Linux 软件免费装
Banner图

Royal MCP – Secure AI Connector for Claude, ChatGPT & any LLM via MCP

开发者 royalpluginsteam
更新时间 2026年9月5日 09:59
捐献地址: 去捐款
PHP版本: 7.4 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

elementor ai chatgpt claude mcp

下载

1.4.14 1.4.0 1.4.44 1.4.1 1.4.17 1.4.4 1.4.5 1.4.7 1.3.0 1.4.10 1.4.11 1.4.9 1.4.12 1.4.21 1.4.8 1.4.22 1.4.23 1.4.24 1.4.16 1.4.18 1.4.25 1.4.27 1.2.3 1.4.13 1.4.19 1.4.29 1.4.30 1.4.31 1.4.28 1.4.33 1.4.34 1.4.35 1.4.20 1.4.26 1.4.32 1.4.6 1.4.37 1.4.38 1.4.39 1.4.40 1.2.2 1.4.15 1.4.36 1.4.41 1.4.42 1.4.43 1.4.45 1.5.0

详情介绍:

The most complete WordPress MCP server — 200+ tools, OAuth 2.0, and nothing leaves your site. Royal MCP gives Claude, ChatGPT, Google Gemini, Perplexity, DeepSeek, Mistral, and every other MCP-compatible AI structured access to your WordPress site: 85 WordPress core tools plus 120 integration tools that auto-load for WooCommerce, Elementor, Divi, ACF, Yoast SEO, UpdraftPlus, WPForms, Solid Security, Contact Form 7, MonsterInsights, W3 Total Cache, Duplicator, BuddyPress, and more. Connect Claude to WordPress Royal MCP connects your WordPress site directly to Claude Code, Claude Desktop, or Claude.ai. Setup takes a minute or less: install the connector, authorize, and start your chat. https://youtu.be/pf-mdRnXezM Edit Elementor with Claude https://youtu.be/HsEIoDz9WmY First-time setup walkthrough: royalplugins.com/support/royal-mcp/connecting-to-claude/ Plugins with dedicated MCP tools WooCommerce, Elementor, Divi, Advanced Custom Fields, Yoast SEO, UpdraftPlus, WPForms, Solid Security, Contact Form 7, MonsterInsights, W3 Total Cache, Duplicator, BuddyPress, Redirection — plus every Royal Plugin (Royal AI Firewall, GuardPress, SiteVault, ForgeCache, Royal Ledger, Royal Links). Not seeing yours? MCP still works. WordPress core operations (posts, pages, media, users, taxonomies, custom fields, menus, options) cover most day-to-day AI workflows for any plugin — read/write ACF via wp_get_post_meta even without ACF-specific tools, edit posts on any custom post type, moderate any plugin's comments. Shared SEO meta tools automatically work with Rank Math, AIOSEO, SEOPress, and SEObolt. A dedicated integration layers specialized tools on top when that plugin exposes its own data model, request features/plugins support here on the wp.org support forum. Connect ChatGPT to WordPress ChatGPT on the web, desktop, and iOS supports MCP servers natively. Add Royal MCP in ChatGPT's Plugins panel, authorize once, and ChatGPT can read your posts, publish drafts, update product prices, moderate comments, and audit SEO across your site — all through ordinary conversation. First-time setup walkthrough: royalplugins.com/support/royal-mcp/connecting-to-chatgpt/ Works with every MCP-compatible AI client Royal MCP is not vendor-locked. Claude/Anthropic, ChatGPT/OpenAI, Gemini/Google, Grok/xAI, Llama/Meta, Mistral, DeepSeek, Qwen/Alibaba, Cohere, and Perplexity all work through MCP-compatible clients like Cursor, Windsurf, Cline, Continue, Zed, JetBrains AI Assistant, OpenCode, Warp, Ollama, and LM Studio, all connecting through the same endpoint. Switch AI vendors without rewriting a single connection. How Royal MCP handles authorization Royal MCP speaks full OAuth 2.0 with PKCE and Dynamic Client Registration (RFC 7591) for Claude Desktop, Claude Code, ChatGPT web, and every modern MCP client. Sessions expire, refresh automatically, and can be revoked globally with one button in wp-admin. Clients that don't speak OAuth get timing-safe API-key auth, per-IP rate limits (60 requests per minute), and the same activity log for every tool call. Where do my credentials go? Nowhere. Your AI client authenticates straight to your WordPress site, and every API key, OAuth token, session, and audit-log entry stays inside your own database. There's no hosted server sitting between your chat and your site, and no license check or telemetry reaching out on activation. Ollama and LM Studio are first-class platforms alongside Claude, ChatGPT, and Gemini if you want to keep AI inference local too. Can I undo what the AI does? Yes. Every MCP client (Claude Desktop, ChatGPT, and the rest) asks you to approve or deny each destructive tool call by default, until you flip that setting in your connector. On top of that, Royal MCP captures