Skip to content

For developers

The capability required to use the MCP server and its tools. Default: edit_pages. You can make access stricter, for example manage_options; the page tools still need edit_pages, because WordPress’s pages endpoint requires it.

add_filter( 'ballesdev_mcp_capability', fn() => 'manage_options' );

The origins allowed in the Origin header. Default: the origins of home_url() and site_url().

add_filter( 'ballesdev_mcp_allowed_origins', function ( array $origins ) {
$origins[] = 'https://admin.example.com';
return $origins;
} );

The instructions sent to MCP clients in initialize and server/discover.

The tools are registered with the WordPress Abilities API as ballesdev/<tool> (for example ballesdev/get-page) in the ballesdev-mcp category, with meta.mcp.public set, so the MCP Adapter plugin can expose them too. Disabled tools fail their permission check and aren’t marked public.

What Where
Settings (disabled tools, retention days) Option ballesdev_mcp
Activity log Table {prefix}ballesdev_mcp_log
Daily log cleanup Cron event ballesdev_mcp_purge_log

Uninstalling the plugin deletes all of it (on multisite, on every site).