Description
Project home page: https://directrelay.wikiofautomation.com
The n8n WordPress Integration That Works Both Ways
You built your content workflows in n8n. Now you need WordPress to listen.
DirectRelay is the free n8n plugin that turns any WordPress site into a first-class automation target: a complete REST API for your n8n workflows, real-time signed webhooks from WordPress to n8n, and native SEO integrations with Rank Math and Yoast. Publish, update, tag, optimize, and react to content changes — automatically, securely, and without writing a single line of PHP.
Whether you run an AI content pipeline, a headless WordPress setup, a multi-channel publishing stack, or a simple “post to social when I publish” workflow, DirectRelay is the WordPress automation plugin for n8n workflow automation — data flows from n8n to WordPress, and WordPress events stream to n8n in real time.
Why DirectRelay Is the Most Complete n8n Plugin for WordPress
- True two-way automation — n8n can read and write WordPress, and WordPress can trigger n8n workflows in real time.
- Everything core is free — no trial, no license key, no nag screens. One API key and one webhook per site; the Pro add-on lifts the limits. 100% GPL.
- Built for AI agents — scoped API keys with agent personas let you hand LLMs and AI tools controlled, auditable access to your site.
- OpenAPI 3.0 included — point any HTTP Request node at the self-describing schema and every endpoint, parameter, and auth scheme is documented for you.
- Security-first design — scoped keys, bcrypt hashing, rate limiting, brute-force protection, IP allowlists, and SSRF-validated media sideloads.
- Zero configuration headaches — install, generate a key, paste it into n8n. Your first workflow runs in minutes.
🔌 A Complete WordPress REST API for Your n8n Workflows
Every content operation your automation needs, exposed through a clean, versioned REST API under /wp-json/directrelay/v1:
- Create, read, update, publish, and delete posts and pages — with markdown support, scheduled publishing, and custom fields.
- Media library uploads via base64 or URL sideload, with per-route permissions.
- Categories and tags — resolve by name or ID, create on the fly.
- Custom meta read and write with core-protected keys blocked.
- Discovery endpoints — list post types and custom fields so workflows adapt to any site, including WooCommerce and custom post types.
- OpenAPI 3.0 spec at
/openapi.json— import into Postman, Swagger UI, or generate n8n HTTP Request node setups instantly. - 30+ documented endpoints, each gated by fine-grained scopes (
posts:write,media:write,seo:read, …).
🔔 Real-Time Signed WordPress Webhooks n8n
The moment something happens on your site, a signed WordPress webhook tells n8n. Point any n8n Webhook trigger node at it:
- 10 event types: created, updated, published, and deleted for posts and pages, plus media uploads.
- HMAC-SHA256 signatures with timestamp headers and replay protection — verify deliveries in one n8n Code node.
- Automatic retries with exponential backoff and a per-attempt delivery log you can inspect in the admin.
- Per-webhook filters — choose exactly which events and post types each workflow receives.
- Workflow presets — social distribution, AI repurposing, search indexing, Slack alerts, CDN purging, and more, each with copy-paste n8n workflow JSON.
🤖 Built for AI Agents
Handing an LLM the keys to your site should not mean handing it everything. Each AI agent gets a scoped, auditable key instead of full admin credentials — safe AI agents for WordPress, without the risk.
- Agent role personas — Full Access, AI Content Agent (drafts only), AI SEO Agent, and AI Publishing Agent.
- Drafts-only enforcement — a content agent physically cannot publish or delete, on any route, ever.
- Post ownership isolation — restrict each agent to content created by its own key.
- Scoped, expiring, IP-allowlisted keys with rotation and full usage analytics.
🔍 Read Rank Math & Yoast SEO from n8n
The only free automation bridge that reads SEO metadata natively:
- Unified read endpoint for Rank Math and Yoast SEO — focus keyphrase, title, description, canonical, Open Graph, Twitter cards, schema type.
