30 days free. No credit card. Full access from the moment you connect your site.

Start free trial

How to Connect Grok to WordPress (Step-by-Step)

Connect Grok to WordPress — AcrossAI setup guide

Connect Grok to your own WordPress site over the Model Context Protocol. Grok reaches your site through a custom connector, and the sign-in happens on your own domain — there is no relay in between, no config file to edit, and no Application Password to copy. Setup takes about a minute once MCP Manager is installed.

Free plugin · No account · Runs on your own server · Any WordPress host

Connection method

Custom connector

Authentication

OAuth sign-in on your domain

Config file

None — nothing to edit

Watch: Grok connector walkthrough

Before you start

You need AcrossAI MCP Manager installed and active on the WordPress site you want Grok to reach, plus an administrator account on that site. If you have not installed it yet, follow the Get Started guide first — it takes about a minute, and the MCP server ships bundled with the plugin. For more on how connector-based clients work, see Grok connectors.

Grok connects over the network rather than through a bridge on your machine, so there is nothing to install locally and no Node.js to set up. It does mean your site has to be reachable from the internet over HTTPS: a site on localhost, behind HTTP basic authentication, or inside a private network cannot be connected, and there is no manual fallback — a connector is the only route Grok offers. MCP Manager needs WordPress 7.0 or later and PHP 8.1 or later.

How to connect Grok to WordPress

Step 1

Open Quick Connect and choose Grok

In wp-admin go to AcrossAI → MCP, open the server you want to expose, and start Quick Connect. Pick Grok from the client list. The wizard hands you a single connector URL — that is the only thing you carry across, and there is no password step to follow it.

The recommended AcrossAI server lives at /wp-json/acrossai/mcp. If you have created your own server, Quick Connect gives you that one’s URL instead.

Step 2

Add a custom connector in Grok

In Grok, open Settings → Connectors and add a custom connector. Give it a name you will recognise in a chat — your site’s name works well — and paste the connector URL from the wizard. Grok discovers what the server offers on its own; there is nothing else to fill in.

https://example.com/wp-json/acrossai/mcp

Paste the full endpoint, not your site’s home page address. Copying it from Quick Connect avoids the typos that make Grok reject a connector before any request reaches WordPress.

Step 3

Sign in on your own domain

Grok opens an authorisation window. The page you land on is served by your own WordPress site — not by AcrossAI and not by xAI. It is your ordinary WordPress login, followed by a screen asking you to approve the connection. Approve it, and your site issues the access token straight to Grok. The authorisation server runs on your domain, so your password is only ever typed into your own site.

There is no Application Password to generate here and nothing to paste back into Grok. That is the whole credential step.

The connection carries the permissions of the account you signed in with, so sign in as the user whose reach you want Grok to have. You can withdraw the authorisation later from AcrossAI → MCP without touching anything in Grok.

Step 4

Check the tools in Grok

Once the window closes, the connector shows as connected and the toolsets your server exposes become available in chat. Ask something harmless to confirm it is live — “Which plugins on this site need updating?” is a good first test.

Want the one-click Grok connector?

AcrossAI Pro turns this setup into a managed one-click connector, with the controls a live site needs:

  • See every connected client and revoke it in one click
  • Require admin approval before anyone connects
  • Gate tools by membership level across ten providers

What Grok can do once it is connected

With Abilities Manager installed alongside it, Grok reaches 350+ abilities across 14 toolsets — rising past 800 once it detects the plugins you already run. From an ordinary chat, without opening wp-admin, it can:

  • Read and edit content — posts, pages and any custom post type with their meta and revisions, and surgically edit a page’s block tree without rewriting the page.
  • Debug a broken site — read the debug log with secrets redacted, check Site Health, list recent fatal errors and un-pause what WordPress auto-disabled.
  • Inspect the database — schema and table sizes, index health, bloated autoloaded options, or EXPLAIN on a slow query.
  • Manage plugins, themes and core — search WordPress.org, install, update, roll back, and verify files against official checksums.
  • Work with files — inside an allowlist you define, with a dangerous-extension blocklist and optional pre-image backups of everything it touches.
  • Reach the plugins you already run — WooCommerce, Elementor, ACF, Rank Math, Yoast, WPCode and more, each registering only when that plugin is active.

