Agent Role
A WordPress role for accounts that cannot log in as people. One application password each, with an optional gate for the official MCP Adapter.
Install
No release zip yet. The repository archive installs, but the folder name will carry the branch suffix and updates will not flow:
wp plugin install https://github.com/roots-and-fruit/agent-user/archive/refs/heads/main.zipGive an AI its own WordPress account. That account can publish and upload. It cannot sign in as a person, reset a password, or open wp-admin.
You keep your own login. If you stop trusting the connection, you revoke one password. Your admin password never goes into ChatGPT, Cursor, or Claude.
What you get
- A user role named Agent, with the same publishing power as an Author.
- A screen at Users → Add Agent that creates the account for you.
- One application password, shown once, in a window with a Copy button on the site address, the username, the password, and the connection details.
- A page for each agent where you choose what that account can do, which abilities it may run, and the note it receives when it connects.
- A normal Users screen that does not offer the Agent role. People stay people. Agents stay agents.
- Revoke on the agent list when you want a new password.
An Agent can create, edit, publish, and delete its own posts, and it can upload files. It cannot change settings, install plugins, edit other people's posts, or manage users.
Connect an AI
- Install and activate Agent Role.
- Open Users → Add Agent.
- Enter a username and a display name. Create the account.
- Copy the password from the window. WordPress will not show it again.
- Paste it into the tool that needs access to your site.
That password works as the REST API password. Your real login password does not work for this account, and the lost-password email does not either.
If the official WordPress MCP Adapter is also active, the agent list can show a ready-made config for Cursor, Claude Desktop, and other MCP apps. The password in that config is a placeholder. Paste the one you copied when the account was created. A setting on the Settings tab, off until you turn it on, limits that connection to Agent accounts. Your own admin password then cannot open it. Each agent can also keep a short note that the adapter sends when that account connects.
If you turn the plugin off
Deactivating Agent Role leaves the accounts in place. They keep the Agent role. The blocks on password login come back when you activate the plugin again.
Deleting the plugin removes the Agent role and the passwords this plugin created. It does not delete the user accounts. A password you created yourself, even one you named "Agent Role," is left alone.
Requirements
WordPress 6.0 or newer. PHP 7.4 or newer. The site must use HTTPS, because WordPress only offers application passwords on a secure site.
License
GPL-2.0-or-later. See readme.txt.