Title: Zloj MCP
Author: zloj.ru
Published: <strong>September 29, 2026</strong>
Last modified: September 29, 2026

---

Search plugins

![](https://ps.w.org/zloj-mcp/assets/banner-772x250.png?rev=3718678)

![](https://ps.w.org/zloj-mcp/assets/icon-256x256.png?rev=3718678)

# Zloj MCP

 By [zloj.ru](https://profiles.wordpress.org/zlojru/)

[Download](https://downloads.wordpress.org/plugin/zloj-mcp.0.3.11.zip)

 * [Details](https://wordpress.org/plugins/zloj-mcp/#description)
 * [Reviews](https://wordpress.org/plugins/zloj-mcp/#reviews)
 *  [Installation](https://wordpress.org/plugins/zloj-mcp/#installation)
 * [Development](https://wordpress.org/plugins/zloj-mcp/#developers)

 [Support](https://wordpress.org/support/plugin/zloj-mcp/)

## Description

Zloj MCP exposes a JSON-RPC HTTP endpoint for MCP clients. Access is gated by a 
bearer token and an optional per-token IP allow list. Read, create, update, and 
delete access can be configured per entity (posts, media, and more).

Each access token belongs to one WordPress user. Tool calls run with that user’s
capabilities, and content created through MCP is authored by that user. The author
cannot be overridden. Users can be listed and read; the plugin does not create, 
update, or delete WordPress users.

Settings are on **Settings  Zloj MCP** (administrators only). Several tokens can
be stored; each is a salt and hash, and the owner’s user ID is part of the hash.
Changing that user ID in the database makes the token stop working. A token migrated
from older single-token storage is not bound this way until you delete it and create
a new one. The owner of an existing token cannot be changed in the settings screen.

#### MCP tools

Read: `post_type_list`, `post_list`, `post_get`, `user_list`, `user_get`, `term_list`,`
media_list`, `comment_list`, `comment_get`.

Write (when enabled): `post_create`, `post_update`, `post_delete`, `media_sideload`,`
media_update`, `media_delete`, `comment_create`, `comment_update`, `comment_approve`,`
comment_spam`, `comment_delete`.

Post meta is read and written via the `meta` field on the post tools. User meta 
is read-only via `user_get` / `user_list`.

## Installation

 1. Upload the plugin folder to `/wp-content/plugins/` or install from the WordPress
    plugin directory.
 2. Activate the plugin through the Plugins screen.
 3. Open **Settings  Zloj MCP** as an administrator, create a token for a user, and
    enable access.

## FAQ

### What is the endpoint URL?

The settings screen shows the full URL, typically `https://example.com/zloj-mcp/`(
path is configurable).

### How do clients authenticate?

Send `Authorization: Bearer <token>` on each request.

### How does Claude sign in?

 1. Use any permalink structure except Plain.
 2. In Settings  Zloj MCP, generate a token and copy it before saving, leave its IP
    list empty, turn on Enable MCP access, allow the entities you need, and save.
 3. In Claude, open Settings  Connectors  Add custom connector. Enter the endpoint 
    URL shown in the plugin settings (for example `https://example.com/zloj-mcp/`).
    Leave the OAuth Client ID and Secret empty.
 4. Click Connect. Claude opens a page styled like the WordPress login screen with 
    one token field. Paste the token and click Authorize.

The token you paste is the one Claude keeps. It does not expire. Each token is a
separate connection. Claude connects from Anthropic’s servers, so a token with an
IP list is refused, and the site must be reachable over public HTTPS.

### Example (curl)

curl -sS -H ‘Authorization: Bearer YOUR_TOKEN’ -H ‘Content-Type: application/json’-
d ‘{“jsonrpc”:”2.0″,”id”:1,”method”:”tools/list”,”params”:{}}’ https://example.com/
zloj-mcp/

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Zloj MCP” is open source software. The following people have contributed to this
plugin.

Contributors

 *   [ zloj.ru ](https://profiles.wordpress.org/zlojru/)

“Zloj MCP” has been translated into 1 locale. Thank you to [the translators](https://translate.wordpress.org/projects/wp-plugins/zloj-mcp/contributors)
for their contributions.

[Translate “Zloj MCP” into your language.](https://translate.wordpress.org/projects/wp-plugins/zloj-mcp)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/zloj-mcp/), check out
the [SVN repository](https://plugins.svn.wordpress.org/zloj-mcp/), or subscribe 
to the [development log](https://plugins.trac.wordpress.org/log/zloj-mcp/) by [RSS](https://plugins.trac.wordpress.org/log/zloj-mcp/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.3.11

 * Missing post, comment, user, or attachment IDs return MCP tool errors (`isError`,
   code `not_found`) instead of a generic JSON-RPC execution failure.
 * Existence is checked before WordPress capabilities, so a bad ID is “not found”,
   not a permission error.