a reverse-state snapshot before every destructive write and hands back a 72-hour undo token. One mcp_undo_last_operation call reverses the change — whether Claude deleted a post, replaced text on an Elementor page, updated a WooCommerce product, or reordered menu items. New posts and pages start as drafts, so nothing the AI writes appears on your live site until you approve publishing. Every tool call also lands in an activity log you can review from wp-admin. Does Royal MCP work with the WordPress Abilities API? Yes. Royal MCP surfaces every AI-callable operation through one endpoint, from three sources: the 85 native tools Royal MCP ships, the 120 integration tools that auto-load when WooCommerce, Elementor, Divi, ACF, Yoast SEO, UpdraftPlus, WPForms, Solid Security, Contact Form 7, MonsterInsights, W3 Total Cache, Duplicator, BuddyPress, and other supported plugins activate, and every ability any plugin registers through WordPress 6.9's Abilities API. Your AI sees them all as MCP tools — one connector, no per-plugin setup, no per-vendor rewrite. See what AI agents do to your site The free Royal AI Firewall companion shows every AI agent hitting your site at the HTTP layer (training crawlers, retrieval bots, AI search engines), not just the ones connected through Royal MCP. Install both for a unified view across MCP tool calls and HTTP-layer bot hits. 85 Core Tools + 120 Integration Tools WordPress Core (85 tools): Third-Party Plugin Integrations (auto-detected) If the plugin is active on your Wordpress site, it's tools auto-register with no additional configuration needed. Royal Plugins Integrations (auto-detected) Every Royal Plugin auto-exposes MCP tools alongside Royal MCP: Supported AI Platforms Compatible Clients & Frameworks Royal MCP works with any MCP-compliant client, IDE, or AI agent framework — no per-tool configuration required. Each entry below describes the specific integration path Royal MCP provides for that target, so customers can answer "will this work with the tool I already use?": * Desktop AI apps - Claude Desktop (native MCP connector via OAuth 2.0), ChatGPT Desktop, Gemini Advanced. * AI code IDEs - Claude Code, VS Code (with MCP extension), Cursor, Windsurf, Continue, Cline, Zed, JetBrains AI Assistant. * API testing tools - Postman, Bruno, Insomnia (use the API key in the X-Royal-MCP-API-Key header). * Custom field plugins - Advanced Custom Fields (ACF) has dedicated acf_* tools that return values formatted per each field's Return Format setting (the same way the ACF UI shows them). MetaBox, JetEngine, Pods, CPT UI, and Custom Field Suite are supported through the wp_get_post_meta / wp_update_post_meta tools, so AI agents can populate custom fields just like a human editor. * Page builders - Elementor and Divi have dedicated tools for safe clone-and-customize workflows (Elementor: clone a page, find/replace text, swap images, get an outline, import templates; Divi: format detection, layout validation, page outline, library read, find/replace with builder-format awareness) - see the Tools list. Widget-level creation from scratch is intentionally out of scope. Beaver Builder, Bricks, Gutenberg, Spectra, and Stackable store standard post content that is readable and writable by AI; page-builder-specific JSON storage is opaque unless covered by a dedicated tool. * Multilingual - WPML, Polylang, TranslatePress: translated posts appear as separate posts and can be read/written via the standard post tools. * AI agent frameworks - Any MCP-compatible framework (LangChain, AutoGen, CrewAI, LlamaIndex, Haystack, etc.). MCP Spec Compliance Royal MCP implements the MCP 2025-11-25 Streamable HTTP transport specification:

安装:

  1. Upload the royal-mcp folder to /wp-content/plugins/
  2. Activate the plugin through the 'Plugins' menu in WordPress
  3. Go to Royal MCP → Settings to configure
  4. Copy your API key — you will need this to authenticate MCP connections
  5. Add your AI platform(s) and enter their API keys
  6. In your AI client (Claude Desktop, VS Code, etc.), configure the MCP server URL and API key
  7. New to MCP? Follow the step-by-step connection walkthrough (with videos) at royalplugins.com/support/royal-mcp/connecting-to-claude/
Full setup guides for each platform are available at royalplugins.com/support/royal-mcp/.

