{"id":342371,"date":"2026-09-03T08:53:17","date_gmt":"2026-09-03T08:53:17","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/sigma-mcp-connector\/"},"modified":"2026-09-03T08:52:54","modified_gmt":"2026-09-03T08:52:54","slug":"sigma-mcp-connector","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/sigma-mcp-connector\/","author":23451260,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"1.0.0","stable_tag":"1.0.0","tested":"7.0.4","requires":"6.0","requires_php":"8.0","requires_plugins":null,"header_name":"Sigma MCP Connector","header_author":"Sigma Development Team","header_description":"MCP server for Claude, Codex, VS Code, Cursor AI, and other MCP clients. Implements OAuth 2.0 Authorization Code + PKCE and exposes WordPress content via authenticated, role-aware JSON-RPC 2.0 tools.","assets_banners_color":"647a6e","last_updated":"2026-09-03 08:52:54","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"https:\/\/www.sigmainfo.net\/","rating":0,"author_block_rating":0,"active_installs":0,"downloads":30,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"1.0.0":{"tag":"1.0.0","author":"sigmadev","date":"2026-09-03 08:52:54","revision":3679372}},"upgrade_notice":{"1.0.0":"<p>Initial release. No upgrade steps required.<\/p>"},"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3679372,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3679372,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3679372,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3679372,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["1.0.0"],"block_files":[],"assets_screenshots":{"screenshot-1.png":{"filename":"screenshot-1.png","revision":3679946,"resolution":"1","location":"assets","locale":"","width":1012,"height":1181},"screenshot-2.png":{"filename":"screenshot-2.png","revision":3679946,"resolution":"2","location":"assets","locale":"","width":1130,"height":604}},"screenshots":{"1":"<strong>Connections<\/strong> \u2014 OAuth client management, active tokens, and live OAuth\/MCP URLs","2":"<strong>Activity Log<\/strong> \u2014 Filterable, paginated audit trail of every OAuth and tool-call event","3":"<strong>Documentation<\/strong> \u2014 Per-client setup instructions and the live Role Access Matrix","4":"<strong>OAuth Consent Screen<\/strong> \u2014 What the authorizing WordPress user sees and approves"}},"plugin_section":[],"plugin_tags":[2353,1556,229563,242115,2061],"plugin_category":[38],"plugin_contributors":[258020],"plugin_business_model":[],"class_list":["post-342371","plugin","type-plugin","status-publish","hentry","plugin_tags-ai","plugin_tags-api","plugin_tags-claude","plugin_tags-mcp","plugin_tags-oauth","plugin_category-authentication","plugin_contributors-sigmadev","plugin_committers-sigmadev"],"banners":{"banner":"https:\/\/ps.w.org\/sigma-mcp-connector\/assets\/banner-772x250.png?rev=3679372","banner_2x":"https:\/\/ps.w.org\/sigma-mcp-connector\/assets\/banner-1544x500.png?rev=3679372","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/sigma-mcp-connector\/assets\/icon-128x128.png?rev=3679372","icon_2x":"https:\/\/ps.w.org\/sigma-mcp-connector\/assets\/icon-256x256.png?rev=3679372","generated":false},"screenshots":[{"src":"https:\/\/ps.w.org\/sigma-mcp-connector\/assets\/screenshot-1.png?rev=3679946","caption":"<strong>Connections<\/strong> \u2014 OAuth client management, active tokens, and live OAuth\/MCP URLs"},{"src":"https:\/\/ps.w.org\/sigma-mcp-connector\/assets\/screenshot-2.png?rev=3679946","caption":"<strong>Activity Log<\/strong> \u2014 Filterable, paginated audit trail of every OAuth and tool-call event"}],"raw_content":"<!--section=description-->\n<p><strong>Sigma MCP Connector<\/strong> implements the Model Context Protocol (MCP) on top of your WordPress site, so AI assistants can act on your content as a real, authenticated WordPress user \u2014 never anonymously, never with more access than that user already has.<\/p>\n\n<p>It exposes a JSON-RPC 2.0 MCP endpoint secured by a full OAuth 2.0 Authorization Code + PKCE flow. An administrator registers each AI client (Claude.ai, Codex, VS Code, Cursor AI, or any other MCP-aware tool) as an OAuth client; a WordPress user then explicitly signs in and approves a consent screen before that client can do anything. From then on, every tool call is checked against that specific user's WordPress capabilities and written to a full audit log.