Self-hosted WordPress MCP server with per-change undo and 203 tools. Free, no relay, no Pro tier.
Cowboy MCP is a free, open-source WordPress plugin that turns any WordPress site into a Model Context Protocol (MCP) server over Streamable HTTP, so Claude, ChatGPT, Cursor, Claude Code, Codex, Gemini and any other MCP client can manage the site in plain English — with per-change undo, database checkpoints and an audit log, so it can be trusted on a live site.
Install: WordPress.org plugin directory (one click, auto-updates) · Try it in your browser: Live Preview · Website & guides: cowboymcp.com · Questions: support forum · Bugs: issues
wp-content, and a Power mode only a human can enable in wp-admin.mcp-remote bridge the Connections tab generates for you.tools/list returns two gateway tools (cowboy_discover, cowboy_run); the agent discovers and runs the other tools on demand instead of loading 203 schemas into its context. On WordPress 6.9+ every tool is also a cowboy-mcp/* ability for WP-CLI, REST and the official MCP Adapter — with undo.wp-admin/includes at request time. Works on hosts without WP-CLI or shell_exec()."More access than any other MCP offers, easy to use, LOVE the change journal and the checkpoints — safe if you break something." — WordPress.org review
| Area | Tools | What the agent can do |
|---|---|---|
| Content | 5 posts/pages/CPTs · 4 taxonomies · 4 comments · 4 media · 6 menus · 1 options | draft, edit, schedule, publish; upload media, fix alt text; build nav menus |
| Gutenberg & Site Editor | 15 (8 on classic themes) | read a page as a block tree and edit it by path; block types, patterns, FSE templates/parts, global styles, navigations |
| Site administration | 5 users · 6 plugins · 5 themes · 4 files · 5 database · 3 WP-CLI/system · 1 site health | install/update/delete plugins & themes safely, manage roles, edit files in wp-content, repair tables, run WP-CLI |
| Diagnostics | 10 | error log, HTTP & email tests, hooks, transients, REST routes, thumbnails, rewrite rules, snapshot, Connection Doctor |
| Safety | 6 rollback · 2 batch/audit | list & undo changes, create/list/restore/delete checkpoints, batch execution, audit-log retrieval |
| WooCommerce | 40 | products & variations, orders & refunds, customers, coupons, tax/shipping/payment settings, reports |
| Wordfence | 17 | scans, blocks, firewall, live traffic, activity, settings |
| ACF / Elementor | 9 / 7 | field groups, fields, repeaters / templates, page content, global styles, widgets |
| Beaver Builder / SiteOrigin | 7 / 12 | builder pages, layouts with dry-run diff, modules, global settings / layouts and row/widget edits, prebuilt layouts, widgets, settings, Widgets Bundle activation |
| Revisions / Events | 3 / 13 | list, diff & restore post revisions / The Events Calendar events, venues, organizers + Events Calendar Pro recurrence |
| SEO / Cache / Forms | 4 / 4 / 1 | Yoast, Rank Math, All in One SEO & SEOPress meta read/write/audit / WP Rocket, LiteSpeed, W3TC / WPForms, Gravity Forms, CF7 |
Plus 17 read-only resources (incl. wordpress://tools/catalog), 4 resource templates (wordpress://posts/{id}, wordpress://options/{name}, wordpress://plugins/{slug}, wordpress://users/{id}) and 8 workflow prompts with argument auto-completion. Integrations register only when their plugin is active.
Updates arrive through the normal WordPress updates screen.
The endpoint is https://yoursite.com/wp-json/cowboy-mcp/v1/endpoint (JSON-RPC 2.0 over Streamable HTTP, MCP 2025-06-18).
Claude Code
claude mcp add --transport http your-site https://yoursite.com/wp-json/cowboy-mcp/v1/endpoint \
--header "Authorization: Bearer YOUR_API_KEY"
Claude desktop & web, ChatGPT (one-click, no key) — turn on Settings → Cowboy MCP → Settings → Desktop Connector, add the endpoint as a custom connector in the app (for Claude, the Add to Claude button on the Connections tab fills it in for you), approve the consent screen on your site (choose full, read-only or custom access). Requires a public HTTPS site.
Claude Desktop on a local site — use the mcp-remote bridge config shown on the Connections tab:
{
"mcpServers": {
"your-site": {
"command": "npx",
"args": ["-y", "mcp-remote", "http://yoursite.local/wp-json/cowboy-mcp/v1/endpoint",
"--header", "Authorization:${AUTH_HEADER}"],
"env": { "AUTH_HEADER": "Bearer YOUR_API_KEY" }
}
}
}
Cursor / Windsurf (Devin Desktop) (~/.cursor/mcp.json, ~/.config/devin/mcp_config.json)
{
"mcpServers": {
"your-site": {
"url": "https://yoursite.com/wp-json/cowboy-mcp/v1/endpoint",
"headers": { "Authorization": "Bearer YOUR_API_KEY" }
}
}
}
Cline: add "type": "streamableHttp" to the entry. VS Code (.vscode/mcp.json): use servers instead of mcpServers and add "type": "http". Zed: put the same url + headers under context_servers in its settings.
