Enable Abilities for MCP
Enable Abilities for MCP gives you full control over which WordPress Abilities are available to AI assistants through the MCP (Model Context Protocol) Adapter. WordPress 6.9 introduced the Abilities API, allowing external tools to discover and execute actions on your site. This plugin extends that functionality by registering a comprehensive set of content management abilities and providing a simple admin interface to toggle each one on or off. Connect from claude.ai with just a URL Since version 2.1 the plugin ships an embedded OAuth 2.1 server built for claude.ai custom connectors. Add your site in claude.ai → Settings → Connectors, log in with your WordPress user, approve the consent screen — connected. No Client ID, no Application Password, no local configuration. Works from the claude.ai web app, mobile apps, and Claude Desktop Each team member authenticates with their own WordPress account and role — a subscriber can never do what only an editor should Every ability execution lands in the activity log under the real user’s name Works on single sites, subdirectory installs, and multisite networks (network-activate so the main site serves the OAuth discovery documents for every subsite) Prefer tokens? Application Passwords (per-user) and a single-admin Bearer token connect Claude Desktop / Claude Code, OpenAI Codex CLI, and Google Antigravity — the Connection tab generates ready-to-paste configuration for each client, and fills in your credentials automatically. Features 91 abilities organized in 18 categories: Core, Read, Write, SEO (Rank Math), SEO (SEOPress), SEO (Yoast), Navigation Menus, Utility, Multilanguage, Custom Post Types, WooCommerce, The Events Calendar, Code Snippets, JetEngine Options Pages, Elementor, LearnDash, Tutor LMS, and AI Agent Readiness (llms.txt) WooCommerce integration — dedicated abilities to manage products, orders, and customers using the native WooCommerce API (HPOS-compatible, formally declared) The Events Calendar integration — list, get, create, and update events with venue, organizer, and date filters claude.ai OAuth custom connector — connect from claude.ai (web, mobile, or desktop) with zero local setup: an embedded OAuth 2.1 server with Client ID Metadata Document (CIMD) support lets each user log in with their own WordPress account and role Admin dashboard with toggle switches for each ability Per-ability control — expose only what you need Third-party ability control — abilities registered by other MCP-ready plugins (e.g. Fluent Forms) appear in the same dashboard, grouped by plugin, with the same per-ability toggles; disabling one removes it from every MCP server on the site Secure by design — proper capability checks, input sanitization, and per-post permission validation WPCS compliant — fully passes WordPress Coding Standards (phpcs) MCP-ready — all abilities include show_in_rest and mcp.public metadata Available Abilities Read (safe, query-only): Get posts with filters (status, category, tag, search) Get single post details (content, SEO meta, featured image) Get categories, tags, pages, comments, media, and users Write (create & modify): Create, update, and delete posts Create categories and tags Create pages Moderate comments Reply to comments as the authenticated user Upload images from external URLs to the media library (with optional auto-assign as featured image) Duplicate any post, page, or custom post type item — including all post meta (ACF, SEO, featured image) and taxonomy terms; saved as a draft by default SEO — Rank Math: Get full Rank Math metadata for any post/page (title, description, keywords, robots, Open Graph, SEO score) Update Rank Math metadata: SEO title, description, focus keyword, canonical URL, robots, Open Graph, primary category, pillar content SEO — SEOPress: Get full SEOPress metadata for any post/page (title, description, focus keyword, robots, canonical, Open Graph, Twitter Card) Update SEOPress metadata: SEO title, description, focus keyword, canonical URL, robots directives, Open Graph, Twitter Card SEO — Yoast SEO: Get full Yoast SEO metadata for any post/page (title, description, focus keyphrase, canonical, robots, Open Graph, Twitter Card) Update Yoast SEO metadata: SEO title, description, focus keyphrase, canonical URL, robots (noindex, nofollow, advanced), Open Graph, Twitter Card Get Yoast sitemap index — fetch and parse the sitemap index, returning all registered sitemap URLs with last modification date Custom Post Types: List all registered custom post types with configuration and taxonomies Get items from any CPT with filtering, search, and taxonomy queries Get full details of a CPT item including all meta fields (WooCommerce, ACF, JetEngine, etc.) Create, update, and delete CPT items with taxonomy and meta field support Get CPT taxonomies with their terms Assign taxonomy terms to CPT items WooCommerce: List products with price, SKU, stock status, categories, and type Get full product detail including gallery, attributes, and variations Update product price, sale price, stock quantity, and status List orders with customer, total, status, and date (HPOS-compatible) Get full order detail: line items, billing/shipping, totals, and notes Update order status with optional note List customers with email, name, total spent, and order count The Events Calendar: List events with start/end date, venue, organizer, and date range filter Get full event detail with resolved venue address and organizer contact Create new events with title, description, dates, venue, and organizer Update existing events Navigation Menus: List menus with item counts and theme locations, and get one menu’s full