Skip to content

AI agents (MCP)

RowSprout Pro

RowSprout Pro lets an AI agent manage RowSprout on your site through the Model Context Protocol (MCP). Connect Claude Code, Claude Desktop, Cursor, VS Code or any other MCP client, and ask in plain language: “Add a page for Leiden and Delft to the plumber template, with an introduction for each, and publish them tomorrow at 09:00.” The agent reads the template, adds the rows, and generates or plans the pages.

RowSprout Pro offers 15 abilities. The MCP abilities reference lists each one with its parameters.

Area The agent can
Templates list them, read one in full (properties, rows and status), create one, change its title, content, URL pattern or status
Properties list them, add one
Rows (groups) list them, add one, change its values
Generating queue pages now, follow their progress, read a generated page
Planning read the planning, plan or clear rows, spread moments over many rows

Some things are deliberately not possible, to keep live pages safe:

  • Nothing can be deleted: no templates, properties, rows or pages. Use the WordPress admin for that.
  • Properties can be added, but not changed or removed.
  • On a WPML translation the agent can read and generate, but not write: translations are made with WPML’s own tools.
  • RowSprout Pro with a valid licence. Without one, the abilities are not registered.
  • WordPress 6.9 or later, which has the Abilities API built in. RowSprout Pro brings the MCP adapter itself; it is shared with other plugins that use it, such as Rank Math and WP Rocket.
  • A user for the agent. The agent acts as that WordPress user, with exactly that user’s rights: it can only change templates the user may edit. A separate user with the Editor role keeps the agent away from settings and plugins, and makes its changes recognisable in the revision history.
  • An application password for that user. Go to Users → Profile, scroll to Application Passwords, enter a name such as “Claude Code” and click Add New Application Password. Copy the password right away; WordPress shows it only once. WordPress offers application passwords only on sites with HTTPS (or in a local development environment).

The MCP endpoint of your site is:

https://example.com/wp-json/mcp/mcp-adapter-default-server

Claude Code and other clients with HTTP support

Section titled “Claude Code and other clients with HTTP support”

Clients that speak MCP over HTTP connect directly. The application password goes in an Authorization header as Basic authentication, so first encode username:application password in Base64:

Terminal window
# macOS / Linux
printf '%s' 'agent-user:abcd efgh ijkl mnop qrst uvwx' | base64
Terminal window
# Windows PowerShell
[Convert]::ToBase64String([Text.Encoding]::UTF8.GetBytes('agent-user:abcd efgh ijkl mnop qrst uvwx'))

Then add the server to Claude Code:

Terminal window
claude mcp add --transport http rowsprout https://example.com/wp-json/mcp/mcp-adapter-default-server \
--header "Authorization: Basic <the Base64 string>"

For a project-wide setup, the same in .mcp.json:

{
"mcpServers": {
"rowsprout": {
"type": "http",
"url": "https://example.com/wp-json/mcp/mcp-adapter-default-server",
"headers": {
"Authorization": "Basic <the Base64 string>"
}
}
}
}

The Base64 string is your password in a different form, not encrypted: keep it out of version control, just like the password itself.

Claude Desktop and other clients without HTTP support

Section titled “Claude Desktop and other clients without HTTP support”

For clients that only start local MCP servers, the @automattic/mcp-wordpress-remote proxy forwards to your site. It needs Node.js. In Claude Desktop’s configuration file (Settings → Developer → Edit Config):

{
"mcpServers": {
"rowsprout": {
"command": "npx",
"args": ["-y", "@automattic/mcp-wordpress-remote@latest"],
"env": {
"WP_API_URL": "https://example.com/wp-json/mcp/mcp-adapter-default-server",
"WP_API_USERNAME": "agent-user",
"WP_API_PASSWORD": "abcd efgh ijkl mnop qrst uvwx"
}
}
}
}

On your own machine, the client can also start WP-CLI directly, without an application password:

{
"mcpServers": {
"rowsprout-local": {
"command": "wp",
"args": [
"--path=/path/to/wordpress",
"mcp-adapter", "serve",
"--server=mcp-adapter-default-server",
"--user=agent-user"
]
}
}
}

The MCP adapter does not list every ability as a tool of its own. It offers three general tools, and the agent finds its way from there:

Tool What the agent does with it
mcp-adapter-discover-abilities gets the list of abilities, including RowSprout’s 15
mcp-adapter-get-ability-info reads one ability’s description and parameters
mcp-adapter-execute-ability runs one, for example {"ability_name": "rowsprout/list-templates", "parameters": {}}

Along with the abilities, the agent receives general guidance on how RowSprout works: placeholder tokens, how generation works, planning, what to check afterwards. The reference shows that text in full.

A typical task goes like this:

  1. list-templates, then get-template to see the properties, rows and status.
  2. add-template-group or update-template-group for the rows, add-template-property for a new column.
  3. generate-pages to build the pages now, or autofill-group-planning / set-group-planning to plan them.
  4. get-generation-status until the pages are done, and get-generated-page to check the result.
  • Generating is queued. generate-pages puts pages in the background queue and returns straight away; they are usually built within a minute. A good agent checks with get-generation-status.
  • Changing a URL leaves no redirect. When the agent changes a value that feeds a page’s address, the page moves and the old address stops working. The agent is told to warn you about this; check it yourself for pages that are already indexed.
  • Simultaneous edits are caught. If someone saves the template in the editor while the agent is working on it, the agent’s next change is refused instead of overwriting yours. The agent then reads the template again and retries.
  • Pages only appear for published templates. For a draft template, rows wait until the template is published.

To check the endpoint and the password without a client, start a session with curl:

Terminal window
curl -i -u 'agent-user:abcd efgh ijkl mnop qrst uvwx' \
-H 'Content-Type: application/json' -H 'Accept: application/json, text/event-stream' \
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"test","version":"1"}}}' \
https://example.com/wp-json/mcp/mcp-adapter-default-server

A working setup answers 200 with an Mcp-Session-Id header. Send that header along with the next request to call an ability:

Terminal window
curl -u 'agent-user:abcd efgh ijkl mnop qrst uvwx' \
-H 'Content-Type: application/json' -H 'Accept: application/json, text/event-stream' \
-H 'Mcp-Session-Id: <the session id>' \
-d '{"jsonrpc":"2.0","id":2,"method":"tools/call","params":{"name":"mcp-adapter-execute-ability","arguments":{"ability_name":"rowsprout/list-templates","parameters":{"per_page":5}}}}' \
https://example.com/wp-json/mcp/mcp-adapter-default-server
Answer Cause
401 with rest_forbidden Wrong username or application password, or application passwords are not available (no HTTPS).
No rowsprout/… abilities in the list RowSprout Pro is inactive or has no valid licence.
An ability answers with a permission error The user may not edit that template.

The abilities are ordinary WordPress Abilities, so PHP code can call them too, without MCP:

$result = wp_get_ability( 'rowsprout/get-generation-status' )->execute( [ 'template_id' => 123 ] );

They check the permissions of the current user, as they do for an agent. The how-to guide Import rows from a spreadsheet uses them this way.