WordPress MCP Connector
Turn Your WordPress Site Into An MCP Server
What makes it different
In detail
What each part actually does
Activating the plugin turns the site you already run into an MCP server. Nothing else to host, nothing else to sign up for.
How the connection is made
The plugin adds one JSON-RPC 2.0 endpoint under wp-json on your own domain, and that single endpoint serves every client.
There is no middleware to host, no daemon to keep alive and no separate service to open an account with. Zero external dependencies, no Composer install, no build step.
What an agent can reach
Its own tools cover WordPress core: posts, pages, media, comments, users, taxonomies, menus, plugins, themes and settings, which is most of what an editor does in wp-admin. That works on a plain site with nothing else installed.
Everything past core comes from WordPress Abilities, the standard way added in WordPress 6.9 for a plugin to describe what it can do and who may use it.
Profiles, the part that matters
A profile decides what a given connection can see. A content profile exposes posts and media and nothing else. An administrative profile exposes more. You can define your own, which is what most people settle on once they know which dozen tools they actually use.
Abilities from other plugins start switched off in every profile, Full Access included, and you turn them on profile by profile.
Authentication done properly
ChatGPT and Claude connect over real OAuth 2.0 with PKCE rather than a shared key pasted into a settings box. You paste your site address into the assistant and sign in to WordPress.
Since 1.6.8 there is no client ID or secret to generate first, because both sides identify themselves with a published metadata document, and the approval screen names the app asking and the domain that published it.
It runs on your server, not ours. The endpoint is on your domain, the profiles are yours to set, and nothing about your site passes through us.
What you get
Everything the plugin can reach
All 21 of these ship in the free plugin, which you install and run yourself.
Integrations and security
- MCP server endpoint
- WordPress core tools
- Zero external dependencies
- ChatGPT via OAuth 2.0
- Claude via OAuth 2.0
- OAuth 2.0 with PKCE
- Capability checks on every call
- Admin-only authorization
- WordPress Abilities from any plugin
What sets it apart
- Real OAuth, not a shared key
- Profiles decide what agents see
- Your server, no middleman
- Works with any plugin’s Abilities
- One endpoint, every client
- Free, with no upgrade path
- Profile-based access control
- Encrypted client secrets
- Token expiry and refresh
- Cursor and Windsurf support
- Guided client setup
- Precise edits, previewed and reversible, and duplication of any page, post or product as a draft
Ready to install WordPress MCP Connector?
Most people have it running in a few minutes, and the setup guide covers each screen along the way.
The two other ways to put an agent inside WordPress
Most alternatives fall into one of two groups: a developer library you have to write code against, or a bare-bones server that offers a handful of endpoints and stops there.
| What to compare | How it works here |
|---|---|
| Finished plugin vs developer library | Here you install the plugin, pick a profile and connect. The official WordPress adapter is a library for turning your own abilities into tools, so someone has to write and maintain PHP before an agent can do anything. |
| OAuth for ChatGPT vs tokens only | ChatGPT connects over OAuth here. A server that only accepts bearer tokens or Basic Auth may run fine in Claude Desktop and Cursor, yet ChatGPT users never get past the first screen. |
| Opt-in abilities vs everything at once | Any plugin that registers WordPress Abilities gets tools here, and each stays off until you switch it on, marked Write or Destructive when it can change things. Without that step, whatever a server exposes is open to every connection. |
| Scoped profiles vs all or nothing | Profiles let you hand an agent a read-only connection. With no permission layer, a server exposes everything the signed-in user can do, so there is no way to offer a safe research-only link. |
| Encrypted secrets vs plaintext options | Client secrets are stored encrypted. A plugin that writes API credentials into the options table as plain text gives them away in every database export and nightly backup. |
| Self-hosted vs relay service | Your MCP client talks to the REST API on your own site. No relay service sits between them, so your content does not pass through anyone else on the way. |
Cost
What it costs
The plugin is free. The only things you pay for are ones you already have.
The plugin
Free on WordPress.org, with no per site license and no paid tier holding features back. Install it on one site or on fifty.
Your hosting
It runs inside the WordPress site you already pay to host. There is no service of ours in the middle and nothing extra to run.
Your AI tools
Whatever you use to connect, ChatGPT, Claude, Cursor or Windsurf, is billed by whoever provides it. We are not between you and them.
If you would rather not run it yourself, we manage WordPress for other companies, and that is a separate service rather than a license for this plugin.
Content teams publishing at volume
Stores with big catalogs
Agencies running many client sites
1. Install and pick a profile
2. Connect your AI client
3. Put it to work
Free on WordPress.org
MountDev AI MCP Connector for WordPress
Get it from the WordPress plugin directory, or find it from your own dashboard under Plugins, Add New. Cascadia Web Services publishes it for free under the GPL.
Documentation
How the connection is made, what an agent can reach, profiles, authentication, prerequisites and what to do when the connection will not hold.