| 开发者 | mumega |
|---|---|
| 更新时间 | 2026年7月30日 01:01 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.0 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
SITE_URL/wp-json/mcpwp/v1/mcp and send the key in the X-API-Key header.Each key is stored in WordPress as a password hash and is bound to the existing WordPress user who created it. The plaintext is displayed only once. A user with the Mumega MCP settings capability can revoke an active key from Setup & Keys.
Read permits non-mutating operations. Write permits retained content, media, and taxonomy mutations that the bound WordPress user is allowed to perform. Admin is the stronger scope required for sensitive operations such as publishing, private-content mutation, and delete operations on individual drafts. Tool-category selection narrows which groups of tools the key can call.
No plugin-initiated outbound request is made. The plugin sends authenticated results only to the MCP client chosen by the site owner. Any provider processing performed by that client is controlled by the owner's client configuration, outside this plugin.
When local logging is enabled, the plugin stores tool name, status code, duration, API-key ID, and time. It does not store request arguments or response content. The site owner controls retention in Settings.