DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk4 min

WordPress MCP Server Setup: URLs, Authentication, and Settings to Verify

WordPress.com hosted MCP and the self-hosted MCP Adapter use different endpoints and authentication. Here’s how to choose and verify the right setup.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the connection route that matches where WordPress runs: WordPress.com and eligible Jetpack-connected sites use WordPress.com’s hosted MCP server, while other self-hosted sites use the MCP Adapter installed on the site. Their endpoints and authentication flows are different, so do not swap their URLs or credentials.

Choose the right WordPress MCP connection

Connection path Hosting model Endpoint Transport and authentication Requirements
WordPress.com hosted MCP Hosted by WordPress.com; eligible Jetpack-connected self-hosted sites use the same hosted server, not a separate Jetpack endpoint. https://public-api.wordpress.com/wpcom/v2/mcp/v1 HTTP with browser-based OAuth 2.1. MCP access is available on WordPress.com paid plans and, for a free site, during its first 30 days after creation. Jetpack-connected self-hosted sites need Jetpack AI or Jetpack Complete.
Self-hosted MCP Adapter The MCP endpoint is provided by the Adapter on your WordPress site. https://your-site.com/wp-json/mcp/mcp-adapter-default-server, using your actual scheme and host. HTTP through the remote proxy, or local WP-CLI STDIO. HTTP proxy setup uses a WordPress username and application password, or an appropriate configured OAuth mechanism. Learn WordPress lists WordPress 6.9 or higher and PHP 7.4 or higher for the Adapter.

Sources: WordPress.com MCP Server documentation, WordPress Developer Blog, and Learn WordPress.

Set up WordPress.com hosted MCP

  1. In your WordPress.com account settings, enable MCP.
  2. Add https://public-api.wordpress.com/wpcom/v2/mcp/v1 as the server endpoint in an MCP-capable client.
  3. Complete the browser authorization flow when prompted. WordPress.com documents OAuth 2.1 with PKCE, dynamic client registration, token rotation, and no need to manage client secrets or tokens manually.

Connect with Claude Code or Codex

For Claude Code, run:

claude mcp add --transport http wpcom-mcp https://public-api.wordpress.com/wpcom/v2/mcp/v1

Then run /mcp in Claude Code to authenticate. For Codex, WordPress.com documents:

codex mcp add wpcom-mcp --url https://public-api.wordpress.com/wpcom/v2/mcp/v1

Connect with other clients

Follow the client’s current instructions to add the hosted endpoint and authorize in a browser. WordPress.com documents Claude Desktop setup through its Connectors Directory. To review or revoke access, open WordPress.com account Security → Connected Apps. Source: WordPress.com MCP Server documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set up the self-hosted MCP Adapter

Install the official Adapter on the WordPress site, then choose HTTP or local WP-CLI STDIO. Learn WordPress describes installing the plugin from GitHub Releases, either by uploading the ZIP through WordPress admin or using WP-CLI. Its stated minimums are WordPress 6.9 and PHP 7.4. Source: Learn WordPress.

Use HTTP with the remote proxy

The Developer Blog’s minimum proxy configuration is shown below. Replace the example site address, username, and application password with credentials for your installation; do not use tutorial sample credentials on a real site.

{
  "mcpServers": {
    "wordpress-mcp-server": {
      "command": "npx",
      "args": ["-y", "@automattic/mcp-wordpress-remote@latest"],
      "env": {
        "WP_API_URL": "https://your-site.com/wp-json/mcp/mcp-adapter-default-server",
        "WP_API_USERNAME": "your_wordpress_user",
        "WP_API_PASSWORD": "your_application_password"
      }
    }
  }
}

WP_API_URL must point to the Adapter endpoint on the target site. Use an application password or a configured OAuth mechanism supported by your setup. Source: WordPress Developer Blog.

Use local WP-CLI STDIO

For a local WordPress installation on the same computer as the MCP client, Learn WordPress recommends STDIO: it avoids a network connection and does not expose the site externally. The Adapter’s example invokes wp and mcp-adapter serve, specifying the WordPress installation path, the server identifier mcp-adapter-default-server, and a WordPress user. Confirm WP-CLI can reach the intended installation path and that the chosen user has the capabilities needed for the actions you plan to use. Source: Learn WordPress.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Put settings in the right client configuration

Client interfaces and configuration formats can change; use the current documentation for your client. The documented configuration locations and keys differ:

  • Claude Desktop: Open Settings → Developer and edit claude_desktop_config.json; server definitions use mcpServers.
  • Claude Code: Configure through its command or a project .mcp.json / home configuration.
  • Cursor: Use its Tools and MCP settings and configuration file.
  • VS Code: Use .vscode/mcp.json; the top-level server key is servers, not mcpServers.

Source: WordPress Developer Blog.

Check permissions and exposure before connecting

Finding an ability does not mean the connected user can execute it. The Adapter lesson says execution requires an authenticated user with the capabilities required by that ability’s permission callback. The project README states, “WordPress abilities are private by default.” Public discovery is opt-in; execution remains subject to permission checks. Give the client user only the capabilities needed for the abilities it will call. Sources: Learn WordPress and WordPress/mcp-adapter README.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot a connection that does not work

  1. Confirm the route. Determine whether you are using WordPress.com hosted MCP or a self-hosted site with the Adapter. These paths use different endpoints.
  2. Check the URL exactly. For WordPress.com, use https://public-api.wordpress.com/wpcom/v2/mcp/v1. For the Adapter, use the actual site host followed by /wp-json/mcp/mcp-adapter-default-server.
  3. Check transport and configuration key. Ensure the client is configured for the selected HTTP or STDIO path and uses its expected settings format; for example, VS Code uses servers, while the Claude Desktop example uses mcpServers.
  4. For WordPress.com, enable MCP and finish browser authorization. Review account Security → Connected Apps if you need to check or revoke access.
  5. For self-hosted HTTP, verify all three environment values. Check WP_API_URL, WP_API_USERNAME, and WP_API_PASSWORD, along with the application password or supported OAuth configuration.
  6. For STDIO, verify the local installation path and user. Confirm WP-CLI reaches the intended site and the account has the required capabilities.
  7. If using a reverse proxy, inspect forwarding. It must preserve the Host header and forward the full request path, including /wp-json/mcp/.
  8. If the local remote-proxy connection fails, check Node.js and certificates. Multiple Node.js installations and local SSL certificate issues are documented troubleshooting possibilities.
  9. Reload after changing MCP settings or enabled tools. Restart or reload the client connection so it refreshes the available tools; WordPress.com explicitly recommends restarting the client during troubleshooting.

Sources: WordPress.com MCP Server documentation, WordPress Developer Blog, and Learn WordPress.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.