WordPress.com for AI agents

WordPress.com manages hosted WordPress sites, content, and Jetpack-connected features, used by publishers and small businesses running a WordPress site. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Files and storageOAuth 2.0MCP + RESTwordpress.com
AUDIT LOG · WORDPRESS.COMPOLICY: acme-support
09:41:07 · claude · u_8f2read
wordpress_com.list_sites
List Sites✓ allowed · 212ms
09:41:08 · claude · u_8f2read
wordpress_com.get_post
Get Post✓ allowed · 164ms
09:41:09 · claude · u_8f2write
wordpress_com.create_draft_post
Create Draft Post✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
wordpress_com.delete_draft_post
Delete Draft Post✕ blocked · policy: deny
EVERY WORDPRESS.COM CALL, ON THE RECORD
01 · USE CASES

What agents do in WordPress.com.

01

Create a draft post

Start a new draft post with a title and body for later review and publishing.

02

Get site statistics

Pull traffic and engagement stats for a site, a read-only overview.

03

Confirm before deleting a draft

Check with the user before deleting a draft post, since unpublished work would be lost.

02 · ACTIONS

10 WordPress.com actions, graded by risk.

Every WordPress.com action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

7

Look things up. Allowed by default.

  • wordpress_com.get_post
    Get Post
  • wordpress_com.list_sites
    List Sites
  • wordpress_com.list_content
    List Content
  • wordpress_com.get_site_overview
    Get Site Overview
  • wordpress_com.list_cms_resources
    List CMS Resources
  • wordpress_com.list_blogging_prompts
    List Blogging Prompts
  • wordpress_com.list_reader_subscriptions
    List Reader Subscriptions

write

2

Create and change things. Allow, or ask the user first.

  • wordpress_com.create_draft_post
    Create Draft Post
  • wordpress_com.update_draft_post
    Update Draft Post

destructive

1

Delete, cancel or archive. Ask first, or deny outright.

  • wordpress_com.delete_draft_post
    Delete Draft Post
03 · HOW IT WORKS

WordPress.com in three steps.

  1. 01Your users connect WordPress.comThey sign in to WordPress.com on Arc0 Connect, under your brand, and approve the access you ask for.
  2. 02You set the rulesReads run, writes like “create Draft Post” can wait for the user, and “delete Draft Post” can be denied outright.
  3. 03Any agent can actYour agent calls WordPress.com through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('wordpress_com', {
  read: 'allow',
  write: 'ask',        // create_draft_post
  destructive: 'deny',  // delete_draft_post
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How WordPress.com connects.

Users sign in to WordPress.com on Arc0 Connect and approve the scopes you request. Build with Arc0’s WordPress.com OAuth app, or bring your own so the WordPress.com consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

The same WordPress.com connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
OAuth 2.0
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use WordPress.com from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

WordPress.com and Arc0, answered.

Q01

Can I use WordPress.com with Claude, ChatGPT or Cursor?

Yes. Connect WordPress.com to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the WordPress.com actions you allow.

Q02

How do users connect WordPress.com?

Users sign in to WordPress.com on Arc0 Connect and approve the scopes you request. Build with Arc0’s WordPress.com OAuth app, or bring your own so the WordPress.com consent screen names you. Tokens refresh automatically, and you can export them whenever you want.

Q03

Which WordPress.com actions can my agent take?

10 in total: 7 read, 2 write and 1 destructive, such as “create Draft Post”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in WordPress.com?

Yes. Actions like “delete Draft Post” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call WordPress.com too?

Yes. The same WordPress.com connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug WordPress.com into your agent.

Your users connect WordPress.com once, under your brand. Your agent gets 10 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan