# Automattic

**Canonical:** https://apis.io/providers/automattic/  
**Website:** https://automattic.com/  
**APIs profiled:** 9

Automattic is the company behind WordPress.com, Jetpack, WooCommerce, Tumblr, Gravatar, Akismet, WordPress VIP, Pocket Casts, Day One, Beeper and Simplenote. Its developer platform centres on the WordPress.com REST API at public-api.wordpress.com, which serves three parallel namespaces — the WordPress.com-native /rest/v1.x family, the WordPress-core-compatible /wp/v2 family, and the WordPress.com and Jetpack platform extensions in /wpcom/v2 — all behind a single OAuth 2.1 and OpenID Connect authorization server with PKCE, dynamic client registration and resource indicators. Every /rest/ version publishes a machine-readable help document and every /wp/ and /wpcom/ namespace publishes a route index, so the whole surface is self-describing even though Automattic does not ship OpenAPI for it. Automattic also runs a hosted Model Context Protocol server for WordPress.com, publishes OpenAPI for Akismet and for the Jetpack ai-plugin surface, and exposes a GraphQL Platform API for the enterprise WordPress VIP product.

## Kin Score — 56.8 / 100 (strong)

Scored 2026-08-24 under rubric 0.13.0. Trend: flat (-0.3 from 57.1).

| Facet | Score |
|---|---|
| Discoverability | 92.6 |
| Contract Quality | 35.7 |
| Governance | 30.3 |
| Contract Governance | 30.3 |
| Operational Transparency | 52.6 |
| Developer Ergonomics | 80.4 |
| Commercial Clarity | 60.5 |
| Access Clarity | 60.5 |

## Agent readiness — 62.3 (agent-ready)

| Dimension | Value |
|---|---|
| Spec Presence | yes |
| Agentic Access | derived |
| Reversibility Documented | documented |
| MCP Server | verified |
| Auth Clarity | served |
| Idempotency | no |
| Error Semantics | verified |
| OpenAPI Examples | partial |
| Rate Limit Signal | no |
| Event Surface Described | yes |
| Agent Skills | derived |
| Well Known Catalog | no |
| Consent Identity | yes |
| Agent Card | no |
| Dry Run Mode | yes |
| Delegated Identity | served |
| Protected Resource Metadata | verified |
| Dynamic Client Registration | yes |
| Agentic Commerce | no |

## APIs (9)

- **WordPress.com REST API v1.1** — The primary WordPress.com REST API. 253 endpoints covering sites, posts, pages, comments, media, taxonomy, menus, themes, stats, Reader subscriptions, notifications, sharing and...
- **WordPress.com REST API v1.2** — Additive alternate version of the WordPress.com REST API. Publishes only the 38 endpoints whose contract differs from v1.1; clients mix versions per endpoint rather than migrati...
- **WordPress.com REST API v1.3** — Additive alternate version of the WordPress.com REST API, publishing 19 endpoints including WordPress.com marketplace search.
- **WordPress.com REST API - wp/v2 namespace** — The WordPress core REST API shape as served by WordPress.com, site-scoped at /wp/v2/sites/{site}/. 348 operations across posts, pages, comments, media, taxonomies, block types, ...
- **WordPress.com REST API - wpcom/v2 namespace** — The WordPress.com and Jetpack platform extension namespace — 1,716 operations covering hosting and code deployments, domains and DNS, plans and checkout, marketplace, agency too...
- **WordPress.com MCP Server** — Automattic's hosted Model Context Protocol server for WordPress.com. Streamable HTTP transport secured with OAuth 2.1 (PKCE S256, dynamic client registration, token rotation, no...
- **Akismet API** — Akismet is Automattic's spam-classification service. Six operations — key verification, comment check, submit spam, submit ham, key sites and usage limit — authenticated with an...
- **Jetpack AI-Plugin API** — A small OpenAPI-described surface for listing and creating blog posts across a user's Jetpack and WordPress.com sites, published alongside the OpenAI plugin manifest at /.well-k...
- **WordPress VIP Platform API** — The GraphQL API for WordPress VIP, Automattic's enterprise WordPress and Node.js platform. Documented operation categories cover apps, domains, organizations, users, integration...

## MCP servers (1)

- **Automattic MCP Server**

## Agentic access (1)

- **Automattic Agentic Access** — 2384 operations · 1218 acting · 20 human-in-the-loop

## Security (4)

- **Automattic Authentication** — oauth2/openIdConnect/http/apiKey · 6 schemes
- **Automattic Domain Security** — TLSv1.3 · HSTS · DMARC
- **Automattic Vulnerability Disclosure** — Hackerone · security.txt · contact published
- **Automattic Trust Center** — FedRAMP Moderate, SOC 2 Type I, ISO 27001, SOC 1, GovRAMP, TX-RAMP

## Tags

Company, Content Management, Publishing, Blogging, Website Hosting, Web Publishing, Content, Comments, Spam Filtering, Media, Analytics, Domains, E-Commerce, Open-Source, Developer Tools, MCP

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/providers/automattic/). Scores are computed from the provider's own public artifacts under a published rubric.
