30 days free. No credit card. Full access from the moment you connect your site.

Start free trial

Connect n8n to WordPress

Connect n8n to WordPress — AcrossAI setup guide

Give n8n an endpoint it can call on your own WordPress site, so a workflow can run your abilities on a schedule or in response to an event — with no person in the chat. n8n talks to your domain directly; there is no relay in between and no account to create.

No account · No relay · Runs on your own server · Any WordPress host

Endpoint

/wp-json/acrossai/mcp

Authentication

Authorization: Bearer — not OAuth

Status

AcrossAI Pro · beta · off by default

Before you start

You need AcrossAI MCP Manager installed and active on the WordPress site the workflow will call, an administrator account on that site, and AcrossAI Pro, which is where the n8n endpoint lives. MCP Manager requires WordPress 7.0 or later; Abilities Manager, which supplies the abilities themselves, requires WordPress 6.9 or later; both need PHP 8.1 or later. The official WordPress MCP Adapter ships bundled inside MCP Manager, so there is nothing separate to install. Your n8n instance also has to be able to reach the site over HTTPS — see the troubleshooting notes below if it cannot.

Three things to know before you plan around it. The endpoint ships in beta, so its behaviour may change between releases. It is switched off by default and stays off until an administrator enables it. And it authenticates with a bearer token rather than OAuth: there is no browser consent step, which is what makes it usable from an unattended workflow, and it also means the token on its own is the whole credential.

How to connect n8n to WordPress

Step 1

Confirm the MCP server on your site

In wp-admin go to AcrossAI → MCP and open the server you want n8n to reach. On a fresh install that is the recommended AcrossAI server at /wp-json/acrossai/mcp. Check which toolsets and abilities it exposes while you are there — the workflow can only call what this server publishes.

Step 2

Switch the n8n endpoint on

The n8n endpoint is an AcrossAI Pro feature and it is off until someone turns it on. An administrator enables it from AcrossAI → MCP. Until that happens n8n has nothing to call, and the site behaves exactly as it did before.

This endpoint is in beta. Its behaviour may change between releases, so try it on a staging site before you hang production automation off it, and read the changelog when you update.

Step 3

Give n8n the URL and the bearer token

Issue a token from AcrossAI → MCP, then store it in n8n as a credential that sends it in an Authorization header. There is no OAuth flow and no browser redirect here — the header is the entire handshake, which is exactly what an unattended workflow needs.

Point the node at your own domain plus the server path, and send the token with every request:

POST https://example.com/wp-json/acrossai/mcp

Authorization: Bearer <your-token>
Content-Type: application/json

Keep the token in n8n’s credential store rather than typing it into a node field — credentials are excluded when a workflow is exported or shared, node parameters are not. Anyone holding the token can do whatever the WordPress account behind it can do, so treat it like a password and rotate it if a workflow leaves your instance.

Step 4

Run it once by hand, then put it on a trigger

Execute the workflow manually and confirm you get a response rather than a 401 or a 403. Once a read-only call works, attach the trigger you actually want — a schedule, a webhook, or an event from another system in the workflow — and activate it.

The token resolves to a WordPress user, and every ability runs that user’s own capability check. A workflow can never exceed what that account could already do, so issuing the token from a suitably limited account is the simplest way to bound what the automation can touch.

What n8n can do once it is connected

With Abilities Manager installed alongside MCP Manager, a workflow reaches 350+ abilities across 14 toolsets — rising past 800 once the site detects the plugins you already run. Because nothing here needs a human in the chat, the useful shape is scheduled and event-driven work:

  • Publish and update on a schedule — create or revise posts, pages and custom post types, with their meta, at a fixed time each day rather than when someone remembers.
  • Keep WordPress in step with another system — when a record changes in the tool that owns it, the same workflow updates the matching content, user or option here.
  • Run routine housekeeping — clear caches, inspect cron, check autoloaded options, and report what it found.
  • Watch for trouble unattended — poll Site Health, pending updates and recent fatal errors, and raise an alert wherever your team already looks.
  • Read structured data out of the site — content, taxonomies, users, database schema — and hand it to the rest of the workflow to act on.
  • Reach the plugins you already run — WooCommerce, Elementor, ACF, Rank Math, Yoast, WPCode and more, each registering only when that plugin is active.

