Skip to content

Easy MCP AI - Settings Reference ​

Easy MCP AI runs an MCP server inside WordPress so AI clients can read and manage the site. Since version 2.0.0 its screens live under the Easy MCP AI menu in the WordPress admin sidebar (placed just after Settings), in five sections: Dashboard, Connections, Tools, Activity, and Settings. The same five appear as tabs across the top of every plugin screen. The menu also has a Change history shortcut (opens Activity on its Change history tab) and About Us (Themeisle; hidden when white-labelled).

Feature gating: none. There is no Pro version or license. Every plugin screen needs the manage_options capability (administrators). Any setting can also be locked from wp-config.php or an environment variable; see wp-config constants.

The MCP endpoint is https://example.com/wp-json/easy-mcp-ai/v1/mcp (with Plain permalinks: https://example.com/?rest_route=/easy-mcp-ai/v1/mcp).

In this article

Plugins screen row ​

Action links on the Easy MCP AI row: Getting Started (opens the plugin), Plugin (Tools, Plugins tab), Abilities (Tools, Abilities tab), External Data (Tools, External data tab), and Settings. Row meta: Rate Plugin. The Themeisle SDK adds a rollback link and a feedback prompt on Deactivate.

The links and row meta are hidden when EASY_MCP_AI_HIDE_ADMIN is set. EASY_MCP_AI_HIDE_PLUGIN_ROW removes the plugin from the Plugins list entirely.

Setup wizard ​

Opens automatically after a fresh activation, at Easy MCP AI > Set up (admin.php?page=easy-mcp-ai-setup). Until setup is finished or skipped, Set up is the only menu item and every other plugin screen redirects to it. The wizard is skipped automatically on sites that already have an API token, an OAuth approval, or a logged tool call.

After setup, Set up leaves the menu. The URL still works, but nothing in the UI links back to it.

Every step has a Skip setup link (confirmation dialog: "Skip setup?"). Skipping and finishing do the same thing.

Step 1: Connect ​

Title "Connect your AI". One card per client, as an accordion:

ClientHow it connects
ClaudeConnect to Claude opens claude.ai with the server pre-filled (OAuth, no token)
Claude CodeTerminal command claude mcp add --transport http wordpress <endpoint>, then /mcp > Authenticate
ChatGPTOpen ChatGPT connectors, then paste the server URL (OAuth)
CursorAdd to Cursor deep link (one click)
Codex CLITerminal command with an API token. Generate a token into this command creates one
OpenCodeopencode.json snippet with an API token. Generate a token into this config creates one

On public sites, Claude, ChatGPT, and Cursor are shown first, and the rest sit under More ways to connect. On local sites (localhost, .local, .test, private IPs), the terminal and config clients come first, and cloud clients are marked "Needs a public URL".

More ways to connect also has a copyable prompt for any other client ("Connect to my WordPress MCP server at … and authenticate via OAuth.").

A token generated here is named "[client name] (setup)" (for example "Codex CLI (setup)"), belongs to the current user, has Full access (every tool), and expires in 30 days.

Step 2: Verify ​

Waits for the first tool call from the new client and shows "Connected." when it arrives. Detection needs a real tool call recorded in the audit log, so it never succeeds while the Audit log setting is off. After 60 seconds it offers Open full diagnostics. Continue unlocks once a call is detected. I'll connect later moves on to step 3 anyway.

Step 3: Try prompts ​

Title "Try these first". Five example prompts, each with Copy. A checkbox (off by default) opts in to anonymous telemetry; it sets the same value as Share anonymous usage data in Settings. Finish — go to Dashboard completes setup.

Dashboard ​

Easy MCP AI > Dashboard. The main column holds the status card, the connect card, Tools information, and Diagnostics. A side column (also shown on Connections, Tools, and Settings) holds MCP URL, an attention card, Recent activity, and Help.

