WP/Elementor MCP 401 on OVH (tres.ovh) — fix

Symptom: Claude MCP wordpress-elementor → AUTH_HEADER_REJECTED 401 rest_forbidden. Even bogus creds returned rest_not_logged_in (instead of invalid_username) = auth never evaluated.

Diagnosis test (reusable):

curl -s -u "nobody_x:bad pass" "https://SITE/index.php?rest_route=/wp/v2/users/me"
  • rest_not_logged_in → header lost or app-password check skipped
  • invalid_username → auth pipeline OK

Two causes, both needed fixing:

  1. OVH shared hosting (Apache + PHP-FPM) strips Authorization. Plain permalinks = no .htaccess. WP File Manager can’t create dotfiles → use OVH FTP Explorer. www/.htaccess:

    CGIPassAuth On
    SetEnvIf Authorization "(.*)" HTTP_AUTHORIZATION=$1
  2. A plugin resolves current user before REST_REQUEST is defined → WP skips app-password check. wp-content/mu-plugins/rest-app-password.php:

    <?php
    add_filter( 'application_password_is_api_request', function ( $is_api ) {
        if ( $is_api ) return true;
        $uri = $_SERVER['REQUEST_URI'] ?? '';
        return isset( $_GET['rest_route'] ) || strpos( $uri, '/wp-json/' ) !== false;
    } );

Verified 2026-09-24: users/me → id 1 admin9451; MCP initialize → “Elementor MCP v1.0.0”.

Closed 2026-09-24: old app password revoked (verified incorrect_password), new one in ~/.claude.json, auth-test.php deleted (404).