---
title: Connect AI assistants to your WordPress site with the SEOPress MCP server
url: "https://www.seopress.org/support/guides/seopress-mcp-server/"
lang: en-US
updated: 2026-09-30
---

# Connect AI assistants to your WordPress site with the SEOPress MCP server

Since version 10.3, SEOPress includes a built-in MCP server. **MCP** (Model Context Protocol) is the open standard AI assistants use to talk to external tools. Once your site is connected, Claude, ChatGPT, Cursor or any other MCP client can read and manage your SEO data directly from a conversation: titles, meta descriptions, robots directives, social metadata, content analysis, redirections, structured data and more.

The MCP server ships in SEOPress Free. SEOPress PRO adds its own tools on top. There is no extra plugin to install, no third-party service in the middle, and no API key to pay for: the AI client talks directly to your site.

## What you can do with it

A few prompts you can type in your AI client once the site is connected:

- “List the pages that have no meta description and write one for each of them.”
- “Which posts are set to noindex? Tell me if any of them looks like a mistake.”
- “Run the content analysis on post 123 for the keyword ‘wordpress seo’ and tell me what to fix.”
- “Rewrite the SEO titles of my 10 latest posts so they stay under 60 characters.”
- “Create a 301 redirection from /old-page/ to /new-page/.” (SEOPress PRO)
- “Run the technical audit of the site and summarize the issues by priority.” (SEOPress PRO)

The assistant picks the right tools by itself. You stay in control of what it is allowed to do, as explained below.

## Requirements

- SEOPress 10.3 or later (SEOPress PRO 10.3 or later for the PRO tools).
- WordPress 6.9 or later. The MCP server is built on the [WordPress Abilities API](https://www.seopress.org/support/guides/seopress-abilities/), which ships with WordPress 6.9.
- A site served over HTTPS. Clients that run in the cloud (claude.ai, ChatGPT) need a public HTTPS address to reach your site.
- A WordPress user account with the capabilities matching what you want the assistant to do.

Local sites (`localhost`, `127.0.0.1`, `*.localhost`) work without HTTPS with the clients that run on your own machine: Claude Code, the Claude desktop app and Cursor. claude.ai and ChatGPT run on their own servers and cannot see a local site.

## Step 1: enable the MCP server

The MCP server is off by default. Nothing is exposed until you turn it on.

1. Go to **SEO > Advanced**, **Advanced** tab.
2. In the **Abilities API** section, turn on **Expose abilities to AI agents and external tools**.
3. Click **Save changes**.
4. Open the **MCP** tab of the same page.

The MCP tab shows everything you need: the state of the connection, the readiness checks, the MCP server URL, the instructions for each client, the connected clients and the list of tools.

Your MCP server URL looks like this:

```
https://example.com/wp-json/seopress/mcp/v1
```

If your permalinks are set to Plain, the URL uses the query string form (`https://example.com/?rest_route=/seopress/mcp/v1`). It works too: copy it exactly as the MCP tab shows it.

## Step 2: connect your AI client

Every client signs in over OAuth. You paste the URL, your browser opens your own site, you log in to WordPress and approve the connection. There is no password or API key to create or to copy.

### Claude (claude.ai, desktop app, Claude Code)

**claude.ai and the desktop app**

1. Open **Settings > Connectors**, then **Add custom connector**.
2. Paste your MCP server URL. Leave every other field empty.
3. Your browser is sent to your site. Log in to WordPress if needed, then approve the connection.

**Claude Code**

Run the command shown in the MCP tab. It looks like this:

```
claude mcp add --transport http --scope user SEOPress "https://example.com/wp-json/seopress/mcp/v1"
```

Then run `/mcp` in Claude Code to sign in.

### ChatGPT

1. In ChatGPT, open the settings screen that lists your connectors (**Settings > Integrations > Plugins > Add** in the app), and choose **Add MCP server**. Custom MCP servers require developer mode to be enabled in ChatGPT.
2. Give it a name, choose the **Streamable HTTP** type, and paste your MCP server URL. Leave the bearer token and header fields empty.
3. Click **Authenticate** next to the server, log in to your site and approve the connection.

