GetMCP/Blog/Build with MCP

Let AI Draft and Edit Your WordPress Posts — Without Giving It the Publish Button

InfiWebs · · 5 min read
Let AI Draft and Edit Your WordPress Posts — Without Giving It the Publish Button

The workflow most people have with AI and WordPress is copy-paste. Draft in the AI, paste into the editor, spot a problem, paste it back, repeat. What they actually want is for the AI to pull the real article, revise the real draft, check the real metadata — and for publishing to stay a human decision. That’s what GetMCP’s WordPress template is for, and the second half is the important part.

Seventeen tools, and what each one is for

Install the WordPress template from Templates and you get a server with 17 tools built on WordPress’s own REST API:

  • Posts: list_posts, get_post, create_post, update_post, delete_post
  • Custom fields: get_post_meta, update_post_meta
  • Pages: list_pages, get_page, create_page, update_page
  • Taxonomy and media: list_categories, list_tags, list_media
  • Users: list_users, get_user, create_user

Two of them install switched off: delete_post and create_user. Turn them on from the Tools tab only if an AI should be able to do those things. Everything else is on, and two details make the editing loop actually work: update_post changes only the fields you send and leaves the rest alone, and get_post with context=edit returns the raw, unrendered source — so the AI edits what’s really in the post, not a rendered copy of it.

Setting it up

  1. Install the template. The install dialog asks for your WordPress site domain once — example.com, no https:// — and every one of the 17 tools is built from it. No editing a placeholder into seventeen URLs.
  2. Create an application password for the WordPress user the AI should act as: Users → Profile → Application Passwords. Give it a name like “GetMCP” and copy the password it shows.
  3. Add it to the server. Open the server’s Authentication tab and enter your WordPress username and the application password as the outbound credential — the template already expects Basic auth, so there is nothing else to choose. Then set the server to Active.
  4. Connect your AI client with the Connect to Claude or Connect to Cursor button, or the snippet under How to connect.

Which WordPress user you pick matters more than any GetMCP setting. The tools can only do what that account can do. An Editor can draft, edit and publish posts but can’t create users or change settings; an Author can only touch their own posts. GetMCP doesn’t add capabilities — it inherits them.

Keeping the publish button to yourself

create_post and update_post both accept a status argument — draft, pending, private or publish. If you’d rather the AI could never publish, don’t rely on prompting it not to. Open each of those two tools in the Tool Editor and delete the status parameter.

This works because of how GetMCP treats a tool’s schema: an argument the tool doesn’t declare is dropped before the request is built, so it never reaches WordPress — and when WordPress gets a post with no status, it creates a draft. An AI that “decides” to publish sends status: publish, GetMCP discards it, and the post lands in Drafts for you to review. Every attempt is on the Logs tab with the arguments the AI sent, so you can see it tried.

Prefer a workflow where the AI can mark something ready without publishing? Keep the parameter but edit its allowed values to draft and pending — anything else is rejected before the call, and “Pending Review” is exactly the queue an editor already knows.

What it’s like once it’s connected

  • “Pull up my draft about the spring launch and tighten the intro — keep my voice.”
  • “Read the published post on onboarding and list every claim that’s out of date.”
  • “Add the SEO description custom field to the last five posts that don’t have one.”
  • “Which category has the fewest posts this year? Draft two ideas for it.”
  • “Create a page for the new pricing, as a draft, using the same structure as the current one.”

Categories and tags come back with their IDs, which is what create_post and update_post expect — so “file this under Tutorials” works without you looking anything up. Custom fields cover whatever your theme or SEO plugin registered with show_in_rest; anything not exposed that way is invisible to the REST API, and therefore to the AI.

Seeing exactly what changed

Every tool call is logged with the arguments the AI sent and the response WordPress returned, and the log’s replay re-runs a call so you can reproduce anything odd without involving the AI. For before-and-after on an edit, keep WordPress’s own revisions on — update_post goes through the same REST API the block editor uses, so every change the AI makes is a revision you can compare and roll back like any other.

Managing several sites

Install the template once per site — each server carries its own domain and its own application password — and if you want them all in your AI at one address, turn on the MCP Gateway: the tools arrive as blog__update_post, docs-site__update_post and so on, so the AI always knows which site it’s editing. WooCommerce works the same way, with its own template and store domain.

The template is in GetMCP 1.6.0 on both the WordPress plugin and the standalone app; details are on the changelog, and support is the fastest way to reach us if a tool doesn’t behave the way you expect.

InfiWebs
← All posts

Leave a reply

Try GetMCP

Ship MCP for your product, in days.

Install the plugin, import your API, share one URL. Your users will start calling your tools from Claude tonight.