=== AdMindra MCP – AI Connector for ChatGPT & Claude ===
Contributors: 3onab, viktorygrahn
Tags: mcp, ai, chatgpt, claude, ai assistant
Requires at least: 6.9
Tested up to: 7.1
Requires PHP: 8.0
Stable tag: 1.1.1
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Let ChatGPT or Claude check, explain and edit the content of your site over a secure MCP server with OAuth. Content edits only when you allow them.

== Description ==

**Ask ChatGPT or Claude about your site — and let it fix the text.**

AdMindra MCP turns your site into a secure MCP server for the AI assistant you
already use. Connect ChatGPT, Claude or Claude Code in a minute, sign in with
OAuth (no passwords, no API keys), and ask in plain language:

* "Which plugins need updating, and is anything inactive?"
* "Why does the registration page show a raw shortcode?"
* "Rewrite the introduction on the About page, shorter."
* "What does this template file actually do?"

= Reads by default, edits content when you allow it =

Out of the box the assistant only reads. Switch **content edits** on under
Tools → AdMindra MCP and it can also change the title, text and excerpt of a
post or page, and the site title and tagline. The text from before each
change is kept as a revision, so it can be undone in the editor (unless
revisions are switched off in `wp-config.php`).

The assistant never installs, updates, activates, deactivates or deletes a
plugin or theme, writes a file, publishes or deletes a post, or touches users
and other settings. There is no switch that allows any of that.

* **Administrators only.** Other roles are refused at the consent screen, and
  every tool checks the `manage_options` capability on every call.
* **You approve each assistant** on a consent screen that names it, and can
  disconnect it at any time.
* **No overwrites unseen.** An edit must name the version of the post it
  read; if somebody changed it in wp-admin meanwhile, the edit is refused.
* Only files of installed plugins and themes can be read. `wp-config.php`,
  hidden files, symbolic links, and files whose names suggest secrets,
  credentials or backups are refused.

= What the assistant can do =

* Read the site status: WordPress and PHP version, and whether MCP is ready.
* List the installed plugins and themes, with versions and which are active.
* List the updates that WordPress's own update check last found, with the
  installed and offered version and whether each fits your WordPress and PHP,
  so it can tell you which to run now and which to wait with. You run them
  on WordPress's Updates screen; the assistant gives you the link.
* Check published pages for shortcodes that are not registered.
* Find and read posts and pages, and read one source file of an installed
  plugin or theme (up to 128 KiB).
* With content edits on: edit a post or page, and the site title and tagline.

= Fixing plugins and themes too =

**AdMindra MCP Maintenance** is a separate add-on that lets the same assistant
also replace plugin and theme files and run updates, with an encrypted
backup, a health check and automatic rollback. It is free with an AdMindra
account and is downloaded there, not from WordPress.org. AdMindra MCP works
fully without it.

= 100% free =

No account, no paid tier, nothing locked. AdMindra MCP sends nothing to
AdMindra. Built on the official MCP Adapter.

= Made by AdMindra =

AdMindra MCP is developed by Viktor Grahn at
[3on Reklambyrå & Webbyrå AB](https://3on.se), a Swedish web and advertising
agency, and the team behind [AdMindra](https://admindra.com).

* Documentation: [admindra.com/wordpress-plugin](https://admindra.com/wordpress-plugin/#admindra-mcp)
* Support: [admindra.com/support](https://admindra.com/support/)

== Installation ==

1. Install and activate **AdMindra MCP**.
2. It needs **MCP Adapter** 0.7 or newer, the free MCP server plugin from
   the WordPress AI team. If it is not active yet, Tools → AdMindra MCP (and
   the Plugins screen) show a button: WordPress installs and activates it on
   its own screen and brings you back. You can also install it yourself
   under Plugins → Add New.
3. Make sure the site uses HTTPS and pretty permalinks (Settings →
   Permalinks, anything but "Plain").
4. Open **Tools → AdMindra MCP** and copy the MCP URL, normally
   `https://your-site/wp-json/mcp/mcp-oauth-server`.
5. Connect your assistant (step-by-step instructions with your own URL are
   on the same screen):
   * **Claude** (claude.ai, desktop and mobile): Settings → Connectors → Add
     custom connector, paste the URL, leave the OAuth client ID and secret
     empty, and choose Connect.
   * **Claude Code**: `claude mcp add --transport http mysite <MCP URL>`, then
     `/mcp` → Authenticate.
   * **ChatGPT**: add a custom MCP connector with the URL and OAuth.
   No client secret and no WordPress password are needed.
6. Sign in to WordPress as an administrator when asked, and approve the
   consent screen, which names the assistant.
7. Ask the assistant for the site status. Switch content edits on under
   Tools → AdMindra MCP when you want it to change text.

