Description
Ostheimer Cockpit for WebMCP turns your WordPress site into a set of structured tools for
AI agents that run through your browser. It implements the experimental
WebMCP Draft Community Group Report,
which is not a W3C Standard. Compatible browser agents can discover what your
site can do and act on it. The plugin requires no separate MCP server and no
plugin API key.
The agent drafts; the human approves.
How it works
- Install and activate the plugin, then open the normal WordPress dashboard
or the Cockpit for WebMCP page — both register the agent tools in your
browser. A native dashboard box shows the live status and quick links. - Enable experimental WebMCP support. Chrome 149+ offers an origin trial and
a local testing flag; the cockpit links to the current Chrome instructions. - Tell your browser’s AI agent what to do, for example:
“Write a draft post about pumpkin recipes and submit it for review.” - The agent drafts the content and submits it with the status
Zur Prüfung (pending review) — it never publishes on its own. - You review the draft in the review queue and approve it with one click.
Tool registration and WordPress requests run in your browser tab and your own
WordPress installation. The plugin itself does not send content to the plugin
developer or another third-party service. Your chosen browser, AI agent, or
extension may process prompts, page content, tool inputs, or tool results on
external systems under its provider’s terms and privacy policy.
Agent tools included
create_post/update_post— common core post fields: title, content,
excerpt, slug, author, scheduling date (planned posts), comment and ping
status, password protection, sticky, post format, page attributes
(parent, template, order).- Featured images in one step — the agent passes an image URL or uploads
self-generated images as Base64 (PNG, JPEG, WebP, GIF), the plugin puts
them into the media library and sets the featured image. - Taxonomies by name —
categories_names/tags_namesresolve names to
terms; missing tags are created automatically. - SEO fields are written to Yoast SEO or Rank Math automatically when
active, so agents can set meta titles and descriptions where your SEO
plugin actually reads them. list_posts,get_post,get_post_markdown— search and read content in
agent-friendly formats.list_terms,get_site_info,get_activity— context and audit trail.upload_media,upload_media_base64— media library uploads.- Developers can register their own agent tools with the
webmcp_cockpit_tools filter — anything a PHP callback can do becomes an
agent tool.
Safe by design
- Agent content lands in a dedicated review status, invisible to visitors.
- Publishing is only possible from the review queue, and only for users with
the publish capability. - Successful and failed agent tool calls plus workflow actions are written to
a controllable activity log with timestamp and user. Read entries contain
metadata only, never post content, search terms, tool inputs or tool results. - Session-bound authentication with a dedicated workflow nonce; per-user rate
limiting on write operations. - Works with caching plugins (Autoptimize, WP Rocket, LiteSpeed Cache,
W3 Total Cache, SG Optimizer) and with the Classic Editor and Gutenberg.
For developers
The cockpit is extensible: register custom tools via
apply_filters( ‘webmcp_cockpit_tools’, $tools ) with a name, description,
JSON schema and PHP callback. Custom tools appear alongside the built-in ones
in the browser agent’s tool list.
Screenshots


Installation
- Upload the
ostheimer-webmcp-cockpitfolder to/wp-content/plugins/, or install it through the WordPress plugin directory. - Activate the plugin through the Plugins screen.
- Open the normal WordPress dashboard or Cockpit for WebMCP in your admin menu. The dashboard box shows the live registration status and quick links.
- Keep that dashboard or cockpit tab open and talk to your browser’s AI agent.
Requirements: WordPress 6.0+, PHP 7.4+, and a browser or extension that
implements the experimental WebMCP API (document.modelContext). Chrome 149+
offers WebMCP through an origin trial or the
chrome://flags/#enable-webmcp-testing flag for local testing. WebMCP is in
early preview and its API may change.
FAQ
-
Can the AI agent publish posts on its own?
-
No. By design the agent can only create or update drafts and content in the
dedicated review status. Published or scheduled content cannot be changed or
moved by an agent. Publishing is a separate, capability-protected action that
a human performs in the review queue. -
Which AI agents work with this?
-
Any compatible browser agent or extension that uses the experimental WebMCP
API (document.modelContext). The Model Context Tool Inspector can list and
manually call tools for testing. Its natural-language prompts may be processed
by an external AI provider, so review the extension’s current terms before
using private content. -
Does it send my content to external services?
-
The plugin itself does not send your content to the plugin developer or another
third-party service. Tool calls reach your own WordPress REST API using your
logged-in session. However, the browser, AI agent, or extension you choose may
send prompts, page content, tool inputs, or tool results to its provider.
Review that provider’s terms and privacy policy before using private content. -
Do I need an MCP server or API keys?
-
No separate MCP server or plugin API key is required. The tools live on the
WordPress admin page and the browser mediates between the agent and that page.
The browser agent itself may still require its own account or configuration. -
Which browsers are supported?
-
Chrome 149+ exposes experimental WebMCP through an origin trial or the
chrome://flags/#enable-webmcp-testing flag for local testing. Other browsers
or extensions can work if they implement the current draft. WebMCP is an early
preview, not a W3C Standard, and support may change. WordPress continues to
work normally when WebMCP is unavailable. -
Does it work with Yoast SEO / Rank Math?
