Claude Code + WordPress

Connect Claude Code to WordPress.

Give Claude Code a bearer-protected MCP connection to your WPGuard server. Inspect one registered site, preview the exact change, and keep important requirements attached to the field they protect.

Self-hosted · Streamable HTTP · Claude Code project or user scope

How do I connect Claude Code to WordPress?

Add WPGuard as an HTTP MCP server and send its token in the Authorization header. Keep the token in Claude Code’s environment instead of committing it to the project.

.mcp.json
{
  "mcpServers": {
    "wpguard": {
      "type": "http",
      "url": "http://127.0.0.1:8642/mcp",
      "headers": {
        "Authorization": "Bearer ${WPGUARD_TOKEN_ADMIN}"
      }
    }
  }
}

Choose the right scope

Use a project .mcp.json when the server definition belongs with one trusted workspace. Use Claude Code’s user scope when the connection should remain private across projects. Project configurations require trust before Claude Code uses them.

Use Claude’s documented HTTP format

Claude Code requires type: "http" for a Streamable HTTP entry. It also accepts the CLI form with --transport http and an Authorization header. Review the official Claude Code MCP documentation →

Verify the Claude MCP connection before an edit.

Prove that Claude Code can reach the server and use a read-only tool before you give it a WordPress mutation.

Check server status

Run claude mcp get wpguard or claude mcp list. Open /mcp inside Claude Code to see connection errors. A 401 means the header is missing, unexpanded, or does not match a configured server token.

Start with site_list

Call site_list first. An empty result means the connection works but no WordPress site is registered. Register a staging site, then inspect it with wp_site_context before choosing a field or action.

Use a reachable endpoint

127.0.0.1 works only when Claude Code and WPGuard run on the same host. Put WPGuard behind an authenticated HTTPS endpoint or a tunnel you control when the client runs elsewhere.

Preview the selected value

Name the registered site and exact target. Preview supported option, post-meta, or post-content changes with apply=False. Review the old value, proposed value, correction result, state tag, and change digest before approval.

Claude Code approval and WPGuard approval are separate controls.

Claude Code decides whether the MCP tool may run. WPGuard decides whether a guarded write matches an approved packet and applicable correction checks.

Keep permissions explicit

Use a recon token for discovery when no write is needed. Mutate and admin tokens expose broader operations. A caller with mutate access can approve packets, so enforce a separate human reviewer outside WPGuard when your workflow requires identity separation.

Verify desktop and mobile

After the write, ask WPGuard to capture both viewports and check the expected text, headings, overflow, and broken images. The receipt keeps the screenshots and their hashes with the result.

The WPGuard connection guide documents token scopes and remote access. The security boundary documents the operations each control covers.

Connect Claude Code to one staging site.

List the sites. Inspect the target. Preview one reversible change.