Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Model Context Protocol (MCP) is an open standard that lets an AI application discover and use tools provided by an external service. For WordPress, that means a compatible AI client can connect to a WordPress MCP server and perform the actions or read the data that server makes available—subject to authorization and WordPress permissions. MCP does not automatically expose every site feature or grant unrestricted access.

There are two distinct WordPress connection paths: WordPress.com’s hosted MCP service, and the installable WordPress MCP Adapter, which connects selected WordPress Abilities API capabilities to MCP. The right choice depends on where your site is hosted, whether your account is eligible for the hosted service, and how much control you need over exposed capabilities.

What MCP does in a WordPress connection

MCP standardizes how an AI client communicates with a server that offers capabilities such as tools and resources. In a WordPress setup, the client might be an AI application; the server provides a defined interface to WordPress functionality. The client discovers what is available, then requests actions or information through that interface. What it can do depends on the server’s exposed capabilities and the connected user’s permissions.

This is an integration layer, not a built-in switch that makes an entire WordPress installation available to an AI. The MCP protocol, server configuration, authentication, and WordPress permission checks all affect what the client can access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose a WordPress MCP connection path

Path Best fit How access is controlled
WordPress.com hosted MCP Eligible WordPress.com accounts and Jetpack-connected self-hosted sites Account authorization through OAuth 2.1; revoke a connected client in account settings
WordPress MCP Adapter A site-level integration where the owner wants to expose selected Abilities API capabilities Opt-in ability exposure and WordPress permission checks for the current user

The hosted service and adapter are separate architectures. Their tool catalogs should not be assumed to be identical.

WordPress.com’s hosted MCP server

WordPress.com documents the MCP server at https://public-api.wordpress.com/wpcom/v2/mcp/v1. To connect a supported client, enable MCP in WordPress.com account settings, add the server in the client, and complete the browser-based authorization. The documented authentication flow uses OAuth 2.1, with PKCE, dynamic client registration, and rotating tokens. You can revoke access under Account → Security → Connected Apps. See the WordPress.com MCP documentation.

Eligibility depends on the hosting setup. WordPress.com’s documentation, last updated September 21, 2026, says MCP is available on all paid plans; free WordPress.com sites can use it for the first 30 days after site creation. For a self-hosted site connected through Jetpack, the documented requirement is Jetpack AI or Jetpack Complete. Plan details and availability may change, so check the current eligibility guidance before configuring a connection.

WordPress MCP Adapter for site-level control

The WordPress MCP Adapter maps capabilities registered with the WordPress Abilities API into MCP tools and resources. The adapter can be installed from its GitHub releases; after activation, it registers a default MCP server and adapter abilities. Its listing describes HTTP and STDIO transports and compatibility with MCP revisions 2025-11-25 and 2026-07-28; installation and compatibility details are subject to change. See the WordPress MCP Adapter listing and the WordPress Developer Blog introduction.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The adapter does not expose every registered ability by default. Exposure is opt-in, and permission checks still apply for the current WordPress user. Developers can also build a custom server to choose which abilities are available. WordPress’s implementation guidance recommends beginning with a small set of non-destructive, read-only abilities, then expanding only after testing.

How to connect an AI client to WordPress

For WordPress.com or Jetpack-connected sites

  1. Confirm that the WordPress.com account or Jetpack-connected site meets the documented eligibility requirements.
  2. Enable MCP in WordPress.com account settings.
  3. Add https://public-api.wordpress.com/wpcom/v2/mcp/v1 as an MCP server in a supported client.
  4. Complete the browser authorization flow, then use the client’s available WordPress tools.
  5. To end access, open Account → Security → Connected Apps and revoke the client.

Most users of a supported, preconfigured client only need the endpoint and browser authorization flow. Developers implementing their own client can follow WordPress.com’s custom-client guide, which documents client registration, authorization-code flow with PKCE, token exchange, and authenticated MCP requests. Do not embed a client secret in a distributed desktop or command-line app.

For a self-hosted site using the adapter

  1. Install the WordPress MCP Adapter using the method documented in its plugin listing or GitHub releases.
  2. Register or select the Abilities API capabilities that the site should make available through MCP.
  3. Explicitly enable only the intended abilities, starting with non-destructive, read-only capabilities.
  4. Test the connection with a compatible client and verify that the current WordPress user’s permissions produce the expected access.

Exact client configuration depends on the adapter version, transport, and client. Follow the installation and configuration instructions for the version you use rather than assuming every client supports every transport or MCP revision.

Security and permissions to check

  • Limit the available tools. With the adapter, expose only abilities that the client needs. Avoid making destructive or highly privileged actions available to an unaudited client.
  • Use least privilege. Use a dedicated WordPress user with only the capabilities needed for the MCP tasks, and design permission callbacks carefully.
  • Protect custom clients. Follow the documented OAuth 2.1 flow, including PKCE for public clients; do not ship a client secret inside software distributed to users.
  • Review AI-generated changes. Treat proposed edits and actions as work that needs human review. WordPress.org says plugin developers remain responsible for all code, including AI-assisted code, and the same plugin review rules apply regardless of how code was produced. See the Plugin Developer Handbook guidelines.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Which WordPress MCP server should you use?

There is no universal best choice in the official documentation; choose based on hosting, eligibility, and the control you need.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
hosting servers
  • easy to use
  • Free app
  • Compatible with all devices
  • It gives the best comparison between ten different hosts
  • Choose WordPress.com’s hosted MCP service if your account or Jetpack-connected site qualifies and you want an account-authorized hosted connection.
  • Choose the MCP Adapter if you want a site-level integration that maps selected Abilities API capabilities into MCP, with exposure and permissions configured for that site.
  • Pause before connecting if you cannot confirm which tools the server exposes, which user’s permissions apply, or how to revoke access.

WordPress.org’s separate MCP server for plugin development

WordPress.org also documents an MCP server for plugin-development tasks, including guideline lookup, readme validation, status checking, and submission. It assists developers but does not replace plugin review or the developer’s responsibility for the code. The documented server requires Node.js version 18 or later. See the WordPress.org Plugin Directory MCP server guide.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.