October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

How to Connect Claude to WordPress Without Exposing API Keys

WordPress MCP can connect Claude to WordPress.org's service or a specific site using a WordPress Application Password. Learn which route fits and how to limit credential exposure.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

You can connect Claude to WordPress using a WordPress username and an Application Password; the documented WordPress MCP setups do not put an Anthropic API key in the WordPress connection settings. The Application Password is still a sensitive, reusable credential. Use HTTPS, a dedicated WordPress user with only the capabilities needed, and revoke the password if it is exposed or no longer required.

Choose the WordPress connection that matches your goal

WordPress documents two distinct MCP routes. One connects a client to the WordPress.org MCP service and its tools; the other connects to a specific WordPress install through the MCP Adapter and that site’s registered Abilities. They are not interchangeable: authorizing the WordPress.org service does not automatically give Claude access to an arbitrary self-hosted site.

As an Amazon Associate I earn from qualifying purchases.

Route What Claude connects to Who configures and maintains it Credential and revocation
WordPress.org MCP service The documented tools exposed by the WordPress.org MCP service, not an arbitrary WordPress site. WordPress.org MCP setup guide. The user authorizes the WordPress.org flow; the guide can configure supported MCP clients. A WordPress.org account Application Password is created for the connection. Reauthorize to replace the existing MCP Application Password, or revoke the connection in WordPress.org account security settings.
Site-specific MCP Adapter A WordPress install’s MCP endpoint and the Abilities registered and exposed by that site. WordPress Developer Blog MCP Adapter guide. The site owner or developer configures the adapter, endpoint, abilities, and permission checks; those components need ongoing maintenance. A WordPress username and Application Password authenticate to the site. Revoke the credential for its WordPress user when access is no longer needed.

For the WordPress.org route, follow the official setup guide. It documents running npx -y @wporg/mcp, authorizing in a browser, and configuring supported clients including Claude Desktop and Claude Code. For a site-specific connection, use the site’s MCP Adapter endpoint and verify that the abilities Claude needs have actually been registered and made available.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Connect Claude to a WordPress site with the MCP Adapter

The site-specific route is appropriate when Claude needs to interact with a particular WordPress installation. The adapter maps WordPress Abilities into MCP primitives so an MCP client can discover and execute the functionality the site exposes. The adapter alone does not make every WordPress feature available: the relevant ability must exist, be registered, and have suitable permission checks.

  1. Confirm the site is ready. Check that the WordPress site has the MCP Adapter configured, that the desired Abilities are registered, and that Application Passwords are available for the integration user. Site configuration and plugin versions affect what is available.
  2. Create a dedicated integration user. Assign only the capabilities required for the intended tasks. Avoid using an administrator account simply for convenience.
  3. Create an Application Password for the integration. In WordPress, open Users → Profile for that user and use the Application Passwords section to add a credential with a recognizable name. WordPress displays the generated value once; copy it directly to the client configuration and store it securely.
  4. Configure the MCP client. In Claude Desktop or Claude Code, use the configuration form documented for the adapter and your client version. The configuration needs the site’s MCP API endpoint, the WordPress username, and the Application Password. Keep the endpoint on HTTPS; do not paste a live password into prompts, issue reports, or shared configuration examples.
  5. Test the narrowest intended task. Confirm that Claude can discover and use only the expected abilities. If an ability is unavailable or denied, review its registration and permission callback rather than granting the integration user broad capabilities by default.

The MCP Adapter guide covers the site-specific approach and its security considerations; the related WordPress abilities and MCP implementation discussion describes the adapter’s role in exposing site functionality. Exact setup fields can vary by client and deployment, so use the configuration example for the versions you run.

Connect to the WordPress.org MCP service

This guided flow is for the WordPress.org MCP service, not for attaching Claude to any WordPress site you choose. The WordPress.org instructions describe running npx -y @wporg/mcp, completing browser authorization, and configuring supported clients such as Claude Desktop and Claude Code. The guide also provides a manual client-configuration option with a WordPress API endpoint, username, and Application Password.

During authorization, WordPress creates an Application Password for the connection. The password is shown only once. The WordPress.org guide says that authorizing again replaces the existing MCP Application Password; you can also revoke the connection through the WordPress.org account security settings.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Understand which credential is being used

In the documented WordPress MCP configurations, WordPress authenticates the connection with a WordPress username and Application Password. Those examples do not include an Anthropic API key in the WordPress MCP-server settings. That describes these configurations only; it does not establish that every plugin, proxy, custom workflow, or architecture involving Claude will never need an Anthropic API key. A WordPress plugin that calls an external AI API has a separate credential flow.

An Application Password is not the password you use to sign in at wp-login.php. It is a separate credential intended for programmatic access, including the REST API. WordPress generates it per application, stores it hashed, shows it once, and lets you revoke it individually. WordPress’s Application Passwords handbook recommends treating these credentials as secrets and creating one for each integration.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Protect the Application Password and the abilities it can reach

Use HTTPS and least privilege

WordPress Application Password authentication uses HTTP Basic Authentication. The WordPress REST API authentication handbook documents this method over HTTPS. Basic Authentication carries reusable credentials, so never send an Application Password over unencrypted HTTP. Give the MCP integration user only the WordPress capabilities needed for its intended actions.

Review site ability permissions

For a site-specific adapter, the abilities exposed to Claude determine what it can attempt to do. Follow the adapter guide’s security advice:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Check each ability’s permission_callback and require the minimum WordPress capability for that action.
  • Do not use unrestricted permission callbacks for destructive operations.
  • Avoid exposing powerful abilities to unaudited AI clients.
  • Prefer read-only abilities for public MCP endpoints, and monitor and log usage.
  • Consider custom authentication if the deployment requires it; Application Passwords are the default approach described in the guide.

Treat client configuration as sensitive

A client configuration example containing an Application Password is a secret-bearing configuration, even if the file is local or the value is supplied through an environment variable. The WordPress setup material reviewed here does not promise that Claude client configuration files or environment settings are encrypted at rest. Do not commit a live credential to source control, share it in screenshots or logs, or copy it into a prompt. Protect backups and other copies as well. If the credential is exposed, revoke it in WordPress and create a replacement.

Best Value
hosting servers
  • easy to use
  • Free app
  • Compatible with all devices
  • It gives the best comparison between ten different hosts

WordPress’s connector settings reference describes masking API-key values and default Application Password values in certain REST settings responses. That behavior applies to those responses; it does not establish that every credential stored by WordPress, a plugin, or a Claude client is protected in the same way. See the Application Password REST API reference for credential-management endpoints and the WordPress connector settings reference for the relevant settings behavior.

Revoke access when it is no longer needed

For a site integration, remove the specific Application Password from the integration user’s WordPress profile or use the applicable credential-management controls. For the WordPress.org MCP service, use the account security settings; authorizing the connection again replaces its existing MCP Application Password, according to the setup guide. Removing a credential is preferable to leaving an unused integration active.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.