- Auto-detects which SEO plugin is active. One call, one format, any site.
⚡ IndexNow Instant Indexing
Opt-in IndexNow auto-ping: the moment a post goes live, its URL is submitted to the IndexNow aggregator (Bing, Yandex, Seznam, Naver) for near-instant crawling. The verification key is published automatically at yoursite.com/indexnow-key.txt.
🛡️ Production-Grade Security
- Scoped API keys — bcrypt-hashed, prefix-identifiable, never stored in plain text.
- Sliding-window rate limiting and escalating brute-force IP blocks with a manual block/unblock console.
- Per-key IP allowlists, global bypass IPs, optional HTTPS enforcement, and key expiry.
- SSRF-validated media sideloading with redirect-hop re-verification and size caps.
- Protected meta — WordPress core internals and plugin stamps are never agent-writable.
- Single-site build: each free install manages exactly one site. Multi-site fleet management is available in the add-on.
Get Started in 3 Minutes
- Install DirectRelay and open the DirectRelay dashboard.
- Generate an API key — pick a scope preset or build your own.
- Paste the key into your n8n HTTP Request node (or import the OpenAPI spec) and your first automation is live.
Who Is DirectRelay For?
- AI content teams running generation pipelines through n8n workflows.
- Agencies managing publishing automation across client content operations.
- Headless WordPress builders who need a reliable, documented REST API.
- Anyone who wants WordPress and n8n to talk to each other — reliably and securely.
DirectRelay is free software licensed under the GPL. Use it, study it, modify it, redistribute it.
DirectRelay Pro (separate add-on plugin)
SEO metadata writes (Rank Math / Yoast), bulk publishing, human approval workflows, AI guardrails, advanced analytics, and dark mode are provided by the separate DirectRelay Pro add-on plugin, distributed from https://directrelay.wikiofautomation.com/directrelay-pro. The Pro add-on is never distributed via WordPress.org and is not required to use any free feature — the free plugin is fully functional on its own.
External services
This plugin supports optional integrations with external services. The services and their data handling policies are outlined below. All transmissions are initiated by the plugin only when the administrator has explicitly enabled the relevant feature; no data is sent silently or by default.
The free plugin distributed on WordPress.org does NOT use the following services: Envato/CodeCanyon purchase-code validation, license-server activation, or any third-party license check. There is no purchase code, license key, or activation token collected, stored, transmitted, or required to use any feature of the free plugin. (License management is provided by the separate DirectRelay Pro add-on plugin distributed from directrelay.wikiofautomation.com/directrelay-pro.)
n8n Webhooks (outgoing)
- What it is and what it is used for: DirectRelay dispatches signed JSON payloads to user-configured webhook URLs when WordPress post events occur. The webhook receiver can be n8n, Make, an AI agent, or any other HTTP endpoint the administrator chooses.
- What data is sent and when: The configured webhook target URL receives the post ID, title, full post content, status, taxonomies, and read-only SEO fields. Transmission only happens when the administrator has created an active webhook rule and the corresponding post event fires.
- Service Terms & Privacy:
- The webhook receiver is the user’s choice; DirectRelay itself does not transmit data to any third party by default.
- n8n (optional) Terms: https://n8n.io/legal/self-serve-terms/
- n8n (optional) Privacy: https://n8n.io/legal/
IndexNow
- What it is and what it is used for: Submits published post URLs to the IndexNow aggregator (api.indexnow.org), which routes them to participating search engines (Bing, Yandex, Seznam, Naver) for instant indexing. Pings fire when a post transitions to published; edits to already-published posts are not re-pinged.
- What data is sent and when: Sends the site hostname, the plugin-generated IndexNow key, the key-location URL (yoursite.com/indexnow-key.txt), and the published post URL. Transmitted only when the administrator enables IndexNow in plugin settings and a post transitions to published.
