# WordPress and WooCommerce MCP: connecting your site to an AI assistant

> WordPress can now expose its functions to an AI assistant: the Abilities API describes what the site can do, the official MCP Adapter translates that into MCP, and WooCommerce relies on both for its products and orders. The whole stack is still young and moving fast. I set it up on your site with limited permissions, and write the abilities your plugins are missing.

- Source canonique : [https://allaux.fr/en/wordpress-woocommerce/mcp](https://allaux.fr/en/wordpress-woocommerce/mcp)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Short answer

> There is no MCP server in WordPress core. The official route in late 2026 is the Abilities API (in core since WordPress 6.9) plus the MCP Adapter plugin maintained by the WordPress team, still at version 0.x. WooCommerce enables its MCP integration under Settings, Advanced, Features; it is still presented as a developer preview. The server to use is the adapter’s, under /wp-json/mcp/mcp-adapter-default-server; the former WooCommerce-specific endpoint is deprecated, as is Automattic’s old wordpress-mcp repository, archived in January 2026.

## Connecting WordPress or WooCommerce to AI?

- **Describe my need in the form** — WordPress and WooCommerce versions, hosting, assistant used, tasks to delegate: I reply personally. ([/contact](/contact))

## How the pieces fit together

The Abilities API is a registry: each plugin declares “abilities”, meaning named actions with typed inputs, typed outputs and a permission callback based on WordPress capabilities. WordPress 7.0, released in May 2026, completed that foundation on the JavaScript side.

The MCP Adapter then decides what an AI agent may see and call. An ability is only exposed over MCP if its metadata says so. The adapter works over HTTP for a remote site, and over STDIO through WP-CLI for a local environment.

WooCommerce has published its own canonical abilities for products and orders since version 10.9. A common misunderstanding: on the adapter’s shared server, the assistant doesn’t see one tool per ability, but three generic tools to discover abilities, read their description and run them.

## What gets in the way in practice

Installed on its own, the adapter often seems to do nothing: core abilities are few and read-only. For an assistant to actually work on your shop, you need write abilities, provided by a plugin or written for your site. Community plugins adding dozens of them exist, but each one widens what a compromised token would allow.

Authentication usually relies on a WordPress application password. The classic trap is creating it on an administrator account: the assistant then inherits every right of that account. A dedicated user, with a role limited to what is needed, changes the level of risk completely.

## My work on WordPress and WooCommerce

- **Setting up the adapter and WooCommerce MCP** — Installation, enabling the feature, checking the endpoint, connecting your MCP client (Claude, ChatGPT, n8n) over HTTP, or locally through WP-CLI for testing.
- **Dedicated user, minimal rights** — An account and role specific to the assistant, a separate application password per use, mandatory HTTPS, and no bypass of secure transport in production.
- **Bespoke abilities for your plugins** — Declaring abilities for your business functions (quotes, supplier stock, loyalty, bookings), with input and output schemas and WordPress capability checks.
- **Audit of an existing setup** — Review of installed MCP plugins, abilities actually exposed, accounts used and logs, with a list of fixes ranked by risk.

## The steps of a setup

1. **Start from tasks, not from the tool** — We list what the assistant should look up or change: pending orders, products without images, low stock, content to update.
2. **Check the prerequisites** — WordPress, WooCommerce and PHP versions, plugin compatibility, HTTPS, and whether your host allows application passwords.
3. **Install on a copy** — First trials on staging: the adapter and the WooCommerce integration still change from one version to the next.
4. **Expose only what is needed** — Only useful abilities are marked public for MCP, each with a capability check; sensitive actions stay out of scope or behind confirmation.
5. **Connect and verify** — Connecting the MCP client, then control questions with known answers, to check the assistant reads the right data.
6. **Document revocation** — You know which application password to delete and which account to disable to cut access in a minute.

## Already tried and nothing answers?

- **Send me what you installed** — List the MCP plugins enabled and the message your assistant shows: I’ll tell you where it gets stuck. ([/contact](/contact))

## Why I can help on this

I build MCP servers for real. The site you are reading is driven by an MCP server I wrote: each operation of its API becomes a tool, each token has precise scopes (reading pages, writing, publishing), and a safeguard refuses to send a page that is too thin before the call is even made. On PrestaShop, I built an MCP module with limited-scope keys, an action log and undo for changes, described on the PrestaShop MCP page.

On WordPress I apply the same discipline: one tool per real need, minimal rights and a trace of what the assistant did. On the code side, writing an ability is ordinary plugin development, which I have practised for a long time, see bespoke WooCommerce plugin.

## Don’t

> Don’t reuse an administrator application password for an assistant, don’t allow insecure transport outside a local machine, and be wary of pre-2026 tutorials recommending an endpoint or plugin that has since been archived.

## Related pages

- **MCP server for a shop** — The general approach: which tools to expose, with which rights, and how to keep a trace of calls. ([/expertises/serveur-mcp-boutique-pilotable](/expertises/serveur-mcp-boutique-pilotable))
- **PrestaShop MCP** — Official module, bespoke module and tools for your modules. ([/prestashop/mcp](/prestashop/mcp))
- **Shopify MCP** — What Shopify already provides and what has to be built. ([/shopify/mcp](/shopify/mcp))
- **Agentic commerce** — ACP, UCP and purchases by agents: what is actually available in France. ([/guides/commerce-agentique](/guides/commerce-agentique))

## An AI assistant plugged into your WooCommerce, without opening the door

- **Send my request** — Setup, bespoke abilities or audit of an existing installation: describe your site in the contact form. ([/contact](/contact))

## FAQ

### Is there an official MCP server for WordPress?

Not in core. The official bridge is the MCP Adapter plugin, maintained by the WordPress team, which exposes over MCP the abilities declared through the Abilities API. It is still at version 0.x, so it may change.

### Does WooCommerce have native MCP?

Yes, since WooCommerce 10.3, as a developer preview to enable in the advanced features. Since 10.9, WooCommerce provides canonical abilities for products and orders, served by the adapter’s server.

### Do I need WordPress 6.9 or later?

It is strongly advised, since the Abilities API is part of core there. On an older version the setup becomes makeshift; I then recommend updating WordPress first, on a copy of the site.

### My host blocks application passwords: what now?

Some firewalls or configurations disable REST API authentication. We first find the cause; depending on it, we adjust the configuration or use another authentication method supported by your MCP client.

### Can the assistant create orders or refunds?

Only if an ability allows it and the account used has the right. I recommend keeping financial operations outside the assistant’s scope, or behind explicit human confirmation.
