WordPress MCP Compatibility Checklist
Studio supports authenticated WordPress REST operations. An installed plugin is usable through Studio only when its desired action has a compatible REST endpoint and the connected user has permission.
Supported and unverified workflows
| Workflow | Current support |
|---|---|
| Posts and pages | Core REST reads and changes, subject to native permissions and access mode. |
| Plugin-specific settings | Requires a compatible REST route; dashboard-only actions are not guaranteed. |
| Theme files and WP-CLI | No dedicated file editor or WP-CLI tool is included. |
| Paid direct-mode activation | Pending; current purchases apply to the separate hosted service. |
A practical pre-purchase check
- Confirm the site uses HTTPS and accepts authenticated REST requests.
- Choose direct WordPress mode or the separately hosted customer workspace.
- List the target REST routes and verify the user’s capabilities.
- Read a known draft and confirm its ID and title.
- For changes, test a disposable staging draft and read it back.
Successful status checks verify connectivity; they do not prove every plugin’s settings are remotely editable.
Can I use a CDN?
Public pages may use a CDN. The Studio OAuth and authenticated REST routes return private no-store headers. Configure the CDN to respect those headers and bypass caching for authentication and Studio REST endpoints. A firewall must also allow OAuth discovery and authorized requests.
WordPress and MCP compatibility checklist
Short answer: WPBridge Studio works with WordPress content that is accessible through an authorized REST endpoint. Installing a plugin does not automatically make all of that plugin’s admin screens available to an AI client.
| What you want to do | What must be true | How to verify |
|---|---|---|
| List pages or posts | The core WordPress REST API is reachable and the user has access to the requested records. | Read /wp/v2/pages or /wp/v2/posts and inspect IDs, statuses and titles. |
| Read private drafts | Authentication succeeds and the WordPress user has permission to read those drafts. | Request status=draft; confirm that an expected draft appears. |
| Update an existing page | Writing is enabled at each relevant Studio access layer; the user can edit that page. | Update a disposable staging page, then read it back by its returned ID. |
| Change an SEO plugin setting | The installed SEO plugin registers a compatible authenticated REST route. | Inspect REST namespaces and route methods; do not assume a dashboard setting has an API. |
| Edit a theme file or run shell commands | A separate approved integration is required. | Do not attempt those operations through the current Studio REST tools. |
Server, hosting and security requirements
- HTTPS: A valid TLS certificate must cover the WordPress site. The relevant OAuth and API endpoints must remain reachable.
- REST API: Confirm that
/wp-json/responds. A working anonymous API index does not prove that authenticated requests can read private content. - WordPress access: Hosted Studio uses a dedicated WordPress user and Application Password. Direct WordPress mode follows a separate authorization process on your site.
- Hosting permissions: The account must permit installation of the WordPress companion plugin. Some managed WordPress products restrict plugin uploads.
- Firewall and CDN: Avoid caching account pages, token responses or authenticated REST requests. Security rules must not strip required authorization headers.
Use the hosted installation walkthrough or direct WordPress setup according to where the connection will run.
Five checks that prove a workflow is ready
- Site identity: List connected sites, select the intended site ID and call
site_status. - User identity: Read
/wp/v2/users/meand confirm the expected WordPress user; never rely on a connection badge alone. - Route availability: Call
discover_routesand locate the exact REST endpoint and supported methods. - Read permissions: Read a known item and match its ID, title and status to WordPress.
- Write permissions, if needed: Create or update a disposable staging draft, then read the saved object again. Do not test deletion on production content.
Pass criteria: Each expected response must come from the correct site, with an appropriate HTTP status and verifiable resource data. A successful read does not itself authorize publishing.
Compatibility questions
Does WPBridge Studio support WooCommerce, Elementor or SEO plugins?
Only their operations exposed through accessible REST endpoints can be considered candidates. Compatibility is feature-by-feature, not an automatic promise covering every plugin or extension. Test your required route before purchasing.
Can I use more than one website?
Hosted Studio accounts can connect authorized sites through their workspace. Each site has its own identity and WordPress permissions. Select and verify the intended site for every high-impact change.
Does an AI client receive administrator rights automatically?
No. WordPress decides the capabilities of the authenticated user. For routine content work, use a dedicated least-privilege account where practical; read the security guidance.
What if the site connects but an action fails?
Read the returned status and error message, verify the REST route and the active access mode, and follow the connection troubleshooting guide.
Technical references
Review the WordPress REST API reference and WordPress Application Passwords documentation for the underlying endpoint and credential behavior.
Validate the specific REST operation before assuming MCP compatibility
First identify the tool, then its WordPress route. A registered REST namespace is only an entry point to an endpoint catalog; it is not a promise that a tool can edit an installed plugin. Check the intended HTTP method, accepted parameters, authenticated user and any read-only restriction. For worked examples, use the WordPress MCP tools and REST endpoint reference.
The official WordPress MCP Adapter uses registered WordPress abilities, while the observed WPBridge Studio Website Admin connection exposes authorized REST operations. Compare the actual methods and permission checks instead of treating these as identical implementations.
Compatibility guides for specific workflows
For store operations, consult WooCommerce and ChatGPT API requirements before touching customer orders. Compare MCP versus direct WordPress REST API access when designing the connection, and review the connector evaluation checklist before choosing a plan.