Log in to the WordPress admin panel, write a post, set a category, save it as a draft… Wouldn’t it be convenient if you could perform this entire sequence of tasks simply by giving instructions to an AI in natural language?
Using MCP (Model Context Protocol), you can perform operations such as retrieving, creating, and updating WordPress posts from AI agents like the Codex App.
In this article, I’ll explain the quickest steps to set up an MCP server using the WordPress plugin “AI Engine” and connect to it from OpenAI’s Codex App. I’ve limited the scope to what you can safely test on a verification site, from installing the plugin to verifying its operation in the Codex App.
More in-depth topics, such as the mcp-adapter method and connecting to OpenClaw, are covered in my paid Note. For now, please use this article to get a feel for “interacting with WordPress via AI.”
What is WordPress MCP?
MCP (Model Context Protocol) is an open standard protocol for securely connecting AI agents to external tools. Proposed by Anthropic, various services and tools are currently working to support it.
WordPress MCP is a mechanism that uses this protocol to make WordPress sites controllable by AI agents. Specifically, WordPress acts as an MCP server, allowing AI agents (MCP clients) to retrieve, create, and update posts via HTTP.
What WordPress MCP Can Do
- Retrieve lists of posts and pages, search, and view content
- Create and update draft posts
- Retrieve and set categories and tags
- View the media library
- Retrieve site and user information
- WooCommerce product management (depending on plugin configuration)
Simply instruct the AI to “Show me the list of latest drafts” or “Save a draft post with this title,” and the task will be completed without opening the admin panel.
Try it first on a test site
While WordPress MCP is convenient, it grants the AI agent permissions to create and update posts. To prevent unintended publication or overwriting of posts, we recommend testing the functionality on a staging site first.
It is safest to test it in a local environment (such as Herd or dbngin) or on a test subdomain. Wait until you have thoroughly verified its behavior before implementing it on your live site.
Two Methods for Implementing WordPress MCP
There are two main methods for plugins that turn WordPress into an MCP server.
- AI Engine Method
This method uses the MCP functionality of the “AI Engine” plugin developed by Meow Apps. It is a standalone plugin that provides authentication via HTTP endpoints and Bearer tokens. In addition to post operations, it also supports direct manipulation of meta fields, as well as AI image generation and image analysis features.
- mcp-adapter Enable Abilities for MCP Method
This method combines the official WordPress “mcp-adapter” with the third-party “Enable Abilities for MCP.” Operations are organized in a way that makes them easy to pass to AI, and the configuration is well-suited for managing custom post types.
This article focuses exclusively on the AI Engine method. This is because a single plugin launches the MCP server and allows for the quickest connection to the Codex App.
Detailed comparisons with the mcp-adapter method and connection procedures for OpenClaw are covered in my paid Note.
Installing and Configuring AI Engine
First, install AI Engine on a WordPress site for testing.
Installing AI Engine
- Log in to the WordPress admin panel
- Go to “Plugins” → “Add New”
- Type “AI Engine” into the search bar
- “AI Engine – The Chatbot, AI Framework & MCP for WordPress” will appear; click “Install Now”
- After installation is complete, click “Activate”
You can use the MCP features with the free version of AI Engine. The paid Pro version includes additional features such as Advanced MCP Tools, but these are not necessary for this procedure.
Enabling MCP Features
Once you’ve installed AI Engine, enable the MCP features.
- Open “Meow Apps” → “Settings” in the admin panel
- Switch to the “MCP” tab
- Check the “Enabled” box
Configuring the Bearer Token
Configure the token used for MCP connection authentication. Since this token is as sensitive as a password, please use a random string that is difficult to guess.
You can generate a 24-character random string by running the following command in the terminal.
openssl rand -base64 32 | tr -d "= /" | cut -c1-24
Paste the generated string into the “Bearer Token” field on the AI Engine MCP settings screen and save it.
Tip: A Bearer Token is like a password that “only lets in those who have this string.” When included in the AI Engine MCP URL, the Codex App uses that token for authentication during connection. In other words, since the URL itself contains authentication information, be sure to replace it with a dummy string in screenshots or examples in articles.
Warning: Never disclose this token. If you post it directly in a GitHub repository or blog post, there is a risk that a third party could gain unauthorized access to your WordPress site.
Checking MCP Features
In the “MCP Features” section of the same MCP settings screen, you can select the features you want to provide.
- Check “WordPress” — Enables standard operations such as posts, pages, categories, tags, and media
- Check “Dynamic REST” (optional) — Adds flexible access to REST API endpoints
For now, simply check “WordPress” to enable basic post management.
Checking the MCP URL
The connection URL is displayed at the bottom of the MCP settings screen. It follows the format shown below.
https://example.com/wp-json/mcp/v1/xxxxxxxxxxxxxxxx
The URL with the random string at the end includes a Bearer Token. You will register this URL with the Codex App in the next step.
The easiest method is to simply use the URL displayed directly below “If you prefer, you can also include the bearer token directly in the URL.”
Steps to Register the MCP Server with the Codex App
Once the AI Engine is ready, register it as an MCP server in the Codex App (OpenAI).
Open the MCP settings screen in the Codex App
- Open the Codex App
- Go to “Settings” → “MCP” → “Servers”
- Click “Add Server”
Enter server information
- Enter any name for the server name (e.g.,
my-wordpress-mcp) - Select “Streaming-enabled HTTP” for the type
- Paste the MCP URL displayed by AI Engine into the URL field
- Save
If you are using a URL format that includes a Bearer Token, you do not need to set authentication information separately in the headers. You can connect simply by pasting the URL as is into the URL field.
