Tools Reference
Every tool has a name (namespaced, e.g. woocommerce.search_products), a type (read or write), and a required access tier. Reads of public content are public; writes always require a same-session nonce. See Security for what each tier means.
Tool names are grouped by namespace: wordpress.* for content, woocommerce.* for the store, store.* for site knowledge, cpt.* for custom post types, and one namespace per integration (content.*, buddypress.*, forms.*, memberships.*, lms.*, bookings.*, subscriptions.*). The manifest at /wp-json/mcpify/v1/manifest always reflects exactly what is enabled on your site.
WordPress tools (Free)
All WordPress tools are read tools over public content, at the Anonymous tier.
| Tool | Description | Key parameters |
|---|---|---|
wordpress.get_site_info | Site name, description, URL, and basic public metadata | - |
wordpress.get_menu | Items of a registered navigation menu | location |
wordpress.search | Full-text search across public posts and pages | query, per_page |
wordpress.get_post | A single published post or page by ID or slug | id or slug |
wordpress.list_posts | List published posts with paging and filters | per_page, page, category |
wordpress.list_categories | Public categories | per_page |
wordpress.list_tags | Public tags | per_page |
Password-protected posts are excluded from all of these, including search results. See Security.
WooCommerce catalog tools (Free)
Available only when WooCommerce is active. All read tools over public catalog data, at the Anonymous tier.
| Tool | Description | Key parameters |
|---|---|---|
woocommerce.get_store_info | Store name, currency, and public store settings | - |
woocommerce.search_products | Search products by keyword | query, per_page |
woocommerce.get_product | A single product by ID or slug | id or slug |
woocommerce.list_products | List products with paging, category, and price filters | per_page, page, category |
woocommerce.get_product_variations | Variations of a variable product | id |
woocommerce.check_product_stock | Stock status and quantity for a product | id |
woocommerce.list_categories | Product categories | per_page |
Cart tools (Pro)
The visitor's native WooCommerce cart. At the Session tier, so guests are supported; the write tools additionally require a same-session nonce.
| Tool | Type | Description |
|---|---|---|
woocommerce.get_cart | read | The current cart contents and totals |
woocommerce.add_to_cart | write | Add a product (and quantity/variation) to the cart |
woocommerce.update_cart_item | write | Change the quantity of a cart line |
woocommerce.remove_cart_item | write | Remove a line from the cart |
Checkout tools (Pro)
| Tool | Type | Description |
|---|---|---|
woocommerce.get_checkout_fields | read | The fields WooCommerce expects at checkout |
woocommerce.apply_coupon | write | Apply a coupon code to the cart (tightly rate-limited) |
woocommerce.remove_coupon | write | Remove an applied coupon |
The checkout tools help an agent prepare an order (build a cart, apply a coupon, read the required fields). Completing payment stays in WooCommerce's own secure checkout. MCPify never handles card data.
Order and customer tools (Pro)
| Tool | Type | Tier | Description |
|---|---|---|---|
woocommerce.list_my_orders | read | Authenticated | The current customer's orders |
woocommerce.get_my_order | read | Authenticated | One of the current customer's orders by ID |
woocommerce.track_order | read | Anonymous | A guest order, verified by order number + billing email |
woocommerce.notify_me | write | Authenticated | Subscribe the signed-in customer to a back-in-stock alert (product_id) |
woocommerce.get_related_products | read | Anonymous | Related or cross-sell products for an item |
Order tools are ownership-scoped: a customer can never read another customer's orders. HPOS is fully supported. notify_me takes no email parameter - the address comes from the account.
Site knowledge tools (Pro)
| Tool | Type | Description |
|---|---|---|
store.get_policies | read | Your shipping, returns, FAQ and about text, as written in Settings |
store.list_integrations | read | Which ecosystem integrations are currently active |
Custom Post Type tools (Pro)
For each custom post type you allowlist in the admin, MCPify generates read tools (list and get) under the cpt.* namespace, using the post type's own labels and public fields. Nothing is exposed until you opt a CPT in. See Pro features.
Integration tools (Pro)
Each appears only when its plugin is active.
| Tool | Type | Tier | Plugin |
|---|---|---|---|
content.get_custom_fields | read | Anonymous | ACF - returns only fields you allowlist |
buddypress.search_members | read | Anonymous | BuddyPress / BuddyBoss - never email addresses |
buddypress.list_groups | read | Anonymous | Public groups only |
forms.list_forms | read | Anonymous | Gravity Forms, Contact Form 7, WPForms |
forms.submit_form | write | Anonymous | Gravity Forms - only forms you allowlist |
memberships.list_plans | read | Anonymous | PMPro, RCP, MemberPress - hidden levels excluded |
memberships.my_status | read | Authenticated | The user's own membership |
lms.list_courses | read | Anonymous | LearnDash, LifterLMS, Tutor LMS |
lms.my_courses | read | Authenticated | The user's own enrolments and progress |
bookings.list_services | read | Anonymous | WooCommerce Bookings, Amelia, Bookly |
subscriptions.list_mine | read | Authenticated | WooCommerce Subscriptions |
Calling a tool
Run any tool over REST with a single POST:
curl -X POST "https://example.com/wp-json/mcpify/v1/execute" \
-H "Content-Type: application/json" \
-d '{ "tool": "woocommerce.search_products", "params": { "query": "blue shirt", "per_page": 5 } }'
Write tools additionally need a session and the WordPress REST nonce:
curl -X POST "https://example.com/wp-json/mcpify/v1/execute" \
-H "Content-Type: application/json" \
-H "X-WP-Nonce: THE_NONCE" \
--cookie "your-session-cookies" \
-d '{ "tool": "woocommerce.add_to_cart", "params": { "product_id": 42, "quantity": 1 } }'
A server-side agent sends an API key instead of a session (Pro):
curl -X POST "https://example.com/wp-json/mcpify/v1/execute" \
-H "Content-Type: application/json" \
-H "X-MCPify-Key: YOUR_AGENT_KEY" \
-d '{ "tool": "wordpress.search", "params": { "query": "returns policy" } }'
Tools that ask for confirmation first
If you flag a tool under Settings > Require confirmation, its first call does not run. It answers with HTTP 202 and a single-use token:
{
"success": false,
"error": { "code": "confirmation_required", "message": "..." },
"data": { "tool": "woocommerce.add_to_cart", "confirmation_token": "a1b2...", "expires_in": 300 }
}
Ask the user, then re-send the identical call with the token:
{ "tool": "woocommerce.add_to_cart", "params": { "product_id": 42, "quantity": 1, "_confirm": "a1b2..." } }
The token is single-use and bound to those exact parameters. _confirm is stripped before schema validation, so it never reaches your tool.
The admin Playground lets you run any tool from the dashboard and see the exact JSON an agent receives. See the Admin guide.