Aller au contenu principal

Pro Features

The free edition covers read and discovery - everything an agent needs to understand your catalog and content. Pro adds the tools that let an agent act, a third delivery surface for server-side agents, governance controls, and a layer of integrations with the plugins your site already runs.

The paywall follows the security boundary: free is read and public, Pro is write, private, and custom.

Commerce​

Cart tools​

Let an agent build and manage the visitor's native WooCommerce cart:

  • woocommerce.get_cart - view the cart and totals
  • woocommerce.add_to_cart - add a product, quantity, or variation
  • woocommerce.update_cart_item - change a line's quantity
  • woocommerce.remove_cart_item - remove a line

These use WooCommerce's own session cart, so the agent's changes are exactly what the shopper sees. They sit at the Session tier, so they work for guests as well as signed-in customers.

Checkout tools​

  • woocommerce.get_checkout_fields - the fields checkout expects
  • woocommerce.apply_coupon / woocommerce.remove_coupon - manage coupons

Payment always stays inside WooCommerce's secure checkout. MCPify never handles card data. Coupon attempts carry a deliberately tight rate limit, because a success/failure pair is otherwise an oracle for guessing codes.

Order tools​

Give a logged-in customer's assistant access to that customer's own orders:

  • woocommerce.list_my_orders
  • woocommerce.get_my_order

Orders are strictly ownership-scoped - no customer can read another's - and HPOS (High-Performance Order Storage) is fully supported.

Guest order tracking​

woocommerce.track_order lets a shopper who checked out without an account look up their order with the order number plus the matching billing email. It works on guest orders only: a registered customer's order still requires their login.

Recommendations and stock​

  • woocommerce.get_related_products - related or cross-sell products for a given item
  • woocommerce.notify_me - a signed-in customer asks to be emailed when an out-of-stock product returns. The address comes from their account, never from the request, so nobody can be subscribed by someone else. Mail is sent from a scheduled event in batches, so a restock never stalls the request that caused it.

Answer accurately​

Store policies​

store.get_policies returns the shipping, returns, FAQ and about text you write in Settings. It gives an agent a grounded source for the questions customers actually ask, instead of leaving it to guess from page content.

Per-tool agent descriptions​

Override the agent-facing description of any tool from the Tools screen. This is how you steer exactly when and how an agent reaches for a given tool, in your own words, without touching code.

Custom content​

For each custom post type you allowlist in Settings, MCPify generates read tools (list and get) under the cpt.* namespace, using the type's labels and public fields. Nothing is exposed until you opt a type in, so a CPT holding private data stays private by default.

MCP server endpoint​

Pro exposes a JSON-RPC 2.0 MCP endpoint at /wp-json/mcpify/v1/mcp, implementing initialize, tools/list, tools/call and ping on protocol version 2024-11-05.

This is the surface server-side agents connect to - ChatGPT, Claude desktop, and agent frameworks - using the same registry, the same gate and the same rate limits as the browser and REST surfaces. It also fires the same extension points, so your hardening and your webhooks observe server-side agents exactly as they observe browser traffic.

Governance​

Per-agent API keys​

Issue a labelled key per agent and send it as X-MCPify-Key. Keys are stored hashed, need at least 32 characters, and can never reach a capability-gated tool. See Security.

Confirmation for sensitive actions​

Flag any tool so it refuses to run until the caller returns a single-use token bound to that exact call. See Security for what this does and does not guarantee.

Webhooks​

POST a small metadata-only notification to your own URLs after every tool call: tool name, success, status, time, site URL. Never parameters, never results.

IP allowlist​

Restrict the API to a list of addresses. Read the limitation behind a reverse proxy before relying on it.

Granular permissions​

Override the access tier of any individual tool. Overrides can only ever tighten a tool, never loosen it.

Audit export​

The activity log - which records denials as well as successes - exports to CSV for compliance or off-site review.

Insight​

A usage dashboard summarises recent activity: total calls, success and error split, and the most-used tools, with a warning when the error rate crosses 30% so a misconfigured agent surfaces on its own.

Works with your favourite plugins​

MCPify includes an ecosystem-integration layer. Each integration appears automatically only when its plugin is active, and every one respects the same rules: public or ownership-scoped data only, never emails or private fields.

IntegrationToolsSupported plugins
Custom fieldscontent.get_custom_fieldsAdvanced Custom Fields (ACF)
Communitybuddypress.search_members, buddypress.list_groupsBuddyPress, BuddyBoss
Formsforms.list_forms, forms.submit_formGravity Forms (submit), Contact Form 7, WPForms
Membershipsmemberships.list_plans, memberships.my_statusPaid Memberships Pro, Restrict Content Pro, MemberPress
LMSlms.list_courses, lms.my_coursesLearnDash, LifterLMS, Tutor LMS
Bookingsbookings.list_servicesWooCommerce Bookings, Amelia, Bookly
Subscriptionssubscriptions.list_mineWooCommerce Subscriptions

store.list_integrations reports which are active, and a documented PHP API lets you add your own.

Two of these start closed

ACF fields and submittable forms expose nothing until you name what may be shared. ACF fields routinely hold cost price, supplier or internal notes the theme never renders; and a programmatic form submit skips honeypot and JavaScript anti-spam while still firing the form's notifications. Both are opt-in by design - see the Admin guide.

WordPress Abilities API bridge​

On WordPress 6.9+, MCPify can bridge the server-side Abilities API into its tool registry, adding the browser WebMCP layer that the Abilities API does not provide on its own. This is off by default and enabled with a single filter:

add_filter( 'mcpify_abilities_enabled', '__return_true' );

Editions​

MCPify ships as one codebase in three builds:

EditionWhereLicensing
FreeWordPress.orgFree, with an optional in-dashboard upgrade
ProDirect / annual licensePer-site license
CodeCanyonCodeCanyonOne-time purchase

The WordPress.org build is a single package: the Pro tools ship with it and unlock at runtime when a valid license or trial is present. There is no separate premium ZIP to install. The Pro and CodeCanyon builds carry an edition marker instead. Everything else - the engine, the security gate, the REST, OpenAPI, MCP and in-page surfaces - is identical across editions.

Get Pro

See the Support page for purchase and licensing links, or buy directly from the Themesic store to pay less than on CodeCanyon.