Connection Verification and Basic Operations
Once registration is complete, verify the connection via the Codex App chat.
Example connection verification prompt
Try entering the following in the Codex App chat.
my-wordpress-mcpというMCPが使えるか確認してもらえますか?
If the Codex App returns the site name, WordPress version, and other details, the connection was successful.
Retrieving the Post List
Let’s start with read-only operations.
WordPressの最新の投稿を5件、タイトルとステータス付きで教えてください。
The AI will retrieve WordPress post data via MCP and display a list.
Checking Site Statistics
このWordPressサイトの投稿数、固定ページ数、カテゴリ数を教えてください。
You can also retrieve site-wide information like this simply through the chat, without opening the admin panel.
For now, let’s focus on read operations
This article will not cover write operations such as creating or updating posts. The reason is as follows:
- Even on a test site, there is a risk that unintended posts could be published
- Post creation and updates should only be performed after understanding the WordPress permission structure on the AI Engine side
- First, you should focus on “read confirmation” to understand how the connection and data retrieval work
For practical operations such as creating, updating, and managing media, I have summarized verification commands and precautions in a paid Note.
Security Precautions
While the WordPress MCP is convenient, it opens a gateway for external access to WordPress. Please note the following points.
Bearer Token Management
- Set the token to a random string that is difficult to guess (the OpenSSL command mentioned above is recommended).
- Do not include the token directly in Git repositories or blog posts
- If there is a risk of leakage, immediately regenerate the token from the AI Engine settings screen
Testing on a Development Site
- Do not deploy directly to the production site. Always verify behavior on a test site first
- Once testing is complete, disable MCP features when not in use
- Uncheck unnecessary features in AI Engine’s “MCP Features” to minimize permissions
Information on AI Engine Vulnerabilities
In the past, a privilege escalation vulnerability (assigned a CVE) involving the MCP feature has been reported in the AI Engine plugin. This affected users who had both Dev Tools and the MCP module enabled.
Although this has been fixed, please always keep the plugin updated to the latest version. As a general rule, never neglect security updates for WordPress core, PHP, or other plugins.
Topics Not Covered in This Article
This article focuses solely on the quickest way to connect to the AI Engine Codex App. The following topics are not covered:
- Registering MCP with OpenClaw
To use WordPress MCP with OpenClaw,
openclaw mcp setyou must register the MCP serveropenclaw gateway restartand apply the changes.- mcp-adapter Enable Abilities for MCP method
The method using the official WordPress mcp-adapter involves an authentication flow that differs from the AI Engine method, such as generating an Application Password or using “Generate Credentials.”
- Practical Procedures for Post Creation, Updates, and Media Operations
Details on writing operations—such as creating drafts, updating existing posts, and uploading media—are summarized along with verification commands.
- Comparison and Selection of the Two Methods
The AI Engine method excels at direct manipulation of meta fields and AI image generation, while the mcp-adapter method organizes the operations passed to the article management AI. I explain this in detail on Note, including how to choose between them based on your specific use case.
The full version containing this content is scheduled for release in the paid Note titled “WordPress MCP Practical Manual: Codex App / OpenClaw Connection and Comparison of the Two Methods.”
Frequently Asked Questions
- Is AI Engine free to use?
Yes. You can use the MCP features with the free version of AI Engine. The Pro version includes additional features such as Advanced MCP Tools, AI Forms, and Embeddings, but these are not required for the steps in this article.
- Does it work in a local environment (localhost)?
Yes, it does. If you register the
http://localhost:xxxx, you can connect to a local WordPress testing environment. However, if SSL is enabled in your local environment, the connection may fail due to certificate validation. In that case, you can sometimes resolve the issue by"env": {"NODE_TLS_REJECT_UNAUTHORIZED": "0"}to resolve the issue.- Can I use it with Claude Desktop or Claude Code?
Yes. Since the AI Engine MCP endpoint is exposed as HTTP (Streamable HTTP), any client that supports MCP can connect to it. Instructions for setting it up in Claude Desktop are also available in the official AI Engine documentation.
- Is it safe to use on a production site?
Please thoroughly test it on a staging site first and ensure you understand the permission structure and token management before considering implementation.
- Is it okay to perform operations via the WordPress admin panel while connected to MCP?
No problem. Operations via MCP are also requests made through the REST API, so they generally do not conflict with operations from the admin panel. However, if you edit the same post at the same time, the version saved later will overwrite the previous one.
Summary
In this article, we explained the quickest steps to turn WordPress into an MCP server using the AI Engine plugin and connect to it from the Codex App.
Let’s review the steps.
- Install and activate AI Engine
- Enable the MCP feature and set the Bearer Token
- Register the displayed MCP URL with the Codex App’s MCP server
- Verify the connection and perform read operations via the chat
With just one plugin and some Codex App settings, you can set up a system to retrieve WordPress information from an AI agent. Give it a try to streamline article management or as a starting point for an AI-driven content workflow.
The complete version—covering practical operations for creating and updating posts, a comparison with the mcp-adapter method, and connecting to OpenClaw—is covered in the paid Note article “WordPress MCP Practical Manual: Codex App / OpenClaw Connection and Comparison of the Two Methods.” Once you’ve gotten a feel for the connection process in this article, please consider this as your next step.


Comment