Every MCP client reads the same small object: a command, its args, and three env variables. Only the file it lives in and the key it sits under change. This page is the reference for that object — every field annotated, and a table of which top-level key each client expects.
Free plugin · No account · Runs on your own server · Any WordPress host
Config file
JSON everywhere, TOML for Codex
Top-level key
mcpServers and four others
Bridge command
npx -y @automattic/mcp-wordpress-remote@latest
Before you start
You need AcrossAI MCP Manager installed and active on the WordPress site you want to reach, plus an administrator account on that site. If you have not installed it yet, follow the Get Started guide first — it takes about a minute, and the official WordPress MCP Adapter ships bundled inside the plugin, so there is nothing separate to install.
You also need Node.js on the machine running the client, because the connection runs through an npx bridge. Nothing is installed permanently — npx fetches the bridge on demand. You do not have to write any of this by hand: Quick Connect in wp-admin generates the finished object with your real values. This page exists so you can read what it generated, adapt it, or write it yourself.
How to write the MCP JSON config for WordPress
Step 1
Let Quick Connect generate the object
In wp-admin go to AcrossAI → MCP, open the server you want to expose, and start Quick Connect. Choose your client and the wizard prints the finished object with your real site URL and username already in place, under the right top-level key for that client.
If your client is not in the list, pick any client that uses mcpServers and rename the key using the table further down. The inner object is identical in every case.
Step 2
Generate an Application Password
Click Generate password in the wizard. This creates a standard WordPress Application Password — not your login password — scoped to this connection and revocable at any time from your user profile. It becomes the value of WP_API_PASSWORD.
The password is shown once, at creation. Copy it whole, including the spaces — WordPress accepts them, and JSON has no problem with spaces inside a string. If you lose it, generate a new one rather than trying to recover it.
Step 3
Read every field in the object
This is the whole thing. The outer key is the client’s own (mcpServers here); everything inside it is identical across every client:
{
"mcpServers": {
"your-site-mcp-adapter-default-server": {
"command": "npx",
"args": ["-y", "@automattic/mcp-wordpress-remote@latest"],
"env": {
"WP_API_URL": "https://example.com/wp-json/acrossai/mcp",
"WP_API_USERNAME": "your-wp-username",
"WP_API_PASSWORD": "xxxx xxxx xxxx xxxx xxxx xxxx"
}
}
}
}The server key — your-site-mcp-adapter-default-server — is just a label. Quick Connect builds it as <site-slug>-<last-url-segment> so that several sites, or several servers on one site, never collide in the same file. It is the name your client shows in its UI, so make it recognisable. Keep it to letters, digits and hyphens: some clients reject spaces and dots.
command is the executable your client launches — npx, which ships with Node.js. The client runs it as a child process and speaks MCP to it over stdio; the bridge then speaks HTTP to your site. Nothing listens on a port on your machine.
args is an array, one element per argument — never a single string with spaces in it. -y tells npx to install the package without prompting, which matters because nothing is attached to a terminal to answer the prompt. @automattic/mcp-wordpress-remote@latest is the bridge package; @latest re-resolves on each launch, so pin a version here if you would rather control upgrades yourself.
env is a flat map of environment variables handed to that child process. Three are required:
WP_API_URL— the full URL of your MCP server route, not your homepage. The default ishttps://example.com/wp-json/acrossai/mcp. No trailing slash. If you created additional servers in MCP Manager, each has its own final segment and its own entry here.WP_API_USERNAME— the WordPress username the connection acts as. Not the display name and not the email address. Every ability runs that user’s capability checks, so this field decides what the AI is allowed to do.WP_API_PASSWORD— the Application Password from step 2, spaces and all. Never your login password.
There is one optional fourth variable. On a local development site with a self-signed certificate, Node rejects the TLS handshake and the server never starts. Add "NODE_TLS_REJECT_UNAUTHORIZED": "0" to env for that entry only:
"env": {
"WP_API_URL": "https://mysite.local/wp-json/acrossai/mcp",
"WP_API_USERNAME": "your-wp-username",
"WP_API_PASSWORD": "xxxx xxxx xxxx xxxx xxxx xxxx",
"NODE_TLS_REJECT_UNAUTHORIZED": "0"
}Note the value is the string "0", not the number 0 — environment variables are strings. Never set it on an entry pointing at a production site; it disables certificate verification for that process.
Step 4
Paste it under your client’s top-level key and restart
Open your client’s config file, find its top-level key — use the table below — and add the server entry inside it, alongside any MCP servers already there. Do not replace the file. Then restart the client completely: MCP clients read this file at startup and receive their tool list once, at connection time.
Ask something harmless to confirm it is live — “Which plugins on this site need updating?” is a good first test.
Which top-level key does your client use?
The inner object never changes. The wrapper does. Getting this wrong is the single most common reason a correctly written config produces a client with no server in it — the file parses, the key is unrecognised, and nothing is reported.
| Top-level key | Clients | Format |
|---|---|---|
mcpServers | Claude Desktop, Claude Code, Cursor, Windsurf, Gemini CLI, Cline, Roo Code, Kilo Code, Amazon Q, Antigravity | JSON |
servers | VS Code, GitHub Copilot | JSON |
context_servers | Zed | JSON |
mcp | OpenCode | JSON |
mcp_servers | Codex | TOML |
Codex is the one real outlier: its config is TOML, not JSON, so the same three fields are written as a table rather than an object. The values are identical — only the syntax differs:
[mcp_servers.your-site-mcp-adapter-default-server]
command = "npx"
args = ["-y", "@automattic/mcp-wordpress-remote@latest"]
[mcp_servers.your-site-mcp-adapter-default-server.env]
WP_API_URL = "https://example.com/wp-json/acrossai/mcp"
WP_API_USERNAME = "your-wp-username"
WP_API_PASSWORD = "xxxx xxxx xxxx xxxx xxxx xxxx"A server key containing hyphens is a bare TOML key and is legal, but if yours contains a dot or any other punctuation it must be quoted: [mcp_servers."my.site-server"]. This is another reason to keep the key to letters, digits and hyphens.
