v1.3.0 Open-source WordPress bridge + MCP server View latest release →
WordPress × Model Context Protocol

Give AI a safe control plane for WordPress.

Connect Claude, ChatGPT, Codex, Gemini, Cursor and other MCP clients to WordPress through a bridge built around least privilege, human approval and reversibility.

GPL-2.0-or-later Local-first connection No admin password sharing
Secure bridge active
MCP
C
ClaudeDesktop + Code
O
OpenAIChatGPT + Codex
G
GeminiCLI
+
Any MCPcompatible client

Bridgistic

Policy + execution layer

HMAC signed Scoped keys Approvals Snapshots Audit log Rollback
WP
Contentposts + media
WC
CommerceWooCommerce
DB
Site dataoptions + database
FS
Systemfiles + tools
Guard: dry-run → approval → snapshot → execute Every request attributable to a key
Claude  Desktop
Claude  Code
ChatGPT
OpenAI  Codex
Gemini  CLI
Any MCP  client
The missing safety layer

AI access should not mean full-admin access.

Bridgistic separates what an AI assistant can do from what it is technically capable of asking for.

Direct credential approach

Powerful — but too much trust at once.

A generic admin credential can turn a small prompt mistake into a production incident with very little containment.

  • Broad authority: credentials often carry more permission than a task needs.
  • No policy gate: the agent can move straight from intent to execution.
  • Weak reversibility: recovery depends on whatever backup workflow already exists.
Bridgistic control plane

Give the agent exactly enough access.

Mint a dedicated key, narrow its scopes, preview risky actions, require approval, snapshot first and keep an audit trail.

  • Least privilege: Read-only → Content Manager → Safe Admin → Developer Mode.
  • Human checkpoints: destructive writes can pause for explicit approval.
  • Built-in recovery: automatic snapshots precede destructive operations.
Setup without the ceremony

Install once. Connect the AI you already use.

The WordPress wizard generates the connection details; your MCP client handles the rest.

Install Bridgistic

Upload the free WordPress plugin and activate it. Your content and theme are not modified during activation.

Plugins → Add New → Upload Plugin

Create a scoped key

Choose your client and a permission preset in AI / MCP Connections. Start Read-only and widen later.

Bridgistic → AI / MCP Connections

Connect and verify

Install the desktop extension or paste the generated config, then call bridgistic_get_site_info to verify.

run bridgistic_get_site_info
Choose your connection path

Local-first by default. Cloud when you need remote MCP.

Local mode keeps the connection between your own machine and WordPress. Bridgistic Cloud exists for remote-only clients such as ChatGPT.

Public beta

Bridgistic Cloud

A hosted OAuth relay lets remote-only MCP clients connect without running a local server process.

  • Designed for ChatGPT and remote MCP clients
  • OAuth 2.1 + PKCE connection flow
  • Scoped tenant credential encrypted at rest
  • Free during public beta
Important: Bridgistic Cloud has not yet completed an independent third-party security review. Prefer local mode for supported clients and avoid high-risk production access until the beta is fully vetted.
Security is the product

A guardrail between AI intent and production execution.

Bridgistic authenticates each request, checks the key’s scope, applies the safety policy, creates a recovery point and records the result.

Read security model
01

Authenticate

HMAC-SHA256 signs method, path, timestamp, nonce and body hash. Replay protection rejects reused nonces and stale requests.

Signed
02

Authorize

Each key carries explicit scopes. A denied action fails before the underlying WordPress operation runs.

Scoped
03

Guard

Risky operations can dry-run first and wait in the Approvals queue until a human allows them.

Approved
04

Snapshot

Destructive writes can capture the target before mutation, creating a recovery point for rollback.

Reversible
05

Execute + audit

The action runs with its result attached to the key’s audit trail so changes stay attributable.

Logged
// canonical signed request
METHOD \n PATH \n TIMESTAMP \n NONCE \n sha256(body)
→ HMAC-SHA256(secret, canonical_request)
Built for real WordPress operations

More than a connector. A controlled operating layer.