== Frequently Asked Questions ==

= Can the assistant change my site? =

Only its content, and only after you switch content edits on: the title,
text and excerpt of posts and pages, and the site title and tagline. Each
change keeps a revision. It cannot install, update, activate or delete
plugins or themes, write files, or change users and other settings.

= How do I undo an edit? =

Open the post or page in the editor and choose Revisions. The text before the
assistant's change is there.

= Why do I need MCP Adapter? =

MCP Adapter, by the WordPress AI team, is the MCP server: it is what ChatGPT
and Claude talk to. AdMindra MCP adds the tools, OAuth sign-in and the
settings screen on top. AdMindra MCP activates without it and shows a button
that opens WordPress's own install screen for it.

= Do I need an AdMindra account? =

No. The plugin works on its own and sends nothing to AdMindra.

= Which AI clients can connect? =

Claude (claude.ai, the desktop and mobile apps, and Claude Code) and ChatGPT
(chatgpt.com), each identified by the OAuth client metadata document it
publishes, so nothing has to be registered or pasted. If ChatGPT shows you a
connection-specific client URL, paste it under Tools → AdMindra MCP. No other
client is trusted.

= Claude asks for an OAuth client ID =

Leave the client ID and secret under Advanced settings empty. Claude
identifies itself with its own client metadata, and this plugin trusts it.

= How do I disconnect an assistant? =

Users → Profile → Application Passwords: delete the entry with the
assistant's name. Its access and refresh tokens stop working at once.

= The OAuth discovery links show a 404 or a login page =

Both `/.well-known/oauth-protected-resource` and
`/.well-known/oauth-authorization-server` must reach WordPress. Save your
permalinks again, exclude those paths and `/wp-json/mcp/` from page caches,
and ask your host whether the web server answers `.well-known` itself.

= The assistant gets 401 =

The token expired or was revoked, or the host strips the `Authorization`
header before PHP sees it. Reconnect, and ask the host to pass
`Authorization: Bearer` through.

= I had "AdMindra WP MCP" =

That was this plugin's name up to 0.11.0. Deactivate and delete it; AdMindra
MCP picks up your settings.

== External services ==

This plugin connects to the AI service that a site administrator chooses to
connect (ChatGPT by OpenAI, or Claude by Anthropic). Nothing is contacted
until an administrator starts connecting one of them. The plugin sends
nothing to AdMindra or to 3on Reklambyrå & Webbyrå AB.

= ChatGPT (OpenAI) =

ChatGPT is an AI assistant by OpenAI. The plugin uses it as the MCP client
that reads the site, at the administrator's request.

* **When ChatGPT connects**, the plugin downloads ChatGPT's public OAuth
  client metadata document from `https://chatgpt.com/oauth/client.json` (or
  the connection-specific `https://chatgpt.com/oauth/…/client.json` an
  administrator saved under Tools → AdMindra MCP), to verify that the client
  asking for access is ChatGPT. The request contains no data about the site
  beyond what any web request carries (the server's IP address and
  WordPress's user agent, which includes the site's address). The document
  is cached and fetched again only when the cache expires.
* **After an administrator approves the consent screen**, ChatGPT receives
  the results of the tools it calls, and only those: the WordPress and PHP
  versions and the site's address, the installed plugins and themes with
  their versions, the updates WordPress last found, the titles, addresses
  and shortcodes of the pages it checks, the posts and pages it finds or
  reads, and the contents of the source files it reads.

Terms of use: https://openai.com/policies/terms-of-use/
Privacy policy: https://openai.com/policies/privacy-policy/

= Claude (Anthropic) =

Claude is an AI assistant by Anthropic. The plugin uses it as the MCP client
that reads the site, at the administrator's request.

* **When Claude or Claude Code connects**, the plugin downloads Claude's
  public OAuth client metadata document from
  `https://claude.ai/oauth/mcp-oauth-client-metadata` (Claude) or
  `https://claude.ai/oauth/claude-code-client-metadata` (Claude Code), to
  verify that the client asking for access is Claude. The request contains
  no data about the site beyond what any web request carries (the server's
  IP address and WordPress's user agent, which includes the site's address).
  The document is cached and fetched again only when the cache expires.
* **After an administrator approves the consent screen**, Claude receives
  the results of the tools it calls, and only those — the same list as for
  ChatGPT above.