Status card and Pause AI access ​

Hidden until at least one API token or OAuth grant exists. It shows "Connected: N API token(s) and N OAuth grant(s)", the stats Tool calls · 24h, Success rate · 24h, and Registered tools, and a weekly summary of AI changes with Review every change →. Buttons: Manage connections and Pause AI access.

Pause AI access (button with a confirmation dialog) keeps clients signed in but refuses every tool call, and clients see an empty tool list. Background tasks are suspended. Refused calls are written to the audit log. While paused, the card turns red with Resume AI access, the top bar status reads "Paused", and an "AI access is paused." banner with Resume AI access appears on the other plugin screens. Off by default. Locked by EASY_MCP_AI_PAUSED; an unrecognised constant value counts as paused.

Connect card ​

Title "Connect your AI client" when nothing is connected (then it is always open), otherwise "Connect another client" (collapsed, Connect an AI client opens it). Three steps: Choose a client (searchable; 8 featured clients plus Show all 18 clients), Add this site (one-click button, URL, command, or config, plus Use an API token instead), and Confirm it works (waits for the first tool call).

The 18 clients: Claude.ai, ChatGPT, Cursor, Claude Code, Claude Desktop & Cowork, OpenAI Codex CLI, GitHub Copilot (VS Code), OpenCode, Windsurf, Zed Editor, Cline (VS Code), Roo Code (VS Code), Google Antigravity, LibreChat, Manus, Pydantic AI (Python), Other (stdio via mcp-remote), and Generic MCP Client.

Tools information ​

Collapsed by default. Shows how many tools are available, the three reasons a client may see fewer (Token permissions, OAuth scope, User capabilities), and hints for tools that are not exposed yet (turned off, filtered by Settings, or an external provider not connected).

Diagnostics ​

Collapsed by default. A summary line ("All N checks passed." or a count of warnings and failures), Last run, and Re-run. The report groups checks into Server, Database, Authentication, Access & safety, Tools, Other plugins, Reachability, Logging, and Network (multisite), each with Pass / Warn / Fail / Skipped badges. The slower checks (Reachability, Logging, Network, and a few others) run only on Re-run; until then they show as one "Detailed check" row.

Some checks have fix buttons: Add the rewrite rule to .htaccess (Authorization header; on multisite only a super admin can write it) and copy buttons for the .well-known discovery files. Footer: Copy system info, Test from the internet (opens easymcpai.com/diagnose for this site), Copy AI prompt, and Email support.

When a blocking check fails, a red "AI clients can't connect." notice appears at the top of every plugin screen with a Diagnostics link.

Side column cards ​

  • MCP URL: the endpoint in a read-only field with a copy button.
  • N change(s) awaiting review: shown only when AI-created posts from the last 7 days are still drafts and Change history is on. Review changes opens Activity filtered to those drafts.
  • Recent activity: the 3 latest tool calls, with View all activity. Empty while the audit log is off.
  • Help: Documentation, Support forum, Rate the plugin, and Share feedback (hidden when white-labelled). Share feedback sends an anonymous message and the plugin version only.

Connections ​

Easy MCP AI > Connections. The connect card sits at the top, then two tabs: OAuth (default) and API tokens.

OAuth tab ​

Sections in order: site-move notice (only when needed), Token lifetimes and client registration, Registered clients, Active grants, and Pending device logins (only when there are some).

Token lifetimes and client registration ​

Collapsed by default, with its own Save settings button.

ControlTypeDefaultLock constant
Access token lifetimeNumber, seconds, minimum 603600 (1 hour)EASY_MCP_AI_OAUTH_ACCESS_TOKEN_TTL
Refresh token lifetimeNumber, seconds, minimum 602592000 (30 days)EASY_MCP_AI_OAUTH_REFRESH_TOKEN_TTL
Enable dynamic client registrationCheckboxOnEASY_MCP_AI_OAUTH_DCR_ENABLED

Dynamic client registration lets clients such as Claude, Cursor, and VS Code register themselves. While it is off, no new client can connect (clients cannot be added by hand), but existing connections keep working.

