メインコンテンツまでスキップ

Tools Reference

Every tool has a name (namespaced, e.g. woocommerce.search_products), a type (read or write), and a required access tier. Reads of public content are public; writes always require a same-session nonce. See Security for what each tier means.

Namespaces

Tool names are grouped by namespace: wordpress.* for content, woocommerce.* for the store, store.* for site knowledge, cpt.* for custom post types, and one namespace per integration (content.*, buddypress.*, forms.*, memberships.*, lms.*, bookings.*, subscriptions.*). The manifest at /wp-json/mcpify/v1/manifest always reflects exactly what is enabled on your site.

WordPress tools (Free)​

All WordPress tools are read tools over public content, at the Anonymous tier.

ToolDescriptionKey parameters
wordpress.get_site_infoSite name, description, URL, and basic public metadata-
wordpress.get_menuItems of a registered navigation menulocation
wordpress.searchFull-text search across public posts and pagesquery, per_page
wordpress.get_postA single published post or page by ID or slugid or slug
wordpress.list_postsList published posts with paging and filtersper_page, page, category
wordpress.list_categoriesPublic categoriesper_page
wordpress.list_tagsPublic tagsper_page

Password-protected posts are excluded from all of these, including search results. See Security.

WooCommerce catalog tools (Free)​

Available only when WooCommerce is active. All read tools over public catalog data, at the Anonymous tier.

ToolDescriptionKey parameters
woocommerce.get_store_infoStore name, currency, and public store settings-
woocommerce.search_productsSearch products by keywordquery, per_page
woocommerce.get_productA single product by ID or slugid or slug
woocommerce.list_productsList products with paging, category, and price filtersper_page, page, category
woocommerce.get_product_variationsVariations of a variable productid
woocommerce.check_product_stockStock status and quantity for a productid
woocommerce.list_categoriesProduct categoriesper_page

Cart tools (Pro)​

The visitor's native WooCommerce cart. At the Session tier, so guests are supported; the write tools additionally require a same-session nonce.

ToolTypeDescription
woocommerce.get_cartreadThe current cart contents and totals
woocommerce.add_to_cartwriteAdd a product (and quantity/variation) to the cart
woocommerce.update_cart_itemwriteChange the quantity of a cart line
woocommerce.remove_cart_itemwriteRemove a line from the cart

Checkout tools (Pro)​

ToolTypeDescription
woocommerce.get_checkout_fieldsreadThe fields WooCommerce expects at checkout
woocommerce.apply_couponwriteApply a coupon code to the cart (tightly rate-limited)
woocommerce.remove_couponwriteRemove an applied coupon
MCPify does not take payment

The checkout tools help an agent prepare an order (build a cart, apply a coupon, read the required fields). Completing payment stays in WooCommerce's own secure checkout. MCPify never handles card data.

Order and customer tools (Pro)​

ToolTypeTierDescription
woocommerce.list_my_ordersreadAuthenticatedThe current customer's orders
woocommerce.get_my_orderreadAuthenticatedOne of the current customer's orders by ID
woocommerce.track_orderreadAnonymousA guest order, verified by order number + billing email
woocommerce.notify_mewriteAuthenticatedSubscribe the signed-in customer to a back-in-stock alert (product_id)
woocommerce.get_related_productsreadAnonymousRelated or cross-sell products for an item

Order tools are ownership-scoped: a customer can never read another customer's orders. HPOS is fully supported. notify_me takes no email parameter - the address comes from the account.

Site knowledge tools (Pro)​

ToolTypeDescription
store.get_policiesreadYour shipping, returns, FAQ and about text, as written in Settings
store.list_integrationsreadWhich ecosystem integrations are currently active

Custom Post Type tools (Pro)​

For each custom post type you allowlist in the admin, MCPify generates read tools (list and get) under the cpt.* namespace, using the post type's own labels and public fields. Nothing is exposed until you opt a CPT in. See Pro features.

Integration tools (Pro)​

Each appears only when its plugin is active.

ToolTypeTierPlugin
content.get_custom_fieldsreadAnonymousACF - returns only fields you allowlist
buddypress.search_membersreadAnonymousBuddyPress / BuddyBoss - never email addresses
buddypress.list_groupsreadAnonymousPublic groups only
forms.list_formsreadAnonymousGravity Forms, Contact Form 7, WPForms
forms.submit_formwriteAnonymousGravity Forms - only forms you allowlist
memberships.list_plansreadAnonymousPMPro, RCP, MemberPress - hidden levels excluded
memberships.my_statusreadAuthenticatedThe user's own membership
lms.list_coursesreadAnonymousLearnDash, LifterLMS, Tutor LMS
lms.my_coursesreadAuthenticatedThe user's own enrolments and progress
bookings.list_servicesreadAnonymousWooCommerce Bookings, Amelia, Bookly
subscriptions.list_minereadAuthenticatedWooCommerce Subscriptions

Calling a tool​

Run any tool over REST with a single POST:

curl -X POST "https://example.com/wp-json/mcpify/v1/execute" \
-H "Content-Type: application/json" \
-d '{ "tool": "woocommerce.search_products", "params": { "query": "blue shirt", "per_page": 5 } }'

Write tools additionally need a session and the WordPress REST nonce:

curl -X POST "https://example.com/wp-json/mcpify/v1/execute" \
-H "Content-Type: application/json" \
-H "X-WP-Nonce: THE_NONCE" \
--cookie "your-session-cookies" \
-d '{ "tool": "woocommerce.add_to_cart", "params": { "product_id": 42, "quantity": 1 } }'

A server-side agent sends an API key instead of a session (Pro):

curl -X POST "https://example.com/wp-json/mcpify/v1/execute" \
-H "Content-Type: application/json" \
-H "X-MCPify-Key: YOUR_AGENT_KEY" \
-d '{ "tool": "wordpress.search", "params": { "query": "returns policy" } }'

Tools that ask for confirmation first​

If you flag a tool under Settings > Require confirmation, its first call does not run. It answers with HTTP 202 and a single-use token:

{
"success": false,
"error": { "code": "confirmation_required", "message": "..." },
"data": { "tool": "woocommerce.add_to_cart", "confirmation_token": "a1b2...", "expires_in": 300 }
}

Ask the user, then re-send the identical call with the token:

{ "tool": "woocommerce.add_to_cart", "params": { "product_id": 42, "quantity": 1, "_confirm": "a1b2..." } }

The token is single-use and bound to those exact parameters. _confirm is stripped before schema validation, so it never reaches your tool.

Test without curl

The admin Playground lets you run any tool from the dashboard and see the exact JSON an agent receives. See the Admin guide.