WordPress application passwords, and save.
- Another security plugin: look for an Application Passwords or REST API setting.
- A site on
http://: WordPress requires HTTPS for Application Passwords. Turn on HTTPS and connect thehttps://address.
“… identifies a Cloudflare security page (block or challenge)”
Cloudflare in front of your site is challenging WPVibe’s requests. WPVibe already retries through its relay address, so this means both routes were stopped. If you manage Cloudflare yourself, allow WPVibe’s relay IP. If your host runs Cloudflare for you, ask them for an exception. The steps are in Firewalls, Bot Protection, and WPVibe’s IP Address.
“Cannot Authorize Application” on the approval page
WordPress uses this title for several refusals. Read the sentence under it:
- “Your website appears to use Basic Authentication…”: your site, usually a staging copy, has a server password in front of WordPress. See the next section.
- “Application passwords are not available…”: they are turned off on the site or for your user. See Application Passwords are turned off above, or log in as another Administrator.
- Anything else: send us the exact sentence and the connection report.
The Go Back button on that page takes you to a WPVibe page that says you clicked Cancel. Nothing changed; ask your AI for a fresh link once the cause is fixed.
“… is behind a server-level password” (HTTP Basic Auth)
Your site has a second password in front of WordPress, and WordPress won’t create an Application Password while it is on. Ask your host to let WPVibe’s relay IP through the password, wait five minutes, then connect again, and turn the password off just for the Approve click. Full steps: Staging sites behind a server password.
If Approve says This route accepts the logged-in browser session only, your browser is still sending the server password with the Approve request. The same fix applies: turn the password off for the Approve click.
“403 Forbidden” as soon as the link opens
This page comes from your own site, not from WPVibe: the link sends you to wp-admin/authorize-application.php on your site. Log in to wp-admin first, then ask your AI for a fresh link and open it.
If you still see Forbidden, a security plugin or your host’s firewall is refusing the approval page. Some firewalls refuse it because the link carries a web address in its query string. Send your host the full address from your browser’s address bar and the time it happened, and ask them to allow that page for logged-in users. Also ask them to allow the logged-in request the Approve button sends next: /wp-json/wpvibe/v1/authorize with the WPVibe plugin, or /wp-json/wp/v2/users/me/application-passwords without it (or the same routes in the ?rest_route= form).
“Cookie check failed” after you click Approve
WordPress couldn’t match the approval page to your login. This usually happens when the page sat open for a while, or you logged in or out in another tab after opening it.
- Ask your AI for a fresh link.
- Open it in a private window, log in there, and click Approve once, right away.
- Check that the address in your browser matches Settings > General, including
www.
If it fails again, a cache may be serving an old copy of the page or dropping your login on /wp-json/. Ask your host, or check your caching plugin, so that logged-in requests to /wp-admin/ and /wp-json/ skip the cache.
“Approve could not reach this site’s REST API”
The WPVibe plugin shows this notice on the approval page, sometimes before you click, as a heads-up. Read what it says:
- If it says Application Passwords are disabled for this account, or this account can’t create them, log in as another Administrator, or have one turn them on.
- If it shows status 500, your server hit an error, and your host can find it in the error log.
- If it names a firewall, ask your host to allow logged-in requests to
/wp-json/wpvibe/v1/authorize. - Otherwise, try a private window first.
“This authorization link has expired” and other link messages
A connect link lasts one hour, and it can be approved only once. If a link expired, looks cut off, or you clicked Cancel, ask your AI to connect the site again for a fresh link. If you had already clicked Approve on a link that then failed, WordPress may have created an unused WPVibe entry under Users > Profile > Application Passwords; you can revoke it there.
Moved your site to a new domain?
WPVibe saves each connection under the address WordPress reports. A new domain counts as a new site, and nothing updates on its own. The old connection may still read the site, but approved changes will fail with a message that the signed approval does not match this site.
- Check that Settings > General shows the new address in both fields.
- Ask your AI to connect the new address, and approve it.
- Once that works, ask your AI to remove the old address from WPVibe.
If only www changed, ask your AI to remove the site first and then connect it again. WPVibe treats the www and non-www addresses as the same site.
Connected, but some saves fail with 403
That’s a different problem: a firewall or host filter is refusing some saves after the connection works. See Firewalls, Bot Protection, and WPVibe’s IP Address.
Still stuck?
Email [email protected] with the connection report, the exact message you saw, and roughly when it happened.