Skip to main content
Glama
oborseth

Official Porkbun MCP Server

Create WP Credentials

create_wp_credentials

Mint a WordPress Application Password for a domain's Cloud for WordPress site, enabling WP REST API access over HTTP Basic auth.

Instructions

CLOUD FOR WORDPRESS ONLY. Mint a WordPress Application Password for a domain's managed WordPress site so you can drive it over the WP REST API at https:///wp-json/ using HTTP Basic auth. The password is returned ONCE (WordPress stores only a hash) — save it immediately. Defaults to a dedicated least-privilege porkbun-agent user with the editor role (created on first use), which can manage content but cannot install code. role: "administrator" grants FULL site control including plugin installation (i.e. arbitrary code execution on the site) and therefore requires acknowledge_full_access: true — only request it if the user explicitly asked for admin-level access. The site must be provisioned and ACTIVE (poll get_hosting) — this works on any Cloud for WordPress site in the account however it was provisioned, but free $0 preview sites are excluded. Revoke any time with delete_wp_credentials. Rate limit: 20 mints per account per hour.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
nameNoLabel shown in wp-admin (letters, digits, dashes), e.g. `Acme-Agent`.
roleNo`editor` (default) = content only, recommended for agents. `administrator` = full control incl. plugin install; requires acknowledge_full_access.
domainYesDomain whose WordPress site to mint credentials for.
dry_runNoValidate without creating anything.
acknowledge_full_accessNoRequired when role=administrator: confirms the user understands the credential can run arbitrary code on the site.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv0.39.4

TDQS

A4.8/5.0
Behavior5/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations only cover the generic safety profile; the description adds the operationally critical facts: the password is returned once and must be saved, the default is a least-privilege porkbun-agent/editor user, administrator implies arbitrary code execution and requires acknowledge_full_access, and there is a 20-per-hour rate limit.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness4/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Front-loaded with the CLOUD FOR WORDPRESS ONLY scope and the core action, then the caveats. Dense but every sentence carries a distinct constraint; only the restated 'save it immediately' warning is mildly redundant with the one-time-return statement.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

No output schema exists, and the description covers what matters about the return value (one-time password, save immediately) plus the credential semantics. For a 5-param mutation with full schema coverage and annotations, nothing material is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so the baseline would be 3, but the description reinforces the role/acknowledge_full_access coupling with consequences the schema cannot encode (full site control, code execution). It adds risk semantics beyond the enum labels rather than merely restating them.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb (mint), resource (WordPress Application Password for a domain's managed WP site), and the downstream purpose (drive it over the WP REST API with Basic auth). An agent can distinguish this instantly from list_wp_credentials, delete_wp_credentials, and deploy_site.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

Explicit prerequisites (site provisioned and ACTIVE, poll get_hosting), explicit exclusion (free $0 preview sites), explicit routing to a sibling for cleanup (delete_wp_credentials), and an escalation condition for the administrator role. Nothing is left to inference.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools