TL;DR: WooCommerce ships its own MCP integration. It is off by default, still labelled a developer preview, and changed its recommended setup in August 2026.
- Turn it on under WooCommerce → Settings → Advanced → Features → WooCommerce MCP, or set the option
woocommerce_feature_mcp_integration_enabledtoyes. - Connect to
/wp-json/mcp/mcp-adapter-default-serverwith a WordPress Application Password. The older/wp-json/woocommerce/mcpendpoint with anX-MCP-API-Keyheader still works but is deprecated. - Since 10.9 the store exposes seven abilities: query, create, update and delete products; query orders, change an order's status, add an order note. There are no refunds, customers or coupons.
- MCP answers when the AI asks. It cannot tell anything that an order just came in.
/ Status
Does WooCommerce have a built-in MCP server?
Yes. WooCommerce 10.3 added an MCP integration as a beta in October 2025, and it is still in core in the current 11.1 releases. The WooCommerce MCP documentation calls it a developer preview that "may change", and the feature is registered as experimental and disabled by default.¹
It is not a separate server. WooCommerce registers its store operations as abilities in the WordPress Abilities API, and the official MCP Adapter, which WooCommerce bundles, publishes them over the Model Context Protocol. That matters for two reasons. The endpoint, authentication and tool layout are the same as any WordPress MCP server. And abilities from other plugins on the site appear on the same server, next to WooCommerce's own.
/ Enable
How do you enable WooCommerce MCP?
In the admin, open WooCommerce → Settings → Advanced → Features and tick WooCommerce MCP under Experimental features. Its description is a fair summary of the whole feature: "AI-generated results and actions can be unpredictable - please review before executing in your store." Permalinks must not be set to Plain, because the endpoint lives under /wp-json/.
From the command line the switch is one option, which is the version to put in a provisioning script:
Shell — enable WooCommerce MCP and check the tools respond
# The feature flag. Gates the MCP endpoints only; abilities register either way. wp option update woocommerce_feature_mcp_integration_enabled yes # Local smoke test over STDIO, no HTTP or credentials involved. echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' \ | wp mcp-adapter serve --server=mcp-adapter-default-server --user=admin
The flag gates the MCP endpoints only. The abilities themselves are registered on every request whether it is on or not, and stay reachable through the Abilities REST API at /wp-json/wp-abilities/v1/. Turning the flag off closes the MCP door, not every door.
/ Auth
Which endpoint and credentials should an MCP client use?
The adapter's default server, https://yourstore.com/wp-json/mcp/mcp-adapter-default-server, with a WordPress username and an Application Password from Users → Profile. WooCommerce's documentation is specific: "Do not use your account password or a WooCommerce REST API key." The server admits any logged-in user with the read capability, and each ability then runs its own permission check. So the client can do exactly what that user can do. Create a dedicated user with the narrowest role that covers the job, not an administrator.
If you followed a tutorial from late 2025, you will have a different setup: the endpoint /wp-json/woocommerce/mcp, and a header X-MCP-API-Key carrying a WooCommerce REST API key as ck_…:cs_…. That is the original 10.3 design. In August 2026 WooCommerce marked it deprecated and said it should not be used for new integrations. It still works, and it has quirks worth knowing if you maintain one:
- It enforces HTTPS in code and answers 403
insecure_transportotherwise. - The key's permission maps to HTTP methods:
readallows GET,writeallows POST, PUT, PATCH and DELETE, andread_writeallows both. - It serves a different set of nine REST-derived abilities, not the seven below.
Plan the move now rather than when a release removes it.
/ Connect
How do you connect Claude Code, Claude Desktop or Cursor?
Most desktop clients speak MCP over STDIO, so a small local proxy translates to HTTP and adds the credentials. WooCommerce documents @automattic/mcp-wordpress-remote, which runs through npx and needs Node 18 or newer:
JSON — mcpServers entry for Claude Desktop, Claude Code or Cursor
{ "mcpServers": { "woocommerce_store": { "command": "npx", "args": ["-y", "@automattic/mcp-wordpress-remote@latest"], "env": { "WP_API_URL": "https://yourstore.com/wp-json/mcp/mcp-adapter-default-server", "WP_API_USERNAME": "mcp-agent", "WP_API_PASSWORD": "abcd efgh ijkl mnop qrst uvwx" } } } }
In Claude Code the same thing is one command: claude mcp add --env WP_API_URL=… --env WP_API_USERNAME=… --env WP_API_PASSWORD='…' woocommerce_store -- npx -y @automattic/mcp-wordpress-remote@latest. VS Code uses a servers key instead of mcpServers. On a local site where the client runs on the same machine, you can skip HTTP entirely and point the client at wp mcp-adapter serve, as in the smoke test above.
Two things in the proxy's README trip people up. Its table says OAuth is enabled by default, but the source only enables it when OAUTH_ENABLED is exactly true, so the config above needs nothing extra. And the WOO_CUSTOMER_KEY variables it lists belong to an older, separate MCP plugin. WooCommerce core does not read them.
/ Abilities
What can an AI client actually do in the store?
Seven things, the purpose-built abilities WooCommerce added in 10.9:
| Ability | What it does | Marked |
|---|---|---|
woocommerce/products-query | Find products by id or common catalogue filters | read-only |
woocommerce/product-create | Create a product | — |
woocommerce/product-update | Change a product | destructive |
woocommerce/product-delete | Trash, restore, or with force: true permanently delete | destructive |
woocommerce/orders-query | Find orders; line items only with include_line_items: true | read-only |
woocommerce/order-update-status | Move an order to another status | destructive |
woocommerce/order-add-note | Add a note to an order | — |
What is missing is as useful to know: refunds, customers, coupons, reports, variations, categories, shipping, taxes and settings. There is also no order creation and no general order edit. An agent asked to "refund order 1042" has no ability that does it and will say so, or, worse, try to improvise with a status change.
Your client will not list these seven as tools. The default server exposes three meta-tools, discover-abilities, get-ability-info and execute-ability, and every WooCommerce operation is a call to the third with an ability_name. The MCP server article walks through that design and the session header it depends on.
/ Extend
Why does a custom ability not appear on a WooCommerce site?
Usually the adapter version. WooCommerce bundles its own copy of the MCP Adapter, v0.3.0 in the current lock file, while the standalone adapter is at 0.6.1. When several plugins bundle different copies, whichever the autoloader resolves first serves the request. Older copies only honour the nested mcp.public flag. So declare both flags, as WooCommerce's own abilities do:
PHP — an ability that shows up on every adapter version
add_action( 'wp_abilities_api_init', function () { wp_register_ability( 'my-shop/low-stock-report', [ 'label' => 'Low stock report', 'description' => 'Products at or below their low-stock threshold.', 'category' => 'my-shop', 'input_schema' => [ 'type' => 'object', 'default' => [] ], 'execute_callback' => 'my_shop_low_stock_report', 'permission_callback' => fn() => current_user_can( 'edit_products' ), 'meta' => [ 'show_in_rest' => true, // Newer adapters read this; bundled older copies read only the next line. 'mcp' => [ 'public' => true, 'type' => 'tool' ], ], ] ); } );
The woocommerce/ namespace is reserved for core, so use your own prefix. Two details in that snippet save debugging time. The default on the input schema lets a call with no arguments validate. And the permission callback is the real security boundary: an ability open to read is open to every account that can log in.
/ Push
Can WooCommerce MCP tell you when an order comes in?
No. MCP is request and response, started by the client. The agent learns about order 1042 when someone asks it to look, never when the order is placed. That is the same pull-versus-push line drawn in webhook vs API: MCP gives an AI client an API into your store, and "when this happens, do that" needs a webhook.
The two meet in a useful place. Any plugin whose abilities are public appears on the same MCP server. So in one conversation an agent can read orders through WooCommerce's abilities and then set up the outgoing webhook that sends every future paid order to a CRM, a warehouse or Slack.
| Job | WooCommerce MCP alone | Plus Webhook Actions on the same server |
|---|---|---|
| Answer "which orders are on hold?" | Yes: orders-query | Same. It does not replace the store abilities |
| Refund an order, edit a customer, create a coupon | No ability exists | Not this either. It does not add store abilities |
| Send each new order to another system as it happens | Not possible: MCP only answers when asked | The agent creates a webhook on any WooCommerce hook; delivery runs queued and retried with no agent involved |
| Know when a delivery failed | — | Delivery log, plus failure notifications by email, Slack and other channels |
| Stop an agent from deleting live config by accident | Your client's approval prompt | Destructive abilities refuse to run (HTTP 428) until re-sent with "confirmed": true |
| Keep agents to read-only | A narrower user role | One setting hides every write ability from the Abilities and MCP surface |
Seeing it run beats reading about it. The live preview boots a throwaway WordPress with Webhook Actions already installed and demo deliveries sitting in the log — no signup, nothing left on your machine afterwards.
/ Exposure
What does WooCommerce MCP not protect you from?
Personal data in the model's context. An order query returns names, emails, addresses and payment details, and whatever the client sends to its model provider goes with them. WooCommerce's own documentation raises this. Decide whether that is acceptable under your privacy policy before connecting a production store, not after.
Text the model reads as instructions. Order notes, product reviews and customer-entered fields are written by strangers. An agent that reads them while holding write access can be steered by them. Keep write abilities on a separate, deliberately-used connection, and read-only users for everything routine.
A credential in a dotfile. The Application Password sits in plain text in the client's config. Never commit that file, give the user a narrow role, and revoke the password from the profile screen when the experiment ends.
A preview's breaking changes. The endpoint and auth already changed once in ten months. WooCommerce recommends testing on staging, and logs every call under WooCommerce → Status → Logs with the source woocommerce-mcp. Read those logs after a session, because they record what the agent actually did, which is not always what it told you.
mcp_integration, the experimental flag and default-off state read from FeaturesController.php; the seven abilities from AbilitiesLoader.php. Both on trunk, identical to the 11.1.2 release, read 2026-09-28.