From content tasks to admin workflows, Bridgistic gives AI a structured tool surface without giving up operational control.

Scoped connection keys

Choose a permission preset or individual scopes. Rotate, revoke or delete keys from WordPress at any time.

Least privilege by design

Audit logs

Track the key, action, status, source IP and time for operations while keeping secrets out of logs.

Attributable activity

Snapshots + rollback

Capture pre-change state around destructive writes and restore snapshots when a change needs to be reversed.

Recovery built in

Multi-site connections

Local clients can use a shared connections registry and target WordPress sites by alias from the same MCP server.

Agency-friendly foundation

Playbooks + schedules

Save repeatable routines and run supported playbooks from WordPress or through the MCP tool surface.

Repeatable automation

WooCommerce tools

Structured WooCommerce operations sit behind the same authentication, scopes, guard parameters and audit controls.

Commerce-aware MCP

Developer tools, contained

Database, filesystem and PHP execution require Developer Mode scopes; PHP writes are confined to a protected sandbox.

High-risk tools gated

Health diagnostics

Built-in checks help identify REST, permalink, signing, hosting and configuration problems before they become mysteries.

Faster troubleshooting

Client-ready exports

Generate ready-to-use configs and setup packages from WordPress instead of hand-building connection files from scratch.

Less setup friction
One bridge, many AI clients

Use the model you prefer. Keep the WordPress policy layer consistent.

Bridgistic speaks MCP, so the security model stays on the WordPress side while the AI client can change.

Best first setupLocal

Claude Desktop

Use the one-click .mcpb extension. Claude Desktop prompts for the site URL, key ID and secret and stores the secret in its own extension storage.

Terminal requiredNo
Node.js requiredNo for .mcpb
ConnectionLocal
Recommended path
# 1. Create a Read-only key in WordPress
Bridgistic → AI / MCP Connections

# 2. Download the desktop extension
bridgistic.mcpb

# 3. Double-click it and paste:
WordPress Site URL  https://example.com
Key ID              wpk_...
Key Secret          wps_...

# 4. Verify in Claude
run bridgistic_get_site_info
SupportedLocal

Claude Code

Install Bridgistic from the Claude Code plugin marketplace, then provide your site connection through environment variables.

Install pathPlugin marketplace
Build requiredNo
ConnectionLocal
Claude Code
/plugin marketplace add wordpressistic/bridgistic
/plugin install bridgistic@bridgistic-marketplace

export BRIDGISTIC_SITE_URL="https://example.com"
export BRIDGISTIC_KEY_ID="wpk_..."
export BRIDGISTIC_KEY_SECRET="wps_..."

# Verify
run bridgistic_get_site_info
SupportedLocal

OpenAI Codex CLI

Run the published MCP server through npx and configure it in Codex using the mcp_servers section.

Node.js20+
Configconfig.toml
ConnectionLocal
~/.codex/config.toml
[mcp_servers.bridgistic]
command = "npx"
args = ["-y", "bridgistic-mcp-server"]
env = {
  BRIDGISTIC_SITE_URL = "https://example.com",
  BRIDGISTIC_KEY_ID = "wpk_...",
  BRIDGISTIC_KEY_SECRET = "wps_..."
}
SupportedLocal

Gemini CLI

Gemini CLI can launch Bridgistic locally through npx. The consumer Gemini web/mobile app is a different connector model.

Node.js20+
Configsettings.json
ConnectionLocal
~/.gemini/settings.json
{
  "mcpServers": {
    "bridgistic": {
      "command": "npx",
      "args": ["-y", "bridgistic-mcp-server"],
      "env": { "BRIDGISTIC_SITE_URL": "https://example.com" }
    }
  }
}
Public betaRemote

ChatGPT

ChatGPT uses a remote MCP connector over HTTPS, so it connects through Bridgistic Cloud rather than launching the local server.

