Skip to content

The bridge (npm package)

@ballesdev/wp-realmcp is the program your AI client starts. It talks to the client over stdin/stdout and forwards every message to your site over HTTPS with your Application Password. It has no dependencies and needs Node.js 22 or later.

All settings are environment variables. The names match Automattic’s mcp-wordpress-remote, so switching only means changing the package name.

Variable Required Description
WP_API_URL Yes Your site URL (https://example.com, or https://example.com/blog for a site in a subdirectory) or the full endpoint (https://example.com/wp-json/ballesdev/mcp). A site URL becomes ?rest_route=/ballesdev/mcp, which works with any permalink setting; its query string is kept.
WP_API_USERNAME Yes* WordPress username.
WP_API_PASSWORD Yes* Application Password, with or without spaces. On a command line, quote it if it has spaces.
CUSTOM_HEADERS No Extra HTTP headers, as JSON ({"X-Name":"value"}) or as Name:Value pairs separated by commas.
WP_API_TIMEOUT_MS No Maximum time per request, in milliseconds. Default: 120000.
WP_ALLOW_INSECURE_HTTP No Set to 1 to send credentials over plain http:// to a site that isn’t local. Without it, the bridge refuses.
LOG_FILE No File for a detailed log: each method, its HTTP status and how long it took.

* Leave both out only if CUSTOM_HEADERS carries an Authorization header.

  • It never logs credentials or message contents, and stdout carries only MCP messages.
  • It doesn’t follow redirects: a redirect would turn the request into a GET or drop the password. Point WP_API_URL at your site’s final address.
  • localhost, loopback addresses and .local, .localhost and .test domains count as local, so plain HTTP works there without WP_ALLOW_INSECURE_HTTP.
  • Errors come back to the client as MCP errors that say what to fix, and also go to stderr, which clients save in their MCP logs.
  • When the client closes stdin, the bridge waits for requests still in flight and exits.