WP/Elementor MCP 401 on OVH (tres.ovh) — fix
Symptom: Claude MCP wordpress-elementor → AUTH_HEADER_REJECTED 401 rest_forbidden.
Even bogus creds returned rest_not_logged_in (instead of invalid_username) = auth never evaluated.
Diagnosis test (reusable):
curl -s -u "nobody_x:bad pass" "https://SITE/index.php?rest_route=/wp/v2/users/me"rest_not_logged_in→ header lost or app-password check skippedinvalid_username→ auth pipeline OK
Two causes, both needed fixing:
-
OVH shared hosting (Apache + PHP-FPM) strips
Authorization. Plain permalinks = no.htaccess. WP File Manager can’t create dotfiles → use OVH FTP Explorer.www/.htaccess:CGIPassAuth On SetEnvIf Authorization "(.*)" HTTP_AUTHORIZATION=$1 -
A plugin resolves current user before
REST_REQUESTis defined → WP skips app-password check.wp-content/mu-plugins/rest-app-password.php:<?php add_filter( 'application_password_is_api_request', function ( $is_api ) { if ( $is_api ) return true; $uri = $_SERVER['REQUEST_URI'] ?? ''; return isset( $_GET['rest_route'] ) || strpos( $uri, '/wp-json/' ) !== false; } );
Verified 2026-09-24: users/me → id 1 admin9451; MCP initialize → “Elementor MCP v1.0.0”.
Closed 2026-09-24: old app password revoked (verified incorrect_password), new one in ~/.claude.json, auth-test.php deleted (404).