30 days free. No credit card. Full access from the moment you connect your site.

Start free trial

Connect Kilo Code to WordPress

Connect Kilo Code to WordPress — AcrossAI setup guide

Connect Kilo Code to your own WordPress site over the Model Context Protocol. Kilo Code is a VS Code extension, so the config lives inside the project you have open — one entry in .kilocode/mcp.json and your editor can read and change your site directly. There is no relay in between, no account to create, and your credentials never leave your machine.

Free plugin · No account · Runs on your own server · Any WordPress host

Config file

.kilocode/mcp.json

Top-level key

mcpServers

Scope

Project (repo root)

Before you start

You need AcrossAI MCP Manager installed and active on the WordPress site you want Kilo Code to reach, plus an administrator account on that site. MCP Manager needs WordPress 7.0 or later and PHP 8.1 or later, and the official WordPress MCP Adapter ships bundled inside it — there is nothing separate to install. If you have not set it up yet, follow the Get Started guide first.

You also need Node.js on the machine running VS Code, because the connection runs through an npx bridge — nothing is installed permanently, npx fetches the bridge on demand. And decide which project you want this connection to belong to: Kilo Code stores MCP servers per project, so open that repository in VS Code before you begin.

How to connect Kilo Code to WordPress

Step 1

Open Quick Connect and choose Kilo Code

In wp-admin go to AcrossAI → MCP, open the server you want to expose, and start Quick Connect. Pick Kilo Code from the client list — or any other client that uses the mcpServers key, because the generated JSON is identical. Everything below is generated for you with your real site URL and username already filled in; the snippets here are only so you know what to expect.

Step 2

Generate an Application Password

Click Generate password in the wizard. This creates a standard WordPress Application Password — not your login password — scoped to this connection and revocable at any time from your user profile.

The password is shown once, at creation. Copy it whole, including the spaces — WordPress accepts them. If you lose it, generate a new one rather than trying to recover it.

Step 3

Paste the config into .kilocode/mcp.json

Kilo Code reads its MCP servers from .kilocode/mcp.json, and that file is project-scoped: it belongs at the root of the repository you have open in VS Code, not in your home directory. Create the folder first if it is not there yet — mkdir .kilocode at the repo root — then add mcp.json inside it and paste the entry under the mcpServers key. If the project already has other MCP servers, add this one alongside them rather than replacing the file.

You can also let the extension create and open the file for you: Kilo Code sidebar → MCP Servers → Configure MCP Servers. That edits the same .kilocode/mcp.json in the project you currently have open.

The generated config looks like this, with your own values in place of the placeholders:

{
  "mcpServers": {
    "your-site-mcp-adapter-default-server": {
      "command": "npx",
      "args": ["-y", "@automattic/mcp-wordpress-remote@latest"],
      "env": {
        "WP_API_URL": "https://example.com/wp-json/acrossai/mcp",
        "WP_API_USERNAME": "your-wp-username",
        "WP_API_PASSWORD": "xxxx xxxx xxxx xxxx xxxx xxxx"
      }
    }
  }
}

Because the file sits inside the repository, it is committed with everything else unless you say otherwise. It holds an Application Password, so add .kilocode/mcp.json to .gitignore on any shared project.

Step 4

Reload VS Code and check the tools

Save the file, then reload the window — Command Palette, Developer: Reload Window — so Kilo Code picks up the change. Open the Kilo Code sidebar → MCP Servers and your site should be listed with its toolsets underneath. Ask something harmless to confirm it is live — “Which plugins on this site need updating?” is a good first test.

What Kilo Code can do once it is connected

With Abilities Manager installed alongside it, Kilo Code reaches 350+ abilities across 14 toolsets — rising past 800 once it detects the plugins you already run. From the sidebar, in the same window as your theme and plugin code, it can:

  • Read and edit content — posts, pages and any custom post type with their meta and revisions, and surgically edit a page’s block tree without rewriting the page.
  • Debug a broken site — read the debug log with secrets redacted, check Site Health, list recent fatal errors and un-pause what WordPress auto-disabled.
  • Inspect the database — schema and table sizes, index health, bloated autoloaded options, or EXPLAIN on a slow query.
  • Manage plugins, themes and core — search WordPress.org, install, update, roll back, and verify files against official checksums.
  • Work with files — inside an allowlist you define, with a dangerous-extension blocklist and optional pre-image backups of everything it touches.
  • Reach the plugins you already run — WooCommerce, Elementor, ACF, Rank Math, Yoast, WPCode and more, each registering only when that plugin is active.

