Automattic

WordPress.com

Included as a hosted editorial and site-management surface with per-tool and per-site controls, OAuth user identity, live operation discovery, and mandatory confirmation for writes.

Content, CMS, creative & DAMSystem of productionBYO-UI-ready platform
An illustration of access surfaces surrounding a governed system.
System roleSystem of production
Access maturityBYO-UI-ready platform
MCP supportOfficial MCP server
Reference updatedJun 19, 2026
BYO-UI reviewedJul 22, 2026

Concrete capability record

Data, retrieval, actions, identity, and operating limits

A field-by-field summary of what the reviewed first-party references actually support. Publisher update dates and BYO-UI review dates are shown separately below.

01 · Records and state owned

Accounts and sites; posts, pages, comments, media, categories, tags, block patterns, themes, site settings, users, domains, stats, subscribers, products, orders, and connected applications.

02 · Data you can retrieve

List, search, and inspect enabled account, site, content, media, taxonomy, appearance, audience, commerce, and analytics resources through live-discovered facade operations.

03 · Actions and write paths

Create, update, publish, trash, or delete supported content and settings through enabled operations; every write requires explicit user confirmation, with an extra flag for permanent taxonomy deletion.

04 · Authentication and permissions

WordPress.com uses OAuth 2.1 and user approval for tool calls. Existing vendor identity, account, tenant, and permission controls should be treated as the authorization boundary.

05 · Monitoring, approval, and recovery

Read tools start enabled and write tools disabled. Users can toggle individual tools, administrators can block entire sites, and connected clients can be revoked through Connected Apps.

06 · Limits and caveats

MCP requires a paid WordPress.com plan. Facade schemas evolve and should be discovered live; changing tool or site settings requires reconnecting so clients refresh available tools.

Agent access

MCP support

Official MCP serverBuilt-in hosted WordPress.com account and site MCP; separate WordPress Studio and self-hosted WordPress MCP tooling are outside this profileCurrent service on paid WordPress.com plans

Support: Official MCP server

Read scope: Expose only enabled account and site operations, preserving site identity, content status, author, taxonomy, theme context, requested fields, and the live operation schema used.

Write scope: Honor tool and site toggles, default new posts and pages to drafts, and distinguish reversible trash actions from permanent deletes or updates that publish immediately.

Authentication: WordPress.com uses OAuth 2.1 and user approval for tool calls.

Approval boundary: Describe the exact operation and target, preview content and status changes, request explicit confirmation, send `user_confirmed: true`, and require the additional permanent-delete flag where applicable.

Protocol does not erase product boundaries.

Confirm the current tool catalog, plan, region, scopes, rate limits, terms, and write behavior before implementation.

Editorial assessment

Access-maturity dimensions

A comparative architecture lens—not a quality score, market ranking, or buying recommendation. Scale: 1–5.

Data access4
Action access4
Event access4
Identity4
Governance4
Agent access4
UI extensibility4
Portability4
Observability3
Documentation5

Proposed customer-shaped experiences

What customers could create on top.

The output could be an export, report, graph, artifact, application, agent, workflow, or downstream feed. These proposals are derived from documented access—not claims that Automattic ships them.

Single-platform patterns

  • Editorial, publishing, and site-management studio
  • Campaign asset assembly room
  • Brief-to-experience studio
  • Content approval queue
Use in the brief builder →

Multi-platform compositions

  • WordPress.com + CRM or campaign platform: campaign asset assembly room
  • WordPress.com + work-management system + analytics or distribution platform: cross-system decision workspace
Explore composition recipes →

Evidence and dates

First-party references, with publisher and review dates separated

“Publisher updated” is shown only when the page exposes an update date. “BYO-UI reviewed” records when this research checked the reference. A missing publisher date is reported as missing—not replaced with the review date.

4 recorded sources
MCPRepresentative source
https://developer.wordpress.com/docs/mcp/ ↗

WordPress.com uses OAuth 2.1 and user approval for tool calls. Full write capabilities arrived in 2026. Distinguish the managed WordPress.com server from the separate WordPress/mcp-adapter for self-hosted sites and…

Publisher updated
Jun 19, 2026
BYO-UI reviewed
Jul 12, 2026

Targeted first-party MCP/agent-role review; broader API inventory retained

APISource inventory
https://developer.wordpress.com/docs/api/ ↗

First-party API reference or API overview recorded for this platform.

Publisher updated
Oct 7, 2025
BYO-UI reviewed
Jul 12, 2026

Full-profile first-party re-verification on 2026-07-12; see the private audit ledger.

Developer docsSource inventory
https://developer.wordpress.com/ ↗

First-party developer documentation or platform overview.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

HomepageSource inventory
https://wordpress.com/ ↗

First-party product homepage used to confirm product identity and current positioning.

Publisher updated
Not stated by publisher
BYO-UI reviewed
Jul 10, 2026

Inventory source: structurally normalized; content was not individually reopened in this pass.

Verified fact

Tied to cited first-party evidence reviewed for this profile.

Source inventory

Official links recorded for deeper research but not necessarily reopened endpoint by endpoint.

Editorial assessment

System role, maturity interpretation, and architectural boundary.

Proposed design

Interface patterns and compositions—not vendor product claims.