Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start by identifying which WordPress MCP setup is failing: the WordPress.org MCP server for Plugin Directory tasks, or a self-hosted WordPress MCP Adapter that exposes a site’s registered Abilities. They use different credentials, endpoints, and launch methods, so a password reset is not a universal fix.

Use the checks below in order: confirm the server and transport, then troubleshoot its specific authorization method. This keeps you from rotating a valid credential when the actual problem is a wrong endpoint, missing HTTP header, or local runtime issue.

Identify which WordPress MCP connection is failing

“WordPress MCP” can refer to two different services. The WordPress.org MCP server supports WordPress.org account and Plugin Directory workflows. The self-hosted WordPress MCP Adapter exposes Abilities registered on a WordPress site.

For the self-hosted Adapter, also establish the transport: local STDIO launched through WP-CLI, or HTTP through the @automattic/mcp-wordpress-remote proxy. Check the MCP client’s configured server or launch command before changing credentials. The WordPress.org server’s authorization steps do not configure a self-hosted site, and the Adapter’s endpoint and authentication settings do not fix a WordPress.org account connection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Connection path Where it fits First checks
WordPress.org MCP server WordPress.org account and Plugin Directory workflows Authorization completed, current application password saved in the client
Self-hosted Adapter with STDIO Local WordPress development through WP-CLI WP-CLI availability, WordPress path, configured server name, selected user
Self-hosted Adapter with HTTP Connecting to a site over HTTP via the remote proxy MCP REST endpoint, authentication configuration, Authorization header forwarding; Node.js and local SSL where applicable

Fix WordPress.org MCP authentication errors

The official WordPress.org guide says an application password may have expired or been revoked. Its recommended fix is to run the authorization flow again and replace the saved credential in the MCP client configuration. Reauthorization replaces the existing application password, and the new password is displayed only once, so copy it into the client when it is issued.

  1. Run the WordPress.org MCP server’s authorization flow again.
  2. Copy the newly generated application password when it appears.
  3. Update the credential in the MCP client’s configuration, replacing the old password.
  4. Reload or restart the client if it does not pick up the updated configuration, then try the connection again.

If reauthorization does not resolve the error, verify that the client is configured for the WordPress.org server rather than a self-hosted Adapter. For the latter, troubleshoot the site endpoint and its authentication method instead.

Check self-hosted Adapter settings by transport

Local STDIO through WP-CLI

For a local connection, verify that WP-CLI is installed and that the configured --path points to the intended WordPress installation. Check that the MCP server name in the launch configuration exists and that the selected WordPress user is valid for the Abilities the client needs to use.

  • Confirm the client is launching the intended MCP server through WP-CLI.
  • Check the WordPress installation path for typos or a different site than expected.
  • Verify the configured server name and selected user.

HTTP through the remote proxy

For an HTTP connection, validate the complete configuration: the site’s MCP REST endpoint, username, and application password or custom OAuth setup. Also confirm that the client configuration is saved in the location used by that client; reload or restart it after making changes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If the endpoint and credentials look correct, check whether the request’s Authorization header reaches WordPress. Some CGI environments or web-server configurations strip authentication headers before the application receives them. WordPress’s REST API FAQ includes Apache and Nginx forwarding examples. Ask the site administrator to review the applicable server configuration rather than repeatedly changing a credential that may already be valid.

Investigate local proxy, SSL, or network failures

When the HTTP proxy fails in local development, check whether multiple Node.js installations are causing the client to run under an unexpected version or path. The WordPress Developer Blog also identifies local SSL certificate problems as a possible cause in local HTTP proxy setups.

For a server-to-itself connection failure, check the network path as well as the MCP settings: DNS resolution, SSL, firewall rules, and HTTP authentication rules can all prevent the request from reaching or authenticating with the site. These checks are especially relevant when a connection works from another machine but fails from the server hosting WordPress.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use cookies and nonces only for the right authentication flow

WordPress REST API cookie authentication is intended for requests made in the context of a logged-in user. It requires a nonce with each request, sent in the X-WP-Nonce header. That browser-oriented flow is distinct from the application-password or custom OAuth configuration used for an MCP connection. Do not replace the MCP client’s configured credentials with browser cookies unless the specific client integration is designed to use cookie-and-nonce authentication.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For the REST API’s cookie authentication details, see WordPress REST API authentication.

Review access when exposing site Abilities

A self-hosted Adapter exposes registered Abilities, and the available operations and authorization are specific to the site. Use a least-privilege WordPress user for the connection and review the permissions associated with the Abilities exposed to the client. A successful connection alone does not establish that the user should have broader access.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.