How to Connect WordPress to ChatGPT Safely
Separate the three credentials
For hosted Studio, separate three credentials and grants: your Studio website account signs in to the dashboard and approves the AI client; a dedicated WordPress Application Password verifies the intended website through the authenticated dashboard; and an OAuth grant authorizes the particular AI client. In direct WordPress mode, authorization instead takes place on your WordPress site without a separate hosted account.
These controls serve different purposes. Successful Studio account sign-in does not prove the WordPress user has permission to publish, and an accepted WordPress credential does not grant an AI client access until its authorization is complete.
Start with a dedicated WordPress user
Choose a role that matches the intended task. A draft-review workflow needs different rights from site settings administration. Create an Application Password in that user’s WordPress profile and enter it only in the signed-in Studio dashboard’s site-connection form. Keep the main WordPress login password separate.
Install the companion on staging and leave read-only enabled. Confirm the exact site URL and user identity before connecting additional sites with similar names.
Complete OAuth once
For hosted Studio, use https://wpbridgestudio.com/mcp in the available custom MCP connector flow in your ChatGPT account and select OAuth. For direct WordPress mode, use the site-specific MCP URL displayed by the plugin instead. The server validates the callback, resource, requested scopes and PKCE challenge before presenting its consent form.
Submit the form once and allow the browser to return to ChatGPT. A request becomes consumed after approval. Submitting the same old form again can produce an expired-or-used message even when the first password submission was accepted. Start from the existing connector to create a fresh request when needed.
Verify actual read-only results
Ask for list_sites, site_status and wordpress_read /wp/v2/users/me. Check the HTTP result and WordPress identity. This establishes more than a generic claim that the plugin is installed: it demonstrates that the authenticated request can reach the intended endpoint as the intended user.
For a denied request, inspect the native endpoint permission requirements before increasing privileges. For a missing route, discover the installed REST routes instead of assuming a plugin implements an API.
Enable changes gradually
Enable writing in both the workspace and the companion only after read verification succeeds. Test one disposable draft on staging, read it back and inspect the result. Be precise about the post, requested fields and status; “improve my site” is not a useful scope for an irreversible deletion.
Keep the setup documentation and security explanation available to the team members responsible for the sites.
How to connect ChatGPT to WordPress without sharing your main password
Short answer: install WPBridge Studio on the WordPress site, choose the direct or hosted MCP connection, complete the correct OAuth grant, then verify the intended site and WordPress account through read-only API tools. Hosted Studio uses a dedicated WordPress Application Password for the service-side site connection; this is not the password for your ChatGPT account.
What exact MCP URL should I use?
Hosted Studio: https://wpbridgestudio.com/mcp. Direct WordPress mode: the HTTPS MCP URL shown in Settings → WPBridge Studio on the site, commonly https://YOUR-SITE/wp-json/wpbridge-studio/v1/mcp. Use the precise URL generated for your setup.
How do I confirm ChatGPT connected to the right WordPress site?
Read the WordPress site status and /wp/v2/users/me, then verify one known page ID. Read-only evidence is preferable to attempting a production edit as the first test.
Can ChatGPT work on several WordPress websites?
A hosted Studio account may manage multiple verified websites subject to its allowance and the authorization granted for each. Always identify the site ID before changing any content. See multi-site verification workflows.
Compare the WordPress ChatGPT MCP connector and MCP plugin setup tutorial. The connection diagnostics cover expired OAuth grants, 401 responses and permission denials.