Registered clients ​

Columns: Client (name and auth method), Client ID (copyable), Redirects to, Registered, Status (Active or Unusable, plus how many access tokens the client holds). Actions: Rotate secret (confidential clients only; the new secret is shown once) and Revoke (removes the registration, its grants, and its tokens). Registrations nobody approved are deleted automatically after 7 days (EASY_MCP_AI_OAUTH_CLIENT_RETENTION).

Active grants ​

One row per user who approved a client. Columns: Client and user, Access level, Granted, Last used. Actions:

  • Edit scope: opens "Edit scope for [client name]". It can only narrow a grant (Full access, Read-only, or Custom with a Read / Write grid per category). Widening needs the user to approve again. The change applies to live tokens at once.
  • Revoke: signs that client out for that user immediately.

Pending device logins ​

Read-only list of terminal and headless clients waiting for a code to be entered. Columns: Client, User, Status, Started, Expires. Logins expire after 10 minutes.

Site-move notice ​

Appears when the site address changed (host, scheme, or path) and active OAuth tokens were issued for the old address. Those tokens are refused. Buttons: Revoke them (removes the old grants and any client left with none) and Dismiss (keeps them listed with an "Issued for a previous address" badge; they stay refused). Old-address tokens idle for 30 days are deactivated automatically.

API tokens tab ​

API tokens are for clients that cannot use OAuth. A token signs in as one WordPress user with the tools you allow.

Table columns: Token (name and user), Prefix (first 14 characters; the full token is shown only once), Access ("All tools", a preset name, or a tool count), Last used, Expires, Status (Active / Expired / Revoked, plus Self-service or Issued on another site badges). Row actions: Edit, Re-bind (only for tokens issued on another site), Revoke, and Delete. The list shows the newest 200 tokens.

Create token ​

Create token opens a side panel:

FieldTypeDefaultNotes
NameText, requiredEmptyWhich client holds it
WordPress userSelectThe current adminEvery tool runs with this user's permissions. Lists users who can publish posts (Authors and above)
Access levelPreset cardsFull accessFull access, Read-only, or Custom (see below)
ExpiresSelect30 days7 days, 30 days, 60 days, 90 days, Never, or Custom date (then an Expiration date picker). Dates are in UTC and the token works until the end of that day
ActiveSwitchOnEdit only. A revoked token can be switched back on here

Access presets (the same three appear on the OAuth consent screen):

  • Full access: all tools, current and future, including plugin integrations, external data, and WordPress Abilities.
  • Read-only: every read tool that exists when the token is saved. It can view content, settings, and the user list, but cannot change anything. Tools added later are not included.
  • Custom: pick tools one by one in a searchable tree grouped by category (Select all / Clear). At least one tool is required.

A "Security note" warns whenever the choice is not Read-only. After Create token, the full token (wpmcp_…) is shown once with a copy button. Editing a token's tools may need the client to refresh its tool list.

Re-bind ​

API keys only work on the site that issued them. Only the host is compared, so switching between www and non-www, or http and https, keeps them working. On a copied database (staging, clone), the keys are refused and an "issued on a different site" banner appears. Re-bind (confirmation: "Re-bind this token to this site?") makes one key work on the current site without affecting the original. EASY_MCP_AI_API_KEY_SITE_HOST overrides the host keys are bound to (no screen).

Screens outside the plugin menu ​

OAuth approval screen ​

Shown to the WordPress user when an AI client connects over OAuth. Title "Authorize Application". It shows the client name, the WordPress account it will act as, the client ID, and where it redirects. The user needs the Minimum capability to authorize setting (Authors and above by default); logged-out users go through the login screen first. It is skipped when an earlier approval already covers the request.

