Give a WordPress MCP client its own user and a separately revocable Application Password, then grant only the capabilities and exposed abilities needed for its specific tasks. Do not default to an administrator account. Authorization has two parts: access to the MCP server as a whole and permission checks for each individual ability.
How WordPress MCP permissions work
An MCP client makes requests as an authenticated WordPress user. The WordPress MCP Adapter maps registered WordPress abilities into MCP components; it does not create a universal “MCP role” with a fixed permission set. The user’s capabilities, the abilities exposed by the server, and the authorization code for each ability all shape what the client can do.
Roles bundle capabilities
WordPress roles are collections of capabilities, and users may also receive capabilities directly. As WordPress Developer Resources explains, “User capabilities are the specific permissions that you assign to each user or to a User role.” The capability needed depends on the operation and on the site’s installed plugins and custom abilities, so there is no reliable one-size-fits-all MCP capability list.
Exposure is not authorization
The adapter’s documentation describes ability exposure as opt-in: an ability must be made available through MCP before a client can discover and invoke it. Exposure alone does not authorize the current user. The ability’s permission callback must still permit that user to perform the operation.
#1 Best Overall
There are therefore two authorization layers to review: the transport-level permission that can restrict access to the MCP server as a whole, and the permission callback on each exposed ability. The server-wide gate does not replace the individual checks. MCP annotations such as a read-only hint are behavioral metadata, not a substitute for server-side WordPress authorization.
Choose permissions by the client’s tasks
Start with a concrete task list, then match the user’s capabilities and the MCP abilities to it. For example, a client that only reads published posts should not receive content-editing or store-management access. If it must create drafts, upload media, or change store data, add only the capabilities and abilities needed for those operations, with their permission callbacks enforced.
Rank #2
| Workflow | WordPress user access | MCP abilities to expose |
|---|---|---|
| Read public content | Anonymous access may suffice for public REST API data; an authenticated account is not automatically necessary. | Only relevant read abilities, if MCP access is needed. |
| Read private or protected content | An authenticated user with access to the specific content. | Relevant read abilities only; each must authorize the user. |
| Create or edit content | Capabilities for the precise content operations required. | Only the corresponding write abilities, with their permission callbacks. |
| Manage WooCommerce data | A dedicated user with only the capabilities the client needs, as WooCommerce’s MCP integration guidance recommends. | Only relevant WooCommerce abilities; their own permission callbacks still apply. |
WordPress describes its REST API as providing “public data accessible to any client anonymously, as well as private data only available after authentication.” If the client needs private content, authenticate it as a suitably limited user rather than broadening its access to unrelated data.
Set up a dedicated user and credential
- List the operations. Specify whether the integration will read public or private content, create drafts, edit posts, upload media, or manage store data. Avoid vague requirements such as “WordPress access.”
- Create a dedicated WordPress user. Assign the narrowest role or direct capabilities that support those tasks. Do not use an administrator account by default.
- Create a named Application Password for the integration. WordPress calls these “revocable, per-application credentials for programmatic access.” An Application Password authenticates as its associated WordPress user; it does not narrow that user’s capabilities.
- Use the credential only over HTTPS. WordPress advises HTTPS because Basic Authentication credentials can otherwise be intercepted. Application Passwords are available by default for HTTPS requests, although site code or security plugins can disable or restrict them.
- Review the MCP server-wide gate and each exposed ability. Check that the transport permission matches the intended access and that every exposed ability’s permission callback checks the appropriate capability or authorization condition. Remove abilities the client does not need to discover or invoke.
- Test allowed and denied operations as the integration user. Confirm intended tasks work and an unneeded operation is rejected. Revisit the account and exposure list when the workflow or installed plugins change.
Read-only access versus write access
For a read-only workflow
Expose read abilities only and give the user only the access needed for the relevant content. Public REST data may be available anonymously; private or protected data requires authentication or explicit exposure. If private data is needed, authentication should not become a reason to grant unrelated write permissions.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesWhen the client must write
Grant only the capabilities required for the precise create, update, upload, or delete operation. WordPress REST endpoints support content creation and modification subject to authentication and permissions. The adapter’s Abilities API endpoints can require GET for read-only abilities, POST for regular input-taking abilities, and DELETE for destructive abilities; the applicable method and permission checks depend on the ability and installed version.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Verify the installed abilities and avoid broad fixes
Review the abilities and permission callbacks registered by the installed MCP Adapter, WordPress core, WooCommerce, and other relevant plugins. The available capabilities and checks are site- and version-dependent. The adapter repository describes MCP exposure as opt-in and its default server as providing discovery, ability information, and ability execution through meta-tools; confirm the behavior against the release installed on your site because repository documentation can change.
Rank #4
Application Passwords are the adapter’s documented default authentication method, but OAuth or other authentication methods can be implemented, and sites may customize authentication. Likewise, security should come from appropriate authentication and authorization rather than disabling the REST API wholesale: WordPress warns that doing so can break administration features that rely on it.
When an integration is retired or a credential is compromised, revoke its Application Password. Because the credential belongs to a particular WordPress user, removing or changing that user’s access is a separate control from revoking the credential.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




