Choose the setup path that matches where WordPress is hosted: WordPress.com and eligible Jetpack-connected sites use WordPress.com’s hosted MCP server, while a self-hosted site uses the WordPress MCP Adapter. Their endpoints and authentication methods are different, so use the matching settings below rather than swapping URLs or credentials.
Choose the right WordPress MCP connection
| Connection path | Endpoint | Transport and authentication | What it requires |
|---|---|---|---|
| WordPress.com hosted MCP | https://public-api.wordpress.com/wpcom/v2/mcp/v1 | Hosted HTTP connection; browser-based OAuth 2.1 | MCP enabled in the WordPress.com account. Available on paid plans and, for a free site, during its first 30 days after creation, according to WordPress.com. |
| Eligible Jetpack-connected site | Same WordPress.com hosted endpoint | Browser-based OAuth 2.1 | Jetpack AI or Jetpack Complete; WordPress.com says these sites use its hosted server, not a separate Jetpack endpoint. |
| Self-hosted WordPress with MCP Adapter | https://your-site.com/wp-json/mcp/mcp-adapter-default-server |
HTTP through a remote proxy, or local WP-CLI STDIO | Install the Adapter; for HTTP, configure the site URL and WordPress user credentials. For STDIO, use WP-CLI on the machine with the site. |
The WordPress.com plan and Jetpack eligibility details are documented in the WordPress.com MCP Server guide. Adapter transport and setup options are described by the WordPress Developer Blog and Learn WordPress.
Set up WordPress.com’s hosted MCP server
This route keeps the MCP server on WordPress.com. The documented endpoint is https://public-api.wordpress.com/wpcom/v2/mcp/v1; it is not the self-hosted Adapter route.
- In your WordPress.com account settings, enable MCP for the site.
- Add
https://public-api.wordpress.com/wpcom/v2/mcp/v1as the server URL in an MCP-capable client. - Complete the browser authorization prompt to connect your WordPress.com account.
WordPress.com documents OAuth 2.1 with PKCE, dynamic client registration, token rotation, and no need to enter client secrets manually or manage tokens yourself. To review or revoke access, go to Account settings → Security → Connected Apps. See the WordPress.com setup documentation for client-specific instructions.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Claude Code and Codex
For Claude Code, run the documented command in a terminal:
claude mcp add --transport http wpcom-mcp https://public-api.wordpress.com/wpcom/v2/mcp/v1
Then run /mcp in Claude Code and complete the browser authorization. For Codex, WordPress.com documents:
codex mcp add wpcom-mcp --url https://public-api.wordpress.com/wpcom/v2/mcp/v1
Other clients may present their own browser authorization flow. WordPress.com’s documented Claude Desktop route is through its Connectors Directory.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Set up the self-hosted MCP Adapter
Use this route when the WordPress site is self-hosted and you want its Adapter to expose abilities to an MCP client. Learn WordPress states that the Adapter requires WordPress 6.9 or later and PHP 7.4 or later. Its lesson describes installing the plugin from GitHub Releases, either by uploading the ZIP through WordPress admin or using WP-CLI; consult the lesson for the current installation steps.
The default endpoint pattern is https://your-site.com/wp-json/mcp/mcp-adapter-default-server. Replace the example host with your site’s actual scheme and domain. For a local WordPress installation on the same computer as the MCP client, Learn WordPress recommends WP-CLI STDIO: it needs no network connection and does not expose the site externally. For an HTTP connection, the Developer Blog documents use of the @automattic/mcp-wordpress-remote proxy.
HTTP proxy configuration
Use the following as a configuration pattern, replacing every example value with the real site URL and a dedicated WordPress user’s credentials. Treat the password as a secret; do not copy an example credential from a tutorial into a live configuration.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
{
"mcpServers": {
"wordpress-mcp-server": {
"command": "npx",
"args": ["-y", "@automattic/mcp-wordpress-remote@latest"],
"env": {
"WP_API_URL": "https://your-site.com/wp-json/mcp/mcp-adapter-default-server",
"WP_API_USERNAME": "your_wordpress_user",
"WP_API_PASSWORD": "your_application_password"
}
}
}
}
The HTTP example expects WP_API_URL, WP_API_USERNAME, and WP_API_PASSWORD. The documented example uses a WordPress application password; a custom OAuth arrangement may be used where the setup supports it. Refer to the Developer Blog configuration example.
Local WP-CLI STDIO
With STDIO, the client starts the Adapter through the local wp command instead of reaching a network URL. Configure the WordPress installation path, server identifier mcp-adapter-default-server, and a WordPress user in the client’s WP-CLI command configuration. The exact configuration varies by client; the Learn WordPress lesson provides the Adapter’s local example.
Recommended Free Tools
Put the configuration in the right client location
Client configuration formats are not interchangeable. In particular, the documented VS Code example uses a top-level servers key, while Claude Desktop and the Developer Blog’s proxy example use mcpServers.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Claude Desktop: Open Settings → Developer, then edit
claude_desktop_config.jsonand put server definitions undermcpServers. For the WordPress.com hosted route, the documented alternative is the Connectors Directory. - Cursor: Configure the connection in its Tools and MCP settings and configuration file.
- Claude Code: Add a server with the CLI, or configure it in a project
.mcp.jsonor home configuration. - VS Code: Use
.vscode/mcp.jsonand its top-levelserverskey.
These locations and examples are described in the WordPress Developer Blog. Client interfaces can change, so check the chosen client’s current documentation if labels or file formats differ.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Verify endpoint, transport, credentials, and permissions
Check the connection in this order so that a wrong route or configuration key is not mistaken for an authentication problem.
- Identify the hosting route. WordPress.com and eligible Jetpack-connected sites use the hosted endpoint. A self-hosted site needs the MCP Adapter and its own endpoint.
- Confirm the exact URL. The hosted path is
https://public-api.wordpress.com/wpcom/v2/mcp/v1. The Adapter default path is/wp-json/mcp/mcp-adapter-default-serveron your site. They are not interchangeable. - Match the transport and configuration key. Use browser OAuth for WordPress.com, HTTP proxy credentials for an Adapter HTTP connection, or local WP-CLI STDIO for a local Adapter. Verify the client’s expected top-level key, such as
serversormcpServers. - Check authentication. For WordPress.com, confirm MCP is enabled and finish the browser authorization. For self-hosted HTTP, verify the endpoint, username, and application password or supported OAuth configuration.
- Check local access and capabilities. For STDIO, make sure WP-CLI points to the intended WordPress installation. Use a WordPress user with only the capabilities required by the abilities the client will call.
- Check proxy routing. If an HTTP reverse proxy sits in front of the site, confirm it preserves the Host header and forwards the complete request path, including
/wp-json/mcp/. - Refresh the client. Restart or reload the MCP connection after changing settings or enabled tools so the client rediscovers the available tools. WordPress.com specifically recommends restarting the client during troubleshooting.
If a local remote-proxy connection still fails, the Developer Blog’s troubleshooting guidance points to multiple Node.js installations and local SSL certificate issues as items to check.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Understand discovery and execution permissions
Seeing an ability in discovery does not mean every user can run it. The Learn WordPress lesson says execution requires an authenticated user with the capabilities required by that ability’s permission callback. The project README states, “WordPress abilities are private by default.” Public discovery is opt-in; execution remains subject to authentication and WordPress permission checks.
When configuring either route, grant the connected WordPress user only the capabilities needed for the intended actions. Review the Learn WordPress lesson and the MCP Adapter README for permission behavior.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