  • Access level (radio): Read-only, Full access, or Custom. Full access is preselected when the client asks for everything; otherwise Custom.
  • Customize permissions (collapsible): a Category / Read / Write table used with Custom. Plugin categories appear only when their plugin is active.
  • Buttons: Deny and Approve & Continue.

OAuth requires HTTPS, except on local addresses or with EASY_MCP_AI_OAUTH_ALLOW_HTTP.

Device login ​

For clients without a browser. The user opens https://example.com/?easy_mcp_ai_oauth=device ("Connect a Device"), enters the 8-letter Code shown by the client (format XXXX-XXXX), clicks Continue, and then sees the approval screen. Codes expire after 10 minutes.

Self-service API keys on the profile page ​

When Self-service API keys is on in Settings, eligible users (those with the Minimum capability to authorize) get an "Easy MCP AI API keys" section on their own Profile page. Administrators do not see it when editing another user.

  • Create API key (collapsible): Key name, Expires after (7, 30 (default), 60, or 90 days, Custom with a UTC date, or No expiration), and Allowed tools (checkboxes for the tools that user may call; no "all tools" option). Generate key shows the key once.
  • A table of the user's keys with Revoke (no confirmation).
  • A user can hold up to 10 active keys, including keys an admin created for them (EASY_MCP_AI_SELF_SERVICE_MAX_KEYS, 1 to 1000; no screen).
  • Admins see these keys in the API tokens table with a Self-service badge.

Tools ​

Easy MCP AI > Tools controls which tools exist for every client. 283 tools in total: 134 core, 95 from plugin integrations, and 54 from external data providers. Per-token and per-grant access is set separately under Connections.

Toolbar: section switch Core / Plugins / Abilities / External data (each with a count), a Show filter (All / Read-only / Write), Search, and a Descriptions switch (display only, remembered per browser). Each group has a master checkbox and per-tool checkboxes with Read or Write badges. Changes are saved with Save changes and apply to every client on its next call.

Core ​

Read-only view of the WordPress tools every site gets. No checkboxes here; destructive core tools are switched off under Settings > Advanced > Disabled tools, and disabled ones show a "Disabled" badge.

Groups: Posts (10), Pages (5), Media (7), Taxonomy (19), Comments (13), Users (8), Site Settings (5), Menus (10), Plugins (5), Themes (4), Revisions (4), Post Meta (3), Search (1), Blocks (9), Custom Post Types (5), Templates (3), Global Styles (2), Appearance (5), Widgets & Sidebars (7), Change History (3), Audit Log (1), and Site Health, Cron & Error Log (5).

Off by default on new installs (17 tools): wp_update_site_settings, wp_create_user, wp_update_user, wp_delete_user, wp_update_user_meta, wp_delete_user_meta, wp_update_template, wp_update_global_styles, wp_run_cron_event, wp_activate_plugin, wp_deactivate_plugin, wp_update_plugin, wp_switch_theme, wp_update_theme, wp_update_theme_mod, wp_delete_theme_mod, and wp_update_custom_css. Existing installs keep their previous choices on upgrade.

Plugins ​

Tool groups for third-party plugins. Every integration is listed, but a group can only be enabled while its plugin is installed and active. All groups are off by default. A plugin that isn't installed shows a Not installed badge and an Install button, which downloads and activates it from WordPress.org and turns its tools on (Install and enable). Users who can't install plugins get a link to the Plugins screen instead.

IntegrationToolsRequirement
WooCommerce47WooCommerce active
ACF / Secure Custom Fields6ACF or SCF; field groups need "Show in REST API"
The Events Calendar10The Events Calendar active
BuddyPress10Activity, Groups, and Messages components
Yoast SEO5Yoast SEO active
Rank Math SEO3Rank Math active; wp_rm_get_head needs Headless CMS Support
All in One SEO (AIOSEO)3AIOSEO 4.9.8 or later
SEOPress7SEOPress active
Slim SEO2Slim SEO active
The SEO Framework2The SEO Framework active

Abilities ​

Tools from the WordPress Abilities API (WordPress 6.9 or later; older versions show a notice). Each ability a plugin registers can be enabled as its own tool, named wp_ability_<slug>, grouped by plugin namespace. All abilities are off by default. Browse plugins with abilities opens the easymcpai.com abilities directory.

