WPBridge Studio
WPBridge Studio developer documentation · October 10, 2026

WordPress MCP Tools Reference: Read, Write and Verify

Which tools can a WordPress ChatGPT MCP connector actually call? This reference describes the five operations exposed in the authenticated WPBridge Studio Website Admin connection tested on October 10, 2026, with safe request examples, WordPress permission checks and read-back verification. It does not imply that other connector editions or AI clients expose identical tools.

Quick answer: the five observable connector operations

Observed WPBridge Studio Website Admin connector tool surface
OperationPurposeWrite access?Evidence you should request
list_sitesIdentify configured WordPress websites and their site IDsNoExpected hostname and intended site ID
site_statusRead site identity, WordPress version and registered REST namespacesNoCorrect site URL and response from the actual installation
discover_routesInspect registered WordPress REST paths, supported methods and parameter schemasNoNamed endpoint and method verified on the chosen site
wordpress_readMake an authorized GET request to a WordPress REST endpointNoHTTP result, intended resource ID and expected saved fields
wordpress_writeIssue an authorized POST, PUT, PATCH or DELETE to an installed WordPress REST endpointYes; must be permittedWordPress response plus an independent read-back

Do not confuse WordPress REST routes with MCP tools. The owner’s site returned a catalog of 216 WordPress REST route patterns in an earlier inspection. Those routes include core and third-party namespaces; they are not 216 independently available MCP tools, and they do not confer permission to invoke or modify each endpoint.

Read-only WordPress MCP workflow: exact sequence

  1. Identify: ask the client to call list_sites and select the intended site ID. Do not infer the target from a similarly named domain.
  2. Check: call site_status for that site; confirm its returned hostname matches the expected WordPress installation.
  3. Authenticate: request wordpress_read of /wp/v2/users/me. Report the actual result without showing tokens or Application Passwords.
  4. Read a resource: request wordpress_read of /wp/v2/pages/41 on the test site, or the corresponding page ID on your own installation.
  5. Verify: compare returned title, link, status and ID with the WordPress record. Report any mismatch; do not proceed to writes.

For the owner-authorized WPBridge Studio installation, the identity and known-product-page REST reads returned HTTP 200 on October 10, 2026. Those observations are documented in the connector demonstration. They are not a guarantee that a customer’s restricted WordPress role can read the same objects.

Use WPBridge Studio to list my authorized sites.
Identify the exact intended site URL, then call site_status.
Use wordpress_read for /wp/v2/users/me.
Read one known published page by ID and report its title and status.
Do not create, update, publish or delete anything.

WordPress REST route examples and parameter behavior

The connected tool accepts a WordPress REST route such as /wp/v2/pages, not the complete public https://example.com/wp-json/... URL. In WordPress’s conventional web URLs, the same REST namespace appears beneath /wp-json/. The connector selects the authorized WordPress site separately from the route.

Illustrative WordPress core routes; role-dependent access
RouteTypical readPractical consideration
/wp/v2/users/meAuthenticated user identityA denied response may indicate missing credentials or a permissions problem
/wp/v2/pagesPage collection and paginationUse per_page and page, then continue across pages when needed
/wp/v2/pages/{id}One WordPress pageVerify the saved ID and status; edit context may require additional rights
/wp/v2/postsPosts and permitted draftsPrivate or draft status depends on the authenticated user’s capabilities
/wp/v2/mediaMedia metadataFile-upload and mutation capabilities are separate from listing media

For authoritative parameter names, consult the WordPress Pages REST reference and WordPress Posts REST reference. Plugin-defined routes can differ; always inspect discover_routes before invoking a non-core endpoint.

How to verify a WordPress content write safely

A successful tool response is not enough. For an approved, non-destructive draft task, use a dedicated WordPress user with the needed permissions, ensure writing is intentionally enabled, and operate on a disposable staging item.

