| 开发者 | beautifulplugins |
|---|---|
| 更新时间 | 2026年10月2日 00:11 |
| PHP版本: | 7.4 及以上 |
| WordPress版本: | 7.1 |
| 版权: | GPLv2 or later |
| 版权网址: | 版权信息 |
claude mcp add commandmcp-remote.cursor/mcp.json block.vscode/mcp.json blockmcp_config.json blockcurrent_user_can() capability check. The token is never trusted on its own.delete badge in the allowlist, and are announced to the client with the MCP destructiveHint annotation so it can ask you to confirm before calling one. They count as writes, so a read-only connection can never call them.get_site_info — WordPress/PHP/DB versions, active theme, environment, debug flagslist_plugins — installed plugins, versions, update availabilitylist_themes — installed themesget_php_error_log_tail — last lines of the server-configured PHP error log (admins only)get_site_settings — general, writing, reading, discussion, and permalink settings from a fixed allowlistupdate_site_settings — change the site title, tagline, front page, posts per page, and date, time and timezone formats (off by default, per token; a fixed allowlist that can never reach the site address, the admin email, registration defaults, or the permalink structure)list_posts, get_post, search_content — content inspectioncreate_post, update_post — content writes (off by default, per token)delete_post — move a post or page to the trash (off by default, per token; permanent deletion is refused unless the site opts in, and the front page and posts page are always refused)restore_post — bring a trashed post back to its previous status (off by default, per token)set_post_meta — assign a page template to a page (off by default, per token; an allowlist of meta keys, not an arbitrary meta writer)list_media — browse the media libraryupload_media — add an image from base64 data (off by default, per token)set_featured_image — set or clear a post's featured image (off by default, per token)list_block_templates — every template and template part available to the active theme, including the ones that exist only as theme filesget_block_template — a template's block markup, or the original theme file version of one that has been customisedupdate_block_template — create a template or override a theme-provided one (off by default, per token; the theme's files are never modified)revert_block_template — discard a customisation so the theme file takes over again (off by default, per token)get_theme_json — the active theme's palette, gradients, spacing scale, font sizes and font families, with the exact reference strings for each, plus the layout widths and which blocks the theme stylesupdate_global_styles — change colours, typography, spacing, and per-block styling (off by default, per token; writes the same user layer the Site Editor saves to)reset_global_styles — discard the style customisations and fall back to the theme (off by default, per token)list_block_types — every block registered on the site, including ones a theme or plugin adds, with their attribute schemasvalidate_block_markup — check block markup against the registry before saving it: unregistered blocks, attributes that do not exist, values outside what an attribute accepts, blocks used outside the parent they need, unbalanced delimitersrender_block_template — render markup or a template to HTML, so the agent can see what its own output actually produceslist_navigation_menus — menus with their items as a nested list rather than raw block markupcreate_navigation_menu — build a menu from a list of items and get back the id a template's navigation block needs (off by default, per token)update_navigation_menu — replace a menu's items or rename it (off by default, per token)list_taxonomies, list_terms — taxonomy inspectioncreate_term, assign_terms, update_term — term writes (off by default, per token)delete_term — remove a term (off by default, per token; posts using it are never deleted, they simply lose the assignment)list_comments — review the moderation queuemoderate_comment — approve, unapprove, spam, unspam, trash, untrash (off by default, per token)reply_to_comment — reply as the connected user (off by default, per token)get_seo_meta — read the meta description and focus keyword for a post or pageupdate_seo_meta — write them back through the active SEO plugin's own post meta (off by default, per token)sokket_register_tools. Anything you add inherits the whole permission model, the audit log, and the transport for free, and shows up in the admin allowlist automatically. Filters are also provided for rate limits, upload restrictions, audit retention, the settings-read allowlist, and OAuth authorization rights.
Full documentation: beautifulplugins.com/docs/sokket-site-connector-for-mcp/
claude mcp add --transport http sokket-site-connector-for-mcp https://example.com/wp-json/sokket/v1/mcp --header "Authorization: Bearer YOUR_TOKEN"
Then ask your agent what versions the site is running — and watch the call appear in the audit log.The Model Context Protocol is the standard way for an AI client to work with an external system. The system exposes tools — named operations with typed arguments — and the AI decides which to call. Sokket makes your WordPress site one of those systems, so an AI agent can read and manage it directly instead of being told about it second-hand.