屏幕截图:

  • AI platform configuration with connection testing
  • Activity log showing authenticated MCP requests
  • Claude Desktop MCP connector setup
  • WooCommerce product management via Claude
  • OAuth consent screen for Claude Desktop connector

升级注意事项:

1.4.37 Adds six Royal AI Firewall tools, a Royal Tools admin page with one-click install links to the free Royal Plugins family, a connection-health diagnostic tool, an Elementor widget-settings read tool, and expands wp_update_post / wp_update_page with menu_order and other missing fields plus real read-after-write response shape. 1.4.36 Adds three diagnostic tools (site status, error-log tail, cron schedule), preserves HTML across several write tools, and adds admin notices for two common environment issues that block OAuth discovery. 1.4.33 Adds scheduling and backdating to the post and page write tools, expands the create-status enum, and exposes a new action hook for ecosystem extensions. 1.4.32 Adds snippet excerpts to wp_search and pagination to wc_get_orders. Note: wc_get_orders response shape changes from a bare array to {orders, page, per_page, total, total_pages}. 1.4.31 Security hardening and ergonomic improvements for post-identifying tools. Recommended for all users. 1.4.30 Adds the first structural-write Elementor tool plus capability-order hardening across six integration wrappers. Recommended for all users. 1.4.29 Reliability fix for the runtime DB migration. Recommended for anyone on 1.4.27. 1.4.28 Adds Authorization: Bearer header support for API keys and covers the post URL slug in the SEO meta tools. Both changes are strictly additive. 1.4.27 Reliability patch: MCP session state moved onto a dedicated table. No customer action required. 1.4.26 Security patch: per-tool capability checks across the OAuth tool surface. Recommended for all users. 1.4.25 Recommended update. Settings page UX pass and new in-product setup guides for Claude.ai, ChatGPT, Claude Desktop, and Cursor. 1.4.24 Recommended update. Adds Advanced Custom Fields integration and enables variable-product creation in WooCommerce. 1.4.23 Strongly recommended update. AI Platforms model dropdowns refreshed across every provider. 1.4.22 Recommended update. Fixes Test Connection on Claude, restores clearing of manual OAuth credentials, and adds two new self-check admin notices. 1.4.21 Recommended update for WordPress 7.0: preserves escape sequences inside Gutenberg block content on the post and page write tools. 1.4.17 Critical fix for OAuth authorization codes. Also adds a Reset OAuth State button and Activity Log entries for MCP tool calls. 1.4.16 Recommended update: OAuth failures now write to Activity Logs with the exact error code, description, and HTTP status. 1.4.15 Critical update: four fixes to the API key flow, session TTL, and cache headers. Existing keys keep working. 1.4.14 Recommended update: unauthenticated GET on the MCP endpoint returns 401 with WWW-Authenticate so web-based MCP clients trigger OAuth discovery correctly. 1.4.13 Recommended update: OAuth endpoint caching hardened plus 17 new WooCommerce tools (variable products, attributes, coupon CRUD). 1.4.12 Recommended update: fixes tool-list silent failure on Claude Desktop and adds a slug alias on wp_get_taxonomies. 1.4.11 Adds wp_update_term, the term-meta tools, and wp_get_taxonomies, with existing term tools accepting any registered taxonomy. 1.4.10 Adds 16 new tools spanning Royal Ledger, ForgeCache, and Royal Links integrations, SEO meta, permalink structure, and post revision history plus restore. 1.4.9 Adds 13 new tools across theme appearance, menu item CRUD, and comment moderation, with theme writes gated by an admin toggle and opt-in allowlist filter. 1.4.8 Fixes a setup failure on sites updated from an early build. Recommended for anyone unable to add Royal MCP as a Claude connector. 1.4.7 Adds plugin-settings read (sensitive keys redacted) and allowlisted options write. New "Allow AI to write WordPress options" toggle is OFF by default. 1.3.0 Major security and feature update. Recommended for all users. 1.2.3 Security: SSRF protection for outbound requests plus wp.org compliance fixes. 1.2.0 Security hardening and MCP spec compliance improvements. Recommended for all users.