### Cursor

1. Open or create `.cursor/mcp.json` (this project only) or `~/.cursor/mcp.json` (every project).
2. Add the SEOPress server. If the file already has an `mcpServers` object, add the `SEOPress` entry inside it:

```
{
    "mcpServers": {
        "SEOPress": {
            "type": "http",
            "url": "https://example.com/wp-json/seopress/mcp/v1"
        }
    }
}
```

1. Restart Cursor, open **Settings > Customize > MCPs**, click **Authenticate** next to SEOPress and approve the connection.

### Other MCP clients

Any client that supports the Streamable HTTP transport can connect. If it supports OAuth, give it the MCP server URL and it will find the sign-in page by itself.

If it does not, you can authenticate with a WordPress [Application Password](https://wordpress.org/documentation/article/application-passwords/) sent in a Basic `Authorization` header:

```
{
    "mcpServers": {
        "SEOPress": {
            "type": "http",
            "url": "https://example.com/wp-json/seopress/mcp/v1",
            "headers": {
                "Authorization": "Basic BASE64_OF_USERNAME_COLON_APPLICATION_PASSWORD"
            }
        }
    }
}
```

On a site where OAuth cannot run, the MCP tab offers this method directly: it creates the Application Password for you and writes it into the configuration to copy. The password is shown once and SEOPress never stores it.

### The approval screen: read only, or read and change

When a client connects over OAuth, your site displays an approval screen. It shows which client is asking, which WordPress account it will act as, and the list of tools it will get. You then choose what the connection may do:

- **Read and change**: every tool is available.
- **Read only**: only the tools that read data are served. The tools that change data are not shown to this connection, and are refused if the client asks for one by name.

Click **Allow this connection** to finish, or **Refuse** to cancel.

The client chooses its own name when it registers, and nothing can verify it. Only approve a connection you have just started yourself.

## Step 3: check that it works

Ask your assistant which tools it has. It should list the tools shown in the **Exposed tools** section of the MCP tab.

If nothing appears, open the **Diagnostics** panel at the top of the MCP tab and click **Run the readiness checks**. Every line that is not green says what to change on your site.

## Available tools

Tool names are prefixed with `seopress__`. For instance, the ability `seopress/get-post-title-description` is served as the tool `seopress__get-post-title-description`.

### SEOPress Free

| Tool | What it does | Access | Who can use it |
| --- | --- | --- | --- |
| `get-post-title-description` | Reads the custom SEO title and meta description of a post | Reads only | Users who can edit the post |
| `update-post-title-description` | Sets or clears the SEO title and meta description of a post | Can change data | Users who can edit the post |
| `get-post-robots-settings` | Reads the robots directives of a post (noindex, nofollow, canonical URL, primary category…) | Reads only | Users who can edit the post |
| `update-post-robots-settings` | Updates the robots directives of a post | Can change data | Users who can edit the post |
| `get-post-social-settings` | Reads the Facebook/Open Graph and X/Twitter metadata of a post | Reads only | Users who can edit the post |
| `update-post-social-settings` | Updates the Facebook/Open Graph and X/Twitter metadata of a post | Can change data | Users who can edit the post |
| `analyze-post-content` | Runs the content analysis on a post and returns the score, checks and recommendations | Reads only | Users who can edit the post |
| `list-posts-missing-metadata` | Lists the posts with no custom SEO title and/or meta description | Reads only | Users who can edit posts |
| `list-posts-by-content-score` | Lists posts with the verdict of their last content analysis | Reads only | Users who can edit posts |
| `list-posts-noindexed` | Lists the posts carrying an explicit noindex directive | Reads only | Users who can edit posts |
| `get-global-titles-settings` | Reads the site-wide title and meta description templates | Reads only | Users who can manage the Titles & Metas settings |
| `get-sitemap-settings` | Reads the XML and HTML sitemap configuration | Reads only | Users who can manage the XML / HTML Sitemap settings |
| `get-instant-indexing-settings` | Reads the Instant Indexing configuration and submission log. API keys are never returned | Reads only | Users who can manage the Instant Indexing settings |
| `get-global-social-settings` | Reads the Knowledge Graph and default social settings | Reads only | Users who can manage the Social Networks settings |

