Project home page:
https://directrelay.wikiofautomation.com
The n8n WordPress Integration That Works Both Ways
You built your content workflows in n8n. Now you need WordPress to listen.
DirectRelay is the free n8n plugin that turns any WordPress site into a first-class automation target: a complete REST API for your n8n workflows, real-time signed webhooks from WordPress to n8n, and native SEO integrations with Rank Math and Yoast. Publish, update, tag, optimize, and react to content changes — automatically, securely, and without writing a single line of PHP.
Whether you run an AI content pipeline, a headless WordPress setup, a multi-channel publishing stack, or a simple "post to social when I publish" workflow, DirectRelay is the WordPress automation plugin for n8n workflow automation — data flows from n8n to WordPress, and WordPress events stream to n8n in real time.
Why DirectRelay Is the Most Complete n8n Plugin for WordPress
- True two-way automation — n8n can read and write WordPress, and WordPress can trigger n8n workflows in real time.
- Everything core is free — no trial, no license key, no nag screens. One API key and one webhook per site; the Pro add-on lifts the limits. 100% GPL.
- Built for AI agents — scoped API keys with agent personas let you hand LLMs and AI tools controlled, auditable access to your site.
- OpenAPI 3.0 included — point any HTTP Request node at the self-describing schema and every endpoint, parameter, and auth scheme is documented for you.
- Security-first design — scoped keys, bcrypt hashing, rate limiting, brute-force protection, IP allowlists, and SSRF-validated media sideloads.
- Zero configuration headaches — install, generate a key, paste it into n8n. Your first workflow runs in minutes.
🔌 A Complete WordPress REST API for Your n8n Workflows
Every content operation your automation needs, exposed through a clean, versioned REST API under
/wp-json/directrelay/v1:
- Create, read, update, publish, and delete posts and pages — with markdown support, scheduled publishing, and custom fields.
- Media library uploads via base64 or URL sideload, with per-route permissions.
- Categories and tags — resolve by name or ID, create on the fly.
- Custom meta read and write with core-protected keys blocked.
- Discovery endpoints — list post types and custom fields so workflows adapt to any site, including WooCommerce and custom post types.
- OpenAPI 3.0 spec at
/openapi.json — import into Postman, Swagger UI, or generate n8n HTTP Request node setups instantly.
- 30+ documented endpoints, each gated by fine-grained scopes (
posts:write, media:write, seo:read, …).
🔔 Real-Time Signed WordPress Webhooks → n8n
The moment something happens on your site, a signed WordPress webhook tells n8n. Point any n8n Webhook trigger node at it:
- 10 event types: created, updated, published, and deleted for posts and pages, plus media uploads.
- HMAC-SHA256 signatures with timestamp headers and replay protection — verify deliveries in one n8n Code node.
- Automatic retries with exponential backoff and a per-attempt delivery log you can inspect in the admin.
- Per-webhook filters — choose exactly which events and post types each workflow receives.
- Workflow presets — social distribution, AI repurposing, search indexing, Slack alerts, CDN purging, and more, each with copy-paste n8n workflow JSON.
🤖 Built for AI Agents
Handing an LLM the keys to your site should not mean handing it everything. Each AI agent gets a scoped, auditable key instead of full admin credentials — safe AI agents for WordPress, without the risk.
- Agent role personas — Full Access, AI Content Agent (drafts only), AI SEO Agent, and AI Publishing Agent.
- Drafts-only enforcement — a content agent physically cannot publish or delete, on any route, ever.
- Post ownership isolation — restrict each agent to content created by its own key.
- Scoped, expiring, IP-allowlisted keys with rotation and full usage analytics.
🔍 Read Rank Math & Yoast SEO from n8n
The only free automation bridge that reads SEO metadata natively:
- Unified read endpoint for Rank Math and Yoast SEO — focus keyphrase, title, description, canonical, Open Graph, Twitter cards, schema type.