<\/p>\n\n<h4>Key Features<\/h4>\n\n<ul>\n<li><strong>OAuth 2.0 + PKCE<\/strong> \u2014 Authorization Code grant with mandatory PKCE, hashed client secrets, short-lived access tokens, and long-lived refresh tokens<\/li>\n<li><strong>27 Role-Aware MCP Tools<\/strong> \u2014 Read and write posts, pages, media, taxonomies, menus, ACF fields, post meta, and users, each gated by a specific WordPress capability<\/li>\n<li><strong>Live Role Access Matrix<\/strong> \u2014 Generated at runtime from real WordPress role capabilities, shown identically on the Connections page, the Documentation page, and the OAuth consent screen, so it can never drift out of sync with what's actually enforced<\/li>\n<li><strong>Per-Role Rate Limiting<\/strong> \u2014 Configurable request ceilings so no single connection can overwhelm the site<\/li>\n<li><strong>Full Activity Log<\/strong> \u2014 Filterable, paginated audit trail of every OAuth and tool-call event, with before\/after snapshots on content-mutating calls and configurable retention<\/li>\n<li><strong>Built-In Setup Documentation<\/strong> \u2014 Step-by-step configuration instructions for Claude.ai, Claude Desktop, Codex, VS Code (GitHub Copilot), and Cursor AI<\/li>\n<li><strong>No External Dependencies<\/strong> \u2014 No bundled third-party service, no analytics, no phone-home; the plugin only responds to requests from clients you explicitly register and authorize<\/li>\n<\/ul>\n\n<h4>Who Is This For?<\/h4>\n\n<ul>\n<li><strong>Site owners<\/strong> who want to let an AI assistant help manage content without handing out admin passwords or API keys with unlimited access<\/li>\n<li><strong>Agencies and developers<\/strong> building AI-assisted editorial workflows on top of WordPress<\/li>\n<li><strong>Teams<\/strong> who need an auditable, revocable, role-scoped way to connect AI tools to a WordPress site<\/li>\n<\/ul>\n\n<h3>Additional Information<\/h3>\n\n<h4>System Requirements<\/h4>\n\n<p><strong>Minimum<\/strong>\n* WordPress 6.0\n* PHP 8.0\n* MySQL 5.7 or MariaDB 10.3<\/p>\n\n<p><strong>Recommended<\/strong>\n* HTTPS enabled\n* Pretty permalinks enabled<\/p>\n\n<h4>Custom Database Tables<\/h4>\n\n<ul>\n<li><code>{prefix}sigma_mcp_oauth_clients<\/code> \u2014 Registered OAuth applications<\/li>\n<li><code>{prefix}sigma_mcp_oauth_codes<\/code> \u2014 Short-lived, single-use authorization codes<\/li>\n<li><code>{prefix}sigma_mcp_oauth_tokens<\/code> \u2014 Access and refresh tokens<\/li>\n<li><code>{prefix}sigma_mcp_log<\/code> \u2014 Legacy per-call log<\/li>\n<li><code>{prefix}sigma_mcp_event_log<\/code> \u2014 Full structured audit log<\/li>\n<\/ul>\n\n<h4>Support<\/h4>\n\n<ul>\n<li><strong>Support Forum:<\/strong> https:\/\/wordpress.org\/support\/plugin\/sigma-mcp-connector\/<\/li>\n<li><strong>Email:<\/strong> mahipatsinh.r@sigmainfo.net<\/li>\n<\/ul>\n\n<!--section=installation-->\n<h4>From the WordPress Plugin Directory<\/h4>\n\n<ol>\n<li>Go to <strong>Plugins &gt; Add New<\/strong> in your WordPress admin<\/li>\n<li>Search for <strong>Sigma MCP Connector<\/strong><\/li>\n<li>Click <strong>Install Now<\/strong>, then <strong>Activate<\/strong><\/li>\n<li>Navigate to <strong>Sigma MCP<\/strong> in the admin sidebar to get started<\/li>\n<\/ol>\n\n<h4>Manual Installation<\/h4>\n\n<ol>\n<li>Download the plugin ZIP file<\/li>\n<li>Go to <strong>Plugins &gt; Add New &gt; Upload Plugin<\/strong><\/li>\n<li>Select the ZIP file and click <strong>Install Now<\/strong><\/li>\n<li>Activate the plugin<\/li>\n<li>Navigate to <strong>Sigma MCP<\/strong> in the admin sidebar<\/li>\n<\/ol>\n\n<h4>After Activating<\/h4>\n\n<ol>\n<li>Go to <strong>Sigma MCP \u2192 Connections<\/strong> and generate an OAuth client for the AI tool you want to connect.<\/li>\n<li>Copy the Authorization URL, Token URL, and MCP Server URL shown there.<\/li>\n<li>Follow <strong>Sigma MCP \u2192 Documentation<\/strong> for exact setup steps in Claude.ai, Claude Desktop, Codex, VS Code, or Cursor AI.<\/li>\n<li>Approve the WordPress consent screen when the client first connects.<\/li>\n<\/ol>\n\n<p>HTTPS is strongly recommended in production \u2014 OAuth tokens should not travel over plain HTTP. Pretty permalinks must be enabled so <code>\/wp-json\/...<\/code> and <code>\/.well-known\/...<\/code> requests resolve correctly.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20this%20plugin%20send%20my%20data%20to%20claude%2C%20openai%2C%20or%20any%20other%20third%20party%3F\"><h3>Does this plugin send my data to Claude, OpenAI, or any other third party?