Authentication Methods
Comprehensive guide to authenticating with More MCP using OAuth 2.0 PKCE, Application Passwords, or static API keys.
Authentication Strategies
More MCP provides two primary authentication pathways depending on your client environment:
- OAuth 2.0 with PKCE: Recommended for interactive multi-user clients and web apps.
- Static API Keys (
MMCP-Key): Recommended for local developer tools, CI/CD runners, and terminal agents (Claude Code, Cursor).
WordPress core Application Passwords are also supported when legacy authentication headers are needed.
Method 1: Static API Keys
Static API keys provide zero-friction setup for developer machines.
Creating an API Key
Navigate to More MCP -> Settings -> Authentication in your WordPress admin:
- Select Add Key.
- Set the User Association. The AI client will inherit the exact WordPress capabilities of this user (for example, Administrator or Editor).
- Set an optional expiration date.
- Copy the generated key.
Using the Key in HTTP Requests
Pass the key using the custom header MMCP-Key or standard Authorization: Bearer:
curl -X POST https://yourdomain.com/wp-json/more-mcp/v1/mcp \
-H "MMCP-Key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","method":"tools/list","id":1}'
All static keys are cryptographically hashed using SHA-256 before database insertion. If a key is compromised, you can revoke it instantly from the admin table without altering your WordPress login password.
Method 2: OAuth 2.0 with PKCE
More MCP implements an RFC 7636-compliant OAuth 2.0 authorization server directly inside WordPress.
The Authorization Flow
- The client generates a random
code_verifierand computes its SHA-256code_challenge. - The client opens the WordPress authorization URL in a browser:
https://yourdomain.com/wp-json/more-mcp/v1/oauth/authorize? response_type=code& client_id=YOUR_CLIENT_ID& redirect_uri=YOUR_REDIRECT_URI& code_challenge=CODE_CHALLENGE& code_challenge_method=S256 - The WordPress administrator reviews requested scopes and clicks Approve.
- The browser redirects back to the client with an authorization code.
- The client exchanges the authorization code and
code_verifierfor anaccess_tokenandrefresh_token.
Token Lifecycle & Refresh
- Access tokens are short-lived (default: 1 hour).
- Refresh tokens are single-use with automatic rotation. When a refresh token is used, a new pair is issued and the old one is invalidated immediately.
Security Best Practices
- Always enforce HTTPS across your entire domain.
- Create dedicated WordPress accounts for AI clients rather than sharing personal admin accounts, ensuring granular audit logging.
- Regularly review active keys in More MCP -> Settings -> Keys.