常见问题:

What is MCP and why does my WordPress site need it?

Model Context Protocol (MCP) is an open standard created by Anthropic that lets AI assistants interact with external data sources. Without MCP, AI tools like Claude or ChatGPT can only work with content you copy and paste into them. With Royal MCP installed, these AI platforms can directly read your WordPress posts, create new content, manage your WooCommerce products, check your security status, and trigger backups — all through a structured, authenticated protocol.

How is Royal MCP different from other WordPress MCP plugins?

Security. Most MCP plugins (and 41% of all public MCP servers) have no authentication at all. Royal MCP requires an API key for every session, rate-limits requests to prevent abuse, logs every interaction for audit purposes, and filters sensitive data (emails, PHP version, admin credentials) from responses. We built this plugin with the same security standards we apply to GuardPress, our WordPress security plugin used on thousands of sites.

Does Royal MCP duplicate what WordPress core now does?

No. WordPress 6.9 added the Abilities API (a primitive for registering AI-callable functions), and the wordpress/mcp-adapter package bridges abilities to the MCP protocol. Royal MCP is a full MCP server with the security layer, connector flows, and plugin integrations the bare primitive does not include: enforced API key auth, OAuth 2.0 for Claude Desktop, per-IP rate limiting, audit logging, sensitive-data redaction, 85 ready-to-use WordPress core tools, and 120 integration tools for WooCommerce, GuardPress, Royal AI Firewall, SiteVault, ForgeCache, Royal Ledger, Royal Links, Elementor, Divi, ACF, Yoast SEO, UpdraftPlus, WPForms, Redirection, Solid Security, Contact Form 7, MonsterInsights, W3 Total Cache, Duplicator, and BuddyPress.

Does Royal MCP work with WooCommerce?

Yes. When WooCommerce is active, Royal MCP automatically adds 29 MCP tools spanning product management (simple and variable, including variation CRUD and global attribute management), full coupon management (list/get/create/update/delete + bulk trash purge), order management (view, create, update, add notes, update status), customer data, and store statistics. No additional configuration is needed — the tools appear automatically in the MCP tools list.

Can AI assistants configure my plugins for me?

Yes, with safety controls. Royal MCP exposes two tools for plugin configuration:

  • wp_get_plugin_settings lets AI read any plugin's stored settings by slug. Sensitive values (API keys, secrets, tokens, passwords, license keys, OAuth credentials) are automatically replaced with [REDACTED] before they leave your server, so AI assistants can understand a plugin's configuration without ever seeing stored credentials.
  • wp_update_option lets AI write to WordPress options, but only after passing three security gates:
  • The site admin must enable the "Allow AI to write WordPress options" toggle on the Royal MCP settings page (off by default)
  • The option name must be in a runtime allowlist. The default allowlist is intentionally tiny — blogname, blogdescription, posts_per_page, date_format, time_format, show_on_front, page_on_front. Plugin authors opt their own settings in via the royal_mcp_writable_options filter.
  • A hard denylist permanently blocks writes to sensitive option names (siteurl, home, license keys, secrets, salts, etc.) regardless of the allowlist or the toggle.
Plugin authors can opt in their settings with one line: add_filter('royal_mcp_writable_options', fn($opts) => array_merge($opts, ['my_plugin_settings']));

How do I connect Claude Desktop to WordPress?

Install Royal MCP, go to Royal MCP → Settings, and copy your API key and MCP server URL. In Claude Desktop, add a new MCP server configuration with the URL and include the X-Royal-MCP-API-Key header with your API key. Full step-by-step guide at royalplugins.com/support/royal-mcp/. If the connection fails, see the next FAQ.

The connector won't connect — where do I start?