<\/h3><\/dt>\n<dd><p>No, not automatically. Sigma MCP Connector does not make outbound connections to any AI provider and does not phone home for analytics, licensing, or updates. It works the other way around: it turns your own WordPress site into an MCP server that a client you explicitly register can connect <strong>into<\/strong> \u2014 and only after a logged-in WordPress user explicitly approves an OAuth consent screen naming that specific client. From that point on, every request runs as that WordPress user, restricted to their existing WordPress role and capabilities, and is written to the Activity Log.<\/p><\/dd>\n<dt id=\"what%20can%20a%20connected%20ai%20tool%20actually%20do%3F\"><h3>What can a connected AI tool actually do?<\/h3><\/dt>\n<dd><p>Exactly what the authorizing WordPress user's role allows \u2014 nothing more. Every one of the 27 tools is checked with <code>current_user_can()<\/code> against a specific WordPress capability on every single call, not just at connection time. Revoke the user's role, or revoke the token from the Connections page, and access stops immediately.<\/p><\/dd>\n<dt id=\"what%20data%20is%20stored%2C%20and%20where%3F\"><h3>What data is stored, and where?<\/h3><\/dt>\n<dd><p>OAuth client registrations, tokens, and the activity log are stored in five plugin-owned database tables on your own WordPress database \u2014 nothing is sent off-site. You control log retention (or disable it) from the Activity Log screen.<\/p><\/dd>\n<dt id=\"which%20ai%20tools%20does%20this%20work%20with%3F\"><h3>Which AI tools does this work with?<\/h3><\/dt>\n<dd><p>Any MCP-aware client that supports OAuth 2.0 Authorization Code + PKCE \u2014 Claude.ai, Claude Desktop, Codex, VS Code (GitHub Copilot), and Cursor AI are documented in detail on the plugin's Documentation screen, with copy-paste config examples for each.<\/p><\/dd>\n<dt id=\"can%20i%20revoke%20access%3F\"><h3>Can I revoke access?<\/h3><\/dt>\n<dd><p>Yes. Deactivate or delete an OAuth client, or revoke an individual token or all tokens for a user, from <strong>Sigma MCP \u2192 Connections<\/strong> \u2014 access is checked on every request, so revocation takes effect immediately.<\/p><\/dd>\n<dt id=\"does%20this%20require%20https%3F\"><h3>Does this require HTTPS?<\/h3><\/dt>\n<dd><p>It works over HTTP for local development, but HTTPS is strongly recommended (and the admin screen will warn you) in production, since OAuth access and refresh tokens should never travel unencrypted.<\/p><\/dd>\n<dt id=\"what%20happens%20if%20i%20deactivate%20the%20plugin%3F\"><h3>What happens if I deactivate the plugin?<\/h3><\/dt>\n<dd><p>Deactivating stops the OAuth\/MCP endpoints and clears the scheduled log-purge cron job, but does not delete any data. Uninstalling (deleting) the plugin removes its database tables, options, and transients.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>1.0.0<\/h4>\n\n<p>Initial release.<\/p>\n\n<ul>\n<li>OAuth 2.0 Authorization Code + PKCE flow with client registration, token issuance\/refresh\/revocation, and a WordPress-native consent screen<\/li>\n<li>MCP server endpoint (JSON-RPC 2.0) exposing 27 role-aware tools<\/li>\n<li>Per-tool WordPress capability checks enforced on every call, plus per-role rate limiting<\/li>\n<li>Role Access Matrix generated at runtime from real WordPress role capabilities<\/li>\n<li>Connections, Activity Log, and Documentation admin screens<\/li>\n<li>Custom database tables: OAuth clients, authorization codes, tokens, and event log<\/li>\n<li>Nonce verification, capability checks, prepared statements, and full output escaping throughout<\/li>\n<\/ul>","raw_excerpt":"Turn WordPress into a secure, role-scoped MCP server so Claude, Codex, VS Code, and Cursor AI can read and edit content via OAuth 2.0.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/342371","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=342371"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/sigmadev"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=342371"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=342371"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=342371"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=342371"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=342371"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=342371"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}