Every ability runs WordPress’s own capability check for the account you authorised, so Grok can never do anything that account could not already do. See the full platform overview for the complete catalogue.

Frequently asked questions

Is connecting Grok to WordPress free?

Yes. AcrossAI MCP Manager and Abilities Manager are both free and GPL on WordPress.org, and there is no AcrossAI account to create. You use the Grok access you already have — AcrossAI never charges for AI inference, because none of it runs here.

Does my site data pass through AcrossAI servers?

No. Grok connects straight to your own domain and every request terminates at your /wp-json/ route. The OAuth authorisation server runs on your domain too, so the sign-in never leaves it either. There is no relay, no gateway and no telemetry. Whatever Grok reads is still processed by xAI, so treat it as you would any other prompt.

Do I need an Application Password or a config file?

No. Grok connects through a connector, and a connector authorises over OAuth, so there is no file on your machine to edit and no long-lived password to copy. The only credential involved is your normal WordPress login, entered on your own site. Clients that read a local config file — Cursor, VS Code, Claude Desktop and the rest — use an Application Password instead.

Can Grok break my site?

Every ability runs WordPress’s own capability check for the account you authorised, so Grok can never exceed what that account can already do. Higher-risk operations refuse to run without an explicit confirmation flag, file access is confined to an allowlist you define, search-and-replace is a dry run by default, and any ability can be disallowed site-wide.

How do I disconnect Grok again?

Remove the connector in Grok, or withdraw the authorisation from AcrossAI → MCP on your site. Access is re-checked on every request, so withdrawing it takes effect immediately even if the connector is still listed in Grok.

Troubleshooting

Grok will not accept the connector URL

The URL has to be the full MCP endpoint on an https:// address — https://example.com/wp-json/acrossai/mcp — not your home page and not the /wp-json/ root. A plain http:// address is refused before any request reaches WordPress, as is a host Grok cannot resolve. Copy the URL from Quick Connect rather than typing it, and open it once in a browser to confirm your site answers on it.

The sign-in window opens and then closes without connecting

The authorisation page is served by your own site, so anything that interferes with loading it in a pop-up will end the flow early: a security plugin that hardens wp-login.php, an IP or country firewall rule, a bot challenge in front of the login page, or HTTP basic authentication on a staging domain. Open your own login page in a normal browser tab first — if that is blocked or challenged, the connector will be too. Blocking third-party cookies in the browser you authorise from can have the same effect.

Authorisation is refused after you sign in

That is the sign-in working and the access gate saying no. A new server requires manage_options until you add a rule, and the gate fails closed. Either sign in as an account that holds that capability, or open the server in AcrossAI → MCP and add an access rule for the role you want to allow.

The connector is connected but has no tools

That is the connection working and the catalogue being empty. Either Abilities Manager is not installed — MCP Manager will serve an empty catalogue quite happily — or the abilities exist but are not exposed to this particular server. Open AcrossAI → MCP, select the server, and check its Tools and Abilities tabs. After changing what a server exposes, remove the connector in Grok and add it again: MCP clients receive their tool list once, at connection time.

It worked yesterday and stopped today

Access is re-checked on every request, not just at authorisation. A change to the role, capability or membership of the account you signed in with takes effect immediately, and an existing connector does not keep working on yesterday’s permissions. Withdrawing the authorisation has the same effect.

Connect a different AI client

The same server works with every MCP client. Some connect the way Grok does, through a connector and an OAuth sign-in; others read a config file on your machine and use an Application Password. See the guides for ChatGPT, Claude Desktop, Claude Code, Cursor, VS Code, Windsurf and every other client.

Not installed yet?

Install MCP Manager on your site, then come back and run Quick Connect.


Keep reading