Create Accountor Login
Docs

WordPress MCP Connector

Setup, configuration and reference for WordPress MCP Connector. Updated October 1, 2026

Free on WordPress.org

MountDev AI MCP Connector for WordPress

Install it straight from the WordPress plugin directory, or search for it in your own dashboard under Plugins, Add New. It is free, GPL licensed, and published by Cascadia Web Services.

Updated October 1, 2026

What the connector does

The WordPress MCP Connector is a free plugin that turns your WordPress site into an MCP server. Once it is installed, an AI client such as ChatGPT, Claude, Cursor or Windsurf can read and change things on your site directly, using tools rather than by you copying text back and forth.

The problem it solves is narrow and familiar. An assistant will happily write you a product description, a redirect rule or a page of copy, and then you become the transport layer. You open wp-admin, find the right screen, paste, save, and do it again for the next one. Everything the assistant knows about the site is whatever you remembered to paste in the other direction. The connector removes both halves of that. The assistant reads the real site and writes back to it.

It runs on your own server. There is no relay service in the middle, nothing is proxied through us, and no copy of your content goes anywhere else. The plugin is the whole product and it is free, with no paid tier waiting behind it.

How the connection is actually made

Activating the plugin adds one JSON-RPC 2.0 endpoint to your site, under wp-json on your own domain. That single endpoint serves every client. There is no middleware to host, no daemon to keep alive and no separate service to open an account with, which is why the plugin has zero external dependencies, no Composer install and no build step.

Because the endpoint speaks an open standard rather than a vendor format, one server works with many clients. Model Context Protocol is published by Anthropic as a shared specification, so a client that adopts it later should connect without waiting on a plugin update.

What an agent can actually reach

The connector’s own tools cover WordPress core: posts, pages, media, comments, users, taxonomies, menus, plugins, themes and site settings, which is most of what an editor does in wp-admin. They work on a plain WordPress site with nothing else installed.

Everything past core comes from WordPress Abilities. WordPress 6.9 added a standard way for a plugin to describe what it can do, what it needs and who may use it. Any plugin that registers abilities gets tools in the connector, grouped by the plugin’s own categories, with nothing extra to install or configure. When the plugin updates its abilities, your assistant sees the change. Since version 2.2.0 each ability’s title names the plugin it comes from, such as FluentCRM: Get Contact, and one ability with a schema an AI client rejects no longer breaks the whole tool list. On WordPress older than 6.9 the connector’s own tools work as before.

Version 2.0.0 removed the connector’s own tools for WooCommerce, Rank Math, Yoast SEO, Elementor, Jetpack and Contact Form 7. Each was code that had to keep in step with another plugin’s updates. Several of those plugins now describe their own actions as abilities, which is the better source, so what an agent can do in them is whatever that plugin chose to offer. Sites that have been built on for a few years, which is most of the ones we see through managed WordPress work, usually run several plugins, so check which of yours register abilities before planning work around them.

Since version 1.7.0 there are also precise edits. An assistant can change one sentence on a page, or one spelling across many pages, without resending the whole page. Every change is previewed as the sentence before and after, backed up, read back and checked after saving, and undone automatically if the check fails. Precise edits change visible text only, never links, image addresses or code. From 1.7.1 each one is listed on the Changes tab with the page, what changed, when and by whom, and you can undo it from there yourself. Since 2.2.0 each change reads as a short sentence, with the full before and after text behind Show details. Version 1.8.0 adds duplication. An assistant can copy a post, page or product as a new draft, keeping the content, the layout as your builder stored it, the featured image, the page template and the terms. The copy is always a draft, and it is refused unless the connected account may edit what is being copied. Version 2.0.0 extends precise edits to SiteOrigin Page Builder, Zion Builder, Live Composer and the new widgets in Elementor 4.

Profiles, which are the part that matters

Profiles decide what any given connection can see, so a content profile exposes posts and media and nothing else, while an administrative profile exposes more. You can define your own, which is what most people settle on once they know which dozen tools they actually use. Abilities from other plugins start switched off in every profile, Full Access included, and you turn on the ones you want profile by profile. Tools that can change your site are labeled Write, and those that may delete or overwrite are labeled Destructive.

