WordPress and WooCommerce MCP: connecting your site to an AI assistant
WordPress can now expose its functions to an AI assistant: the Abilities API describes what the site can do, the official MCP Adapter translates that into MCP, and WooCommerce relies on both for its products and orders. The whole stack is still young and moving fast. I set it up on your site with limited permissions, and write the abilities your plugins are missing.
Connecting WordPress or WooCommerce to AI?
How the pieces fit together
The Abilities API is a registry: each plugin declares “abilities”, meaning named actions with typed inputs, typed outputs and a permission callback based on WordPress capabilities. WordPress 7.0, released in May 2026, completed that foundation on the JavaScript side.
The MCP Adapter then decides what an AI agent may see and call. An ability is only exposed over MCP if its metadata says so. The adapter works over HTTP for a remote site, and over STDIO through WP-CLI for a local environment.
WooCommerce has published its own canonical abilities for products and orders since version 10.9. A common misunderstanding: on the adapter’s shared server, the assistant doesn’t see one tool per ability, but three generic tools to discover abilities, read their description and run them.
What gets in the way in practice
Installed on its own, the adapter often seems to do nothing: core abilities are few and read-only. For an assistant to actually work on your shop, you need write abilities, provided by a plugin or written for your site. Community plugins adding dozens of them exist, but each one widens what a compromised token would allow.
Authentication usually relies on a WordPress application password. The classic trap is creating it on an administrator account: the assistant then inherits every right of that account. A dedicated user, with a role limited to what is needed, changes the level of risk completely.
My work on WordPress and WooCommerce
-
Setting up the adapter and WooCommerce MCP
Installation, enabling the feature, checking the endpoint, connecting your MCP client (Claude, ChatGPT, n8n) over HTTP, or locally through WP-CLI for testing.
-
Dedicated user, minimal rights
An account and role specific to the assistant, a separate application password per use, mandatory HTTPS, and no bypass of secure transport in production.
-
Bespoke abilities for your plugins
Declaring abilities for your business functions (quotes, supplier stock, loyalty, bookings), with input and output schemas and WordPress capability checks.
-
Audit of an existing setup
Review of installed MCP plugins, abilities actually exposed, accounts used and logs, with a list of fixes ranked by risk.
The steps of a setup
-
Start from tasks, not from the tool
We list what the assistant should look up or change: pending orders, products without images, low stock, content to update.
-
Check the prerequisites
WordPress, WooCommerce and PHP versions, plugin compatibility, HTTPS, and whether your host allows application passwords.
-
Install on a copy
First trials on staging: the adapter and the WooCommerce integration still change from one version to the next.
-
Expose only what is needed
Only useful abilities are marked public for MCP, each with a capability check; sensitive actions stay out of scope or behind confirmation.
-
Connect and verify
Connecting the MCP client, then control questions with known answers, to check the assistant reads the right data.
-
Document revocation
You know which application password to delete and which account to disable to cut access in a minute.
Already tried and nothing answers?
Why I can help on this
I build MCP servers for real. The site you are reading is driven by an MCP server I wrote: each operation of its API becomes a tool, each token has precise scopes (reading pages, writing, publishing), and a safeguard refuses to send a page that is too thin before the call is even made. On PrestaShop, I built an MCP module with limited-scope keys, an action log and undo for changes, described on the PrestaShop MCP page.
On WordPress I apply the same discipline: one tool per real need, minimal rights and a trace of what the assistant did. On the code side, writing an ability is ordinary plugin development, which I have practised for a long time, see bespoke WooCommerce plugin.
Related pages
-
MCP server for a shop
The general approach: which tools to expose, with which rights, and how to keep a trace of calls.
-
PrestaShop MCP
Official module, bespoke module and tools for your modules.
-
Shopify MCP
What Shopify already provides and what has to be built.
-
Agentic commerce
ACP, UCP and purchases by agents: what is actually available in France.
An AI assistant plugged into your WooCommerce, without opening the door
Describe your need in one minute
A few targeted questions so I can reply with an estimate rather than another questionnaire.