Connect with an Application Password

By the end of this page an MCP client is connected to your site with a WordPress Application Password, sent as a header with every request. Use this for any MCP client that speaks Streamable HTTP and can send a header. Claude Code can connect this way too, although signing in through OAuth needs no password at all.

Before you start

  • The site is on HTTPS, or is a local environment. WordPress offers Application Passwords only there.
  • You know which WordPress account the client should act as. The client gets that account’s permissions, inside the tool groups that are switched on.

1. Switch on HTTP clients

  1. Go to Settings → Block Theme MCP and open the Connect tab.
  2. Under Sign in with an Application Password, click Switch on.

The notice “Sign-in with an Application Password is switched on.” appears. The same switch is on the Settings tab, under Ways to connect, as MCP clients over HTTP (Application Passwords).

2. Create an Application Password

  1. On the Connect tab, follow the Profile → Application Passwords link. It opens your profile at the Application Passwords section.
  2. Type a name in New Application Password Name, for example Block Theme MCP.
  3. Click Add Application Password.
  4. Copy the password. WordPress shows it once. It looks like this:
XXXX XXXX XXXX XXXX XXXX XXXX

3. Let the Connect tab build the header

  1. Go back to the Connect tab.
  2. Paste the password into the Application Password field.

Two lines fill in as you paste. The first is the header your client sends with every request:

Authorization: Basic <base64 of admin:app-password>

The second is a finished command for Claude Code:

claude mcp add --transport http example-com \
  https://example.com/wp-json/btm/v1/mcp \
  --header "Authorization: Basic <base64 of admin:app-password>"

On your screen the part in angle brackets is replaced by the real value, and admin by your login name. Use the Copy button next to the line you need. The two buttons stay disabled until the field holds a password.

4. Give the client the endpoint and the header

  • For Claude Code, run the copied command in your terminal.
  • For another client, enter two things in its settings for a remote MCP server:
    • the address under Endpoint (Streamable HTTP, POST only):, for example https://example.com/wp-json/btm/v1/mcp
    • the Authorization header from step 3

What is sent and what is not

  • The password you paste on the Connect tab stays in your browser. The field has no name and sits in no form. A script on the page builds the two lines from it. Nothing is sent to your site and nothing is saved. Reload the page and the field is empty again.
  • Your client sends the header with every request. The value is your login name and the Application Password, base64-encoded. Base64 is an encoding, not encryption, which is why the site must be on HTTPS.
  • WordPress keeps a hash of the Application Password, never the password itself.

Check that it worked

Ask the client to list its tools, or to call btm.site-info. The answer includes the site address and the tool groups that are on.

Without a browser to hand, test the endpoint with curl:

curl -s -X POST https://example.com/wp-json/btm/v1/mcp \
  -H "Authorization: Basic <base64 of admin:app-password>" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/list"}'

A JSON reply with a tools list means the connection works.

If something goes wrong

  • “You must be logged in to use Block Theme MCP tools.” (401) even though you sent the header. Your host or a proxy is removing the Authorization header before WordPress sees it. See Troubleshooting.
  • “MCP clients over HTTP are switched off in Settings → Block Theme MCP.” (403) Repeat step 1.
  • The Connect tab says Application Passwords are not available. The site is on plain HTTP, or something on the site has turned Application Passwords off.

To stop a client, revoke its Application Password on your profile screen. See Revoke a connected app.