dev.wpagent/wpagent-mcp

Manage WordPress & WooCommerce from any MCP client — 58 tools over a signed REST API.

E-CommerceTypeScriptv1.1.4

wpagent-mcp

An MCP server that lets Claude — or any MCP-compatible client — actually operate a WordPress site: plugins, content, themes, menus, media, users, WooCommerce, Elementor and WP-CLI.

It talks to your site through the free WpAgent bridge plugin over a REST API where every request is signed with HMAC-SHA256. No site credentials are involved, and no data passes through a third-party service: the connection is client → your WordPress, directly.

Install

Nothing to install ahead of time — the config below fetches it on demand.

  1. Install the WpAgent plugin on your WordPress site and activate it.
  2. In the WordPress admin, open WpAgent and generate an API key. Choose the permissions you want the assistant to have; a read-only key is a sound way to start.
  3. Add the server to your MCP client. For Claude Desktop, in claude_desktop_config.json:
{
  "mcpServers": {
    "wpagent": {
      "command": "npx",
      "args": ["-y", "wpagent-mcp"],
      "env": {
        "WP_SITE_URL": "https://your-site.com",
        "WP_API_KEY_ID": "wpaia_xxxxxxxxxxxx",
        "WP_API_SECRET": "the secret shown once when you generated the key"
      }
    }
  }
}

For Claude Code:

claude mcp add wpagent \
  --env WP_SITE_URL=https://your-site.com \
  --env WP_API_KEY_ID=wpaia_xxxxxxxxxxxx \
  --env WP_API_SECRET=... \
  -- npx -y wpagent-mcp

Environment variables

VariableRequiredWhat it is
WP_SITE_URLyesYour site's base URL, no trailing slash
WP_API_KEY_IDyesThe key id shown in the plugin
WP_API_SECRETyesThe secret, displayed once at generation
WP_SITE_LABELnoA friendly name; defaults to the hostname

What it can do

AreaExamples
Pluginslist, search wordpress.org, install, activate, deactivate, update, delete
Contentposts, pages, products, any custom post type, with meta and featured images
Themeslist, search, install, activate, theme mods, custom CSS, logo, colours
WooCommercesettings, orders, coupons, shipping zones, payment gateways, tax rates, stats
Structuremenus, widgets, sidebars, taxonomies, terms, redirections
Mediabrowse, upload, delete
Users & commentslist, create, update, moderate
Auditbest-practices check over security, SEO, performance, with auto-fixes
WP-CLIallowlisted commands, off unless enabled in wp-config.php

What it will not do

The API has no path to arbitrary PHP, no path to your database, and no path to wp-config.php. WP-CLI execution is disabled unless the site owner adds define('WPAIA_ENABLE_WPCLI', true); on the server, and even then only allowlisted commands run — db, eval, eval-file, shell, server, config and package are always refused.

Safety

  • Every request is signed with HMAC-SHA256 and carries a timestamp; requests older than five minutes are rejected.
  • Permissions are per key and checked on every route, so a read-only key stays read-only.
  • Every call is written to an audit log you can read in the WordPress admin.
  • Revoking a key in WordPress takes effect immediately.

Ask the assistant to confirm before destructive actions, and keep a current backup — it can delete content when you tell it to.

Related

  • WpAgent — hosted dashboard built on the same bridge, with a free read-only tier
  • The bridge plugin is GPL-2.0-or-later; this server is MIT.

Licence

MIT © KipDev

Installation

Source-derived launch command. Check the maintainer’s required arguments and credentials before running:

bash
npx -y wpagent-mcp

Set up in your AI client

Merge this template into ~/Library/Application Support/Claude/claude_desktop_config.json. Keep existing servers. Add any arguments, credentials, and permissions required by the maintainer; this template has not been install-tested.

json
{
  "mcpServers": {
    "dev-wpagent-wpagent-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "wpagent-mcp"
      ]
    }
  }
}

Restart Claude Desktop completely for changes to take effect. Confirm the server appears connected in the client’s tool list, then try a read-only example from its documentation.

Claude Desktop setup reference

Package

wpagent-mcpnpm

Compatible MCP Clients

dev.wpagent/wpagent-mcp works with any MCP-compatible client. Copy the config snippet from the Configuration section above and add it to the file shown for your client, then restart the application.

  • Claude Desktop~/Library/Application Support/Claude/claude_desktop_config.jsonRestart Claude Desktop completely for changes to take effect.
  • Cursor~/.cursor/mcp.jsonRestart Cursor for changes to take effect.
  • VS Code.vscode/mcp.jsonReload VS Code window for changes to take effect.
  • Windsurf~/.codeium/windsurf/mcp_config.jsonRestart Windsurf for changes to take effect.
  • Claude Code.mcp.jsonSave at the project root, then start Claude Code in that project and review the MCP server approval prompt. Keep real credentials out of shared files.

Learn More