External data ​

SEO and analytics providers. Each provider has a card with setup steps, a credential form, Save [provider] settings, Test connection, and a tool list. A provider's tools stay unavailable until its credentials are saved; the first successful save turns all its tools on. Credentials are checked with the provider when saved and are stored encrypted with the WordPress security salts; if the salts are missing or placeholders, a notice appears and no credentials can be saved. Stored credentials show masked, with Replace key and Remove.

ProviderCredentialsExtra fieldsTools
Google Analytics 4Service account key (pasted JSON; Viewer access)Default property ID11
Google Search ConsoleService account key (pasted JSON)Default property URL (https://example.com/ or sc-domain:example.com)6
DataForSEOLogin (email) and API password (saved together)Balance in USD8
SemrushAPI key (Version 3)Balance in API units13
SE RankingAPI keyBalance in credits15
Ahrefs (DR)API key (free APIv3 key)None1

All external tools are read-only. There is no Google sign-in button; both Google providers use a service-account JSON key. Google providers also have Clear cache. The balance chip in the card header refreshes on click. Ahrefs is off by default, and saving a key switches its tool on. Who can call these tools (except Ahrefs) is set by Minimum capability for External Data tools in Settings.

Activity ​

Easy MCP AI > Activity has two tabs: Audit log (default) and Change history. Both have a filter bar (Filter / Clear), a Period (UTC) picker, pagination (10, 25 (default), 50, or 100 rows), and Clean up entries older than N days (deletes older rows now; confirmation required). Neither tab has export, undo, or restore.

Audit log ​

Every tool call. Filters: Search, Tool, User, Source (API key / OAuth), Status (OK, Error, Refused, Auth failed, Pending), and Period (UTC). Columns: Date, By, Client, Tool, Changes (links to the matching Change history rows), Arguments, Status, Duration, IP. Kept for Audit log retention days.

Change history ​

Before-and-after snapshots of every write made through MCP (edits made directly in wp-admin are not recorded). Filters: Object type, Show (All changes / Drafts awaiting review), Object ID, Tool, User ID, and Period (UTC). Columns: Date, Tool, Action (Create / Update / Delete), Object, By, Status (Draft / Published / Blocked / Done), and actions View before/after (a Field / Before / After table, with a link to the WordPress revision) and Originating call. A Capture settings link opens the capture options in Settings.

Settings ​

Easy MCP AI > Settings. Cards in order: Deployment-controlled settings (only when a constant is set), Access & safety, Logging & history, and Advanced. One Save changes bar saves all cards. A setting locked by a constant is disabled, with a lock icon ("Set by EASY_MCP_AI_… in wp-config.php.").

Deployment-controlled settings ​

Collapsible list of every setting defined outside WordPress, including ones with no screen, with an Invalid badge for values that are ignored in favour of the safe default.

Access & safety ​

SettingTypeDefaultConstant
Rate limitNumber, per minute, 1 to 100060EASY_MCP_AI_RATE_LIMIT_PER_MINUTE
Minimum capability to authorizeSelect: Author and above (default) / Editor and above / Administrators onlyAuthor and above (publish_posts)EASY_MCP_AI_OAUTH_MIN_CAPABILITY
Force draft on createSwitchOffEASY_MCP_AI_FORCE_DRAFT_ON_CREATE
Self-service API keysSwitchOffEASY_MCP_AI_SELF_SERVICE_KEYS
  • Rate limit: the most tool calls one token may make per minute.
  • Minimum capability to authorize: who can approve an AI client on the OAuth screen and who is eligible for self-service keys. It can only be raised above Author. Creating tokens on the Connections screen stays admin-only.
  • Force draft on create: new posts and pages are always saved as drafts, whatever status the AI asked for.
  • Self-service API keys: turning it off does not revoke existing keys.