No. The plugin makes no outbound requests to AI providers or any other external service. AI clients that you configure connect to your site, authenticate with a credential you created, and can only use the tools that credential allows.
No. Sokket is provider-agnostic and stores no AI credentials at all. Your AI client brings its own subscription and authenticates to your site with a token or an OAuth connection you approve.
Any MCP-compatible client that supports remote servers over Streamable HTTP, including Claude Code, Claude Desktop, ChatGPT, Cursor, VS Code, and Windsurf. The "Connect your AI client" tab generates the exact command or configuration for your site.
Claude Desktop's custom connectors have no field for a bearer token, so enable OAuth 2.1 under Settings → General, then add your endpoint URL as a custom connector and leave Client ID and Client Secret blank — the connector registers itself and asks you to sign in and approve. If you would rather not enable OAuth, the plugin also generates an mcp-remote configuration that uses a bearer token instead.
Yes. This plugin is the complete MCP server: every tool, OAuth 2.1, bearer tokens, per-connection permissions, and the audit log. There is no usage limit and no account to create.
The server is disabled by default and rejects every request until you enable it. When enabled, access requires a credential bound to a WordPress user, and each tool call is checked against that user's capabilities plus the connection's own allowlist. Every write tool is off until you enable it, and you can revoke any credential instantly.
Yes — that is the core of the plugin. Each bearer token has its own tool allowlist and an optional read-only ceiling that blocks every write tool regardless of what else is ticked. OAuth connections are scope-based instead: read-only or full access, still bounded by the WordPress user's capabilities.
No. The plugin deliberately ships no filesystem write, database query, or command execution tools. Every write tool is off by default and has to be enabled per connection. get_php_error_log_tail reads only the path the server itself configures in error_log, capped at the last 100 lines, and requires an administrator.
This includes the design tools. update_block_template and update_global_styles write database rows — the same customisation records the Site Editor creates — and never touch a theme's theme.json, templates/, or any other file. If you deactivate the plugin, the theme still renders exactly as those customisations describe, because they belong to your site rather than to Sokket.
Settings are the same story. update_site_settings writes a fixed list of options and nothing else. The site address, the admin email, whether anyone can register, what role they get, and the permalink structure are excluded outright, and that exclusion is enforced in code after any filter has run, so a site cannot open them up by accident. set_post_meta works from an allowlist of meta keys rather than accepting any key you name.
On a block theme, yes — and yes. An agent with the template and style tools enabled can edit templates and template parts, change the palette, typography and spacing, and style individual blocks.
Every one of those changes is reversible, and reversible in more than one way. revert_block_template discards a template customisation so the theme file takes over again, and reset_global_styles throws away the style changes. The Site Editor's own "Reset" and "Clear customizations" work on them too, because they are ordinary WordPress customisation records, not something the plugin invents. And since the theme's files are never modified, switching to another theme and back gives you the theme as it shipped.
These tools are off by default like every other write tool. If you would rather an agent never touched the design, simply leave them unticked.
Yes — that is what the template and global styles tools are for, and they are built on the same WordPress APIs the Site Editor uses, so nothing is special-cased to a particular theme.
On a classic theme the design tools stay available but have far less to work with: list_block_templates returns only whatever block templates a plugin has registered, which on most sites is none, and get_theme_json falls back to the WordPress default palette and spacing scale. Nothing errors, and the content, media, taxonomy, comment, and SEO tools work exactly the same on either kind of theme. Classic menus, widgets, and the Customizer are not covered.
Only if you enable upload_media on a connection bound to a user who can already upload files, and even then the tool is deliberately narrow:
photo.jpg that is not really an image is rejected, and the stored extension is always rewritten to match the real image data.It sees whatever the WordPress user it is bound to can see through the tools you enabled. Notably, list_comments includes commenter email addresses, and get_site_settings includes the site's admin email — the same data that user sees in wp-admin. Leave those tools off if you would rather not share them.
The time, the user, the tool, the outcome, and the id of the post, attachment, term, or comment the call acted on. Tool arguments are never stored, so the log tells you what happened without becoming a second copy of your content.
Yes. Register them through the sokket_register_tools filter and they appear in the admin allowlist automatically, passing exactly the same permission gates as the built-in tools. See the developer documentation.