- Service Terms & Privacy:
- IndexNow Terms: https://www.indexnow.org/
- IndexNow Privacy: https://privacy.microsoft.com/en-us/privacystatement
Cloudflare API (optional)
- What it is and what it is used for: When a site administrator has configured a Cloudflare integration, the plugin can purge the Cloudflare edge cache for specific URLs after a WordPress post event.
- What data is sent and when: Sends the user-configured Cloudflare Zone ID, the user-provided API bearer token, and the specific post URLs to purge. Transmitted only when configured by the site administrator in outgoing webhook actions.
- Service Terms & Privacy:
- Cloudflare Terms: https://www.cloudflare.com/website-terms/
- Cloudflare Privacy: https://www.cloudflare.com/privacypolicy/
Third-Party AI APIs in n8n Workflow Templates (DeepSeek, Moonshot AI / Kimi, Alibaba Qwen)
- What it is and what it is used for: The Pro add-on plugin (separate download) ships copyable n8n workflow templates that demonstrate external AI models feeding WordPress via n8n. The free plugin itself does not call any third-party AI service directly; it only provides the REST endpoints that the n8n workflow calls.
- What data is sent and when: No data is transmitted directly by the WordPress plugin to these AI APIs. The workflow templates run entirely inside the user’s self-hosted or cloud n8n instance using the user’s own API credentials. The WordPress plugin only receives the AI-generated result via the n8n HTTP request back into the REST API.
- Service Terms & Privacy:
- DeepSeek Terms: https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html
- DeepSeek Privacy: https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html
- Moonshot AI Terms: https://www.moonshot.cn/
- Moonshot AI Privacy: https://www.moonshot.cn/privacy
- Alibaba DashScope / Qwen: https://www.alibabacloud.com/help/en/model-studio/terms-of-use
Screenshots






Installation
- Upload the plugin files to
/wp-content/plugins/, or install through the WordPress Plugins screen. - Activate the plugin.
- Open DirectRelay from the admin menu and run the built-in compatibility check.
- Create your first API key (DirectRelay API Keys) and connect it from n8n using either the
X-API-Keyheader or aBearertoken. - Optional: register an outgoing webhook under DirectRelay Webhooks to trigger n8n workflows from WordPress events.
FAQ
-
Does this require n8n?
-
No. DirectRelay exposes a standard WordPress REST API that any HTTP client can use — n8n, Make, custom scripts, AI agents, Postman, or your own code. The n8n-specific touches (OpenAPI schema, workflow presets, webhook payloads shaped for n8n) simply make n8n the smoothest experience.
-
Can n8n post to WordPress automatically?
-
Yes — that is the core use case. n8n can create, update, schedule, and publish WordPress posts and pages, upload media to the media library, and manage categories and tags through the REST API. AI agents can be scoped to drafts-only so generated content waits for human approval.
-
Does DirectRelay work with Make, Zapier, or Pabbly Connect?
-
Yes. The REST API and the signed outgoing webhooks are plain HTTP, so any automation platform can use them — Make, Zapier, Pabbly Connect, custom scripts, and AI agents included. Workflow presets and the OpenAPI spec are n8n-first, but nothing locks you to n8n.
-
Is this safe to run on a production site?
-
Yes. Keys are bcrypt-hashed and scoped, every route is permission-gated and rate-limited, failed authentications trigger escalating IP blocks, media sideloads are SSRF-validated on every redirect hop, and the plugin contains no SEO write path, no trial mode, and no license checks. A built-in compatibility checker verifies permalinks, REST access, and SSL from the dashboard.
-
Does it work with Rank Math AND Yoast SEO?
-
Yes — the free plugin reads SEO metadata from both, auto-detecting which plugin is active and returning one unified format. Writing SEO metadata is available through the separate DirectRelay Pro add-on.
-
Does it work with WooCommerce and Custom Post Types?
-
Yes. Products, orders, and any public custom post type work through the same REST surface, and the discovery endpoints let your n8n workflows enumerate post types and custom fields dynamically.
