Connect Roo Code to your own WordPress site over the Model Context Protocol. Roo Code is a VS Code extension, and it talks to your site directly — there is no relay in between, no account to create, and your credentials never leave your machine. Setup takes about a minute once MCP Manager is installed.
Free plugin · No account · Runs on your own server · Any WordPress host
Config file
.roo/mcp.json
Top-level key
mcpServers
Scope
Project, or global via the sidebar
Before you start
You need AcrossAI MCP Manager installed and active on the WordPress site you want Roo Code to reach, plus an administrator account on that site. If you have not installed it yet, follow the Get Started guide first — it takes about a minute, and the MCP server ships bundled with the plugin. MCP Manager needs WordPress 7.0 or later and PHP 8.1 or later.
You also need Node.js available on the machine running VS Code, because the connection runs through an npx bridge. Nothing is installed permanently — npx fetches the bridge on demand. Decide too whether you want this connection in one project or in every project: Roo Code reads a project file at .roo/mcp.json, and keeps a separate global list reachable from its sidebar.
How to connect Roo Code to WordPress
Step 1
Open Quick Connect and choose Roo Code
In wp-admin go to AcrossAI → MCP, open the server you want to expose, and start Quick Connect. Pick Roo Code from the client list. Everything below is generated for you with your real site URL and username already filled in — the snippets here are only so you know what to expect.
Step 2
Generate an Application Password
Click Generate password in the wizard. This creates a standard WordPress Application Password — not your login password — scoped to this connection and revocable at any time from your user profile.
The password is shown once, at creation. Copy it whole, including the spaces — WordPress accepts them. If you lose it, generate a new one rather than trying to recover it.
Step 3
Paste the config into .roo/mcp.json
Copy the JSON from the wizard, then create .roo/mcp.json at the root of the project you have open in VS Code — the .roo folder sits beside your .git directory, not inside src or a subfolder. Paste the entry under the mcpServers key. If that file already lists other MCP servers, add this one alongside them rather than replacing the file.
The generated config looks like this, with your own values in place of the placeholders:
{
"mcpServers": {
"your-site-mcp-adapter-default-server": {
"command": "npx",
"args": ["-y", "@automattic/mcp-wordpress-remote@latest"],
"env": {
"WP_API_URL": "https://example.com/wp-json/acrossai/mcp",
"WP_API_USERNAME": "your-wp-username",
"WP_API_PASSWORD": "xxxx xxxx xxxx xxxx xxxx xxxx"
}
}
}
}This is a project-scoped connection. A server defined in .roo/mcp.json exists only while that project is the open workspace — open a different repository and the site is gone. To make the connection available everywhere, put the same entry in Roo Code’s global list instead: open the Roo Code sidebar → MCP Servers → Configure MCP Servers and edit the global file it opens. The JSON is identical; only the location changes.
Keeping the file in the repository is deliberate on a team project, but the Application Password is a real credential — add .roo/mcp.json to .gitignore, or use the global list, rather than committing it. Connecting to a local site with a self-signed certificate? Add "NODE_TLS_REJECT_UNAUTHORIZED": "0" to the env block — for local development only.
Step 4
Check the MCP Servers panel
Open the Roo Code sidebar → MCP Servers. Your site should be listed with a green status and the toolsets it exposes underneath. If it is not there, or shows an error, use the panel’s restart control, or reload the VS Code window so Roo Code re-reads the file. Ask something harmless to confirm it is live — “Which plugins on this site need updating?” is a good first test.
What Roo Code can do once it is connected
With Abilities Manager installed alongside it, Roo Code reaches 350+ abilities across 14 toolsets — rising past 800 once it detects the plugins you already run. From inside VS Code, without switching to a browser tab, it can:
- Read and edit content — posts, pages and any custom post type with their meta and revisions, and surgically edit a page’s block tree without rewriting the page.
- Debug a broken site — read the debug log with secrets redacted, check Site Health, list recent fatal errors and un-pause what WordPress auto-disabled.
- Inspect the database — schema and table sizes, index health, bloated autoloaded options, or
EXPLAINon a slow query. - Manage plugins, themes and core — search WordPress.org, install, update, roll back, and verify files against official checksums.
- Work with files — inside an allowlist you define, with a dangerous-extension blocklist and optional pre-image backups of everything it touches.
