You can connect a WordPress site to Cursor, Claude Code, or Codex in about five minutes. Once it’s connected, you can ask your editor “which plugins need updates?” or “list my drafts from last week”, and it answers from the live site, without a browser tab or SSH.
This tutorial uses PressBot’s built-in MCP server, which is how we run pressbot.io day to day. The steps (enable the server, create an Application Password, add one config entry) are the same pattern most WordPress MCP servers use, so they carry over. For a look at the other options, see our comparison of WordPress MCP servers.
Tested September 24, 2026 with Claude Code and PressBot 1.11 on WordPress 7.1. The Cursor and Codex formats follow their current docs.
What You Need
- A self-hosted WordPress site running over HTTPS. Application Passwords only work over HTTPS, or on a site whose environment type is set to
local. - An administrator account. PressBot’s MCP endpoint only answers users who can manage the site.
- The PressBot plugin. The free version gives MCP clients 11 read-only tools: site info, posts, plugins, comments, chatbot conversations, knowledge search, and five site-health checks. Pro ($29/yr) opens all 115 tools, including writes.
- Cursor, Claude Code, Codex, or any MCP client that can call a remote server with a custom header.
Step 1: Turn On the MCP Server
In WordPress, go to PressBot → Settings → MCP Server and turn on Enable MCP Server. The panel shows your endpoint, which is always:
https://your-site.com/wp-json/pressbot/v1/mcp
Under it are ready-made snippets for each client, already filled in with your site’s URL and your username.
Step 2: Create an Application Password
Go to Users → Profile, scroll to Application Passwords, type a name like “Cursor” or “Claude Code”, and click Add New Application Password. Copy the 24-character password; WordPress shows it only once.
Create one per client. It’s a separate login you can revoke from the same screen at any time without touching your real password, and one per client means revoking Cursor doesn’t also cut off Claude Code.
Step 3: Turn It Into a Token
MCP clients send the login as a Basic auth header: your username and the application password, joined by a colon and base64-encoded. The spaces in the password are fine; WordPress strips them before checking.
macOS or Linux:
echo -n 'your-username:abcd EFGH 1234 ijkl MNOP 5678' | base64
Windows PowerShell:
[Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes('your-username:abcd EFGH 1234 ijkl MNOP 5678'))
The output is your token. Treat it like a password.
Step 4: Check the Connection With curl
Before touching an editor, make sure the site answers. This asks the server for its tool list:
curl -s -X POST "https://your-site.com/wp-json/pressbot/v1/mcp" \
-H "Authorization: Basic YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'
A JSON list of tools means it works. An error message tells you exactly what’s wrong; see the troubleshooting table below.
Step 5: Connect Your Editor
Claude Code
One command:
claude mcp add --transport http pressbot https://your-site.com/wp-json/pressbot/v1/mcp \
--header "Authorization: Basic YOUR_TOKEN"
By default the server is saved for the current project and only on your machine. Add --scope user to use it in every project. Check it with claude mcp get pressbot, or type /mcp inside a session.
If you share the project with a team, --scope project writes a .mcp.json file meant to be committed. Don’t commit the token. Claude Code expands environment variables in that file, so reference one instead:
{
"mcpServers": {
"pressbot": {
"type": "http",
"url": "https://your-site.com/wp-json/pressbot/v1/mcp",
"headers": {
"Authorization": "Basic ${WP_MCP_TOKEN}"
}
}
}
}
Cursor
Create .cursor/mcp.json in your project, or ~/.cursor/mcp.json to use the server in every project:
{
"mcpServers": {
"pressbot": {
"url": "https://your-site.com/wp-json/pressbot/v1/mcp",
"headers": {
"Authorization": "Basic ${env:WP_MCP_TOKEN}"
}
}
}
}
Cursor reads ${env:WP_MCP_TOKEN} from your environment, which keeps the token out of the file. You can paste the token directly instead, but then keep the file out of git. Open Cursor’s MCP settings to confirm the server shows as connected with its tools listed.