ConnectionRemote MCP
AuthOAuth 2.1 + PKCE
Cloud statusPublic beta
ChatGPT connector flow
# In ChatGPT
Settings → Connectors → Advanced settings
→ Enable Developer mode
→ Create connector
→ Paste the Bridgistic Cloud MCP URL shown in WP Admin
→ Approve the WordPress consent screen

# Verify
run bridgistic_get_site_info

# Note
Bridgistic Cloud is currently a public beta.
Inspectable, testable, explicit

Security claims should have engineering behind them.

The repository’s automated checks cover the MCP server, shipped bundle, WordPress behavior, cloud connector and real plugin activation in WordPress CI.

HMAC

Signed request contract

Independent integration checks verify signatures and signed round trips instead of testing only helper functions.

CI

Shipped artifact checks

The bundled server and plugin ZIP are validated separately from source builds to catch packaging drift.

WP

Real activation job

The built plugin ZIP is installed and activated in real WordPress via WP-CLI in automated checks.

Beta

Known gaps are disclosed

Live cloud end-to-end, load/abuse testing and independent security review remain explicitly tracked.

Transparent limitation: Bridgistic Cloud is functional but has not yet completed an independent security review. The local bridge remains the safest default for clients that can run it.
Free bridge. Paid scale.

Start with the complete secure core.

The open-source plugin is not a demo. Paid SaaS layers on team, agency and advanced automation capabilities.

Open source

Bridgistic Free

$0 core bridge

For developers and site owners who want controlled AI access to their own WordPress sites.

  • Local MCP bridge for supported clients
  • HMAC keys, scopes and approvals
  • Basic audit logs and limited snapshots
  • Manual playbooks + limited scheduling
  • Multi-site connections builder
  • Cloud connector during public beta
Download free
GPL-2.0-or-later. Security fixes remain in the free version.
SaaS layer

Bridgistic Pro / Agency

Scale with WPistic

For agencies and teams that need centralized operations, advanced skills and managed automation across sites.

  • AI skills marketplace and advanced skills
  • Advanced audit history and export
  • Advanced snapshot retention + history
  • Managed schedules, monitoring and reporting
  • Agency dashboard + team permissions
  • Usage billing + white-label options
Explore WPistic pricing
Exact paid packaging is managed through the WPistic SaaS layer.
FAQ

Before you connect an AI to production.

What exactly does Bridgistic do?
Bridgistic adds a policy-controlled MCP bridge to WordPress. Compatible AI clients call structured tools through a dedicated connection key; the WordPress plugin verifies authentication, scopes and safety rules before an operation runs.
Do I give Claude, ChatGPT or Codex my WordPress admin password?
No. Bridgistic creates its own scoped key ID and secret for the connection. Local requests are HMAC-signed, and the WordPress administrator password is not the integration credential.
Which permission preset should I use first?
Start with Read-only. Move to Content Manager or Safe Admin only when the workflow requires writes. Developer Mode exposes the highest-risk tools and should be reserved for sites you fully control.
Can I require approval before the AI changes my site?
Yes. Keys can require approval for writes or destructive operations. Pending actions appear in Bridgistic → Approvals so a human can allow or deny them.
Can Bridgistic roll back a bad change?
Bridgistic can create snapshots before destructive writes, and snapshots can be restored from WordPress or via the relevant MCP operation. The exact coverage depends on the type of operation.
Is Bridgistic Cloud the same security model as local mode?
The WordPress-side scopes, approvals and safety controls still apply, but the network path is different: the hosted relay participates in the connection. Bridgistic Cloud is currently a public beta without an independent security review, so local mode is the recommended default where available.
Can I manage several WordPress sites from one AI client?
Yes for local clients. Bridgistic supports a multi-site connections.json registry and site aliases. The WordPress Multi-Site screen helps build the file. The hosted cloud connector uses a separate connector entry per site.
Does Bridgistic work with WooCommerce?
Yes. The MCP surface includes structured WooCommerce tools behind the same authentication and guard model. The project’s testing documentation also explicitly notes that live WooCommerce behavior remains a larger integration surface to validate in real environments.
Start read-only

Connect your first WordPress site without surrendering control.

Install the free plugin, mint a Read-only key, connect your MCP client and verify the bridge before granting write access.