Skip to content

Prepare your site for MCP

AI clients talk to WordPress over MCP. Before connecting a client, pick an MCP server on your site and create the credentials your agent will use. Raqvio Agent Guardrails governs both servers below.

WooCommerce MCP MCP Adapter plugin
Server Built into WooCommerce (experimental feature) The MCP Adapter plugin
Endpoint https://your-store.example/wp-json/woocommerce/mcp https://your-store.example/wp-json/mcp/mcp-adapter-default-server
Credentials WooCommerce REST API key, sent as the X-MCP-API-Key: ck_…:cs_… header WordPress application password (HTTP Basic authentication)
Bind the Raqvio Agent Guardrails agent to the WordPress user who owns the key the application password
Tools Products (list, get, create, update, delete) and orders (list, get, create, update), plus Raqvio Agent Guardrails’s get-my-permissions and get-approval-status Discover / get info / execute any ability exposed to MCP — including raqvio-ag/order-create-refund

Both servers require HTTPS, and the site must be reachable from the computer (or service) running the AI client.

Then follow the guide for your client: Claude Desktop, Claude Code, Cursor or ChatGPT.

  1. Enable WooCommerce MCP: WooCommerce → Settings → Advanced → Features, enable WooCommerce MCP (an experimental feature), and save.
  2. Create a user for the agent with the capabilities it needs — for example Shop Manager. Raqvio Agent Guardrails then limits what it may do.
  3. Create an API key: WooCommerce → Settings → Advanced → REST API → Add key. Pick that user, set Permissions to Read (or Read/Write if the agent should change anything), and generate. Copy the consumer key (ck_…) and secret (cs_…) — they’re shown once. Your MCP key is the two joined by a colon: ck_…:cs_….
  4. Add the agent in Raqvio Agent Guardrails: Agent Guardrails → Agents → Add agent, Identity: Any request made by a dedicated WordPress user, pick the user, keep Deny unlisted abilities (recommended), and save. Open Permissions: the WooCommerce MCP tools are listed as woocommerce/products-list, woocommerce/products-update, woocommerce/orders-get and so on. Allow what the agent needs.

The key’s scope is enforced by WooCommerce on top of Raqvio Agent Guardrails: a read-only key can’t write even if Raqvio Agent Guardrails allows it.

Option B — MCP Adapter plugin (application password)

Section titled “Option B — MCP Adapter plugin (application password)”
  1. Install the MCP Adapter plugin (download it from its GitHub releases) and activate it.
  2. Create a user for the agent with the capabilities it needs, then an application password for it (Users → Edit user → Application Passwords). Copy the password — WordPress shows it once.
  3. Add the agent in Raqvio Agent Guardrails: Agent Guardrails → Agents → Add agent, Identity: A specific application password (recommended), pick the user and password, and set permissions.

The agent gets three tools — mcp-adapter-discover-abilities, mcp-adapter-get-ability-info and mcp-adapter-execute-ability — and each ability run through execute-ability is governed on its own.

Clients that connect directly over HTTP send the application password as an Authorization: Basic … header, where … is the Base64 encoding of user-name:application-password. On macOS or Linux:

Terminal window
printf '%s' 'agent-user:abcd efgh ijkl mnop qrst uvwx' | base64

Whichever client you use:

  1. Ask the agent to list a few products.
  2. Open Agent Guardrails → Audit Log: the call appears under your agent’s name, channel mcp, decision Allowed.
  3. Ask for something you denied: the agent receives “Blocked by Raqvio Agent Guardrails: …” and the audit log shows Denied.
  4. With Pro and an approval rule, ask for a large change: it appears in Approvals, and the agent is told the approval id.

If the agent shows as “Unknown agent”, the credential it uses isn’t bound to your agent — see How agents are identified.

API keys and application passwords give the agent the WordPress user’s access. Keep them out of shared or version-controlled files, give each agent its own user and credential, and revoke the credential (the WooCommerce key or the application password) when you stop using it — Raqvio Agent Guardrails then pauses the agent.