-
Yes. SEO title, meta description and canonical URL written by the agent go
directly into the active SEO plugin’s fields. Without an SEO plugin, portable
custom fields are used. -
What is the upload size limit for agent images?
-
Base64 image uploads accept PNG, JPEG, WebP and GIF up to
min( wp_max_upload_size(), 10 MB ) of decoded data. The JSON request body is
roughly 1.37× the image size, so your host’spost_max_sizemust be at least
that; the error message names the exact limit when it is exceeded. -
Does it work with WooCommerce or custom post types?
-
Posts and pages are supported out of the box. Additional post types and
capabilities can be added with thewebmcp_cockpit_toolsfilter — for
example WooCommerce product tools. -
Who can use the agent tools?
-
Only logged-in users with the
edit_postscapability (authors, editors,
administrators). Media uploads additionally requireupload_files,
publishing requires the publish capability. Guests and subscribers get
nothing.
Reviews
There are no reviews for this plugin.
Contributors & Developers
“Ostheimer Cockpit for WebMCP” is open source software. The following people have contributed to this plugin.
ContributorsTranslate “Ostheimer Cockpit for WebMCP” into your language.
Interested in development?
Browse the code, check out the SVN repository, or subscribe to the development log by RSS.
Changelog
1.0.11
- Renames the plugin to Ostheimer Cockpit for WebMCP and aligns the plugin
folder, main file and text domain withostheimer-webmcp-cockpit. - Limits post-list results to posts the current user is allowed to edit, with
regression coverage for separate author accounts. - Moves the plugin pages below WordPress Tools and removes the obsolete
manual translation loader and bundled runtime translation files. - Makes Plugin Check warnings fail the release check.
1.0.10
- Refines the WordPress dashboard box with a clearer action hierarchy, compact
native buttons and consistent spacing in narrow dashboard columns. - Keeps the copy action beside the prompt label and gives the review queue
primary emphasis above the two secondary links.
1.0.9
- Registers all WebMCP tools on the normal WordPress start dashboard (
/wp-admin/)
in addition to the dedicated Cockpit page. - Adds a native, draggable dashboard box with live tool status, a copyable
example prompt, review count, and links to the Cockpit and activity log. - Adds server-side regression coverage for the dashboard widget and asset host.
1.0.8
- Adds a complete metadata-only audit trail for successful and failed WebMCP
tool calls, including read tools such aslist_postsandget_post. - Adds administrator filters for read/write and tool/workflow events, bulk
selection, and nonce-protected deletion of selected, filtered or all log
entries. Agents cannot delete the audit log. - Adds an automatic database migration for the activity type and tool-name
columns when updating the plugin in place.
1.0.7
- Enforces the human review boundary: browser agents cannot update, publish or
unpublish published or scheduled content; only the review queue can publish. - Completes the
create_postandupdate_postschemas for author, scheduling,
password, sticky, post format, page attributes and canonical URL fields. - Keeps agent-facing source output in English and clarifies that the activity
log records agent write actions.
1.0.6
- Tool errors now return a machine-readable signal (
isError: trueplus a
stablecode, following the MCP CallToolResult convention) instead of
relying on localized text prefixes. The readable, translatable message
stays unchanged. - Clarifies that WebMCP is experimental and distinguishes the plugin’s own
data handling from external processing by a chosen browser or AI agent.
1.0.5
- Sharper agent-facing tool descriptions: http(s)-only URLs for
upload_media, formats/size limit/filename handling for
upload_media_base64, precedence and failure behaviour for
featured_image_url/featured_media_id, and the warning behaviour of
create_post when a featured image fails. - Regression suite (
tests/) and documentation for server-side edge cases.
1.0.4
- i18n: the plugin source is now fully English and translation-ready.
A German (de_DE) translation ships with the plugin.
1.0.3
- Fix: a failed featured-image import from
featured_image_url(e.g. a URL
that returns no image) no longer reports success and no longer touches an
existing featured image; imported attachments are verified as real images
from the downloaded bytes, failed imports are cleaned up. - Fix: error messages now name the originally submitted value for invalid
media IDs (e.g.-5) and distinguish URL format errors from network/DNS
errors.
1.0.2
- Fix: invalid
featured_media_idvalues now return a clear error instead of
a silent success; attachments are validated for existence and image type. - Fix: rejected media uploads (wrong type, broken Base64, size limit) are now
recorded in the activity log asmedia_rejectedentries.
1.0.1
- New:
upload_media_base64tool — agents can upload self-generated images
(PNG, JPEG, WebP, GIF) directly into the media library without a public URL.
Real MIME type is verified from the decoded bytes; size capped at 10 MB. - New:
featured_media_idparameter forcreate_post/update_post— assign
a featured image from an existing media ID (takes precedence over
featured_image_url). - Tool errors now return readable messages to the agent.
1.0.0
- Initial release: 10 agent tools for creating, updating and reviewing posts,
full post field coverage, featured images from URL, taxonomy assignment by
name, SEO plugin integration (Yoast SEO, Rank Math), review workflow with
human approval, activity log, rate limiting and a PHP API for custom tools.
