Vizzybl LogoVizzybl LogoVizzybl

WordPress Setup

Connect a WordPress site to Vizzybl: what to check first, the five steps, and what each refusal means.

Last updated

WordPress Setup

Connect a WordPress site so Vizzybl can save drafts and publish to it, from Create and from workflows. Available on Ultra and Enterprise. Only owners and admins of a workspace can connect a site. Start from Settings → Connections → WordPress.

Vizzybl signs in with a WordPress Application Password. No plugin is needed.

Before you start

Check three things on the site first. Each is a common reason a connection fails.

  1. HTTPS on your own domain, with a valid certificate. https://blog.example.com works. An http:// address or a self-signed certificate does not.
  2. Application Passwords are available. They are built into WordPress 5.6 and later, but WordPress hides them until the site runs on HTTPS, and some security plugins switch them off. If Users → Profile has no Application Passwords section, fix that first.
  3. A WordPress user with the Editor role. Create one for Vizzybl rather than using your administrator login. An Author can only write its own posts: it cannot write pages or update a page someone else made.

Connect

  1. In WordPress, sign in as that user and open Users → Profile → Application Passwords.
  2. Enter a name such as "Vizzybl" and click Add New Application Password. WordPress has its own guide to Application Passwords.
  3. Copy the password. WordPress shows it once.
  4. In Vizzybl, open Settings → Connections → WordPress, click Add site, and enter the Site URL, the WP Username and the Application Password. Label is the name you will see in Vizzybl; leave it empty to use the site's domain.
  5. Click Connect site.

Vizzybl signs in to the site before it saves anything, so a wrong address or password is refused straight away. The password is stored encrypted and is never shown again.

Connecting checks that the sign-in works. It does not check the user's role: a user who cannot publish connects, and is refused later when a post or page is written.

If it does not connect

MessageWhat to do
"WordPress sites must be connected over HTTPS."Use the https:// address. If the site has none, add a certificate first.
"The site has an SSL certificate problem."The certificate is self-signed, expired or issued for another name. Use the domain it was issued for, not an IP address.
"That domain didn't resolve."Check the address for typing mistakes, and that the site is public.
"That site URL is not allowed."The address points at a private network. Use the site's public address.
"WordPress rejected your credentials."Create a new Application Password and paste it again, with the username of the user it belongs to. Your normal WordPress password does not work here.
"Couldn't reach the WordPress REST API."Check the address, and that a plugin has not switched the REST API off. Plain permalinks are fine.
"That site URL redirects in a loop."Use the address shown in WordPress under Settings → General → Site Address, with or without www as it is there.
"WordPress didn't respond in time."The site is slow or down. Try again when it loads normally in a browser.

If a post or page is refused later

What you seeWhat to do
"Login succeeded but this user can't publish here."Give the user the Editor role, or check that a security plugin is not blocking the REST API.
Reconnect needed on the site's cardThe Application Password was revoked or changed. Disconnect the site and connect it again with a new one. If a workflow step names this site, choose the site again in the step's Site setting.

After connecting

Each site shows two safety settings on its card, which owners and admins can change:

  • Drafts only — nothing goes live. Nothing Vizzybl writes to the site is published while this is ticked.
  • New posts and pages a day. 10 unless you change it (1 to 100).

Workflows explains both, and the approval an owner or admin gives before anything goes live.

You can connect more than one site. To remove one, click the bin icon on its row and confirm. That deletes the stored password; then revoke the Application Password in WordPress.

Next steps

  • Workflows — Draft and publish pages, with approval before anything goes live
  • Content Rewriting — Rewrite a page and send it to your site
  • Connections — Manage all your connected services