  1. Read the existing target page or draft and record its ID, current status and fields. Make a backup or revision where appropriate.
  2. Ask for a single, specific change: for example, revise the excerpt of one staging draft while keeping its status as draft.
  3. Issue the permitted wordpress_write call using the exact installed REST route and approved fields. The method must be supported by that route.
  4. Check the WordPress response code and resource ID. A rejected or failed request is not a completed change.
  5. Call wordpress_read independently on the same resource ID and compare the saved fields to the request.
  6. Check browser rendering separately when the content contains layouts, forms, scripts, interactive elements or caches.
First read the intended staging draft and report its ID.
Do not proceed if its ID or site URL is unexpected.
If the authorized editing tool is available, update only its excerpt.
Keep the resource as a draft, then read it back independently.
Report the WordPress response and whether saved values match.
Do not publish or delete.

Actual writes remain subject to the account’s WordPress roles, each REST controller’s permission checks and any connector read-only switch. A request allowance or paid package does not confer publishing rights. The WordPress API permissions guide explains typical capabilities.

Why an installed WordPress plugin might not be accessible through MCP

An admin screen is not proof of an API. The connector only reaches functionality that an authorized installed WordPress endpoint exposes. Before committing to a WooCommerce, membership, analytics or custom-plugin workflow, ask the connector to discover the exact route, supported method, parameters and authorization behavior. Do not assume that discovering a route means it permits the requested operation.

The official WordPress MCP Adapter and Abilities API architecture is a separate integration model. Its abilities require appropriate exposure and permission checks. WPBridge Studio’s observed Website Admin tools instead provide a site selector and access to installed WordPress REST routes. These models are related but not interchangeable.

MCP authorization and client compatibility in 2026

Remote MCP servers may use OAuth authorization to obtain user consent and protect tools. The MCP specification was revised on July 28, 2026, including important authorization security guidance. The published specification describes protected-resource metadata, token validation, authorization-server discovery and security safeguards for public clients. See the MCP authorization specification for current protocol requirements.

Do not treat this reference as a certificate of full 2026-spec conformance for WPBridge Studio. A compliant client handshake, callback handling, refresh-token behavior and direct or hosted licensing must be tested on the exact installed service and client version. The availability of custom ChatGPT connectors also depends on the user’s current account features.

For production setup, check security and revocation, site compatibility and 401/403 authorization troubleshooting. Never place live OAuth tokens, WordPress Application Passwords or customer data in public examples.

What was verified and what is still outside this reference?

AssertionStatus or scope
Authenticated site identity, connected user and REST page reads on the owner’s Studio siteVerified through the installed connector on October 10, 2026
WordPress REST route discoveryVerified; authorization remains route and user dependent
Owned WordPress demo page and revision evidenceDocumented on the published demonstration
Every plugin, theme-file editor, WooCommerce refund or custom PHP operationNot guaranteed; requires specific APIs and permissions
Independent Claude/Gemini production trials, every ChatGPT account and every MCP versionNot established by this owner’s Website Admin test
Frontend page appearance, search ranking, Google indexing and SEO trafficRequire external/browser and search-performance checks

WordPress MCP tool reference FAQs

Can ChatGPT read a WordPress page without having publishing access?

Yes, when the configured connector advertises a read tool and the authenticated WordPress user can read the intended resource. Writing permissions are separate.

Does 200 OK from /wp/v2/users/me prove an editing tool works?

No. It verifies authenticated identity for that request. Publishing can still fail under read-only controls or WordPress REST permissions.

Can the same tool work on multiple WordPress sites?

A hosted workspace may list multiple authorized sites. Each call must select the correct site ID and use that site’s credentials and capabilities. See agency workflow guidance.

What should I test before purchasing?

Confirm supported client access, site identity, relevant REST route availability, your WordPress user’s permissions, and the actual hosted or direct plan terms. Start with the WPBridge Studio WordPress ChatGPT MCP connector and evaluation scorecard.