Underneath profiles sits a second and harder limit. Every tool call runs the same capability check WordPress applies in wp-admin, against the account the connection authenticated as. Connect as an editor and no profile will let the agent install a plugin, because the account genuinely cannot. Two independent controls, and the tighter of the two wins. Abilities are checked a little differently. WordPress checks the request against what the ability accepts, then asks the ability whether the signed-in user may use it. Checking which records that user may touch is up to the plugin that registered the ability. If the account hygiene on the site is not what it should be, that is the real ceiling and it is worth fixing before anything else, which is the ground managed WordPress security covers.

This is scoping at the site level, and it is worth understanding alongside the scoping in MCP Router, which decides per person and per tool across several servers at once. The plugin controls what exists on this site. The router controls who reaches it. Sites that only ever have one operator can stop at profiles. Teams and agencies usually want both.

Authentication done properly

ChatGPT and Claude connect over real OAuth 2.0 with PKCE rather than a shared key pasted into a settings box. You paste your site address into the assistant and sign in to WordPress. Since version 1.6.8 there is no client ID or secret to generate first, because both identify themselves with a metadata document they publish, and the approval screen names the app asking and the domain that published it. Cursor, Windsurf and other editors connect with a WordPress Application Password, and the Client Setup tab writes their configuration for you.

The details matter more than they look. Authorization codes expire after ten minutes, and PKCE ties a code to the client that requested it, so an intercepted code cannot be redeemed by anyone else. Access tokens last an hour. Refresh tokens last thirty days and rotate on renewal, so a leaked token stops being useful quickly instead of granting quiet access indefinitely. Client secrets are encrypted with AES-256-CBC before they reach the database, which means a stolen export or a nightly backup does not hand over working credentials.

Only administrators can issue OAuth credentials. Approving a connection takes a logged-in WordPress user and an explicit Approve on the consent screen, and the connection then acts as that user, with that user’s role and nothing more. Releases up to and including 1.6.3 had a critical authorization bypass, fixed in 1.6.4, so upgrade before you connect anything. Revocation is equally plain. Remove the Application Password or the OAuth grant in WordPress and the connection stops, with nothing else to rotate and nobody to email. Deleting the plugin, rather than deactivating it, also removes every credential and token it stored.

Back to top

Where it earns its place

Content teams publishing at volume

The work that eats a content team is rarely the writing. It is formatting, setting categories and tags, attaching media, filling SEO fields and scheduling. With the core tools, plus any abilities your SEO plugin registers, an agent does that part against the real site instead of handing you text to paste.

Give that connection a content profile. There is no reason for a publishing workflow to reach user accounts or settings, and the smaller the surface, the less there is to think about later. Apply the same instinct to the account it authenticates as. An author or an editor, not an administrator, so the capability check underneath is doing real work rather than waving everything through.

The archive is the other half of it, and it is the safer half. Ask what is already published on a subject before commissioning another piece. List the posts whose meta description was never filled in. Find everything last touched more than two years ago. Those are read-only questions, they cannot damage anything, and they are the fastest way to find out whether the connection deserves to be widened.

Stores, SEO and forms, through the plugins themselves

Bulk product edits, meta descriptions missing across hundreds of pages, and a form that stopped delivering months ago are the jobs nobody wants and everybody postpones. The connector reaches them through the abilities WooCommerce, your SEO plugin or your form plugin registers, not through tools of its own. What an agent can do there is exactly what that plugin offers, and each ability stays off until you switch it on under Access.

Two cautions still apply. These are writes, so take a backup you have actually restored from before turning an agent loose on a live store or a site’s SEO settings. And ask for a small batch first and check the result before scaling up, because a wrong instruction applied to four thousand products is a bad afternoon. It is the same reasoning as testing an update on staging, which we set out in the piece on what maintenance mode does not protect.

