// HOW IT WORKS
Tell Claude what you need. It talks to WordPress for you. Cowboy MCP connects your AI agent directly to your site — no code, no dashboard clicking, just plain English.
// GET STARTED
Install the plugin
Install Cowboy MCP from the WordPress plugin directory. Activate it, then go to Settings → Cowboy MCP and generate an API key.
Connect your AI agent
Add your site as an MCP server in your AI tool of choice. Use the endpoint URL and API key from step 1. Pick your tool below for the exact config.
Start talking to your site
That's it. Your AI agent can now manage posts, plugins, users, WooCommerce, and more — just by asking in plain English.
// CAPABILITIES
Full control over your WordPress site through plain English. 157 tools across 9 integrations.
Content Management
Create, edit, schedule, and bulk-manage posts and pages. Upload media, assign categories and tags, set featured images, manage revisions.
Site Administration
Update plugins and themes, manage user roles and permissions, configure site settings, and run maintenance tasks across your entire installation.
Page Building
Build with the block editor or Elementor. Manage reusable blocks, templates, global widgets, theme styles, and page layouts.
SEO
Optimize your site with Yoast SEO integration. Manage meta tags, generate sitemaps, configure redirects, and fine-tune schema markup.
Custom Fields
Full ACF integration. Manage field groups, read and write custom field values, configure options pages, and work with repeaters and flexible content.
E-Commerce
Manage your entire WooCommerce store. Create products, process orders, generate coupons, track inventory, and handle customer data.
Forms
Build and manage Gravity Forms, review submitted entries, configure email notifications, and set up confirmations.
Performance
Purge caches, trigger preloading, manage CDN integration, and keep your site fast — without touching the dashboard.
Security
Run Wordfence scans, manage firewall rules, review blocked IPs, monitor live traffic, and respond to security alerts — all hands-free.
Backups
Trigger UpdraftPlus backups on demand, schedule recurring backups, restore from any point, and manage remote storage destinations.
// SAFETY & SECURITY
Your site stays locked down. Every operation is guarded.
Destructive operations (delete, update) require explicit confirmation. No accidental nuking.
Preview what any tool will do before it does it. See the blast radius before you pull the trigger.
Every MCP action is logged with timestamp, user, tool, and parameters. Full accountability trail.
120 requests per minute by default. Configurable per-key. Prevents runaway agents.
Your actual API keys are never stored. Only encrypted hashes are saved, so even a database breach won't expose them.