30 days free. No credit card. Full access from the moment you connect your site.

Start free trial

Connect Custom MCP Client to WordPress

Connect Any MCP Client to WordPress — AcrossAI setup guide

Connect any MCP client to your own WordPress site, including one you built yourself. MCP Manager exposes a standards-compliant Model Context Protocol endpoint on your own domain — there is no relay in between, no account to create, and your credentials never leave your machine. If your client accepts a command, an args array and an env object, it will connect.

Free plugin · No account · Runs on your own server · Any WordPress host

Config file

Client-specific — see your client’s docs

Top-level key

mcpServers or its variants

Entry shape

command · args · env

Before you start

You need AcrossAI MCP Manager installed and active on the WordPress site you want the client to reach, plus an administrator account on that site. If you have not installed it yet, follow the Get Started guide first — it takes about a minute, and the MCP server ships bundled with the plugin.

You also need Node.js on the machine running the client, because the connection runs through an npx bridge. Nothing is installed permanently — npx fetches the bridge on demand. The one detail this page cannot give you is where your client keeps its MCP configuration; its own documentation will.

How to connect any MCP client to WordPress

Step 1

Open Quick Connect and copy a config

In wp-admin go to AcrossAI → MCP, open the server you want to expose, and start Quick Connect. If your client is not in the list, pick any client that uses a JSON file — the command, the arguments and the environment variables are identical for every client, and only the wrapper around them changes. The wizard fills in your real site URL and username.

Step 2

Generate an Application Password

Click Generate password in the wizard. This creates a standard WordPress Application Password — not your login password — scoped to this connection and revocable at any time from your user profile.

The password is shown once, at creation. Copy it whole, including the spaces — WordPress accepts them. If you lose it, generate a new one rather than trying to recover it.

Step 3

Add the entry to your client’s config file

Every MCP client that launches a local bridge asks for the same three things: a command to run, an args array to pass it, and an env object of environment variables. AcrossAI needs exactly one command, two arguments and three variables:

"your-site-mcp-adapter-default-server": {
  "command": "npx",
  "args": ["-y", "@automattic/mcp-wordpress-remote@latest"],
  "env": {
    "WP_API_URL": "https://example.com/wp-json/acrossai/mcp",
    "WP_API_USERNAME": "your-wp-username",
    "WP_API_PASSWORD": "xxxx xxxx xxxx xxxx xxxx xxxx"
  }
}

The name on the left is yours to choose; <site-slug>-<last-url-segment> is the convention Quick Connect uses. What differs between clients is only the file that entry goes in and the top-level key that wraps it:

  • mcpServers — the most common spelling. Claude Desktop, Claude Code, Cursor, Windsurf and Cline all use it.
  • servers — VS Code and clients that follow its workspace format.
  • context_servers — Zed.
  • mcp — clients that nest MCP settings inside a larger settings file, sometimes as mcp.servers.
  • mcp_servers — TOML-based clients, where the entry becomes an [mcp_servers.your-site] table with command, args and env beneath it.

Consult your client’s documentation for the file path — it is usually a dotfolder in your home directory or a file inside the project. If you already have other MCP servers configured, add this one alongside them rather than replacing the file. If your client offers a settings form instead of a file, enter npx as the command, the two arguments as separate rows, and the three variables as environment variables.

Step 4

Restart the client and check the tools

Restart the client so it re-reads its configuration. Your site should appear as an MCP server, and the toolsets it exposes become available. Ask something harmless to confirm it is live — “Which plugins on this site need updating?” is a good first test.

If the site runs locally behind a self-signed certificate, add NODE_TLS_REJECT_UNAUTHORIZED set to 0 to the env object. Do not carry that setting over to a production site.