One thing worth saying plainly. A large bulk edit is a great many database writes in a short window, and on shared hosting that is felt. If the site is already slow under ordinary load, the connector is not what will fix it, and the honest sequence is performance work first and bulk automation second.

Agencies running many client sites

The plugin is per site, so twenty clients means twenty servers. That is where a gateway stops being optional. Attach each site as a provider in MCP Router, grant staff access per client, and revoke centrally when an engagement ends.

Without that, offboarding means asking people to remove entries from their own configuration, which is a request rather than a control. If you deliver under a white label arrangement, being able to demonstrate when access ended is worth having before a client asks for it.

The same holds under a reseller arrangement, where the end client relationship is not yours and the boundary matters more rather than less. One credential per site, one profile per connection, and a record of who held what.

Small teams without a developer

This is a finished plugin, not a developer library. You install it, pick a profile and connect a client. Nothing is compiled and no code is written, which is the entire reason it exists in this form.

The tasks that suit it best are the ones that feel technical but are really just tedious. Updating a page, fixing a form, working out why an email stopped sending. Describing the problem to an assistant that can look at the actual site beats hunting for a tutorial written against a version of WordPress you are no longer running.

If the site itself is what is holding you back rather than the tooling, that is a different problem and it is what managed WordPress is for. And if the work you want automated reaches past WordPress into the systems around it, the connector is one input to a larger design rather than the whole answer, which is where business process automation starts.

Back to top

Setting it up, and what it is not

Three steps

Install the plugin and pick a profile on the Access tab. Connect your AI client: paste your site address into ChatGPT or Claude and sign in, or use an Application Password for Cursor, Windsurf and other editors. Then put it to work. On a site you already administer the whole thing takes about ten minutes.

Start with a narrow profile and a read-only task on the first day. Ask the agent to list something, or to summarize what is on the site. Once you have seen it read correctly, widen it. The instinct to grant everything immediately and test with a real change is the one to resist.

A worked first hour

Install from the WordPress Plugin Directory and activate. Open Settings, then MCP Connector, and on the Access tab select a read-only profile. Do not connect anything yet.

Decide which account the connection will authenticate as. If the answer is your own administrator account, because that is the one you happen to be logged into, stop and create a separate account at the lowest role that can do the job. This one decision sets the ceiling on everything that follows, and it is much harder to change later once people are relying on the connection.

For Cursor, Windsurf or another editor, log in as that account, create an Application Password under Users then Profile, and copy it. Open the Client Setup tab, which generates the configuration block for your client with your own endpoint already filled in, and paste it across. For ChatGPT or Claude, copy the address shown on the settings page, add it as a custom connector in the assistant, and leave any Client ID and Secret fields empty. When the WordPress window opens, sign in as that account and approve the request. The connection then acts as that account and nothing more.

Ask a read-only question first. Something as dull as listing the ten most recently modified posts. If real titles from your site come back, then the transport, the authentication and the profile are all working, and you have proved it without changing a byte.

Then widen once, not twice. Move to a profile that permits writing and make one small change you can verify by eye. A meta description on a single page, or a category on a single post. Go and look at it in wp-admin. Only once that has come back correct is it reasonable to ask for anything in bulk.

The sequence takes under an hour and it moves every likely failure into a moment where nothing is at stake.

Prerequisites

WordPress 5.8 or higher and PHP 7.4 or higher. The current release is 2.2.0, tested up to WordPress 7.1.2. Tools from other plugins need WordPress 6.9 or later, because that is when WordPress added Abilities.

The site has to be served over HTTPS. WordPress requires that for Application Passwords whatever plugin you are using, so a site still on plain HTTP cannot connect Cursor, Windsurf or any other editor that uses them. Most hosts now issue certificates as standard, and if yours does not, that is worth solving before anything else here. It is one of the things managed hosting takes off your hands.

The site also has to be reachable from the internet. A hosted client such as ChatGPT connects inbound to your endpoint, so a site behind HTTP basic auth, on a private network, or on a staging domain that blocks outside traffic will not be reachable by it. That is a networking condition rather than a plugin limitation, and it is the most common reason a first connection fails.