Logging & history ​

SettingTypeDefaultConstant
Audit logSwitchOnEASY_MCP_AI_AUDIT_LOG_ENABLED
Audit log retentionNumber, days, 1 to 36530EASY_MCP_AI_AUDIT_LOG_RETENTION
Change historySwitchOnEASY_MCP_AI_CHANGE_LOG_ENABLED
Change history retentionNumber, days, 1 to 365030EASY_MCP_AI_CHANGE_LOG_RETENTION

Old entries are pruned daily. Change history can be kept forever only by setting EASY_MCP_AI_CHANGE_LOG_RETENTION to 0; the field itself starts at 1. Audit log retention has no keep-forever option. Advanced capture settings → opens the capture options.

Advanced ​

SettingTypeDefaultConstant
Minimum capability for External Data toolsSelect: Administrators only (default) / Editor and above / Author and aboveAdministrators onlyEASY_MCP_AI_EXTERNAL_DATA_MIN_CAPABILITY
Max title lengthNumber, characters, 0 to 20000 (no limit)EASY_MCP_AI_MAX_TITLE_LENGTH
Disabled toolsCheckbox grid of 28 destructive toolsThe 17 off-by-default tools checkedEASY_MCP_AI_DISABLED_TOOLS
Whitelist toolsText, comma-separated patternsEmpty (all tools)EASY_MCP_AI_ALLOWED_TOOL_PATTERNS
IP whitelistTextarea, one IP or CIDR range per lineEmpty (all addresses)EASY_MCP_AI_IP_WHITELIST
Share anonymous usage dataSwitchOffNone
  • Minimum capability for External Data tools: who can call the Google Analytics, Search Console, DataForSEO, Semrush, and SE Ranking tools. Tools a user cannot call are hidden from their client. Ahrefs is not affected.
  • Max title length: a longer post or page title makes the tool return an error.
  • Disabled tools: checked tools return an error for every client, whatever a token allows. The grid covers the 11 delete tools (posts, pages, media, comments, categories, tags, blocks, custom post type items, menus, menu items, revisions) plus the 17 off-by-default tools.
  • Whitelist tools: when set, only tools matching a pattern (for example wp_get_*, wp_list_*) are available, for every token. * and ? are wildcards. A live line shows how many tools stay available.
  • IP whitelist: requests from other addresses get a 403 and are logged. Cloud clients such as claude.ai and ChatGPT connect from the vendor's servers, not your IP. Behind a proxy, set EASY_MCP_AI_TRUSTED_PROXIES.
  • Share anonymous usage data: telemetry (versions, theme, active plugins, locale, install date, client types, tool usage). Also set by the setup wizard checkbox.

Capture settings ​

Opened with Advanced capture settings → or the Change history Capture settings link. Includes a "What is not recorded here" card listing 24 known gaps in change history. Saved with Save capture settings.

SettingTypeDefaultConstant
Option recording modeSelect: All options except churn (recommended) / Allowlist only (legacy)All options except churnEASY_MCP_AI_CHANGE_LOG_OPTION_MODE
Extended meta captureSwitchOnEASY_MCP_AI_CHANGE_LOG_CAPTURE_META
Capture raw database writesSwitchOffEASY_MCP_AI_CHANGE_LOG_CAPTURE_DB
Raw-write retentionNumber, days, 0 to 3650 (0 = never prune)7EASY_MCP_AI_CHANGE_LOG_DB_RETENTION
Record external write intentSwitchOnEASY_MCP_AI_CHANGE_LOG_EXTERNAL_INTENT
  • Extended meta capture: term, user, and comment meta plus network options. Post meta is always captured.
  • Capture raw database writes: custom-table and direct SQL writes during tool calls.
  • Record external write intent: records a marker when a write-style call changed nothing locally but contacted a remote service.

wp-config constants ​

Every setting above can be set with a constant in wp-config.php or an environment variable of the same name. Precedence: constant, then environment variable, then the saved value, then the default. A locked setting cannot be changed in the admin, and an invalid value falls back to the safe default with a warning. wp easy-mcp-ai config export prints the saved settings as define() lines.

