WP MCP Server releasesself-updates
Exposes a Model Context Protocol (MCP) server on your WordPress site, allowing AI agents to connect and interact with your site's REST API.
Install
The author publishes release zips, so WP-CLI can install straight from GitHub:
wp plugin install https://github.com/lapsrj/wp-mcp-plugin/releases/download/v1.1.1/wp-mcp-plugin.zipShips its own WordPress updater (built-in updater), so new versions show up under Dashboard → Updates.
Readme
WP MCP Plugin
A WordPress plugin that exposes a Model Context Protocol (MCP) server on your site, allowing AI agents to connect and interact with your content through the REST API.
Features
- Streamable HTTP transport — agents connect directly via your site URL
- Automatic route discovery — all REST API routes become MCP tools (posts, pages, media, users, WooCommerce, ACF, custom post types, etc.)
- OAuth 2.1 authentication — MCP clients authenticate automatically via browser login and consent (PKCE, no tokens to manage)
- Basic Auth support — also supports Application Passwords for clients that don't support OAuth
- Settings page — generate auth tokens and copy-ready config snippets in one click
- Endpoint filtering — allowlist/blocklist endpoints by category (Post Types, Taxonomies, Core, Plugin) or use Compact Mode
- Description control — per-category verbose/minimal tool descriptions to optimize token usage
- ACF support — detects Advanced Custom Fields and adds ACF parameters to writable routes
- Media uploads — supports base64 file uploads via MCP
- Zero configuration — activate and connect
Installation
- Download the latest release
- Upload the zip via Plugins > Add New > Upload Plugin (or extract to
/wp-content/plugins/) - Activate the plugin through the Plugins menu
- Go to Settings > MCP
- Copy the config snippet for your MCP client
Client Configuration
The MCP endpoint is at:
https://your-site.com/wp-json/mcp/v1
OAuth 2.1 (Recommended)
MCP clients that support OAuth will authenticate automatically — they open your browser, you log in to WordPress and approve the connection. No tokens to copy or manage.
Claude Desktop
Add to claude_desktop_config.json:
{
"mcpServers": {
"wordpress": {
"url": "https://your-site.com/wp-json/mcp/v1"
}
}
}
Claude Code / Cursor
Add to .mcp.json:
{
"mcpServers": {
"wordpress": {
"type": "streamable-http",
"url": "https://your-site.com/wp-json/mcp/v1"
}
}
}
Basic Auth (Legacy)
For clients that don't support OAuth, you can use Application Passwords directly.
- Go to Settings > MCP
- Select a user and click Generate Connection
- Copy the config snippet with the embedded auth token
Claude Desktop
{
"mcpServers": {
"wordpress": {
"url": "https://your-site.com/wp-json/mcp/v1",
"headers": {
"Authorization": "Basic YOUR_TOKEN"
}
}
}
}
Claude Code / Cursor
{
"mcpServers": {
"wordpress": {
"type": "streamable-http",
"url": "https://your-site.com/wp-json/mcp/v1",
"headers": {
"Authorization": "Basic YOUR_TOKEN"
}
}
}
}
Use the Settings > MCP page to generate
YOUR_TOKENautomatically. The token is shown only once — generate a new one if you lose it.
Settings
All settings are under Settings > MCP > Settings tab.
Endpoint Filtering
Control which REST API endpoints are exposed as MCP tools. Four modes are available:
| Mode | Behavior |
|---|---|
| All Endpoints | Every discovered REST API route is exposed. (Default) |
| Allowlist | Only the selected endpoints are exposed. |
| Blocklist | All endpoints are exposed except the selected ones. |
| Compact Mode | Replaces all tools with a single universal wp_api tool for minimal token usage. |
In Allowlist and Blocklist modes, endpoints are grouped by category:
- Post Types — routes for registered post types (posts, pages, custom post types)
- Taxonomies — routes for registered taxonomies (categories, tags, custom taxonomies)
- Core — other
/wp/v2/*routes (users, comments, settings, search, etc.) - Plugin — non-core namespaces (
/wc/v3/*,/acf/v3/*, etc.)
Each category has:
- A group checkbox to select/deselect all endpoints in the category
- An "Include new items" toggle — automatically includes newly discovered endpoints in that category (e.g. after installing a plugin or registering a custom post type)
Tool Descriptions
Control which tools get verbose descriptions vs minimal one-liners. Minimizing descriptions reduces token usage on every tools/list call.
| Mode | Behavior |
|---|---|
| All Verbose | Every tool gets full verbose descriptions. |
| Allowlist | Only selected tools/categories keep verbose descriptions; the rest get minimal. |
| Blocklist | All tools are verbose except selected ones, which get minimized. |
| All Minimal | Every tool gets minimal one-liner descriptions. (Default) |
The Allowlist and Blocklist modes use the same category-based grouping as endpoint filtering, with per-category "Include new items" toggles.
When switching to Allowlist mode for the first time, Post Types and Taxonomies are pre-selected as verbose, while Core and Plugin default to minimal.
How It Works
- The plugin registers a REST API endpoint at
/wp-json/mcp/v1 - MCP clients discover OAuth metadata via
/.well-known/oauth-protected-resourceand authenticate through your WordPress login - When connected, the client discovers all registered WordPress REST routes
- Each route becomes an MCP tool with its parameters derived from the endpoint schema
- Tool calls are executed as internal REST API requests (no HTTP overhead)
- The authenticated user's permissions apply to all operations
Tool Naming
Routes are converted to underscore-separated tool names:
| Route | Tool Name |
|---|---|
/wp/v2/posts |
posts |
/wp/v2/posts/(?P<id>[\d]+) |
posts_id |
/wp/v2/categories |
categories |
/wp/v2/media |
media |
/wc/v3/products |
wc_v3_products |
/acf/v1/posts/(?P<id>[\d]+) |
acf_v1_posts_id |
Every tool accepts a method parameter to specify the HTTP verb (GET, POST, PUT, PATCH, DELETE).
Requirements
- WordPress 6.0+
- PHP 7.4+
- HTTPS recommended (required for Application Passwords on most setups)
License
Read the full README on GitHub →
Releases
| Tag | Published | Asset | Downloads |
|---|---|---|---|
| v1.1.1 | Mar 14, 2026 | wp-mcp-plugin.zip | 8 |
| v1.1.0 | Mar 14, 2026 | wp-mcp-plugin.zip | 7 |
| v1.0.9 | Mar 14, 2026 | wp-mcp-plugin.zip | 3 |
| v1.0.8 | Mar 14, 2026 | wp-mcp-plugin.zip | 3 |
| v1.0.7 | Mar 14, 2026 | wp-mcp-plugin.zip | 3 |
| v1.0.6 | Mar 14, 2026 | wp-mcp-plugin.zip | 2 |
| v1.0.5 | Mar 6, 2026 | wp-mcp-plugin.zip | 0 |
| v1.0.4 | Mar 5, 2026 | wp-mcp-plugin.zip | 1 |
| v1.0.3 | Mar 2, 2026 | wp-mcp-plugin.zip | 0 |
| v1.0.2 | Mar 2, 2026 | wp-mcp-plugin.zip | 4 |
| v1.0.1 | Mar 2, 2026 | wp-mcp-plugin.zip | 1 |
| v1.0.0 | Mar 2, 2026 | wp-mcp-plugin.zip | 4 |