You need an administrator account to set it up, because only administrators can open the plugin’s settings and issue credentials. You do not need one to use it afterward, and you should not use one.

And you need an AI client that speaks MCP. The plugin is the server half of the connection. It does not include a client and it is not one.

When the connection does not work

Check these in order. Each one is cheaper to test than the one after it.

First, is the site reachable from outside your own network over HTTPS. Load it on mobile data with wifi turned off. If that fails, nothing after this matters yet. If it loads, run Test Connection on the Endpoints tab. Since version 2.2.0 it also checks the site from outside, the way ChatGPT and Claude reach it, through your CDN, firewall and host, and names what is in the way and who answered. A site can load in a browser and still turn AI clients away. We have seen a host’s server refuse anything that identified as a Python client, so ChatGPT reported that PKCE support was missing when it never saw the settings at all. Copy report gives a plain-text version to send to your host, who will need to allow /.well-known/oauth-authorization-server, /.well-known/oauth-protected-resource, /wp-json/mountdev-ai-mcp-connector/ and /mcp-token for all visitors.

Second, did the authorization complete. The assistant opens a WordPress sign-in window, and the connection only exists once someone signs in and clicks Approve on the consent screen. If that window was closed early, start again from the assistant.

Third, does the profile you selected actually include the tool you are asking for. This is the single most common cause of a tool appearing to be missing, and from the client side it looks identical to the plugin not supporting the feature at all.

Fourth, if the tool comes from another plugin, is that plugin active and is its ability switched on. Abilities exist only while the plugin that registers them is active, and every one starts switched off in every profile, Full Access included. Switch it on under Access, then restart your assistant. A tool that is present on one site and missing on another is nearly always this. Test Connection also names any ability that is switched on but never reaches the assistant, which happens when a plugin registers its abilities only on admin pages.

Fifth, if a call is refused rather than absent, check whether the connected user holds the WordPress capability for it. Capability checks run on every call, and a subscriber level account will be stopped exactly as it should be. A refusal at this layer is the system working, not failing.

Sixth, if a connection worked yesterday and does not today, check whether the Application Password or the OAuth grant was revoked, and whether a refresh token has gone thirty days without use. Both expire quietly and neither announces itself.

What it is not

It is not a hosted service, and that cuts both ways. Nothing is proxied through anybody else, and equally nobody else is watching whether it is up. If the site goes down the connection goes with it, and no one gets paged.

It is not a developer library. If what you wanted was primitives for building your own tools, the official WordPress MCP adapter is that, and it is the right choice for shipping your own integration. This is the finished thing instead. The two serve different people and we would tell you so.

It does not supervise the agent. Profiles decide what is reachable and WordPress capabilities decide what is permitted, but inside those bounds an agent does what it is asked. There is no approval queue. Precise edits are previewed first, backed up, and can be undone from the Changes tab. Other tools write directly, with no dry run and no undo, so scope deliberately and keep a restorable backup, which is the same advice as for any tool that can write to your site.

It does not reach what a plugin does not offer. Tools for other plugins come from the abilities those plugins register. If a plugin registers none, or none for the setting you need, it is not addressable, and no profile setting will make it so.

It is not a full audit log either. The Changes tab lists every precise edit with the page, what changed, when and by whom, kept for 30 days by default and up to a year. Everything else the connected account does is recorded only the way WordPress records any account’s activity.

And it is free with no upgrade path. It is published on WordPress.org under GPL v3, every feature ships in the free version, and there is no premium tier for anything described here to move behind later.

Where to go next

The full tool inventory and the install notes are on the WordPress MCP Connector product page.

If you are connecting more than one or two servers, read the MCP Router documentation before you wire them up individually. Retrofitting a gateway once everybody has their own configuration is harder than starting with one.

And if you would rather not make the profile and account decisions yourself on a site that matters, that is part of managed AI work and it is a reasonable thing to hand over.

Ask Us Anything

We’d love to hear from you!