-
Can I use this on a multisite network?
-
The free build supports one site per install and cannot be network-activated on multisite. Multi-site and multi-domain management is available in the separate DirectRelay Pro add-on.
-
What happens to my keys if I uninstall the plugin?
-
Uninstalling removes all DirectRelay tables, options, and diagnostic logs. Revoke your keys before uninstalling if any n8n workflows are still calling them — revoked keys immediately stop working.
-
How do I rotate an API key without downtime?
-
Open DirectRelay API Keys, click Rotate on the key. A new secret is generated instantly while the key keeps its ID, scopes, and settings; update the key in n8n whenever you like. The old value stops working the moment you rotate.
-
Does it support the Block Editor (Gutenberg)?
-
Yes. Posts created through the API are standard WordPress posts — they open, edit, and publish normally in the Block Editor, and Gutenberg publishes fire the same webhooks as classic publishing.
-
Is there a limit on the number of API keys or webhooks?
-
Yes — one clear limit: the free version supports one active API key and one webhook per site. Revoking a key frees its slot; deleting a webhook frees its slot. There are no request quotas, no monthly caps, and the DirectRelay Pro add-on removes the key and webhook limits entirely.
-
Where can I get support?
-
Post in the WordPress.org support forum, or email help@directrelay.wikiofautomation.com with your WordPress version, plugin version, and a description of the issue.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“DirectRelay – n8n WordPress Plugin: Workflow Automation, REST API, Webhooks & AI Agents” is open source software. The following people have contributed to this plugin.
ContributorsInterested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
All notable changes are documented here. DirectRelay follows semantic versioning for its REST API: the endpoint contract under directrelay/v1 stays backward compatible within major version 5. DirectRelay is the n8n WordPress plugin for workflow automation — a complete WordPress REST API, signed WordPress webhooks, and scoped AI-agent access.
5.1.34
Release date: October 3, 2026
- New: One-time “Enjoying DirectRelay?” review prompt. It appears on DirectRelay screens only after the first successful webhook delivery or the first successful API call — never before something actually worked. Permanently dismissible with a hard two-week display cap, and it makes no external requests: the review form simply opens on WordPress.org.
- Listing: Keyword-tuned directory title, tags, short description, FAQ entries, and screenshot captions so the plugin surfaces for “n8n WordPress plugin”, “WordPress n8n integration”, “WordPress webhooks”, and related searches.
5.1.33
Release date: September 22, 2026
- New: The free version is now limited to one active API key and one webhook per site. Revoke a key or delete a webhook to free the slot. The DirectRelay Pro add-on removes both limits via the
directrelay_ext_key_limitanddirectrelay_ext_webhook_limitfilters. Existing keys and webhooks are never affected — only new creations are limited. - Improved: Admin hints now state the free key and webhook policy upfront instead of failing silently after the fact.
5.1.32
Release date: September 22, 2026
- Security: API keys are now strictly scoped to the DirectRelay REST namespace. A leaked key can no longer act as its bound WordPress user on core
/wp/v2routes or admin endpoints — the scope system can no longer be bypassed. - Security: Markdown links and images published through the API are protocol-checked and escaped, and heading, blockquote, list, and inline text is escaped — closing a stored-XSS surface for compromised agent keys.
- Security: All media sideload paths (featured image, gallery, and the
/media/sideloadendpoint) now validate every redirect hop against SSRF, cap response size, and support IPv6 and literal-IP hosts correctly. - Fix: Resolved a critical installation issue on standard MySQL servers where the API-keys and webhooks database tables silently failed to create (illegal TEXT column defaults). Existing sites are upgraded automatically on update.
- Fix: Markdown H2 headings (
##) kept their text on publish — a broken regex backreference previously wiped all H2 content converted through the default pipeline. - Fix: Create/update requests carrying an inline
seopayload no longer fail after saving; the free plugin reports SEO writes as skipped via aseo_writeresponse marker, and the add-on plugin owns SEO writes through a documented filter. - Improvement: Webhook management is fully functional in the admin — Pause/Activate, Delete, a test-fire dialog, and a per-attempt delivery log viewer now all work.