Every ability runs WordPress’s own capability check for the user behind the token, so a workflow can never do anything that account could not already do. See the full platform overview for the complete catalogue.

Frequently asked questions

Is the n8n endpoint finished?

No. It ships in beta and we say so plainly: the shape of requests and responses may change between releases. It is also an AcrossAI Pro feature and is switched off by default, so nothing appears on your site until an administrator enables it. Build against it on staging first, and read the changelog before you update a site with live automation on it.

Why a bearer token instead of OAuth?

Because there is nobody at the keyboard. OAuth expects a browser and a person to approve the grant; a workflow that fires at 03:00 has neither. A bearer token sent in the Authorization header removes that step. The trade is that the token by itself is the whole credential, so store it in n8n’s credential store and rotate it if it is ever exposed.

Do I need to install the MCP Adapter separately?

No. The official WordPress MCP Adapter ships bundled inside AcrossAI MCP Manager. Install MCP Manager and the adapter is already there. MCP Manager requires WordPress 7.0 or later and PHP 8.1 or later; Abilities Manager requires WordPress 6.9 or later.

Does my site data pass through AcrossAI servers?

No. n8n calls your own domain and every request terminates at your /wp-json/ route. There is no relay, no gateway and no telemetry in between. Be honest about the other end of the workflow, though: if a step passes what it read to a language model, that model’s provider processes it, exactly as it would any other prompt.

Can a workflow do more than the account behind the token?

No. Every ability runs WordPress’s own capability check for the calling user, so the workflow is bounded by that account in exactly the way a person signing in would be. Access is re-checked on every request, so revoking the token or changing the account’s role takes effect immediately — a running workflow does not keep its old permissions.

Troubleshooting

There is no n8n endpoint in AcrossAI → MCP

Two reasons account for almost every case. It is an AcrossAI Pro feature, so a site running only the free plugins will not show it; and even on Pro it is off by default, so an administrator has to enable it before it appears as something n8n can call. Check the plugin version too — this is a beta feature and it is not present in older releases.

n8n returns 401 Unauthorized

The token is not arriving, or not arriving intact. The header must read Authorization: Bearer <token> — one space, the word Bearer capitalised, nothing else appended. A token copied from a terminal often carries a trailing newline or a stray space, which n8n will send verbatim; paste it into a plain field and check the length. Also confirm the credential is actually attached to the node that makes the call, not merely saved in the credential list.

n8n returns 403 Forbidden

The token authenticated but the request was refused. A new server requires manage_options until you add an access rule, and the gate fails closed — so an account without that capability is turned away until a rule admits it. Check the server’s access rules in AcrossAI → MCP, and check the individual ability too: capability checks apply per ability, so a token can be allowed to read and still be refused a write.

The workflow runs by hand but not on its schedule

A manual execution and a scheduled one use the same credential, so the difference is usually on the n8n side. Confirm the workflow is activated — an inactive workflow never fires its trigger — and check the timezone the schedule is evaluated in, which is the n8n instance’s, not WordPress’s. If it worked yesterday and stopped today, suspect the token instead: access is re-checked on every request, so a revoked token or a changed role breaks the scheduled run immediately.

n8n cannot reach the site at all

A connection error rather than a status code means the request never arrived. n8n Cloud can only reach a publicly resolvable HTTPS address, so a local development site or one behind a VPN needs a self-hosted n8n on the same network. Self-signed certificates fail TLS verification for the same reason. If you get a 404 rather than a timeout the host is reachable and the path is wrong — check it against /wp-json/acrossai/mcp and flush permalinks.

Connect a different AI client

The same server also answers the desktop and editor clients, where a person is in the loop and the connection runs through an npx bridge rather than a bearer token. See the guides for Claude Desktop, Claude Code, Cursor, VS Code, GitHub Copilot, Windsurf, Zed, Codex and every other client.

Not installed yet?

Install MCP Manager on your site first — the n8n endpoint is enabled from the same screen.


Keep reading