Skip to main content
Glama

wpagent-mcp

An MCP server that lets Claude — or any MCP-compatible client — actually operate a WordPress site: plugins, content, themes, menus, media, users, WooCommerce, Elementor and WP-CLI.

It talks to your site through the free WpAgent bridge plugin over a REST API where every request is signed with HMAC-SHA256. No site credentials are involved, and no data passes through a third-party service: the connection is client → your WordPress, directly.

Install

Nothing to install ahead of time — the config below fetches it on demand.

  1. Install the WpAgent plugin on your WordPress site and activate it.

  2. In the WordPress admin, open WpAgent and generate an API key. Choose the permissions you want the assistant to have; a read-only key is a sound way to start.

  3. Add the server to your MCP client. For Claude Desktop, in claude_desktop_config.json:

{
  "mcpServers": {
    "wpagent": {
      "command": "npx",
      "args": ["-y", "wpagent-mcp"],
      "env": {
        "WP_SITE_URL": "https://your-site.com",
        "WP_API_KEY_ID": "wpaia_xxxxxxxxxxxx",
        "WP_API_SECRET": "the secret shown once when you generated the key"
      }
    }
  }
}

For Claude Code:

claude mcp add wpagent \
  --env WP_SITE_URL=https://your-site.com \
  --env WP_API_KEY_ID=wpaia_xxxxxxxxxxxx \
  --env WP_API_SECRET=... \
  -- npx -y wpagent-mcp

Environment variables

Variable

Required

What it is

WP_SITE_URL

yes

Your site's base URL, no trailing slash

WP_API_KEY_ID

yes

The key id shown in the plugin

WP_API_SECRET

yes

The secret, displayed once at generation

WP_SITE_LABEL

no

A friendly name; defaults to the hostname

Related MCP server: wp-mcp-control-server

What it can do

Area

Examples

Plugins

list, search wordpress.org, install, activate, deactivate, update, delete

Content

posts, pages, products, any custom post type, with meta and featured images

Themes

list, search, install, activate, theme mods, custom CSS, logo, colours

WooCommerce

settings, orders, coupons, shipping zones, payment gateways, tax rates, stats

Structure

menus, widgets, sidebars, taxonomies, terms, redirections

Media

browse, upload, delete

Users & comments

list, create, update, moderate

Audit

best-practices check over security, SEO, performance, with auto-fixes

WP-CLI

allowlisted commands, off unless enabled in wp-config.php

What it will not do

The API has no path to arbitrary PHP, no path to your database, and no path to wp-config.php. WP-CLI execution is disabled unless the site owner adds define('WPAIA_ENABLE_WPCLI', true); on the server, and even then only allowlisted commands run — db, eval, eval-file, shell, server, config and package are always refused.

Safety

  • Every request is signed with HMAC-SHA256 and carries a timestamp; requests older than five minutes are rejected.

  • Permissions are per key and checked on every route, so a read-only key stays read-only.

  • Every call is written to an audit log you can read in the WordPress admin.

  • Revoking a key in WordPress takes effect immediately.

Ask the assistant to confirm before destructive actions, and keep a current backup — it can delete content when you tell it to.

  • WpAgent — hosted dashboard built on the same bridge, with a free read-only tier

  • The bridge plugin is GPL-2.0-or-later; this server is MIT.

Licence

MIT © KipDev

Install Server
A
license - permissive license
B
quality
C
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • F
    license
    Not graded
    quality
    A
    maintenance
    Production MCP server that runs as a WordPress plugin, exposing 40+ tools for managing posts, pages, custom post types, WooCommerce products, media, users, and menus from any MCP client. Includes API key + OAuth 2.0 authentication, rate limiting (60 req/min per IP), and activity logging. Free on WordPress.org
    9
  • F
    license
    Not graded
    quality
    D
    maintenance
    Enables interaction with WordPress sites through the WordPress REST API, dynamically exposing all routes as MCP tools for content management and site configuration.

View all related MCP servers

Related MCP Connectors

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/THE-KIPDEV/wpagent-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server