- Improvement: The API-key wizard now saves the AI Agent Role, approval, ownership, and velocity settings selected in the UI.
- Improvement: Signed webhooks send
X-DirectRelay-Timestampand a signed-timestamp header for replay protection. The existing body-signature header is unchanged, so current n8n verification workflows keep working. - Improvement: Manual IP blocks added from the Blocked-IPs console are now enforced on every API request (previously display-only), with correct UTC expiry handling.
- Improvement: Post-ownership isolation and drafts-only agent roles are enforced across create, update, publish, delete, and meta routes.
- Improvement: IndexNow pings honor the on/off setting on every code path, verify TLS, ping the single IndexNow aggregator, and log delivery failures instead of erroring. The key-file endpoint now matches exact paths only.
- Improvement: Delivery-log retention now runs even when webhooks are disabled, and log growth is bounded. Media events respect each webhook’s post-type selection, and
post.createdfires on the first real save rather than the editor’s empty shell. - Improvement: Full SQLite / WordPress Playground compatibility across authentication, analytics, and all log pruning.
- Changed: The free build now supports a single site per install. Multisite activation is refused, and multi-site fleet endpoints moved to the add-on plugin.
- Changed: Uninstall now removes all remaining options (including the IndexNow key) and diagnostic log files.
5.1.31
- Refreshed the directory listing metadata and restored the original banner artwork for maximum clarity at both WP.org sizes.
5.1.30
- Rebuilt the feature comparison section so it renders correctly in the WP.org readme parser, and refreshed the branded banner artwork.
5.1.29
- Indexer refresh release: re-issued the stable tag so the directory listing picks up the rewritten description, expanded FAQ, and new short description. No functional changes.
5.1.28
- Removed a duplicated External-services disclosure section that could prevent the readme validator from indexing the listing.
5.1.27
- Complete listing refresh: new directory icons and banners, six new screenshots, expanded FAQ, a full feature inventory, and copy-paste n8n workflow examples.
5.1.26
- Added the animated brand mark used for the directory thumbnail, with a static fallback for environments without animation support.
5.1.25
- Prefix cleanup: removed legacy identifier remnants so the entire codebase is uniformly
directrelay-prefixed.
5.1.24
- Directory-only assets removed from the distribution package; diagnostic logs moved to the uploads directory with safe paths.
5.1.23
- The free plugin became strictly read-only for SEO (WP.org serviceware guideline): SEO writes moved entirely to the add-on plugin, with a documented extension filter for add-on integration.
5.1.22
- Removed all trialware-pattern remnants and renamed every extension hook to the
directrelay_ext_*convention. Plugin Check: 0 errors, 0 warnings.
5.1.21
- Corrected the Plugin URI header so the plugin page and author profile resolve distinctly.
5.1.20
- PHP 8.0+ compatibility hardening and Plugin Check query-annotation cleanups.
5.1.19
- Full SQLite / WordPress Playground compatibility for rate limiting and brute-force tracking.
5.1.18
- Major reliability release: fixed the transactional publish pipeline, restored the SSRF guard on featured-image sideloads, enforced the admin retry budget, repaired agent-role checks, made IndexNow opt-in, and removed a broken parallel webhook dispatcher in favor of the hardened delivery manager.
5.1.0 – 5.1.17
- Initial WordPress.org release cycle: REST API for posts, pages, media, taxonomies, and meta; Rank Math and Yoast SEO reads; HMAC-signed outgoing webhooks with retries; self-hosted OpenAPI 3.0 spec; sliding-window rate limiter; brute-force protection; compatibility checker; and the add-on split with
directrelay_ext_*extension hooks. Multiple correctness and compliance fixes along the way, including REST authentication, admin asset loading, and OpenAPI introspection.