Terms of service: https://www.anthropic.com/legal/consumer-terms
Privacy policy: https://www.anthropic.com/legal/privacy

= Your own site =

The bundled OAuth library adds a Site Health test that loads the site's own
`/.well-known/oauth-protected-resource` and
`/.well-known/oauth-authorization-server` documents, when an administrator
opens Tools → Site Health. That request goes from the server to the site
itself and nowhere else.

The plugin itself never contacts WordPress.org: the "Available updates" tool
reads what WordPress's own update check has already stored, and the Install
MCP Adapter button opens WordPress's own install screen, where WordPress
downloads MCP Adapter from WordPress.org as it does for any plugin.

== Privacy ==

The plugin stores, in your own database, the content edits switch and a
ChatGPT client URL if you saved one. Content edits are kept by WordPress as
revisions. The bundled OAuth library stores a signing secret and creates one
Application Password per connected client, listed under Users → Profile.
Deleting the plugin removes its own options, including any that version
1.0.0 or earlier left behind (its edit switch, audit log and file backups).

AdMindra's privacy policy, which says the same: https://admindra.com/privacy/

== Source and bundled code ==

Everything in the plugin is plain PHP source. It bundles
[wp-media/mcp-oauth](https://github.com/wp-media/mcp-oauth) 2.0
(GPL-2.0-or-later) and
[wp-media/apply-filters-typed](https://github.com/wp-media/apply-filters-typed)
1.2 (GPL-3.0-or-later) by WP Media in `vendor/`, installed with
`composer install --no-dev` from `composer.lock`; their licences are beside
them. Because one bundled library is GPLv3, the plugin as distributed is
covered by GPLv3; AdMindra's own code is GPLv2 or later. The OAuth library is a WP Media project, not an
official WordPress component. Three local changes to it — negotiating the
public-client method for ChatGPT's metadata, stricter token time and scope
checks, and binding codes and refresh tokens to the client that asked for
them — are recorded in `patches/oauth-2.0-chatgpt-and-claims.patch`.

== Changelog ==

= 1.1.1 =
* Activates even when MCP Adapter is not active yet, instead of WordPress
  stopping on an error page. Tools → AdMindra MCP and the Plugins screen
  show one button that opens WordPress's own install screen for MCP Adapter
  and comes back when it is active.
* "Available updates" also says the installed version, what each update
  needs and whether it fits the site, and links WordPress's Updates screen.
  It still only reads.

= 1.1.0 =
* The tools that could replace plugin and theme files, restore a backup and
  run plugin and theme updates are removed from this plugin, together with
  the switch that turned them on and the code behind them. They are the
  separate add-on AdMindra MCP Maintenance.
* New: find, read and edit posts and pages, and the site title and tagline,
  behind a content edits switch that is off by default. Every edit keeps a
  revision and is refused if the post changed since it was read.
* "Available updates" reads WordPress's own stored update check instead of
  starting one, so the plugin never contacts WordPress.org itself.
* The readme lists each external service with what is sent and when.
* Uninstall also removes what 1.0.0 left behind.

= 1.0.0 =
* Renamed from AdMindra WP MCP for the plugin directory ("wp" is not allowed
  in a plugin name). Settings, the audit log and backups carry over.
* Fixed: updating an active plugin over MCP left it deactivated. It now stays
  active, and the health check runs against the new code.
* Fixed: a lock left by a killed request blocked every later edit until it
  was removed by hand. It now expires after 30 minutes.
* The registration audit no longer has one site's name built in; pass
  `search` to look for any text.
* File edits and updates use WordPress's filesystem API, and are refused
  without direct filesystem access.
* Translatable, with Settings, documentation, support, terms and privacy
  links, and an uninstaller.
* Step-by-step connection instructions for Claude, Claude Code and ChatGPT
  on the settings screen.

= 0.11.0 =
* Last release as AdMindra WP MCP.

== Upgrade Notice ==

= 1.1.1 =
Activates without MCP Adapter and offers to install it, instead of an error page.

= 1.1.0 =
File edits and updates moved to the add-on AdMindra MCP Maintenance. New:
content edits, off until you switch them on.