#### 0.3.10

 * Fixed connecting from Claude when the URL is entered without the trailing slash:
   POST requests are no longer redirected, and the OAuth resource matches both forms.
 * GET requests for an event stream now get 405, as Streamable HTTP expects.
 * initialize negotiates the protocol version (2025-06-18, 2025-03-26, 2024-11-05).
 * All notifications get 202. An unknown method returns a JSON-RPC error with HTTP
   200 instead of 404, which clients treated as a lost session.
 * Step-by-step setup for claude.ai, Claude Desktop, and Claude Code in the FAQ 
   and README.

#### 0.3.9

 * Claude can sign in at the MCP URL. The page uses the WordPress login layout and
   asks for one existing access token.
 * Claude keeps that token and sends it as a bearer token. The token does not expire.
   Each token remains its own connection.
 * Tokens stay stored as a salt and hash. The authorization code is sealed and single-
   use.

#### 0.3.8

 * Comment tools: list (site-wide or by post, optional parent for replies), get,
   create, update, approve, spam, delete. Per-token entity access and the token 
   owner’s WordPress capabilities apply.

#### 0.3.7

 * Action log settings sit with the route and the access switch and apply to every
   token.
 * Entity access is stored per token. A new token starts with read checkboxes only.

#### 0.3.6

 * Deleting a token, including one migrated from the old single-token setting, saves
   immediately and does not restore it.

#### 0.3.5

 * The new-token tab opens first: user picker and a note filled with that user plus
   the browser date and time. Delete is only on tabs for tokens that already exist.

#### 0.3.4

 * Fix a fatal error on the settings screen when an older single token is still 
   stored.

#### 0.3.3

 * Route path and the MCP access switch are in a Connection section at the top of
   the settings screen.
 * IP allow lists are stored and checked per token. A previous site-wide list is
   kept on existing tokens until you save.

#### 0.3.2

 * Removed Site, Options, Plugins, and Themes access flags and their tools: `site_info`,`
   option_get`, `plugin_list`, `theme_list`.

#### 0.3.1

 * Removed user create, update, and delete (`user_create`, `user_update`, `user_delete`
   and the matching settings flags). Users stay read-only: `user_list` and `user_get`.

#### 0.3.0

 * Multiple access tokens, one WordPress user each, managed as tabs on the settings
   screen.
 * New token: choose the owner and a note (defaults to that user plus the browser
   date and time). Every tab except the new-token tab can be deleted.
 * Each token stores when it was created and which administrator created it. The
   owner cannot be changed; their user ID is mixed into the token hash, so editing
   that ID invalidates the token.
 * MCP calls run as the token owner. Created content uses that user as author and`
   post_author` cannot be set via MCP.
 * User create, update, and delete are allowed only when the token owner has the
   matching capabilities. Assigning a role also requires `promote_users` and a role
   that user may grant.
 * Only administrators can open or save the settings screen.
 * Action log includes the token ID used for the request.

#### 0.2.7

 * WordPress.org Plugin Check: prepared DB queries in action log list table, Tested
   up to 7.1.

#### 0.2.6

 * Lower minimum PHP version to 7.4 (replace PHP 8+ syntax with 7.4-compatible code).

#### 0.2.5

 * Fix Entity access table column alignment (Read/Create/Update/Delete).

#### 0.2.4

 * Entity access split: create, update, and delete flags per entity (replaces single
   write flag). Discovery `entities` snapshot uses the new shape; top-level `write`
   remains true when any mutate flag is on.
 * New tools: `post_delete`, `user_delete`, `media_update`, `media_delete` (media
   delete is always permanent).
 * Legacy stored `write_*` options enable create+update only; delete requires an
   explicit flag.

#### 0.2.3

 * Reject invalid attachment statuses (including trash) on post_create and post_update.

#### 0.2.2

 * Post/user meta via `meta`, `include_meta`, and `meta_keys` on existing tools;`
   user_*` tools; entity `users`.

#### 0.2.1

 * Tool `post_type_list`; per-entity read/write settings in admin (master switch
   remains access enabled).
 * Fix ToolException property conflict with PHP Exception on 8.4+.

#### 0.2.0

 * MCP tools (list/call), adapters, write guard, option denylist, media sideload
   SSRF/MIME checks.
 * Action log table, pruning, admin log screen with search and pagination.

#### 0.1.0

 * Initial release: settings, token hash storage, IP allow list, MCP JSON-RPC base
   endpoint.

## Meta

 *  Version **0.3.11**
 *  Last updated **23 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.2 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 *  Languages
 * [English (US)](https://wordpress.org/plugins/zloj-mcp/) and [Russian](https://ru.wordpress.org/plugins/zloj-mcp/).
 *  [Translate into your language](https://translate.wordpress.org/projects/wp-plugins/zloj-mcp)
 * Tags
 * [AI](https://wordpress.org/plugins/tags/ai/)[api](https://wordpress.org/plugins/tags/api/)
   [automation](https://wordpress.org/plugins/tags/automation/)[mcp](https://wordpress.org/plugins/tags/mcp/)
   [rest](https://wordpress.org/plugins/tags/rest/)
 *  [Advanced View](https://wordpress.org/plugins/zloj-mcp/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/zloj-mcp/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/zloj-mcp/reviews/)

## Contributors

 *   [ zloj.ru ](https://profiles.wordpress.org/zlojru/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/zloj-mcp/)