WPMate documentation
How it works
WPMate is a hosted MCP (Model Context Protocol) server at https://wpmate.ai/mcp. Your AI assistant calls WPMate's tools, and WPMate passes each request to your WordPress site through the free Mate Connector plugin.
- Your AI signs in to WPMate with OAuth. WPMate never sees your Claude or ChatGPT password, and never asks for your WordPress password.
- Each connected site gets its own secret. Every request to the site is signed with it and expires after five minutes, so it can't be replayed.
- The plugin acts as the WordPress administrator who connected the site, and only through the actions listed in the tools reference. It does not run arbitrary code or SQL.
Requirements: a self-hosted WordPress site (WordPress 6.2 or later, PHP 7.4 or later) served over HTTPS, and an administrator account on it. WordPress.com sites on plans without plugins are not supported.
Set up in 3 steps
1. Create a WPMate account
Sign up at wpmate.ai/signup and confirm your email address with the link we send you.
2. Connect your WordPress site
- In the WPMate dashboard, select Create connection code. The code is valid for 30 minutes and works once.
- On your WordPress site, go to Plugins → Add New, search for Mate Connector, then install and activate it. You can also download the plugin zip and upload it from Plugins → Add New → Upload Plugin.
- Open Settings → WPMate, paste the connection code and select Connect. The site now appears under Sites in your dashboard.
3. Add WPMate to your AI
Follow the steps for Claude or ChatGPT below, then ask something like “List my WordPress sites”.
Connect Claude
- Open WPMate in the Claude directory (or in Claude go to Customize → Connectors and search “WPMate”).
- Select Connect. There’s no URL to copy.
- Sign in to WPMate when asked and select Allow.
The connector works in Claude on the web, desktop and mobile apps, and in Claude Code. On Team and Enterprise plans, an Owner may need to enable WPMate for the organization first.
Connect ChatGPT and other clients
ChatGPT: open Settings → Apps & Connectors. If WPMate is listed, select it and connect. Otherwise turn on developer mode under Advanced settings, select Create, enter https://wpmate.ai/mcp with OAuth authentication, and sign in to WPMate.
Any other MCP client that supports remote servers over Streamable HTTP with OAuth 2.1 (dynamic client registration and PKCE) can use the same URL: https://wpmate.ai/mcp.
What to ask
- “Write a 600-word blog post about winter lawn care and save it as a draft with an SEO title and meta description.”
- “Run an SEO audit on my site and fix the missing meta descriptions on my five newest posts.”
- “Run a security audit. Which plugins need updates?”
- “Find images without alt text and write descriptive alt text for them.”
- “Make the header buttons rounded and change the link colour to dark green.”
- “Install and activate the Redirection plugin.” (You approve this in the dashboard.)
- “Undo the last change to the About page.”
If you have several sites, mention the site name or address in your request. With one site, WPMate uses it automatically.
Tools reference
Read-only tools never change your site. Writes change the site and can be undone. Approval means the change waits until you approve it in the dashboard.
| Tool | What it does | Type |
|---|---|---|
list_sites | Lists the sites connected to your WPMate account. | Read-only |
site_info | WordPress and PHP versions, active theme, plugins, SEO plugin, permalinks and content counts. | Read-only |
list_content | Lists posts, pages or another public post type, newest first. | Read-only |
get_content | Full content, status, SEO fields and featured image of one post or page. | Read-only |
create_content | Creates a post or page, saved as a draft with a preview link unless you ask to publish. Can set SEO title, meta description, categories, tags and featured image. | Write Approval to publish |
update_content | Edits a post or page. WordPress keeps a revision of the previous version. | Write Approval to publish |
trash_content | Moves a post or page to the trash (recoverable for 30 days). | Approval |
list_revisions | Saved revisions of a post or page. | Read-only |
restore_revision | Restores a post or page to an earlier revision. | Write |
upload_media | Adds an image from a public URL to the media library, with alt text; can set it as a featured image. | Write |
list_media | Media library items with size, alt text and URL; can list images missing alt text. | Read-only |
update_media | Sets the alt text, title or caption of a media item. | Write |
list_plugins | Installed plugins, versions, active state and available updates. | Read-only |
manage_plugin | Installs (from WordPress.org), activates, deactivates, updates or deletes a plugin. A snapshot is taken before an update or deletion. | Approval |
list_themes | Installed themes, the active theme and available updates. | Read-only |
manage_theme | Installs a theme from WordPress.org, switches to a theme, or updates one. | Approval |
list_snapshots | Plugin and theme snapshots taken before updates and deletions. | Read-only |
restore_snapshot | Restores a plugin or theme from a snapshot (undoes an update or deletion). | Approval |
get_custom_css | The site's Additional CSS for the active theme. | Read-only |
set_custom_css | Replaces the Additional CSS. The previous CSS is saved as a snapshot. | Write |
restore_custom_css | Restores the CSS from before the last change, or from a given snapshot. | Write |
get_settings | Site title, tagline, timezone, date format, homepage, search visibility and comment defaults. | Read-only |
update_settings | Changes those settings. | Write Approval for search visibility and homepage |
seo_audit | Checks for missing meta descriptions, title length, thin content, heading problems, images without alt text and missing featured images. | Read-only |
security_audit | Checks updates, modified core files, debug and file-editing settings, XML-RPC, admin accounts, open registration, HTTPS, PHP version and PHP files in uploads. | Read-only |
check_approval | Tells the AI whether you approved or rejected a pending change, and the result. | Read-only |
SEO titles and meta descriptions are written to Yoast SEO, Rank Math, All in One SEO or SEOPress when one is active. Without an SEO plugin, WPMate outputs them itself.
