Authentication
Every request to Novamira is authenticated. There is no anonymous access. There are two ways to authenticate an AI client, OAuth sign-in and Application Password, and the Novamira > Configuration page shows the ones that fit the client you chose. The Novamira CLI signs in with OAuth on its own, and falls back to a device-code sign-in automatically when its browser is on another machine.
The three methods
- OAuth sign-in: your AI client connects and you approve it from your WordPress login, in the browser. No password to copy, and you can revoke it any time.
- Application Password: a WordPress credential, separate from your login password, sent as HTTP Basic authentication. The right choice when your client does not support OAuth, or when your host blocks direct connections from cloud AI clients.
Whichever you use, the connection is direct between your AI client and your site. Nothing passes through Novamira’s servers, and every request is authorized against your WordPress user’s capabilities.
There is no single recommended method for every site. The Novamira > Configuration page recommends the one that fits your situation: OAuth is the security-first default, but on hosting that filters cloud AI traffic it recommends the Application Password, and some clients (such as Claude.ai) only support OAuth.
OAuth sign-in
Available from Novamira 1.9.1. Your client opens a standard OAuth authorization flow and you approve access from your WordPress login. There is no password to store: access is issued as tokens that renew on use, and you revoke a client any time from Novamira > Manage Connections. OAuth requires HTTPS (or a local development environment). See Connecting Your AI Client for per-client steps.
Application Password
An Application Password is a WordPress core feature (since 5.6) that lets an application authenticate without your main login password. Your AI client (or the local MCP bridge it launches) sends the WordPress username and application password as HTTP Basic authentication; WordPress validates it and authorizes the request as that user.
HTTPS requirement
WordPress requires HTTPS for Application Passwords, to keep credentials from being sent in plain text. For local development without HTTPS, set the environment type in wp-config.php:
define( 'WP_ENVIRONMENT_TYPE', 'local' );
Do not use this workaround on remote servers. Remote connections must use HTTPS.
Creating and revoking
Create one from Novamira > Configuration (Application Password route), or from Users > Profile > Application Passwords. Copy it immediately; it is shown only once. Revoke it from Novamira > Manage Connections; any client using it loses access at once, and your other credentials keep working.
Best practices
- Create a separate application password for each AI client or workstation.
- Give each a descriptive name (for example, “Claude Desktop – MacBook”) so you can revoke the right one.
- Revoke passwords you no longer use. Manage Connections shows usage details to help you spot inactive ones.
Device code (the Novamira CLI, automatic)
Available from Novamira 1.11.3. Device code is not a method you pick. When you use the Novamira CLI and it runs where it cannot open a browser (a shell reached over SSH, a container), the CLI signs in with a device code on your behalf: it shows a short code, and you approve it from any device where you are signed in to this site. Only approve a code you started yourself.
Managing connections
Novamira > Manage Connections brings your OAuth connected apps and your Novamira Application Passwords together, with usage details and a revoke action for each. Revoking takes effect immediately.
What authentication does not do
Authentication verifies who you are, not what you can do. Once authenticated, your AI client acts with your WordPress user’s capabilities. There is no per-tool access control beyond the WordPress capabilities system; you decide what is exposed by enabling or disabling abilities in the Abilities Hub.