- Auto-detects which SEO plugin is active. One call, one format, any site.
⚡ IndexNow Instant Indexing
Opt-in IndexNow auto-ping: the moment a post goes live, its URL is submitted to the IndexNow aggregator (Bing, Yandex, Seznam, Naver) for near-instant crawling. The verification key is published automatically at
yoursite.com/indexnow-key.txt.
🛡️ Production-Grade Security
- Scoped API keys — bcrypt-hashed, prefix-identifiable, never stored in plain text.
- Sliding-window rate limiting and escalating brute-force IP blocks with a manual block/unblock console.
- Per-key IP allowlists, global bypass IPs, optional HTTPS enforcement, and key expiry.
- SSRF-validated media sideloading with redirect-hop re-verification and size caps.
- Protected meta — WordPress core internals and plugin stamps are never agent-writable.
- Single-site build: each free install manages exactly one site. Multi-site fleet management is available in the add-on.
Get Started in 3 Minutes
- Install DirectRelay and open the DirectRelay dashboard.
- Generate an API key — pick a scope preset or build your own.
- Paste the key into your n8n HTTP Request node (or import the OpenAPI spec) and your first automation is live.
Who Is DirectRelay For?
- AI content teams running generation pipelines through n8n workflows.
- Agencies managing publishing automation across client content operations.
- Headless WordPress builders who need a reliable, documented REST API.
- Anyone who wants WordPress and n8n to talk to each other — reliably and securely.
DirectRelay is free software licensed under the GPL. Use it, study it, modify it, redistribute it.
All notable changes are documented here. DirectRelay follows semantic versioning for its REST API: the endpoint contract under
directrelay/v1 stays backward compatible within major version 5. DirectRelay is the n8n WordPress plugin for workflow automation — a complete WordPress REST API, signed WordPress webhooks, and scoped AI-agent access.
5.1.34
Release date: October 3, 2026
- New: One-time "Enjoying DirectRelay?" review prompt. It appears on DirectRelay screens only after the first successful webhook delivery or the first successful API call — never before something actually worked. Permanently dismissible with a hard two-week display cap, and it makes no external requests: the review form simply opens on WordPress.org.
- Listing: Keyword-tuned directory title, tags, short description, FAQ entries, and screenshot captions so the plugin surfaces for "n8n WordPress plugin", "WordPress n8n integration", "WordPress webhooks", and related searches.
5.1.33
Release date: September 22, 2026
- New: The free version is now limited to one active API key and one webhook per site. Revoke a key or delete a webhook to free the slot. The DirectRelay Pro add-on removes both limits via the
directrelay_ext_key_limit and directrelay_ext_webhook_limit filters. Existing keys and webhooks are never affected — only new creations are limited.
- Improved: Admin hints now state the free key and webhook policy upfront instead of failing silently after the fact.
5.1.32
Release date: September 22, 2026
- Security: API keys are now strictly scoped to the DirectRelay REST namespace. A leaked key can no longer act as its bound WordPress user on core
/wp/v2 routes or admin endpoints — the scope system can no longer be bypassed.
- Security: Markdown links and images published through the API are protocol-checked and escaped, and heading, blockquote, list, and inline text is escaped — closing a stored-XSS surface for compromised agent keys.
- Security: All media sideload paths (featured image, gallery, and the
/media/sideload endpoint) now validate every redirect hop against SSRF, cap response size, and support IPv6 and literal-IP hosts correctly.
- Fix: Resolved a critical installation issue on standard MySQL servers where the API-keys and webhooks database tables silently failed to create (illegal TEXT column defaults). Existing sites are upgraded automatically on update.
- Fix: Markdown H2 headings (
##) kept their text on publish — a broken regex backreference previously wiped all H2 content converted through the default pipeline.
- Fix: Create/update requests carrying an inline
seo payload no longer fail after saving; the free plugin reports SEO writes as skipped via a seo_write response marker, and the add-on plugin owns SEO writes through a documented filter.
