Saltar al contenido principal

Admin Guide

Everything about MCPify is managed from the MCPify menu in the WordPress admin. No code and no config files are required.

Who can access it

The admin screens require the manage_options capability (site administrators). All actions are nonce-protected and all output is escaped.

Dashboard​

The landing screen shows plugin status at a glance: whether MCPify is enabled, how many tools are active, whether WooCommerce tools are available, and quick links to the manifest and OpenAPI endpoints.

It also shows a Usage summary of recent activity - total calls, the success and error split, and your most-used tools. If more than 30% of recent calls failed, a warning appears here, so a misconfigured agent surfaces on its own rather than waiting to be noticed.

Tools​

The Tools screen lists every registered tool grouped by namespace (wordpress, woocommerce, and cpt on Pro).

  • Toggle any individual tool on or off. Disabled tools disappear from the manifest and cannot be called from any surface.
  • Disable a whole group at once from Settings (see below).
  • Each tool shows its type (read/write) and required access tier.
  • On Pro, each tool also gets a Required auth (override) dropdown and an Agent description (override) box. The override can only ever raise the requirement - you cannot use it to make a capability-gated tool public. The description box rewrites what agents are told the tool is for, in your own words.

Changes take effect immediately - the manifest reflects the new state on the next request.

Settings​

The Settings screen controls global behavior:

SettingWhat it does
Master switchTurn all MCPify tool serving on or off
Activity loggingEnable or disable the activity log
Rate limitsPer-caller and global request limits
Disabled groupsTurn off an entire namespace (e.g. all woocommerce tools)
Store policies (Pro)Shipping, returns, FAQ and about text that store.get_policies returns
Webhooks (Pro)One URL per line; each tool call POSTs a metadata-only notification
IP allowlist (Pro)One IP per line; when set, only these may reach the API
API keys (Pro)One label:key per line, minimum 32 characters
Require confirmation (Pro)One tool name per line; these refuse to run until confirmed
ACF field allowlist (Pro)One field name per line; blank exposes nothing
Submittable forms (Pro)One form id per line; blank means no form may be submitted
Tool permission overrides (Pro)Tighten the access tier of specific tools (Tools screen)
Custom post type allowlist (Pro)Choose which CPTs get generated tools
Three fields start closed

ACF fields, submittable forms and the custom post type allowlist all expose nothing until you name what may be shared. That is deliberate: ACF fields often hold cost price or internal notes the theme never renders, and a programmatic form submit skips honeypot and JavaScript anti-spam while still firing the form's notifications.

API keys are shown once

Keys are stored hashed, so an existing key can never be displayed again - it appears masked as label:********. Record a key when you create it. Leave a masked line untouched to keep that key; replace the mask with a new secret to rotate it. Anything shorter than 32 characters is rejected with a notice rather than silently dropped.

Logs​

The Logs screen shows recent tool calls: which tool, the result, and when. It contains no personal data.

Denials are recorded alongside successes - forbidden, rate_limited, invalid_params and tool_unavailable all appear. That is the point: if someone is probing your site, you can see it here rather than having it pass silently.

  • Clear the log at any time.
  • On Pro, export the log to CSV for auditing.

Use the log to see what agents are actually doing on your site and to spot anything unexpected.

Playground​

The Playground lets you run any tool straight from the admin - pick a tool, fill in its parameters, and send. You see the exact request and the raw response envelope.

It is the fastest way to:

  • Confirm a tool returns what you expect.
  • See a tool's input schema in practice.
  • Reproduce and debug an agent's call.
tip

Use the Playground after enabling or restricting a tool to confirm the access tier behaves the way you intended.