Codex CLI — Codex reads the key each time it starts, so add the export to your shell profile too.
export COWBOY_MCP_API_KEY="YOUR_API_KEY"
codex mcp add your-site --url https://yoursite.com/wp-json/cowboy-mcp/v1/endpoint --bearer-token-env-var COWBOY_MCP_API_KEY
Gemini CLI
gemini mcp add --scope user --transport http your-site https://yoursite.com/wp-json/cowboy-mcp/v1/endpoint \
--header "Authorization: Bearer YOUR_API_KEY"
Any client that speaks Streamable HTTP with a Bearer header works the same way (n8n, Opencode, LibreChat, your own agent). Opencode: set "oauth": false on the remote server so it uses the key. Step-by-step guides per client: cowboymcp.com.
Quick smoke test with curl
curl -s -X POST https://yoursite.com/wp-json/cowboy-mcp/v1/endpoint \
-H "Authorization: Bearer YOUR_API_KEY" -H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"cowboy_run","arguments":{"tool":"wp_site_info","arguments":{}}}}'
destructiveHint refuse to run until the call is resent with confirm: true; the refusal includes a preview.dry_run: true and reports exactly what would change.wp_list_changes / wp_undo_change, batch undo, conflict detection, redo-on-undo; 7-day retention by default.{prefix}cowboy_mcp_audit_log (key, tool, arguments, result, IP); pruned after 30 days; secrets redacted on read.{mode: full|read_only|custom, allowed_tools[]}; enforced at dispatch, also for tools called through cowboy_run and batches. readOnlyHint is treated as a security boundary.Origin allowlist; OAuth tokens stored hashed, off by default, admin consent required.siteurl, active_plugins, credentials, the plugin's own settings…), dangerous-SQL and WP-CLI blocklists (eval, shell, db drop, …) applied on a shell-style tokenizer, SSRF validation on outbound requests, wp-content path confinement with atomic writes, a PHP syntax check before every file write and no mu-plugins writes without Power mode, self-delete and last-administrator protection.wp cowboy-mcp doctor and the wp_connection_doctor tool.Factual, dated comparisons live on the site: all WordPress MCP plugins compared · vs Novamira · vs AI Engine · vs WPVibe · vs InstaWP · vs the WordPress MCP Adapter · self-hosted vs hosted. Short version: the endpoint is self-hosted with no relay or metering, every tool is free, and undo + checkpoints + audit log ship together.
cowboy-mcp.php # entry point, constants, activation/uninstall
includes/
class-mcp-transport.php # REST route, JSON-RPC dispatch, sessions (Streamable HTTP)
class-mcp-auth.php # API keys (hashed), Bearer validation, rate limits, Origin allowlist
class-mcp-oauth.php # OAuth 2.1 authorization server (discovery, DCR, consent, tokens)
class-mcp-security.php # denylists, SSRF, SQL/WP-CLI gates, scoping, secret scrubbing
class-mcp-tools.php # registry, gateway meta-tools, dispatch, lazy domain loading
class-mcp-rollback.php # undo journal class-mcp-checkpoint.php # DB checkpoints
class-mcp-audit-log.php # audit table class-mcp-installer.php # WP.org package installer
class-mcp-doctor.php # Connection Doctor class-mcp-compat.php # admin-free reimplementations
class-mcp-resources.php / class-mcp-prompts.php / class-mcp-completion.php
tools/{core,gutenberg,acf,woocommerce,seo,forms,cache,elementor,wordfence}/
admin/ # settings page (Connection, Settings, Activity, Logs, About), assets
languages/ # 12 bundled locales for the admin UI (ru, uk, zh_CN, ja, ko, es, fr, de, pt_BR, it, hi, id)
Tool descriptions and error messages returned to agents are intentionally English; the admin UI is translated.
cowboy_mcp_tools filter — register your own tool definitions and handlers.cowboy_mcp_tool_allowed filter — block specific tools per request.cowboy_mcp_allowed_origins filter — extend the request Origin allowlist.npx wp-env start # local WordPress at http://localhost:8890 with this checkout mounted as the plugin
CLI="$(docker container ls -q --filter 'name=^[0-9a-f]+-cli-1$')"
docker exec "$CLI" wp plugin check cowboy-mcp --format=csv # Plugin Check (install it in wp-env first)
find . -name '*.php' -not -path './node_modules/*' -exec php -l {} + # syntax check
No build step. Pull requests welcome — keep the WordPress.org review invariants (no wp-admin/includes requires, no path constants, prepared/validated $wpdb queries, escaped output).
GPL-2.0-or-later. © Andrew Ivanov (februality).
This listing does not have a supported local package template. Use the maintainer’s documentation for its hosted endpoint, authentication, and client-specific setup. No install command has been inferred.