Codex
Add this to ~/.codex/config.toml, then restart Codex and run /mcp to confirm:
[mcp_servers.pressbot]
url = "https://your-site.com/wp-json/pressbot/v1/mcp"
http_headers = { "Authorization" = "Basic YOUR_TOKEN" }
Claude Desktop
Claude Desktop’s config file only launches local servers. For a remote one, use Settings → Connectors → Add custom connector (sending a custom auth header there is still in limited beta), or run a local bridge such as mcp-remote.
Step 6: Try It
Start a new chat in your editor and ask something only the site knows:
- “Which plugins on my site have updates available?”
- “List my draft posts and when each was last edited.”
- “Show the last 10 chatbot conversations. What are people asking that the site doesn’t answer?”
- “Run a health check on the homepage and tell me if anything looks wrong.”
On Pro you can also make changes: “Write meta descriptions for the posts that are missing one,” “Approve the pending comments that aren’t spam,” “Draft a post about our new opening hours.” For a long job like a full article, PressBot returns a job ID right away and your editor checks back until the draft is ready, so the call doesn’t time out.
Several Sites From One Editor
Add one entry per site, each with its own name and token:
claude mcp add --transport http --scope user shop https://shop.example.com/wp-json/pressbot/v1/mcp \
--header "Authorization: Basic SHOP_TOKEN"
claude mcp add --transport http --scope user blog https://blog.example.com/wp-json/pressbot/v1/mcp \
--header "Authorization: Basic BLOG_TOKEN"
Then say which site you mean: “On shop, list products that are out of stock.”
Staying Safe
- Your editor asks before acting. Claude Code and Cursor both ask for approval before running a tool unless you’ve allowed it. PressBot marks tools that delete or change important settings as destructive, and those tools also say so in their description.
- Writes need Pro and an admin. The free server can’t change anything. On Pro, every tool checks the user’s WordPress permissions before it runs.
- Revoke in one click. Delete the Application Password under Users → Profile and that client is locked out immediately.
- Keep tokens out of git. Use environment variables in shared config files, as shown above.
Troubleshooting
| You see | What it means | Fix |
|---|---|---|
rest_no_route (404) |
The MCP server is off, or the URL is wrong | Turn on Enable MCP Server, and check the URL ends in /wp-json/pressbot/v1/mcp |
rest_forbidden: “MCP access requires administrator privileges” |
No login reached WordPress, or the user isn’t an admin | Check the header name is exactly Authorization, and use an admin account. If it still fails, see the next row. |
invalid_username |
WordPress doesn’t know that username | Use your login name (not the display name) or your email, then rebuild the token |
incorrect_password |
The password isn’t a valid application password | Use the application password, not your normal one, or create a new one |
| Application Passwords section is missing | The site isn’t on HTTPS, or a security plugin or host turned them off | Switch to HTTPS, or re-enable Application Passwords in your security plugin |
Correct token but still rest_forbidden |
Your server strips the Authorization header before WordPress sees it | Check Tools → Site Health, which tests for this. On Apache, your host may need to pass the header through. |
| Timeouts or HTML error pages | A firewall or CDN is blocking POST requests to /wp-json/ |
Allow that path in your firewall or CDN bot protection |
FAQ
Do I need PressBot Pro to use MCP?
No. The free plugin includes an MCP server with 11 read-only tools, 13 if WP Booking Pro is active. Pro adds the full catalog of 115 tools, including creating and editing content, managing plugins, WooCommerce, Yoast, and security.
Is this the same as the WordPress MCP Adapter?
No. The official MCP Adapter is a separate plugin that exposes whatever “abilities” your other plugins register. PressBot ships its own server with its own tools; Pro also registers a few WordPress abilities for WordPress’s own AI features. You can run both. Our MCP server comparison covers when each fits.
Does it work with WordPress.com?
Only on WordPress.com plans that let you install plugins. Otherwise, WordPress.com has its own MCP server that signs in with your WordPress.com account instead of an Application Password.
Can MCP break my site?
On the free plugin, no: every tool is read-only. On Pro, the tools can change things, the same way you can in wp-admin. Keep your editor’s approval prompts on for destructive tools, and read each request before you approve it.