About 90% of "can't connect" / "OAuth failed" / "tools missing" issues resolve in a basic 4-step pass before any host-specific fix is needed. In order: (1) update Royal MCP to the latest version (every recent release fixes meaningful OAuth edge cases), (2) run a conflict test — deactivate all other plugins, switch to a default theme like Twenty Twenty-Five, and purge every cache layer (any cache plugin, your host's server-level cache, Cloudflare/CDN, and browser cache), (3) wipe stale OAuth state — use the Reset OAuth State button in Royal MCP → Settings if you're on 1.4.17 or newer, or run the four DELETE SQL queries documented in our support article, (4) check Royal MCP → Activity Logs for the most recent oauth: row, which records exactly which validation rule fired. Full walk-through with copy-pasteable commands at royalplugins.com/support/royal-mcp/troubleshooting-start-here.html. Only proceed to host-specific fixes (Cloudflare AI Bots toggle, SiteGround /.well-known/ static files, edge-cache exclusions) after the four basics are ruled out — most "advanced infrastructure" tickets we receive actually resolve in those four steps.

I restored my WordPress database from backup and Claude can't reconnect. How do I fix this?

When you restore from backup, the OAuth client credentials Claude was holding no longer match anything on the WordPress side, so Claude's connector ends up with a stale token that no Royal MCP installation will accept. The fix in Royal MCP 1.4.17+ is one click: go to Royal MCP → Settings and click the Reset OAuth State button. This wipes all stale OAuth clients, issued access/refresh tokens, and pending authorization codes. Then in Claude, delete the existing connector entirely, wait 30 seconds, and re-add it from scratch — the full OAuth flow runs fresh against the cleaned-up state and the connection works. On 1.4.16 or older the same effect can be achieved by running four DELETE SQL queries documented at royalplugins.com/support/royal-mcp/troubleshooting-start-here.html. The plugin's settings, API key, and Activity Log are not affected by Reset OAuth State — only the OAuth handshake state.

Claude says "Couldn't register with sign-in service" or "Session not found" — what's wrong?

Both messages (plus "no tools available" in Claude.ai after connecting) usually mean one of Royal MCP's OAuth or sessions database tables is physically missing. The fix is to update Royal MCP to 1.4.29 or newer — the new runtime healer detects missing tables and recreates them automatically on the next pageload, with no deactivate/reactivate required. After updating, delete the existing Royal MCP connector in Claude, wait 30 seconds, then re-add it fresh. If you can't update yet and need to recover immediately, the manual workaround is wp option delete royal_mcp_db_version followed by loading any wp-admin page. Full symptom diagnostic (phpMyAdmin / WP-CLI), the auto-heal explanation, and the manual recovery walkthrough are at royalplugins.com/support/royal-mcp/oauth-tables-missing.html.

I'm auditing my install and can't find the OAuth endpoints under /wp-json/royal-mcp/v1/. Where are they?

By design, Royal MCP's OAuth endpoints (/register, /token, /authorize) are registered as top-level WordPress rewrite rules at the site root, not as REST API routes under /wp-json/royal-mcp/v1/. This is required by the OAuth 2.0 specification (RFC 6749) and the MCP discovery specs (RFC 8414 and RFC 9728), which mandate predictable site-root paths so OAuth-discovery-aware clients can find them without per-plugin configuration. If you're auditing rewrite rules instead of REST routes, you can see ours via wp rewrite list | grep royal_mcp_oauth from WP-CLI. The /wp-json/royal-mcp/v1/ namespace contains the JSON-RPC tool endpoint at /mcp plus supporting REST routes (/posts, /pages, /site, etc.) — but not the OAuth handshake endpoints themselves. Both routing layers are normal and both need to be reachable for the connector to work end-to-end.

Is my content safe?

Royal MCP is designed with defense in depth. API key authentication is required for all MCP sessions. Rate limiting prevents abuse (60 requests per minute per IP). Activity logging records every tool call. Sensitive data is filtered — user emails, usernames, admin email, PHP version, and stored credentials inside plugin settings (api keys, secrets, tokens, passwords) are never exposed through MCP. Comment creation respects your WordPress moderation settings. Post meta values are sanitized before storage. Option writes are disabled by default and gated by three independent checks (admin toggle, allowlist, hard denylist) when enabled. The plugin itself starts disabled by default — nothing is accessible until you explicitly enable it.