item hierarchy Create a new menu, and add pages, posts, categories, tags, or custom URLs as items (with parent and position) Update an item’s title, URL, parent, or position Remove an item, assign a menu to a theme location, or delete a menu entirely (opt-in — destructive) Tutor LMS: Read a lesson’s video source configuration (type, value, and runtime) Set a lesson’s video source (external URL, YouTube, Vimeo, HTML5, or a third-party source such as Bunny.net) using Tutor’s own storage function — avoids the string-only limitation of the generic Update Post Meta ability, which Tutor cannot read back List courses, and get a single course’s full detail with its topics/lessons hierarchy Get a user’s enrollment status and completion progress for a course Get a user’s quiz attempt results, optionally filtered to a single quiz Enroll a user in a course, and unenroll them (both opt-in, manage_options only) Utility: Search and replace text in post content Site statistics overview (includes custom post type counts) Update any post meta field by exact key (with protected internal key blocklist) Requirements WordPress 6.9 or later (Abilities API) MCP Adapter plugin installed and configured PHP 8.0 or later
Top keywords
- seo15×1.44%
- post14×1.34%
- update12×1.15%
- abilities10×0.96%
- full10×0.96%
- claude9×0.86%
- ai8×0.77%
- custom8×0.77%
- list8×0.77%
- metadata8×0.77%
- title8×0.77%
- description7×0.67%
SmartCloud Flow – Block‑based Forms & Workflow Automation
SmartCloud Flow is a block-based forms and workflow plugin for WordPress. It combines a modern Gutenberg editor experience with a React/Mantine runtime for forms, a native -based light-DOM modal block, and an optional AWS backend, so site owners can design forms and supporting UI in WordPress while choosing where submissions should be posted and, in Pro, running submissions, templates, workflows, and integrations in their own AWS account. Flow is part of the WP Suite product family by Smart Cloud Solutions, Inc. WP Suite keeps WordPress as the CMS and editing layer, while optional connected features can extend selected workflows into modular AWS-backed services for identity, AI, APIs, workflows, protected routes, and static delivery. The free Flow features described here do not require a WP Suite account, subscription, or AWS backend unless you explicitly configure an external service or upgrade-only backend feature. Free mode Flow does not require a hosted SaaS backend or a WP Suite connection to render forms. In Free mode, each form can post directly from the browser to a URL you define per form. That endpoint may be: your own custom endpoint, a WordPress-side endpoint you implement yourself, or the Flow backend submission endpoint, if you later deploy it. Pro mode Pro becomes available after connecting your WordPress site to a WP Suite workspace. It is designed to work especially well with the separately deployed WP Suite Flow Backend in your own AWS account. A typical Pro setup is: deploy the Flow backend to AWS, add the published backend API base URL to Gatey as a separate API, choose the desired protection mode for that API (IAM or COGNITO, matching the backend deployment), then select that API in SmartCloud → Flow Settings → API Settings. This lets Flow use Gatey-aware authenticated API access, while keeping the backend in your own AWS account. Key features Gutenberg form builder — Build forms with a dedicated Form block, layout/container blocks, and rich field blocks. Single React runtime per form — Front-end forms run as one mounted React tree. Light-DOM modal block — Wrap any Gutenberg content in a native dialog with class and data-attribute triggers, hash opening, default header/body/actions slots, action-role aware buttons, and a stable browser API on WpSuite.plugins.flow.modals. Light-DOM gallery block — Build a Mantine-free gallery/lightbox from core Image blocks with previous/next controls, optional thumbnails, optional captions/counter, and modal-aware start positions driven by outer trigger classes. Rich display & content blocks — Use styled content primitives such as blockquotes, marks, badges, code blocks, spoilers, lists, tables, timelines, and overflow lists alongside inputs. API-backed options & request controls — Load select, radio, checkbox-group, and tags options from API/autocomplete endpoints with configurable methods, headers, parameters, selected-value mapping, and runtime interpolation. Conditional logic & validation — Show/hide, enable/disable, require/optional, and other rule-based field behavior. Theme overrides & design tokens — Theme both interactive controls and display/content blocks inside the Shadow DOM with Mantine variables and stable --flow-* CSS tokens. Shortcodes & Elementor support — Reuse forms or content roots via shortcode and Elementor integrations. Flexible submission target model — Submit directly from the browser to a per-form endpoint URL with configurable HTTP methods, optional request headers, and runtime interpolation. Runtime events & host-page integration — Listen for submit, draft, wizard, modal, and API-loading error events from outer-page JavaScript. Pro: backend-aware operation — Connect Flow to the AWS-hosted Flow backend for durable submissions, admin tooling, templates, workflows, and webhook-driven automation. Pro: backend form sync — Optionally sync Gutenberg-defined forms into canonical backend form definitions stored in AWS. Pro: admin application — Manage submissions, templates, workflows, and backend/API settings from WordPress admin. Pro: workflow automation — Event-driven automation for emails, webhooks, status changes, and related operational flows. Pro: security & ownership — Deploy into your own AWS account and choose auth modes such as IAM or COGNITO. You can find continuously expanding documentation at: https://wpsuite.io/docs/ This plugin is not affiliated with or endorsed by Amazon Web Services or the WordPress Foundation. All trademarks are property of their respective owners. Free and Pro Usage Notice Flow works in Free mode without registration or subscription. In Free mode: forms are rendered in the browser, submissions are posted directly to the endpoint URL configured for the form, no WP Suite connection is required. Flow does not inherently store submissions in WordPress. If you want submissions handled inside WordPress, you need to implement and expose your own receiving endpoint there. Pro features are optional and become available after connecting your WordPress site to a WP Suite workspace. The main Pro scenario is to use the separately deployed WP Suite Flow Backend in your own AWS account. In that setup: you publish the backend API, register that API in Gatey, choose its protection mode (IAM or COGNITO), and select that API in SmartCloud → Flow Settings → API Settings. This simplifies secure communication between the WordPress-side Flow plugin and the AWS-hosted backend. Machine-readable resources Plugin manifest: https://wpsuite.io/.well-known/ai-plugin.json OpenAPI spec (backend): https://wpsuite.io/.well-known/openapi.yaml External Services This plugin may integrate with the following external services, depending on configuration: Google reCAPTCHA v3 (optional) What it is & what it’s used for: Client-side bot detection. If enabled, Flow can request reCAPTCHA tokens in the browser to protect submissions. What data is sent & when: The browser may contact Google to retrieve a token. That token may then be included in submission requests. How to configure: Enter your reCAPTCHA site key/secret in the relevant Flow or shared WP Suite settings. Links: About reCAPTCHA: https://www.google.com/recaptcha/about/ Google Terms: https://policies.google.com/terms Google Privacy: https://policies.google.com/privacy Customer-configured submission endpoint / Flow backend endpoint What it is & what it’s used for: The endpoint URL configured for a form submission. In Free mode this may be any URL you control. In Pro, it is commonly the AWS-hosted Flow backend. What data is sent & when: Form field values and, depending on your implementation, related submission metadata. For Pro backend flows, uploaded file references, template variables, and workflow/event metadata may also be sent. Where it goes: Requests are sent directly from the browser to the configured endpoint URL, either through direct fetch calls or, in Pro, through a Gatey-integrated authenticated API flow. How it’s called: Standard HTTPS requests. Authentication depends on your configuration and may be none, IAM, or Cognito-based. WP Suite platform connection (optional; workspace linking and shared features) When it applies: When you connect the site to a WP Suite workspace to enable Pro features and shared admin capabilities. What it’s used for: Workspace linking, shared admin capabilities, license/subscription handling, and related WP Suite platform features. What data may be sent: Minimal site/workspace identifiers and authentication/session data required for linking and management. Where it goes: Secure HTTPS requests to WPSuite.io services such as wpsuite.io and api.wpsuite.io. Links: WPSuite.io Privacy Policy: https://wpsuite.io/privacy-policy WPSuite.io Terms of Use: https://wpsuite.io/terms-of-use Amazon Cognito (optional; authentication for protected APIs) When it applies: When your Flow backend API or related WP Suite services are protected with Cognito and the site uses Cognito-based authentication. What it’s used for: User authentication and token-based authorization for protected API calls. Links: AWS Service Terms: https://aws.amazon.com/service-terms/ AWS Privacy: https://aws.amazon.com/privacy/ Stripe (optional; subscription/purchase flow) When it applies: Only when the user opens the optional WP Suite subscription / purchase flow in the shared admin component. What it’s used for: Displaying hosted pricing/subscription UI for optional paid features. What data may be sent: Browser/session data required by Stripe to render the hosted purchase UI and process the purchase flow. Links: Terms: https://stripe.com/legal/consumer Privacy: https://stripe.com/privacy Trademark Notice Amazon Web Services, AWS, Amazon EventBridge, Amazon DynamoDB, Amazon SES, and Amazon Cognito are trademarks of Amazon.com, Inc. or its affiliates. Google reCAPTCHA is a trademark of Google LLC. WordPress is a trademark of the WordPress Foundation. SmartCloud Flow is an independent project and is not affiliated with, sponsored by, or endorsed by Amazon Web Services, Google, or the WordPress Foundation. Source & Build Public (free) source code: All code that ships in the public (free) version of Flow is available here: https://github.com/smartcloudsol/flow Build & distribution: Flow is shipped to WordPress.org as a pre-built distribution. Build steps and developer notes are maintained in the GitHub repository documentation. Shared WP Suite components: Some admin UI modules may originate from shared WP Suite components to support workspace linking, license validation, and subscription management across WP Suite plugins. Pro-only features (source availability): Flow Pro includes additional functionality such as backend-powered submissions management, templates, workflows, and webhook dispatching. The code that enables these paid features is distributed to Pro users but is not published in the public repository.