A hosted MCP server for WordPress.
WPMate exposes your WordPress sites to AI clients as a standard remote MCP server. No server to run, no application passwords to manage: add one URL and sign in.
Connection details
| Server URL | https://wpmate.ai/mcp |
|---|---|
| Transport | Streamable HTTP (stateless) |
| Authentication | OAuth 2.1 with PKCE and dynamic client registration (RFC 7591). Metadata at /.well-known/oauth-authorization-server and /.well-known/oauth-protected-resource/mcp |
| Tools | 26, each with a title and read-only, destructive, idempotent and open-world hints |
| Site requirements | Self-hosted WordPress 6.2+, PHP 7.4+, HTTPS, the free Mate Connector plugin |
How it works
The MCP client talks to WPMate; WPMate talks to your site through the Mate Connector plugin:
- Your AI client signs in to WPMate with OAuth and receives a short-lived access token.
- When the model calls a tool, WPMate checks your plan, the site and whether the action needs approval.
- WPMate sends the action to
/?rest_route=/wpmate/v1/executeon your site, signed with HMAC-SHA256 over a timestamp, a single-use nonce and the body. The plugin rejects unsigned, replayed or stale (older than five minutes) requests. - The plugin runs the action as the administrator who connected the site, using WordPress's own APIs, and returns the result.
Because the plugin implements a fixed set of actions rather than raw REST or SQL access, a model can't do anything outside the documented tools.
Add it to your client
Claude and ChatGPT
In Claude, connect WPMate from the connector directory; no URL needed. For ChatGPT, see ChatGPT for WordPress. Step-by-step: Claude for WordPress.
Claude Code
Add WPMate as a remote HTTP MCP server, then authenticate when prompted:
claude mcp add --transport http wpmate https://wpmate.ai/mcp
Other MCP clients
Any client that supports remote MCP servers over Streamable HTTP with OAuth (including dynamic client registration) can connect with the same URL. Clients that only support local stdio servers can't connect directly.
Tools at a glance
| Area | Tools |
|---|---|
| Sites | list_sites, site_info |
| Content | list_content, get_content, create_content, update_content, trash_content, list_revisions, restore_revision |
| Media | upload_media, list_media, update_media |
| Plugins and themes | list_plugins, manage_plugin, list_themes, manage_theme, list_snapshots, restore_snapshot |
| Design and settings | get_custom_css, set_custom_css, restore_custom_css, get_settings, update_settings |
| Audits and approvals | seo_audit, security_audit, check_approval |
Tools that need approval return approval_required with an approval id. The user approves in the WPMate dashboard, and check_approval returns the outcome.
Hosted connector vs. self-hosted MCP plugin
Some WordPress MCP options run the MCP server inside WordPress itself. A hosted connector like WPMate works differently:
- One URL for all your sites, rather than one MCP endpoint and set of credentials per site.
- OAuth sign-in that works in Claude and ChatGPT, instead of application passwords or API keys pasted into a client.
- Approvals outside WordPress, so a model can't approve its own risky changes.
- Trade-off: requests go through WPMate's server, so your site must accept signed HTTPS requests from it. Data handling is described in our privacy policy.
Frequently asked questions
What is a WordPress MCP server?
An MCP (Model Context Protocol) server exposes tools an AI assistant can call. A WordPress MCP server provides tools such as creating posts or updating plugins, so assistants like Claude and ChatGPT can manage a WordPress site directly.
Is the plugin open source?
Yes. Mate Connector is GPLv2 licensed, and its source is public on GitHub.
Does WPMate store my content?
WPMate passes requests between your AI assistant and your site and keeps an activity log of actions. See the privacy policy for exactly what is stored and for how long.
One URL. Every WordPress site.
Add https://wpmate.ai/mcp to your AI client and sign in.