Skip to main content Skip to navigation
Rack of servers in a server room, representing building a WordPress MCP server

How to Build a WordPress MCP Server

6 min read

Most people connect an AI assistant to WordPress with an existing plugin. But sometimes you want something specific: a small server that exposes only the two or three actions your workflow needs. That is when it makes sense to build a WordPress MCP server yourself.

This guide explains what an MCP server actually is, the main ways to build one for WordPress, and a minimal example to show the shape of the code. It is aimed at developers, but the concepts are explained plainly.

Note: MCP libraries and clients change over time. Treat the example here as an illustration, and check the official MCP documentation and SDK for current details before you build.

What an MCP Server Is

MCP stands for Model Context Protocol, an open standard that lets AI applications connect to outside tools and data. An MCP server is a program that:

  • Publishes a list of tools, each with a name, a description, and a description of its inputs
  • Runs a tool when an AI client asks for it, and returns the result

Servers can also expose other things, such as resources and prompts, but tools are what most WordPress use cases need.

Three Ways to Build a WordPress MCP Server

ApproachHow it worksGood for
Standalone server calling the REST APIA separate program that talks to your site’s WordPress REST APIFast prototypes and small toolsets
Server inside a WordPress pluginYour plugin exposes an MCP endpoint and calls WordPress functions directlyDeep integration and distribution to other users
Existing plugin or serverConfigure a ready-made one instead of writing codeMost site owners

The first approach is the easiest to learn from, so the rest of this guide uses it.

Before You Start

  • A WordPress site you can safely test on, ideally staging
  • A programming language with an MCP SDK, such as Python or TypeScript
  • A WordPress user with limited permissions for the server to use
  • An Application Password for that user (WordPress supports these for REST API authentication)

Step-by-Step: Build a Minimal Server

  1. Decide the tools. Start with one or two, such as “create a draft” and “list recent posts.”
  2. Create a limited WordPress user and generate an Application Password for it.
  3. Store credentials outside your code, for example in environment variables.
  4. Install an MCP SDK following its official instructions.
  5. Define each tool with a clear name, a description, and typed inputs.
  6. Call the WordPress REST API from each tool using the stored credentials.
  7. Run the server and connect an MCP client to it.
  8. Test with harmless requests and check the result in WordPress.

Example: A Tiny Draft-Creating Server

This is an illustration using the official Python SDK’s high-level interface. It is not a complete or production-ready server, and SDK details may change, so verify against the current documentation.

import os
import requests
from mcp.server.fastmcp import FastMCP

mcp = FastMCP("wordpress-drafts")

SITE = os.environ["WP_SITE_URL"]
USER = os.environ["WP_USER"]
APP_PASSWORD = os.environ["WP_APP_PASSWORD"]


@mcp.tool()
def create_draft(title: str, content: str) -> str:
    """Create a draft post on the WordPress site."""
    response = requests.post(
        f"{SITE}/wp-json/wp/v2/posts",
        auth=(USER, APP_PASSWORD),
        json={"title": title, "content": content, "status": "draft"},
        timeout=30,
    )
    response.raise_for_status()
    return f"Draft created with ID {response.json()['id']}"


if __name__ == "__main__":
    mcp.run()

What this does: it defines one tool called create_draft. The description and the typed inputs tell the AI client what the tool is for. The tool posts to the WordPress REST API with the status set to draft, so nothing is published.

Notice what it does not do. It cannot publish, edit, or delete anything, because you never wrote those tools. That is the point: you choose the capabilities.

Connecting a Client

How you register a server depends on the MCP client, such as Claude, Cursor, or another compatible app. A server that runs locally is typically started as a command by the client, while a server on the internet is added by its address. Follow the client’s current documentation, because the settings differ and change over time.

Design Tips for Good Tools

  • Keep tools small and specific. One tool, one job.
  • Write clear descriptions. The AI chooses tools based on them.
  • Validate inputs. Never trust the model’s arguments blindly.
  • Return useful results. Include IDs and status so the client can report accurately.
  • Prefer drafts over publishing. Build the safe version first.
  • Handle errors gracefully. Return readable messages instead of stack traces.

Security and Permissions

A server you write is code that can change your site. Treat it seriously.

  • Use a dedicated low-privilege user. Never use your admin account.
  • Protect credentials. Keep Application Passwords out of your code and out of public repositories.
  • Expose the minimum. Each tool you add widens what the AI can do.
  • Use HTTPS for every remote connection.
  • Add authentication if the server is reachable over a network.
  • Log tool calls so you can review what happened.
  • Be careful with destructive tools. Deleting or publishing should need explicit human approval.

Building your own also means owning the maintenance. If you would rather not, look at our free MCP server for WordPress or see the MCP Manager feature breakdown.

Troubleshooting

The Client Cannot Start or Reach the Server

Check the command or address you registered, the runtime and dependencies, and any error output. Confirm environment variables are set.

The REST API Returns 401 or 403

Check the username and Application Password, whether the REST API is enabled, and whether a security plugin is blocking requests. Also check the user’s capabilities.

The Tool Does Not Appear in the Client

Restart or reconnect the server in the client, and confirm the tool is defined correctly.

The Model Passes Bad Arguments

Improve the tool description and add input validation with clear error messages.

Frequently Asked Questions

Do I have to build my own MCP server?

No. Most site owners can use an existing plugin. Building your own makes sense for custom needs.

Which language should I use?

Any language with a good MCP SDK. Python and TypeScript are common choices. PHP is natural if you want the server inside a plugin.

Does the server need the WordPress REST API?

Not necessarily. A standalone server often uses it, while a plugin-based server can call WordPress functions directly.

Is MCP the same as the REST API?

No. The REST API exposes WordPress data to software. MCP is a standard way for AI clients to discover and use tools.

How do I keep it safe?

Use a limited user, expose few tools, keep credentials secret, log calls, and avoid publishing or deleting tools.

Conclusion

To build a WordPress MCP server, start small: one or two well-described tools, a limited user, and safe behavior such as saving drafts. Once that works and you trust it, add capabilities one at a time.

Prefer not to write code? Read our guide to connecting Claude to WordPress or see how MCP Manager bridges WordPress and AI assistants.

Explore ByteCore Stack Plugins

  • MCP Manager – connect your WordPress site to AI assistants through MCP.
  • SMTP Manager – reliable WordPress email delivery.
  • Lightsail Manager – manage your AWS Lightsail CDN from WordPress.

Leave a Reply