Every ability runs WordPress’s own capability check for the calling user, so Kilo Code can never do anything your account could not already do. See the full platform overview for the complete catalogue.

Frequently asked questions

Is connecting Kilo Code to WordPress free?

Yes. AcrossAI MCP Manager and Abilities Manager are both free and GPL on WordPress.org, and there is no AcrossAI account to create. You use the Kilo Code setup you already have — AcrossAI never charges for AI inference, because none of it runs here.

Does my site data pass through AcrossAI servers?

No. Kilo Code connects straight to your own domain and every request terminates at your /wp-json/ route. There is no relay, no gateway and no telemetry. Whatever Kilo Code reads is still processed by the AI provider behind whichever model you have selected, so treat it as you would any other prompt.

Should I commit .kilocode/mcp.json to the repository?

Not with credentials in it. Because Kilo Code scopes MCP servers to the project, the file lives inside your repo and Git will pick it up like any other file. On a solo project that is convenient; on a shared one, add it to .gitignore and let each developer generate their own Application Password, so revoking one person’s access does not affect anyone else.

Can Kilo Code break my site?

Every ability runs WordPress’s own capability check for the calling user, so Kilo Code can never exceed what your account can already do. Higher-risk operations refuse to run without an explicit confirmation flag, file access is confined to an allowlist you define, search-and-replace is a dry run by default, and any ability can be disallowed site-wide.

How do I disconnect Kilo Code again?

Revoke the Application Password from your WordPress user profile, or remove the entry from .kilocode/mcp.json. Access is re-checked on every request, so revoking takes effect immediately even if the config is still sitting in the repository.

Troubleshooting

Kilo Code does not list the server at all

Almost always a scope mismatch. .kilocode/mcp.json applies only to the project it sits in, and only when that folder is the workspace root — a file one directory down, or in a second folder of a multi-root workspace, is ignored. If you edited the global MCP settings instead, the server will show in every project except the one you are looking at, and the reverse is true too. Open Kilo Code sidebar → MCP Servers → Configure MCP Servers and confirm you are editing the file you think you are. Then check the JSON is valid: a trailing comma or a missing brace makes the whole file be skipped without a message.

VS Code will not create .kilocode/mcp.json

The .kilocode folder has to exist before the file can be written into it — saving a new file at that path does not create the directory, and you will get an ENOENT error instead. Run mkdir .kilocode at the repo root and try again. Two related traps: the folder is hidden, so the VS Code explorer may not show it if your workspace excludes dotfiles, and the folder must be at the root of the open project, not beside the theme or plugin you happen to be editing.

The server appears but has no tools

That is the connection working and the catalogue being empty. Either Abilities Manager is not installed — MCP Manager will serve an empty catalogue quite happily — or the abilities exist but are not exposed to this particular server. Open AcrossAI → MCP, select the server, and check its Tools and Abilities tabs. After changing what a server exposes, reload the VS Code window: MCP clients receive their tool list once, at connection time.

Authentication fails, or it worked yesterday and stopped today

Application Passwords are shown once and are not your login password. Generate a fresh one from Quick Connect rather than retyping an old one, and copy it complete with spaces. If the request is being refused rather than failing, check the server’s access rules — a new server requires manage_options until you add a rule, and the gate fails closed. Access is also re-checked on every request, so a change to your role or capabilities takes effect immediately and a saved config does not keep working.

npx is not found

The bridge runs through npx, which ships with Node.js. Install Node.js on the machine running VS Code and reload the window. If Node is installed through a version manager, VS Code may not inherit your shell’s PATH — in that case point command at the absolute path to npx. On a local site with a self-signed certificate, add "NODE_TLS_REJECT_UNAUTHORIZED": "0" to the env block; never do this against a production site.

Connect a different AI client

The same server works with every MCP client — only the config file and top-level key change. See the guides for Claude Desktop, Claude Code, Cursor, VS Code, GitHub Copilot, Windsurf, Zed, Codex and every other client.

Not installed yet?

Install MCP Manager on your site, then come back and run Quick Connect.


Keep reading