- Reach the plugins you already run — WooCommerce, Elementor, ACF, Rank Math, Yoast, WPCode and more, each registering only when that plugin is active.
Every ability runs WordPress’s own capability check for the calling user, so Roo Code can never do anything your account could not already do. See the full platform overview for the complete catalogue.
Frequently asked questions
Is connecting Roo Code to WordPress free?
Yes. AcrossAI MCP Manager and Abilities Manager are both free and GPL on WordPress.org, and there is no AcrossAI account to create. Roo Code keeps using whichever model provider you have already configured in it — AcrossAI never charges for AI inference, because none of it runs here.
Does my site data pass through AcrossAI servers?
No. Roo Code connects straight to your own domain and every request terminates at your /wp-json/ route. There is no relay, no gateway and no telemetry. Whatever Roo Code reads is still processed by the model provider you have configured in it, so treat it as you would any other prompt.
Should I use .roo/mcp.json or the global list?
Use .roo/mcp.json when the site belongs to one repository — a client project, a theme you maintain — so the connection appears only when that project is open. Use the global list, via Roo Code sidebar → MCP Servers → Configure MCP Servers, when you want the same site available in every workspace. You can hold both: a global entry for your main site and project entries for individual builds.
Can Roo Code break my site?
Every ability runs WordPress’s own capability check for the calling user, so Roo Code can never exceed what your account can already do. Higher-risk operations refuse to run without an explicit confirmation flag, file access is confined to an allowlist you define, search-and-replace is a dry run by default, and any ability can be disallowed site-wide. Roo Code’s own auto-approve settings are worth reviewing too — they decide how much it does before asking you.
How do I disconnect Roo Code again?
Revoke the Application Password from your WordPress user profile, or remove the entry from .roo/mcp.json — and from the global list if you added it there as well. Access is re-checked on every request, so revoking takes effect immediately even if the config is still on the machine.
Troubleshooting
The server works in one project but not another
Expected, and the single most common surprise with Roo Code. .roo/mcp.json is project-scoped: the server exists only inside the repository that holds the file. Open a different folder in VS Code and that site simply is not there. Either copy the entry into each project that needs it, or move it once into the global list — Roo Code sidebar → MCP Servers → Configure MCP Servers. Note that a multi-root workspace does not merge the two: Roo Code reads .roo/mcp.json from the project root, so a file buried in the second folder of a workspace may be ignored.
Roo Code does not list the server at all
Check three things in order. First, the path: the file must be .roo/mcp.json at the root of the open folder — a dot-folder, easy to miss in a file explorer that hides them. Second, the JSON: a trailing comma or a missing brace makes Roo Code skip the whole file, and the MCP Servers panel then shows nothing rather than an error. Third, that your entry sits under mcpServers and not at the root of the object. Then restart the server from the panel, or reload the VS Code window.
I copied my settings over from Cline and nothing happened
Roo Code began as a fork of Cline, so the JSON shape is the same but the files are not shared. Cline keeps its MCP servers in its own extension settings file; Roo Code reads .roo/mcp.json for a project and its own global list for everything else. Copy the contents of the mcpServers object across rather than pointing Roo Code at Cline’s file, and expect to run both side by side without them seeing each other’s servers.
The server appears but has no tools
That is the connection working and the catalogue being empty. Either Abilities Manager is not installed — MCP Manager will serve an empty catalogue quite happily — or the abilities exist but are not exposed to this particular server. Open AcrossAI → MCP, select the server, and check its Tools and Abilities tabs. After changing what a server exposes, restart it from Roo Code’s MCP Servers panel: MCP clients receive their tool list once, at connection time.
Authentication fails, or npx is not found
Application Passwords are shown once and are not your login password. Generate a fresh one from Quick Connect rather than retyping an old one, and copy it complete with spaces. If the request is being refused rather than failing, check the server’s access rules — a new server requires manage_options until you add a rule, and the gate fails closed. A command not found error instead means Node.js is missing, or VS Code was launched from the Dock or Start menu and did not inherit the PATH your shell sets — in that case point command at the absolute path to npx.
Connect a different AI client
The same server works with every MCP client — only the config file and top-level key change. See the guides for Claude Desktop, Claude Code, Cursor, VS Code, GitHub Copilot, Windsurf, Zed, Codex and every other client.
Not installed yet?
Install MCP Manager on your site, then come back and run Quick Connect.
