Declarative tool discovery
Instead of asking a model to construct arbitrary HTTP requests, the MCP protocol delivers explicit JSON schemas defining exact tool signatures, typed input parameters, and required arguments. Clients like Claude, Cursor, Codex, and Windsurf consume these tools natively without guessing endpoint URLs.
Clear separation of discovery and mutation
WPGuard splits WordPress capabilities into strict permission tiers. Inspection tools (such as site_list and wp_site_context) allow models to explore site state safely, while mutation tools require explicit parameters, preview checks, and approved change packets before any database write occurs.
Streamable HTTP with bearer tokens
Rather than exposing administrative WordPress credentials across client machines, WPGuard runs as a dedicated server and secures its Streamable HTTP transport with scoped bearer tokens (recon, mutate, admin). An agent can be restricted to read-only audits or standard post updates without access to raw shell or PHP tools.
Infrastructure-level transport abstraction
WPGuard sits between your AI client and WordPress, connecting to the site over SSH with WP-CLI or via an allowlisted companion plugin. This shields WordPress from unauthenticated external access and provides a central audit log on infrastructure you control.