Install Block Theme MCP

By the end of this page the plugin is active on your site, you know what is switched on and what is switched off after activation, and you know where the settings are.

What you need

  • WordPress 6.9 or newer and PHP 7.4 or newer.
  • An administrator account. The settings screen needs the manage_options capability.
  • A block theme, for the Site Editor templates tools. The Theme files tools also work on the CSS, JS and theme.json of a classic theme.
  • HTTPS, if a client will connect from outside your browser. Sign-in through OAuth needs it, and WordPress offers Application Passwords only on HTTPS sites and local environments.
  • A Linux or macOS server, for the tools that read or write files.

Install and activate

Block Theme MCP is in testing and is being prepared for the WordPress.org plugin directory, so there is no public download yet. Contact us to get the current zip.

  1. In wp-admin, go to Plugins → Add Plugin and click Upload Plugin.
  2. Choose the zip, for example block-theme-mcp-1.2.0.zip, and click Install Now.
  3. Click Activate Plugin.

There is no licence key to enter and no account to create.

Where the settings are

Go to Settings → Block Theme MCP. The plugin’s row on the Plugins screen also has two links, Settings and Connect.

The screen has two cards at the top and four tabs under them.

  • Status shows five rows. Each has a pill, such as On, Off or Blocked, and a Change link that takes you to the setting:
    • Sign in through the browser (OAuth)
    • Application Password (HTTP)
    • Browser agents (WebMCP)
    • Tool groups
    • Theme
  • Get started lists three steps: Choose how clients connect, Choose what an agent may do and Connect a client. A finished step gets a tick. The card goes away when all three are done, or when you click Dismiss.
  • The tabs are Settings, Connect, Tools and Activity.

What is on and off at the start

Nothing outside your browser can connect until you switch a way in on.

SettingAt start
Enable Block Theme MCPOn
MCP clients over OAuth (claude.ai, ChatGPT, Claude Code)Off
MCP clients over HTTP (Application Passwords)Off
Admin screensOn
Front endOff
Polyfill document.modelContextOn
Confirm destructive toolsOn
Keep an activity logOn
Expose non-REST abilitiesOff

Tool groups decide what an agent may do. Three start on and the rest start off.

Tool groupAt start
Theme filesOff
Site Editor templatesOff
Global stylesOff
PatternsOff
Search and replace in contentOff
BrowseOn
Site administrationOn
AbilitiesOn
Read filesOff
Write filesOff
HTTP requestsOff
Run PHPOff

So right after activation, an agent running in a browser tab where you are signed in as an administrator can read basic site information, rename the site, and use any Abilities your site exposes. It cannot touch the theme, templates, content or files until you switch those groups on.

Update the plugin

Upload the newer zip the same way. WordPress asks whether to replace the installed version: click Replace current with uploaded. Your settings and connections are kept.

Next steps