What your client can do once it is connected
Whatever client that object lives in, it reaches the same catalogue. With Abilities Manager installed alongside MCP Manager, that is 350+ abilities across 14 toolsets — rising past 800 once it detects the plugins you already run. From the chat window, without switching to a browser tab, it can:
- Read and edit content — posts, pages and any custom post type with their meta and revisions, and surgically edit a page’s block tree without rewriting the page.
- Debug a broken site — read the debug log with secrets redacted, check Site Health, list recent fatal errors and un-pause what WordPress auto-disabled.
- Inspect the database — schema and table sizes, index health, bloated autoloaded options, or
EXPLAINon a slow query. - Manage plugins, themes and core — search WordPress.org, install, update, roll back, and verify files against official checksums.
- Work with files — inside an allowlist you define, with a dangerous-extension blocklist and optional pre-image backups of everything it touches.
- Reach the plugins you already run — WooCommerce, Elementor, ACF, Rank Math, Yoast, WPCode and more, each registering only when that plugin is active.
Every ability runs WordPress’s own capability check for the user named in WP_API_USERNAME, so the AI can never do anything that account could not already do. See the full platform overview for the complete catalogue.
Frequently asked questions
Do I need to install the MCP Adapter separately?
No. The official WordPress MCP Adapter ships bundled inside AcrossAI MCP Manager, so the /wp-json/mcp/ route exists as soon as the plugin is active. MCP Manager needs WordPress 7.0 or later; Abilities Manager needs 6.9 or later. Both need PHP 8.1 or later.
Does my site data pass through AcrossAI servers?
No. WP_API_URL points at your own domain and every request terminates at your /wp-json/ route. There is no relay, no gateway and no telemetry. Whatever the AI reads is still processed by that AI’s provider, so treat it as you would any other prompt.
Can I connect several sites, or several clients to one site?
Yes, in both directions. Add one entry per site under the same top-level key, each with its own server key and its own WP_API_URL. For several clients on one site, give each its own Application Password — then you can revoke one client without disturbing the others.
Can the AI break my site?
Every ability runs WordPress’s own capability check for the user in WP_API_USERNAME, so the AI can never exceed what that account can already do. Higher-risk operations refuse to run without an explicit confirmation flag, file access is confined to an allowlist you define, and any ability can be disallowed site-wide. Pointing WP_API_USERNAME at a lower-privileged account is the simplest way to narrow the blast radius.
Is the config file safe to commit to a repository?
Not as written — WP_API_PASSWORD is a live credential in plain text. Keep project-level config files out of version control, or have your client read the value from your shell environment if it supports that. If a config has already been committed, revoke that Application Password and generate a new one.
Troubleshooting
The file is valid but the client lists no server
Almost always the wrong top-level key. An entry under mcpServers in a file that expects servers is simply not read, and most clients report nothing at all rather than an error. Check your client’s row in the table above, and confirm your entry is nested inside that key rather than sitting at the root of the file.
The whole file is being ignored
A single syntax error makes most clients skip the entire file silently, taking your other MCP servers with it. The usual causes are a trailing comma after the last entry, a missing closing brace when you pasted a second server in, and // comments — strict JSON allows none of them, even though VS Code’s variant tolerates comments. Run the file through any JSON validator before restarting.
Codex rejects the config
Codex reads TOML, so a pasted JSON object will not parse. Use the [mcp_servers.…] form shown above, remembering that env becomes its own table section rather than a nested object, and that TOML uses = rather than :. Quote the server key if it contains anything beyond letters, digits and hyphens.
The server connects but exposes no tools
That is the transport working and the catalogue being empty, so the config is fine. Either Abilities Manager is not installed, or the abilities exist but are not exposed to the server named in WP_API_URL. Open AcrossAI → MCP, select that server, and check its Tools and Abilities tabs. Restart the client afterwards — tool lists are delivered once, at connection time.
Authentication fails, or it worked yesterday and stopped today
Application Passwords are shown once and are not your login password, so generate a fresh one from Quick Connect rather than retyping an old one, and paste it complete with its spaces. If the request is being refused rather than failing, check the server’s access rules — a new server requires manage_options until you add a rule, and the gate fails closed. Access is re-checked on every request, so a change to your role or a revoked password takes effect immediately even though the config on disk is unchanged.
npx is not found, or a local site will not connect
The bridge runs through npx, which ships with Node.js. Install Node and restart the client. If Node came from a version manager, a desktop client may not inherit your shell’s PATH — point command at the absolute path to npx instead. If the failure is a TLS or certificate error against a .local domain, add "NODE_TLS_REJECT_UNAUTHORIZED": "0" to that entry’s env.
Connect a different AI client
Each guide gives the exact file path and the finished snippet for one client: Claude Desktop, Claude Code, Cursor, Windsurf, VS Code, GitHub Copilot, Zed, Codex, Gemini CLI, Cline, Roo Code, Kilo Code, Amazon Q, Antigravity, OpenCode and every other client.
Not installed yet?
Install MCP Manager on your site, then come back and run Quick Connect.
