start•Last updated: 2026-09-02

Authentication Methods

Comprehensive guide to authenticating with More MCP using OAuth 2.0 PKCE, Application Passwords, or static API keys.

Authentication Strategies

More MCP provides two primary authentication pathways depending on your client environment:

  1. OAuth 2.0 with PKCE: Recommended for interactive multi-user clients and web apps.
  2. Static API Keys (MMCP-Key): Recommended for local developer tools, CI/CD runners, and terminal agents (Claude Code, Cursor).

WordPress core Application Passwords are also supported when legacy authentication headers are needed.

Method 1: Static API Keys

Static API keys provide zero-friction setup for developer machines.

Creating an API Key

Navigate to More MCP -> Settings -> Authentication in your WordPress admin:

  1. Select Add Key.
  2. Set the User Association. The AI client will inherit the exact WordPress capabilities of this user (for example, Administrator or Editor).
  3. Set an optional expiration date.
  4. Copy the generated key.

Using the Key in HTTP Requests

Pass the key using the custom header MMCP-Key or standard Authorization: Bearer:

curl -X POST https://yourdomain.com/wp-json/more-mcp/v1/mcp \
  -H "MMCP-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"jsonrpc":"2.0","method":"tools/list","id":1}'

All static keys are cryptographically hashed using SHA-256 before database insertion. If a key is compromised, you can revoke it instantly from the admin table without altering your WordPress login password.

Method 2: OAuth 2.0 with PKCE

More MCP implements an RFC 7636-compliant OAuth 2.0 authorization server directly inside WordPress.

The Authorization Flow

  1. The client generates a random code_verifier and computes its SHA-256 code_challenge.
  2. The client opens the WordPress authorization URL in a browser:
    https://yourdomain.com/wp-json/more-mcp/v1/oauth/authorize?
      response_type=code&
      client_id=YOUR_CLIENT_ID&
      redirect_uri=YOUR_REDIRECT_URI&
      code_challenge=CODE_CHALLENGE&
      code_challenge_method=S256
  3. The WordPress administrator reviews requested scopes and clicks Approve.
  4. The browser redirects back to the client with an authorization code.
  5. The client exchanges the authorization code and code_verifier for an access_token and refresh_token.

Token Lifecycle & Refresh

  • Access tokens are short-lived (default: 1 hour).
  • Refresh tokens are single-use with automatic rotation. When a refresh token is used, a new pair is issued and the old one is invalidated immediately.

Security Best Practices

  • Always enforce HTTPS across your entire domain.
  • Create dedicated WordPress accounts for AI clients rather than sharing personal admin accounts, ensuring granular audit logging.
  • Regularly review active keys in More MCP -> Settings -> Keys.