MCPServe creates local MCP server profiles for compatible AI clients. Each profile has its own URL, selected WordPress Editor or Author, allowed content types and tools, and revocable credentials. The plugin performs no AI inference. Your chosen client provides the conversation and reasoning.
Every included tool works without payment, a license key, or a trial clock. The configurable expiration of a server profile or credential is a security setting; an administrator can renew or replace it without payment. Builder-managed content is protected from body replacement because this plugin does not edit builder layouts. Theme, plugin, file, user, and critical-setting administration is outside the scope of this connector.
A site administrator creates the profile, but the remote connection must be assigned to an Editor or Author without administrator capabilities. This is rechecked on every MCP request and token refresh. The assigned user explicitly signs in and consents to the requested scopes. Tools check the user’s WordPress permissions at the point of use. OAuth uses authorization code with S256 PKCE; advanced clients can use an expiring server-bound Bearer key. Revoke access in the plugin dashboard.
Use an HTTPS site with pretty permalinks and an AI client that supports remote MCP with OAuth or Bearer authentication. The connector implements stateless Streamable HTTP JSON responses. GET event streams, JSON-RPC batches, resources, and prompts are not implemented. Custom connector availability may depend on the client’s plan. No AI subscription or API key is provided.
This plugin makes no licensing, telemetry, or model API calls. Local assets are bundled with it. The administrator must enable it, create a profile, and approve exact OAuth callback hostnames. Authorized clients may receive permitted site identity, content (including private or draft content accessible to the assigned user), URLs, SEO metadata, image URLs, and taxonomy data. They may transmit those responses to their AI provider. Review your chosen provider’s terms and privacy policy before connecting. For optional clients: https://openai.com/policies/terms-of-use/ , https://openai.com/policies/privacy-policy/ , https://www.anthropic.com/legal/consumer-terms , and https://www.anthropic.com/legal/privacy .
Profiles, assigned user IDs, client identifiers, callback URLs, hashed keys, temporary tokens, and tool activity are stored locally in WordPress. Activity entries include tool name, timestamp, connection/user identifiers and success status, without article bodies, prompts, or raw credentials. Uninstall removes connector settings and operational records while preserving WordPress content and SEO fields.