WordPress MCP Server Setup: A Practical Guide
Understand MCP, OAuth and WordPress REST tools, then set up a hosted WordPress MCP connection.
What does an MCP server provide?
MCP describes tools that an AI client can discover and call. Studio advertises site listing, status, REST route discovery, reads and writes. OAuth binds those calls to a Studio account; WordPress credentials bind the target request to a WordPress user.
Do I need a VPS?
The hosted Studio companion uses the Studio service endpoint, so customers do not deploy a Node application. Their WordPress site still needs HTTPS and plugin support. The separate direct plugin path serves OAuth on WordPress and is a different installation route.
What makes a connection verifiable?
Check three separate results: WordPress credential verification, client OAuth authorization, and a successful authenticated tool response from the client. A connected icon alone does not demonstrate that a particular REST operation is allowed.
Set up your connection
Explore WPBridge Studio, follow the installation guide, then compare packages. Start free and confirm site identity before making changes.
How a WordPress MCP connection works
In one sentence: a WordPress MCP server exposes permitted WordPress actions as tools that an AI client can discover and request, while WordPress remains responsible for checking the authenticated user’s access to individual REST operations.
- An AI client connects to an MCP endpoint and discovers its available tools.
- The customer authorizes the intended client and WordPress site through the configured connection flow.
- The client requests an operation such as listing pages or reading a draft.
- The connector calls the corresponding authorized WordPress REST endpoint and returns its response.
- For changes, the operator checks the actual WordPress result and reads the edited resource back.
For example, a response to /wp/v2/pages can reveal actual page IDs and titles; it does not prove that a separate SEO plugin’s settings API exists. See the compatibility checklist.
Hosted MCP, direct WordPress MCP or an alternative plugin?
| Approach | Where connection infrastructure runs | Important trade-off |
|---|---|---|
| WPBridge Studio hosted workspace | On the Studio service, linked to your authorized WordPress sites | Customer accounts, site verification and hosted usage allowances are handled by Studio; payment and service limits are separate from your AI account. |
| WPBridge Studio direct WordPress mode | On your own HTTPS WordPress site | No separate hosted workspace is needed; configuring your site’s endpoint and access remains your responsibility. Paid direct-mode licensing is pending. |
| WordPress MCP Adapter | Through the WordPress ecosystem’s MCP adapter and its enabled abilities | Uses WordPress’s Abilities API approach; verify the specific operations exposed and any client setup requirements. |
The WordPress AI team announced the public WordPress.org release of the MCP Adapter in October 2026. It is an alternative approach, not part of WPBridge Studio. Read the official WordPress announcement to understand that option before choosing a product.
MCP authentication versus WordPress authorization
OAuth authorization determines whether the selected AI client may reach the connector. The WordPress user associated with the requested site determines which WordPress resources it can access. These controls solve different problems; a connected client does not bypass native WordPress permissions.
For hosted Studio, the website account and the dedicated WordPress Application Password also serve different roles. Keep them separate, use HTTPS, and revoke credentials that are no longer required. Review the permissions and security explanation before enabling writes.
WordPress MCP server FAQs
Can an MCP server edit all WordPress plugins?
No. Editing requires an accessible endpoint, appropriate user capabilities and write access. Plugin features implemented only in a dashboard cannot automatically be invoked through REST tools.
Is an MCP connection the same as an AI subscription?
No. A connector supplies operations; your AI client account, WordPress hosting and any Studio hosted plan are separate services.
How do I test it safely?
Connect a staging site, confirm site_status, read /wp/v2/users/me, inspect available routes and read a known draft. Enable writes separately and verify each saved result.
Where should I go next?
Follow the step-by-step installation guide, review hosted plan limits if you need a managed workspace, or read the direct WordPress instructions for a self-hosted connection path.