Constants with no admin control:

ConstantDefaultPurpose
EASY_MCP_AI_OAUTH_ENABLEDtruefalse switches OAuth off; clients can then use API keys only
EASY_MCP_AI_OAUTH_ALLOW_HTTPfalseAllows OAuth over plain HTTP (local development only)
EASY_MCP_AI_OAUTH_MAX_CLIENTS5000Most registered OAuth clients; 0 refuses new registrations
EASY_MCP_AI_OAUTH_CLIENT_RETENTION7Days an unapproved registration is kept; 0 keeps them
EASY_MCP_AI_SELF_SERVICE_MAX_KEYS10Active self-service keys per user (1 to 1000)
EASY_MCP_AI_API_KEY_SITE_HOSTEmptyHost API keys are bound to, when it differs from the site address
EASY_MCP_AI_TRUSTED_PROXIESEmptyProxy IPs or CIDR ranges whose forwarded client IP is trusted
EASY_MCP_AI_CLIENT_IP_HEADERX-Forwarded-ForHeader that carries the client IP behind a trusted proxy
EASY_MCP_AI_CHANGE_LOG_DB_ROWS_PER_CALL200Raw database rows recorded per tool call; 0 removes the cap
EASY_MCP_AI_TASKS_BACKGROUNDtrueLong-running tasks advance in the background
EASY_MCP_AI_TASKS_TICK_BUDGET_SECONDS0Time one background step may run (0 = from PHP's limit)
EASY_MCP_AI_TASKS_RETENTION_DAYS7Days finished tasks are kept
EASY_MCP_AI_TASKS_MAX_PER_CREDENTIAL5Running tasks per API key or OAuth grant
EASY_MCP_AI_TASKS_MAX_CONCURRENT_TICKS3Background steps running at once across the site
EASY_MCP_AI_TOKEN_KEYSNoneSecret(s) for HMAC hashing of API keys and OAuth tokens; comma-separated, first is current, each at least 32 bytes. Not shown in the admin or exported

White-label and hiding:

  • EASY_MCP_AI_BRAND_NAME: replaces "Easy MCP AI" throughout the admin and turns on white-label mode (hides the logo, About Us, and Share feedback).
  • EASY_MCP_AI_HIDE_ADMIN: 'menu' hides the menu but keeps direct URLs working; true also blocks the plugin's admin pages and admin API with a 403.
  • EASY_MCP_AI_HIDE_PLUGIN_ROW: removes the plugin from the Plugins list (not from WP-CLI).

Labels and behavior that don't match ​

These are real controls, but their wording or behavior differs from what the UI suggests. Document the actual behavior.

WhereWhat the UI saysWhat actually happens
Setup wizard, Generate a token into this command/configThe token "is scoped to read and write content"The token has Full access (every tool)
Dashboard status card, Review every change →Opens the change reviewOpens Activity on the Audit log tab, not Change history
Settings, Advanced card descriptionMentions "credential hashing"There is no hashing control; it is set only with EASY_MCP_AI_TOKEN_KEYS
Settings, Whitelist toolsPatterns with * and ? wildcardsA pattern with no wildcard matches anywhere in the name (post matches wp_get_post); this is intended but not stated in the help text. The counts on the Tools screen treat it as an exact name, so they can differ from what clients get (tested: post gives clients 17 tools while Tools counts 0)
Lock icon tooltip"Set by … in wp-config.php."Also shown when the value comes from an environment variable
Was this helpful?