- Improvement: Webhook management is fully functional in the admin — Pause/Activate, Delete, a test-fire dialog, and a per-attempt delivery log viewer now all work.
- Improvement: The API-key wizard now saves the AI Agent Role, approval, ownership, and velocity settings selected in the UI.
- Improvement: Signed webhooks send
X-DirectRelay-Timestamp and a signed-timestamp header for replay protection. The existing body-signature header is unchanged, so current n8n verification workflows keep working.
- Improvement: Manual IP blocks added from the Blocked-IPs console are now enforced on every API request (previously display-only), with correct UTC expiry handling.
- Improvement: Post-ownership isolation and drafts-only agent roles are enforced across create, update, publish, delete, and meta routes.
- Improvement: IndexNow pings honor the on/off setting on every code path, verify TLS, ping the single IndexNow aggregator, and log delivery failures instead of erroring. The key-file endpoint now matches exact paths only.
- Improvement: Delivery-log retention now runs even when webhooks are disabled, and log growth is bounded. Media events respect each webhook's post-type selection, and
post.created fires on the first real save rather than the editor's empty shell.
- Improvement: Full SQLite / WordPress Playground compatibility across authentication, analytics, and all log pruning.
- Changed: The free build now supports a single site per install. Multisite activation is refused, and multi-site fleet endpoints moved to the add-on plugin.
- Changed: Uninstall now removes all remaining options (including the IndexNow key) and diagnostic log files.
5.1.31
- Refreshed the directory listing metadata and restored the original banner artwork for maximum clarity at both WP.org sizes.
5.1.30
- Rebuilt the feature comparison section so it renders correctly in the WP.org readme parser, and refreshed the branded banner artwork.
5.1.29
- Indexer refresh release: re-issued the stable tag so the directory listing picks up the rewritten description, expanded FAQ, and new short description. No functional changes.
5.1.28
- Removed a duplicated External-services disclosure section that could prevent the readme validator from indexing the listing.
5.1.27
- Complete listing refresh: new directory icons and banners, six new screenshots, expanded FAQ, a full feature inventory, and copy-paste n8n workflow examples.
5.1.26
- Added the animated brand mark used for the directory thumbnail, with a static fallback for environments without animation support.
5.1.25
- Prefix cleanup: removed legacy identifier remnants so the entire codebase is uniformly
directrelay-prefixed.
5.1.24
- Directory-only assets removed from the distribution package; diagnostic logs moved to the uploads directory with safe paths.
5.1.23
- The free plugin became strictly read-only for SEO (WP.org serviceware guideline): SEO writes moved entirely to the add-on plugin, with a documented extension filter for add-on integration.
5.1.22
- Removed all trialware-pattern remnants and renamed every extension hook to the
directrelay_ext_* convention. Plugin Check: 0 errors, 0 warnings.
5.1.21
- Corrected the Plugin URI header so the plugin page and author profile resolve distinctly.
5.1.20
- PHP 8.0+ compatibility hardening and Plugin Check query-annotation cleanups.
5.1.19
- Full SQLite / WordPress Playground compatibility for rate limiting and brute-force tracking.
5.1.18
- Major reliability release: fixed the transactional publish pipeline, restored the SSRF guard on featured-image sideloads, enforced the admin retry budget, repaired agent-role checks, made IndexNow opt-in, and removed a broken parallel webhook dispatcher in favor of the hardened delivery manager.
5.1.0 – 5.1.17
- Initial WordPress.org release cycle: REST API for posts, pages, media, taxonomies, and meta; Rank Math and Yoast SEO reads; HMAC-signed outgoing webhooks with retries; self-hosted OpenAPI 3.0 spec; sliding-window rate limiter; brute-force protection; compatibility checker; and the add-on split with
directrelay_ext_* extension hooks. Multiple correctness and compliance fixes along the way, including REST authentication, admin asset loading, and OpenAPI introspection.