We'll create fresh WordPress site with Secure XML-RPC installed. You have 20 minutes to test the plugin after that site we'll be deleted.
Rather than sending usernames and passwords in plain text with every request, we’re going to use a set of public/secret keys to hash data and authenticate instead.
On your WordPress profile, you will see a new “Remote Publishing Permissions” section listing out the applications that have permission to publish, along with their public and secret keys.
New applications can be added whenever you want. You can also change the names of applications, or revoke publishing permission by deleting them.
Lock graphic designed by Scott Lewis from the thenounproject.com