What your MCP client can do once it is connected

With Abilities Manager installed alongside it, a connected client reaches 350+ abilities across 14 toolsets — rising past 800 once it detects the plugins you already run. Whatever the client’s interface looks like, it can:

  • Read and edit content — posts, pages and any custom post type with their meta and revisions, and surgically edit a page’s block tree without rewriting the page.
  • Debug a broken site — read the debug log with secrets redacted, check Site Health, list recent fatal errors and un-pause what WordPress auto-disabled.
  • Inspect the database — schema and table sizes, index health, bloated autoloaded options, or EXPLAIN on a slow query.
  • Manage plugins, themes and core — search WordPress.org, install, update, roll back, and verify files against official checksums.
  • Work with files — inside an allowlist you define, with a dangerous-extension blocklist and optional pre-image backups of everything it touches.
  • Reach the plugins you already run — WooCommerce, Elementor, ACF, Rank Math, Yoast, WPCode and more, each registering only when that plugin is active.

Every ability runs WordPress’s own capability check for the calling user, so a connected client can never do anything your account could not already do. See the full platform overview for the complete catalogue.

Frequently asked questions

Will my client work if it has no guide of its own?

If it implements the Model Context Protocol, yes. MCP Manager exposes a standards-compliant endpoint and does not special-case clients — it has no idea what is on the other end. The client list in Quick Connect is a convenience for producing the right file format, not a compatibility list.

Is connecting an MCP client to WordPress free?

Yes. AcrossAI MCP Manager and Abilities Manager are both free and GPL on WordPress.org, and there is no AcrossAI account to create. You use whatever AI client and subscription you already have — AcrossAI never charges for AI inference, because none of it runs here.

Does my site data pass through AcrossAI servers?

No. The client connects straight to your own domain and every request terminates at your /wp-json/ route. There is no relay, no gateway and no telemetry. Whatever the client reads is still processed by its AI provider, so treat it as you would any other prompt.

Does it work on any WordPress host?

Yes, provided you can reach wp-admin. Shared hosting, VPS and managed WordPress all work, because everything runs inside your own install. MCP Manager needs WordPress 7.0 or later and PHP 8.1 or later; Abilities Manager needs WordPress 6.9 or later.

Can a connected client break my site?

Every ability runs WordPress’s own capability check for the calling user, so no client can exceed what your account can already do. Higher-risk operations refuse to run without an explicit confirmation flag, file access is confined to an allowlist you define, search-and-replace is a dry run by default, and any ability can be disallowed site-wide. To cut a client off, revoke its Application Password — access is re-checked on every request, so it stops immediately.

Troubleshooting

The client starts, reports no error, and lists nothing

Almost always the wrong top-level key. The entry itself is portable, the wrapper is not: a client looking for servers will walk straight past a block filed under mcpServers and say nothing about it. Check your client’s documentation for the exact spelling and move the entry, keeping command, args and env unchanged. On a TOML client the same entry has to be rewritten as a table rather than pasted as JSON.

My client only accepts a URL, not a command

Some clients speak only remote transports and have no way to launch a local process. Point those at https://example.com/wp-json/acrossai/mcp directly and supply the credentials however the client allows — usually a custom header. The npx bridge exists for clients that cannot do this; if yours can, you do not need Node.js at all.

The server appears but has no tools

That is the connection working and the catalogue being empty. Either Abilities Manager is not installed — MCP Manager will serve an empty catalogue quite happily — or the abilities exist but are not exposed to this particular server. Open AcrossAI → MCP, select the server, and check its Tools and Abilities tabs. After changing what a server exposes, restart the client: MCP clients receive their tool list once, at connection time.

Authentication fails

Application Passwords are shown once and are not your login password. Generate a fresh one from Quick Connect rather than retyping an old one, and copy it complete with spaces. Check the three variable names are spelled exactly WP_API_URL, WP_API_USERNAME and WP_API_PASSWORD — a near miss is silently ignored. If the request is being refused rather than failing, check the server’s access rules: a new server requires manage_options until you add a rule, and the gate fails closed.

npx is not found

The bridge runs through npx, which ships with Node.js. Install Node.js on the machine running the client and restart it. If Node is installed through a version manager, a GUI client may not inherit your shell’s PATH — in that case point command at the absolute path to npx.

Connect a different AI client

If your client is one of these, the guide will save you a step by naming the exact file: Claude Desktop, Claude Code, Cursor, VS Code, GitHub Copilot, Windsurf, Zed, Codex, or the full list of clients.

Not installed yet?

Install MCP Manager on your site, then come back and run Quick Connect.


Keep reading