### SEOPress PRO

| Tool | What it does | Access | Who can use it |
| --- | --- | --- | --- |
| `list-redirections` | Lists the redirections and detected 404s, with pagination, search and filters | Reads only | Users who can read redirections |
| `get-redirection` | Reads a single redirection | Reads only | Users who can read redirections |
| `create-redirection` | Creates a redirection from an origin URL to a target URL | Can change data | Users who can publish redirections |
| `update-redirection` | Updates an existing redirection | Can change data | Users who can edit the redirection |
| `delete-redirection` | Permanently deletes a redirection | Can change data | Users who can delete the redirection |
| `get-post-schemas` | Reads the manual structured data (schema.org) of a post | Reads only | Users who can edit the post |
| `update-post-schemas` | Replaces the manual structured data of a post | Can change data | Users who can edit the post |
| `update-target-keywords` | Updates the target keywords of a post | Can change data | Users who can edit the post |
| `generate-seo-title` | Generates an SEO title suggestion with AI. The suggestion is not saved | Reads only | Users who can edit the post |
| `generate-meta-description` | Generates a meta description suggestion with AI. The suggestion is not saved | Reads only | Users who can edit the post |
| `generate-alt-text` | Generates an alt text and a caption for an image with AI. The suggestion is not saved | Reads only | Users who can edit the image |
| `upload-image` | Downloads an image from a URL and adds it to the Media Library | Can change data | Users who can upload files |
| `get-technical-audit` | Runs the site-wide technical checks and returns a structured checklist | Reads only | Users who can manage the audit tools of SEOPress PRO |

Settings and audit tools are reserved for administrators by default. The three `generate-*` tools use the AI provider configured in SEOPress PRO.

## Security and permissions

The MCP server is designed so that connecting an AI client never gives it more power than you already have.

- **Off by default.** The endpoint refuses every request until you turn exposure on.
- **Your own permissions, never more.** A connection acts as the WordPress account that approved it. Each tool call goes through the same capability checks as the WordPress admin. An Editor connected over MCP cannot read SEOPress settings reserved for administrators, and an Author cannot edit somebody else’s posts.
- **Read only connections.** Chosen on the approval screen, enforced by the server for the whole life of the connection.
- **SEOPress tools only.** The server only serves SEOPress abilities. Abilities registered by other plugins are held back unless you opt in.
- **Tool by tool control.** You can switch off any tool for the whole site.
- **No secret leaves your site.** API keys stored in SEOPress settings are never returned by a tool. Application Passwords created from the MCP tab go from WordPress to your browser and are never stored or logged by SEOPress.
- **Standard OAuth 2.1.** Sign-in uses PKCE, dynamic client registration and tokens bound to your site address. Access tokens last one hour and are renewed automatically. A connection that has not been used for 30 days has to sign in again.
- **Revocable at any time.** One click in the MCP tab cuts a client off immediately.

Tools that change data save to your live site, exactly as if you had edited the post yourself. Ask your assistant to show you what it plans to change before it does, and use a read only connection when you only need an audit.

## Managing the connection

### Connected clients

The **Connected clients** section of the MCP tab lists every client that holds a token for your account: its name, what it was approved for (reading only, or reading and changing), when it was connected and when it was last used. Click **Revoke** to cut one off. The effect is immediate.

Each user only sees and revokes their own connections. One account can hold up to 25 connections.

If you change your site address, the connections issued for the old address are marked **No longer valid**. Revoke them and connect again.

### Choosing which tools are served

The **Exposed tools** section lists every tool with its access level. Use the **Served** toggle at the end of a row to switch a tool off, then save. A tool that is switched off is no longer listed to any client and cannot be called, whatever the permissions of the user.

This is useful to keep a sensitive tool to yourself, for example `delete-redirection`.

### Abilities from other plugins

Other plugins can register their own abilities in WordPress. By default, the SEOPress MCP server does not serve them, so that turning on your SEO tools never hands an AI client another plugin’s tools by accident.

To serve them as well, turn on **Also serve abilities registered by other plugins** in the **Exposed tools** section. Before you save, the MCP tab lists the tools this would add. Read the list: some of them may change or delete data.