Can I use local AI models instead of cloud services?

Yes. Royal MCP supports Ollama and LM Studio for fully local AI inference. When using local models, no data leaves your server — the AI model runs on your own hardware and communicates with WordPress through the MCP protocol on localhost.

What happens if I uninstall Royal MCP?

Royal MCP performs a clean uninstall. All plugin options, database tables (activity logs), transients, and user meta are removed. No orphaned data is left behind.

Does Royal MCP work with Claude Code, VS Code, Cursor, Windsurf, or other AI IDEs?

Yes. Any MCP-compliant client can connect to Royal MCP. Configure your IDE or client with the MCP server URL (https://yoursite.com/wp-json/royal-mcp/v1/mcp) and the API key (sent in the X-Royal-MCP-API-Key header). Claude Desktop additionally supports the native "Add Connector" OAuth 2.0 flow, which Royal MCP handles via Dynamic Client Registration (RFC 7591) — no manual API key management required on that path. The same OAuth flow works in any client that follows the MCP 2025-11-25 spec.

Does Royal MCP work with custom fields, ACF, MetaBox, JetEngine, Pods, or CPT UI?

Yes. Royal MCP exposes WordPress's standard wp_get_post_meta, wp_update_post_meta, and wp_delete_post_meta tools, which read and write any custom field — including Advanced Custom Fields (ACF), MetaBox, JetEngine, Pods, CPT UI, and Custom Field Suite. AI agents can populate ACF fields, set repeater rows, update flexible content blocks, and read computed fields just like a human editor working in the WordPress admin.

Will Royal MCP slow down my WordPress site?

No. The MCP endpoint is a REST route that runs only when an authenticated AI client makes a request — it does not run on visitor-facing pages, frontend templates, or admin screens (except its own settings page). The activity log uses a single indexed database table and writes asynchronously after the response is sent. Rate limiting (60 requests/minute per IP) prevents accidental overload.

Does Royal MCP work on WordPress multisite networks?

Yes, on a per-site basis. Each site in a multisite network has its own API key, its own activity log, and its own settings. AI clients connect to a specific site's MCP endpoint — Royal MCP does not bridge requests between sites in the network.

Can I limit which posts, pages, or post types AI can access?

Yes. The wp_get_posts and wp_create_post tools accept a post_type parameter and validate it against registered public post types, so private or internal post types are not exposed. Plugin authors can disable specific tools entirely with the royal_mcp_disabled_tools filter, or scope the option-write allowlist with royal_mcp_writable_options. WordPress's standard capability checks also apply to every tool call.

Does Royal MCP work with WPML, Polylang, or TranslatePress for multilingual content?

Yes. Translated posts appear as separate WordPress posts (each with its own ID and language meta) and are readable or writable via the standard wp_get_posts, wp_create_post, and wp_update_post tools. AI agents can list posts in a specific language by filtering on the language meta key, or translate a post and write the corresponding translation by ID.

How do I monitor what AI is doing on my site?

Every authenticated MCP request is logged to the Royal MCP activity log with timestamp, client IP, tool name, parameters (sensitive values redacted), and response status. The log is filterable by time range, client, tool, or status code, and exportable to CSV. The log page refreshes via AJAX so you can watch active sessions in real time.

更新日志:

1.5.0 1.4.45 1.4.44.1 1.4.44 1.4.43 1.4.42 1.4.41 1.4.40 1.4.39 1.4.38 1.4.37 1.4.36 1.4.35 1.4.34 1.4.33 1.4.32 1.4.31 1.4.30 1.4.29 1.4.28 1.4.27 1.4.26 1.4.25 1.4.24 1.4.23 1.4.22 1.4.21 1.4.20 1.4.19 1.4.18 1.4.17 1.4.16 1.4.15 1.4.14 1.4.13 1.4.12 1.4.11 1.4.10 1.4.9 1.4.8 1.4.7 1.4.6 1.4.5 1.4.4 1.4.3 1.4.2 1.4.1 1.4.0 1.3.0 1.2.3 1.2.2 1.2.1 1.2.0 1.1.0 1.0.0