By the end of this page the plugin is active on your site, you know what is switched on and what is switched off after activation, and you know where the settings are.
What you need
- WordPress 6.9 or newer and PHP 7.4 or newer.
- An administrator account. The settings screen needs the
manage_optionscapability. - A block theme, for the Site Editor templates tools. The Theme files tools also work on the CSS, JS and
theme.jsonof a classic theme. - HTTPS, if a client will connect from outside your browser. Sign-in through OAuth needs it, and WordPress offers Application Passwords only on HTTPS sites and local environments.
- A Linux or macOS server, for the tools that read or write files.
Install and activate
Block Theme MCP is in testing and is being prepared for the WordPress.org plugin directory, so there is no public download yet. Contact us to get the current zip.
- In wp-admin, go to Plugins → Add Plugin and click Upload Plugin.
- Choose the zip, for example
block-theme-mcp-1.2.0.zip, and click Install Now. - Click Activate Plugin.
There is no licence key to enter and no account to create.
Where the settings are
Go to Settings → Block Theme MCP. The plugin’s row on the Plugins screen also has two links, Settings and Connect.
The screen has two cards at the top and four tabs under them.
- Status shows five rows. Each has a pill, such as On, Off or Blocked, and a Change link that takes you to the setting:
- Sign in through the browser (OAuth)
- Application Password (HTTP)
- Browser agents (WebMCP)
- Tool groups
- Theme
- Get started lists three steps: Choose how clients connect, Choose what an agent may do and Connect a client. A finished step gets a tick. The card goes away when all three are done, or when you click Dismiss.
- The tabs are Settings, Connect, Tools and Activity.
What is on and off at the start
Nothing outside your browser can connect until you switch a way in on.
| Setting | At start |
|---|---|
| Enable Block Theme MCP | On |
| MCP clients over OAuth (claude.ai, ChatGPT, Claude Code) | Off |
| MCP clients over HTTP (Application Passwords) | Off |
| Admin screens | On |
| Front end | Off |
| Polyfill document.modelContext | On |
| Confirm destructive tools | On |
| Keep an activity log | On |
| Expose non-REST abilities | Off |
Tool groups decide what an agent may do. Three start on and the rest start off.
| Tool group | At start |
|---|---|
| Theme files | Off |
| Site Editor templates | Off |
| Global styles | Off |
| Patterns | Off |
| Search and replace in content | Off |
| Browse | On |
| Site administration | On |
| Abilities | On |
| Read files | Off |
| Write files | Off |
| HTTP requests | Off |
| Run PHP | Off |
So right after activation, an agent running in a browser tab where you are signed in as an administrator can read basic site information, rename the site, and use any Abilities your site exposes. It cannot touch the theme, templates, content or files until you switch those groups on.
Update the plugin
Upload the newer zip the same way. WordPress asks whether to replace the installed version: click Replace current with uploaded. Your settings and connections are kept.