Approvals
Changes that are risky or visible to visitors wait for you: publishing, trashing, installing, updating or deleting plugins and themes, switching themes, rolling back a snapshot, and changing search visibility or the homepage.
- The AI tells you a change is waiting for approval.
- Open wpmate.ai/app/approvals, check the details and select Approve or Reject.
- Tell the AI you've decided. It calls
check_approvaland reports the result.
Nothing on the list above runs until you approve it.
Undo and rollback
- Posts and pages: every edit keeps a WordPress revision. Ask “undo the last change to …” or use
restore_revision. - CSS: every change saves the previous CSS. Ask “undo the CSS change”.
- Plugins and themes: a zip snapshot is taken before an update or deletion. Ask “roll back the plugin update” (needs approval).
- Trash: trashed content stays in WordPress's trash for 30 days.
Security
- Signed requests: HMAC-SHA256 signature over a timestamp, a single-use nonce and the request body; requests older than five minutes or reused are rejected.
- Limited actions: the plugin only exposes the tools above. Content is filtered with WordPress's own HTML sanitiser, and CSS that could run scripts is refused.
- OAuth 2.1: AI assistants get short-lived tokens that you can revoke at any time from the dashboard (Sign out all AI assistants).
- HTTPS only: sites must use HTTPS.
- Activity log: every action is listed under Activity.
Data handling is described in the Privacy Policy. Report a security issue to support@wpmate.ai.
Plans and limits
| Plan | Price | Sites | AI actions per day |
|---|---|---|---|
| Starter | Free | 1 (one website for the life of the account) | 100 |
| Pro | $14.99/month or $149.99/year | Unlimited | 750 |
| Agency | $69.99/month or $599.99/year | Unlimited | 5,000 |
The Starter plan is tied to one website: the first site you connect (or, after a downgrade, the first site you use). You can disconnect and reconnect that site, but connecting or using a different website needs Pro. Moved your site to a new domain? Email support@wpmate.ai.
An AI action is one tool call. The daily count resets at midnight UTC. Upgrade, change plan or cancel under Billing.
Troubleshooting
The plugin says the connection code is invalid
Codes expire after 30 minutes and work once. Create a new code in the dashboard. On the Starter plan you can only connect your one Starter website; to connect a different site, upgrade to Pro.
“Site unreachable” or requests time out
WPMate calls /?rest_route=/wpmate/v1/execute on your site. Check that the site loads over HTTPS and that a security plugin, firewall (for example Cloudflare or Wordfence) or host isn't blocking the WordPress REST API or requests from WPMate.
“Request timestamp is too old or the server clock is wrong” or “Invalid WPMate signature”
Your server's clock may be more than five minutes off. Ask your host to enable time synchronisation (NTP). If it keeps happening, disconnect and reconnect the site.
The AI says it has no access
Reconnect WPMate in your AI client's connector settings and sign in again. If you used Sign out all AI assistants, this is expected.
Daily limit reached
The count resets at midnight UTC, or you can upgrade under Billing.
Disconnect and delete
- A site: select Disconnect on the Sites page, or deactivate the plugin. Deleting the plugin removes its settings from WordPress.
- An AI assistant: remove WPMate from its connector settings, or use Sign out all AI assistants in the dashboard.
- Your account: email support@wpmate.ai from your account email. Cancel any paid plan under Billing first.
Support
Email support@wpmate.ai. Include your account email and site address.
WPMate is made by PILOTLAB LLC, Wyoming, USA. WordPress is a trademark of the WordPress Foundation; WPMate is not affiliated with WordPress or Automattic.