## Troubleshooting

The **Diagnostics** panel runs nine checks and tells you what to fix for each one that fails.

| Check | If it fails |
| --- | --- |
| WordPress Abilities API | Update WordPress to 6.9 or later. |
| Abilities exposed to external clients | Turn on **Expose abilities to AI agents and external tools** in the Advanced tab and save. |
| MCP route registered | Another plugin is removing routes from the WordPress REST API. Allow the `/seopress/mcp/v1` route. |
| MCP endpoint answering | A security plugin, a firewall or a CDN is blocking the request, or your host blocks loopback requests. Allow POST requests to the MCP server URL. |
| Application Passwords | Only needed for clients that do not sign in over OAuth. WordPress offers them over HTTPS only, and a security plugin can switch them off. |
| HTTPS | Install a TLS certificate and switch the WordPress Address and Site Address to `https`. |
| Permalinks | A warning only: the URL works in its query string form. Choose any structure other than Plain for a shorter URL. |
| OAuth for browser clients | OAuth needs HTTPS (or a local site). |
| OAuth discovery document | Your server does not route `/.well-known/` requests to WordPress. Choose a permalink structure other than Plain. If WordPress is installed in a subdirectory, add a rule that forwards `/.well-known/` requests to it. |

Other common situations:

- **The client connects but lists no tool.** Check the **Exposed tools** section, and that your WordPress account has the required capabilities.
- **“This connection was approved for reading only”.** The connection was approved as read only. Remove it in your client, connect again and choose **Read and change**.
- **“You do not have permission to use this tool”.** Your WordPress account does not have the capability the tool requires.
- **The connector fails on the first attempt.** Open the two addresses listed under **Discovery documents** in the **Connected clients** section. Both must answer with JSON. If they do not, a security plugin, a cache or a server rule is in the way.
- **A caching or security layer in front of the site.** Exclude `/wp-json/seopress/mcp/` and `/.well-known/oauth-*` from page caching, and do not strip the `Authorization` header.

## For developers

The server implements the MCP Streamable HTTP transport on a single REST route (`POST /wp-json/seopress/mcp/v1`) and supports the protocol revisions `2025-06-18`, `2025-03-26` and `2024-11-05`. It exposes tools only (no resources, no prompts).

Every tool is a WordPress ability registered with `wp_register_ability()` in the `seopress` namespace. The following filters let you adjust the behavior:

| Filter | Purpose |
| --- | --- |
| `seopress_abilities_api_rest_enabled` | Force exposure on or off, whatever the setting says. |
| `seopress_mcp_read_only` | Force every connection to read only. |
| `seopress_mcp_disabled_abilities` | Switch abilities off by name. |
| `seopress_mcp_served_abilities` | Last word on the list of abilities served to clients. |
| `seopress_mcp_exposed_namespaces` | Add ability namespaces to serve besides `seopress`. |
| `seopress_mcp_foreign_namespaces_enabled` | Serve, or not, the abilities of every other plugin. |
| `seopress_mcp_allowed_origins` | Origins allowed to reach the endpoint from a browser. |
| `seopress_mcp_oauth_enabled` | Switch the OAuth server off. |
| `seopress_mcp_oauth_transport_is_secure` | Tell the OAuth server the site is served securely, for instance behind a TLS terminating proxy. |

Example: make every MCP connection read only on a production site.

```
add_filter( 'seopress_mcp_read_only', '__return_true' );
```

Example: serve the abilities of your own plugin alongside SEOPress.

```
add_filter( 'seopress_mcp_exposed_namespaces', function ( $namespaces ) {
    $namespaces[] = 'my-plugin';

    return $namespaces;
} );
```

## FAQ

**Is the MCP server available in SEOPress Free?** Yes. The server and 14 tools ship in SEOPress Free. SEOPress PRO adds 13 tools (redirections, structured data, target keywords, AI generation, image upload, technical audit).

**Does SEOPress send my content to an AI provider?** No. SEOPress only answers the requests of the AI client you connected. What your client does with the answers depends on that client and its provider.

**Do I need an OpenAI or Anthropic API key?** No. You use the subscription of your AI client. Only the three `generate-*` tools of SEOPress PRO rely on the AI provider configured in SEOPress PRO.

**Can several users connect their own client?** Yes. Each connection is tied to the WordPress account that approved it and is limited to that account’s permissions.

**Does it work on a multisite network?** Each site of the network has its own MCP server URL and its own setting.

**How do I turn everything off?** Turn off **Expose abilities to AI agents and external tools** and save. The endpoint and the OAuth server stop answering immediately.
