WordPress MCP Tools Reference: Read, Write and Verify
Which tools can a WordPress ChatGPT MCP connector actually call? This reference describes the five operations exposed in the authenticated WPBridge Studio Website Admin connection tested on October 10, 2026, with safe request examples, WordPress permission checks and read-back verification. It does not imply that other connector editions or AI clients expose identical tools.
Quick answer: the five observable connector operations
| Operation | Purpose | Write access? | Evidence you should request |
|---|---|---|---|
list_sites | Identify configured WordPress websites and their site IDs | No | Expected hostname and intended site ID |
site_status | Read site identity, WordPress version and registered REST namespaces | No | Correct site URL and response from the actual installation |
discover_routes | Inspect registered WordPress REST paths, supported methods and parameter schemas | No | Named endpoint and method verified on the chosen site |
wordpress_read | Make an authorized GET request to a WordPress REST endpoint | No | HTTP result, intended resource ID and expected saved fields |
wordpress_write | Issue an authorized POST, PUT, PATCH or DELETE to an installed WordPress REST endpoint | Yes; must be permitted | WordPress response plus an independent read-back |
Do not confuse WordPress REST routes with MCP tools. The owner’s site returned a catalog of 216 WordPress REST route patterns in an earlier inspection. Those routes include core and third-party namespaces; they are not 216 independently available MCP tools, and they do not confer permission to invoke or modify each endpoint.
Read-only WordPress MCP workflow: exact sequence
- Identify: ask the client to call
list_sitesand select the intended site ID. Do not infer the target from a similarly named domain. - Check: call
site_statusfor that site; confirm its returned hostname matches the expected WordPress installation. - Authenticate: request
wordpress_readof/wp/v2/users/me. Report the actual result without showing tokens or Application Passwords. - Read a resource: request
wordpress_readof/wp/v2/pages/41on the test site, or the corresponding page ID on your own installation. - Verify: compare returned title, link, status and ID with the WordPress record. Report any mismatch; do not proceed to writes.
For the owner-authorized WPBridge Studio installation, the identity and known-product-page REST reads returned HTTP 200 on October 10, 2026. Those observations are documented in the connector demonstration. They are not a guarantee that a customer’s restricted WordPress role can read the same objects.
Use WPBridge Studio to list my authorized sites.
Identify the exact intended site URL, then call site_status.
Use wordpress_read for /wp/v2/users/me.
Read one known published page by ID and report its title and status.
Do not create, update, publish or delete anything.
WordPress REST route examples and parameter behavior
The connected tool accepts a WordPress REST route such as /wp/v2/pages, not the complete public https://example.com/wp-json/... URL. In WordPress’s conventional web URLs, the same REST namespace appears beneath /wp-json/. The connector selects the authorized WordPress site separately from the route.
| Route | Typical read | Practical consideration |
|---|---|---|
/wp/v2/users/me | Authenticated user identity | A denied response may indicate missing credentials or a permissions problem |
/wp/v2/pages | Page collection and pagination | Use per_page and page, then continue across pages when needed |
/wp/v2/pages/{id} | One WordPress page | Verify the saved ID and status; edit context may require additional rights |
/wp/v2/posts | Posts and permitted drafts | Private or draft status depends on the authenticated user’s capabilities |
/wp/v2/media | Media metadata | File-upload and mutation capabilities are separate from listing media |
For authoritative parameter names, consult the WordPress Pages REST reference and WordPress Posts REST reference. Plugin-defined routes can differ; always inspect discover_routes before invoking a non-core endpoint.
How to verify a WordPress content write safely
A successful tool response is not enough. For an approved, non-destructive draft task, use a dedicated WordPress user with the needed permissions, ensure writing is intentionally enabled, and operate on a disposable staging item.
- Read the existing target page or draft and record its ID, current status and fields. Make a backup or revision where appropriate.
- Ask for a single, specific change: for example, revise the excerpt of one staging draft while keeping its status as
draft. - Issue the permitted
wordpress_writecall using the exact installed REST route and approved fields. The method must be supported by that route. - Check the WordPress response code and resource ID. A rejected or failed request is not a completed change.
- Call
wordpress_readindependently on the same resource ID and compare the saved fields to the request. - Check browser rendering separately when the content contains layouts, forms, scripts, interactive elements or caches.
First read the intended staging draft and report its ID.
Do not proceed if its ID or site URL is unexpected.
If the authorized editing tool is available, update only its excerpt.
Keep the resource as a draft, then read it back independently.
Report the WordPress response and whether saved values match.
Do not publish or delete.
Actual writes remain subject to the account’s WordPress roles, each REST controller’s permission checks and any connector read-only switch. A request allowance or paid package does not confer publishing rights. The WordPress API permissions guide explains typical capabilities.
Why an installed WordPress plugin might not be accessible through MCP
An admin screen is not proof of an API. The connector only reaches functionality that an authorized installed WordPress endpoint exposes. Before committing to a WooCommerce, membership, analytics or custom-plugin workflow, ask the connector to discover the exact route, supported method, parameters and authorization behavior. Do not assume that discovering a route means it permits the requested operation.
The official WordPress MCP Adapter and Abilities API architecture is a separate integration model. Its abilities require appropriate exposure and permission checks. WPBridge Studio’s observed Website Admin tools instead provide a site selector and access to installed WordPress REST routes. These models are related but not interchangeable.
MCP authorization and client compatibility in 2026
Remote MCP servers may use OAuth authorization to obtain user consent and protect tools. The MCP specification was revised on July 28, 2026, including important authorization security guidance. The published specification describes protected-resource metadata, token validation, authorization-server discovery and security safeguards for public clients. See the MCP authorization specification for current protocol requirements.
Do not treat this reference as a certificate of full 2026-spec conformance for WPBridge Studio. A compliant client handshake, callback handling, refresh-token behavior and direct or hosted licensing must be tested on the exact installed service and client version. The availability of custom ChatGPT connectors also depends on the user’s current account features.
For production setup, check security and revocation, site compatibility and 401/403 authorization troubleshooting. Never place live OAuth tokens, WordPress Application Passwords or customer data in public examples.
What was verified and what is still outside this reference?
| Assertion | Status or scope |
|---|---|
| Authenticated site identity, connected user and REST page reads on the owner’s Studio site | Verified through the installed connector on October 10, 2026 |
| WordPress REST route discovery | Verified; authorization remains route and user dependent |
| Owned WordPress demo page and revision evidence | Documented on the published demonstration |
| Every plugin, theme-file editor, WooCommerce refund or custom PHP operation | Not guaranteed; requires specific APIs and permissions |
| Independent Claude/Gemini production trials, every ChatGPT account and every MCP version | Not established by this owner’s Website Admin test |
| Frontend page appearance, search ranking, Google indexing and SEO traffic | Require external/browser and search-performance checks |
WordPress MCP tool reference FAQs
Can ChatGPT read a WordPress page without having publishing access?
Yes, when the configured connector advertises a read tool and the authenticated WordPress user can read the intended resource. Writing permissions are separate.
Does 200 OK from /wp/v2/users/me prove an editing tool works?
No. It verifies authenticated identity for that request. Publishing can still fail under read-only controls or WordPress REST permissions.
Can the same tool work on multiple WordPress sites?
A hosted workspace may list multiple authorized sites. Each call must select the correct site ID and use that site’s credentials and capabilities. See agency workflow guidance.
What should I test before purchasing?
Confirm supported client access, site identity, relevant REST route availability, your WordPress user’s permissions, and the actual hosted or direct plan terms. Start with the WPBridge Studio WordPress ChatGPT MCP connector and evaluation scorecard.