Yes. Sokket runs per site — each site in a network has its own settings, credentials, endpoint, and audit log, and is enabled independently. Connect your AI client to each site separately.
No. The MCP endpoint is a REST route (/wp-json/sokket/v1/mcp), so the REST API must be reachable. A security plugin that blocks REST requests or strips the Authorization header will also block Sokket.
The plugin cleans up after itself: the token, audit log, and OAuth tables are dropped, the options are deleted, and the plugin's transients are cleared. Every credential stops working immediately. What it does not remove is your site's own content — including anything an agent created or changed through it. Posts, pages, media, terms, template customisations, and global styles all stay exactly as they are, because they are WordPress records that belong to your site, not to Sokket. Your site keeps looking and working the way it did the moment before you deleted the plugin.
list_block_types, validate_block_markup, and render_block_template. An agent writing block markup previously had no way to check its own work: a misspelled block name or an attribute a block does not have saves without complaint and then renders as nothing. These three let it look up what exists, check markup against the block registry before saving, and render the result to see it.list_navigation_menus, create_navigation_menu, and update_navigation_menu. Menus read back as a nested list of items instead of raw block markup, and a menu is built by naming what each item links to. Every link is resolved against the real page, post, or term, because a navigation link carries four values that must agree and WordPress does not complain when they do not — it saves the menu, renders it, and sends visitors to a 404.update_site_settings — change the site title, tagline, front page, posts per page, and the date, time and timezone formats. This is what makes "use this page as the home page" possible. It writes a fixed allowlist; the site address, the admin email, the registration defaults, and the permalink structure can never be written, because a wrong value there locks you out of your own site, hands over account recovery, opens an administrator factory, or 404s every URL you have ever published.set_post_meta — assign a page template to a page. An allowlist of meta keys rather than an arbitrary meta writer, since post meta is where plugins keep everything from prices to access rules and no capability check tells one key from another.sokket_block_support_attributes, sokket_settings_write_allowlist, and sokket_allowed_post_meta.list_block_templates, get_block_template, update_block_template, and revert_block_template. Templates a block theme ships as files were previously invisible, because WordPress only creates a database row once a template is customised; they are now listed and readable alongside customised ones. Editing a theme-provided template stores an override and leaves the theme file untouched, and revert_block_template discards the override so the file takes over again.get_theme_json, update_global_styles, and reset_global_styles. get_theme_json returns the active theme's palette, gradients, spacing scale, font sizes and families, each with the exact strings to reference it from a block attribute and from CSS, so an agent uses the theme's real preset slugs instead of guessing them. Writes go to the same user layer the Site Editor saves to; the theme's own theme.json file is never modified.create_post and update_post could be corrupted. Running wp_kses_post() over a whole post treats block delimiters as ordinary HTML comments, which entity-encoded ampersands inside block attributes — turning a Tips & Tricks heading attribute into Tips & Tricks and making the editor report "Block contains unexpected or invalid content" — and stripped svg and iframe, emptying a Custom HTML block holding an inline icon. Content is now parsed first and filtered block by block, so the delimiters and attributes are left intact.wp_insert_post(), which expects slashed input and unslashes before writing. Every backslash in post content, titles and excerpts was previously being dropped.sokket_allowed_block_html filter for the HTML permitted inside block inner markup.delete_post and restore_post tools. Posts are moved to the trash, so a call can always be undone. The front page and the posts page are refused outright, and permanent deletion additionally requires the sokket_allow_permanent_delete filter.update_term and delete_term tools. Deleting a term never deletes the posts using it, and the response reports how many objects lost the assignment.get_seo_meta and update_seo_meta, for the meta description and focus keyword. Registered only when Yoast SEO, Rank Math, or SEOPress is active, and written through that plugin's own post meta.create_post and update_post accept a slug, and both now return the resulting slug.delete badge in the token allowlist, and send the MCP destructiveHint annotation so your AI client can ask you to confirm before it calls one. They count as writes, so read-only connections can never reach them.sokket_register_tools can mark them with is_destructive to get the same badge and annotation.list_media, upload_media (base64 images only), and set_featured_image.list_taxonomies, list_terms, create_term, and assign_terms.list_comments, moderate_comment, and reply_to_comment.get_site_settings tool reading a fixed allowlist of WordPress options.