30 days free. No credit card. Full access from the moment you connect your site.

Start free trial

Connect Codex to WordPress

Connect Codex to WordPress — AcrossAI setup guide

Connect Codex to your own WordPress site over the Model Context Protocol. Codex talks to your site directly from the terminal — there is no relay in between, no account to create, and your credentials never leave your machine.

Free plugin · No account · Runs on your own server · Any WordPress host

Config file

~/.codex/config.toml

Top-level key

mcp_servers

Format

TOML — not JSON

Before you start

You need AcrossAI MCP Manager installed and active on the WordPress site you want Codex to reach, plus an administrator account on that site. If you have not installed it yet, follow the Get Started guide first — it takes about a minute, and the MCP server ships bundled with the plugin.

You also need Node.js, because the connection runs through an npx bridge fetched on demand.

How to connect Codex to WordPress

Step 1

Open Quick Connect and choose Codex

In wp-admin go to AcrossAI → MCP, open the server you want to expose, and start Quick Connect. Pick Codex from the client list — the wizard produces a TOML snippet rather than JSON, already filled in with your site URL and username.

Step 2

Generate an Application Password

Click Generate password in the wizard. This creates a standard WordPress Application Password — not your login password — scoped to this connection and revocable at any time from your user profile.

The password is shown once, at creation. Copy it whole, including the spaces. In TOML it must sit inside double quotes, exactly as the wizard prints it.

Step 3

Add it to ~/.codex/config.toml

Open ~/.codex/config.toml — create it if it does not exist — and append the snippet. Codex uses TOML, so this is the one client where you cannot reuse a JSON snippet from another guide.

[mcp_servers.your-site-mcp-adapter-default-server]
command = "npx"
args = ["-y", "@automattic/mcp-wordpress-remote@latest"]

[mcp_servers.your-site-mcp-adapter-default-server.env]
WP_API_URL = "https://example.com/wp-json/acrossai/mcp"
WP_API_USERNAME = "your-wp-username"
WP_API_PASSWORD = "xxxx xxxx xxxx xxxx xxxx xxxx"

The environment variables go in their own .env table beneath the server table. Putting them inline under [mcp_servers.…] is the usual TOML mistake — Codex will start the bridge with no credentials and the connection will fail authentication rather than error clearly.

Step 4

Restart Codex and check the tools

Restart the Codex CLI so it re-reads config.toml. Your site’s toolsets become available in the session. Ask something harmless to confirm it is live — “Which plugins on this site need updating?” is a good first test.

What Codex can do once it is connected

With Abilities Manager installed alongside it, Codex reaches 350+ abilities across 14 toolsets — rising past 800 once it detects the plugins you already run. Without leaving the terminal it can:

  • Debug against the real site — read the debug log with secrets redacted, check Site Health, list recent fatal errors and un-pause what WordPress auto-disabled.
  • Inspect the database — schema and table sizes, index health, bloated autoloaded options, or EXPLAIN on a slow query.
  • Read and edit content — posts, pages and any custom post type, and surgically edit a page’s block tree without rewriting the page.
  • Manage plugins, themes and core — install, update, roll back, and verify files against official checksums.
  • Work with files — inside an allowlist you define, with optional pre-image backups and a changelog of what changed.
  • Reach the plugins you already run — WooCommerce, Elementor, ACF, Rank Math, Yoast, WPCode and more, each registering only when that plugin is active.

Every ability runs WordPress’s own capability check for the calling user, so Codex can never do anything your account could not already do. See the full platform overview for the complete catalogue.

Frequently asked questions

Is connecting Codex to WordPress free?

Yes. AcrossAI MCP Manager and Abilities Manager are both free and GPL on WordPress.org, and there is no AcrossAI account to create. You use the OpenAI subscription you already have — AcrossAI never charges for AI inference, because none of it runs here.

Why TOML and not JSON?

That is Codex’s own configuration format — nothing to do with MCP itself. Every other client on this site uses JSON. Quick Connect detects the client and emits the right format, so use the snippet it gives you rather than translating one by hand.

Does my site data pass through AcrossAI servers?

No. Codex connects straight to your own domain and every request terminates at your /wp-json/ route. There is no relay, no gateway and no telemetry. Whatever Codex reads is still processed by OpenAI, so treat it as you would any other prompt.

Can Codex break my site?

Every ability runs WordPress’s own capability check for the calling user, so Codex can never exceed what your account can already do. Higher-risk operations refuse to run without an explicit confirmation flag, file access is confined to an allowlist you define, search-and-replace is a dry run by default, and any ability can be disallowed site-wide.

How do I disconnect Codex again?

Revoke the Application Password from your WordPress user profile, or remove the two tables from ~/.codex/config.toml. Access is re-checked on every request, so revoking takes effect immediately even if the config is still on the machine.

Troubleshooting

Codex does not see the server

Check the table name is [mcp_servers.…] with an underscore — mcpServers is the JSON convention and means nothing in Codex. Then confirm the file parses as valid TOML; an unquoted value or a stray bracket invalidates everything after it. Restart the CLI after editing.

It connects but authentication fails

Almost always the env table. The environment variables must be in their own [mcp_servers.<name>.env] table, not inline in the server table. Also check the Application Password is wrapped in double quotes and copied complete with its spaces.

The server appears but has no tools

That is the connection working and the catalogue being empty. Either Abilities Manager is not installed, or the abilities are not exposed to this server. Open AcrossAI → MCP, select the server, and check its Tools and Abilities tabs. Restart Codex after changing what a server exposes: clients receive their tool list once, at connection time.

It worked yesterday and stopped today

Access is re-checked on every request, not just at setup. A change to your role, capability or membership takes effect immediately, and a saved config does not keep working. Revoking the Application Password has the same effect.

npx is not found

The bridge runs through npx, which ships with Node.js. Install Node.js and restart the CLI. If Node came from a version manager, set command to the absolute path from which npx rather than relying on PATH.

Connect a different AI client

The same server works with every MCP client — only the config file and format change. See the guides for Claude Code, Cursor, VS Code, GitHub Copilot, Claude Desktop, Windsurf, Zed and every other client.

Not installed yet?

Install MCP Manager on your site, then come back and run Quick Connect.


Keep reading