---
title: "Egenverk Sluice MCP — MCP server inside WordPress"
description: "Sluice MCP runs an MCP server inside WordPress: the agent gets the scopes you choose, every call is logged and every change can be undone."
canonical: https://egenverk.se/en/plugins/sluice-mcp
lang: en
updated: 2026-10-08
alternate: https://egenverk.se/plugins/sluice-mcp.md
---
# Let AI agents in. Only as far as you allow.

**Egenverk Sluice MCP** · Sluice runs an MCP server inside WordPress: the agent gets the scopes you choose, every call is logged and every change can be undone.

## Facts

- Availability: Pre-release
- Requires: WordPress 6.5+, WooCommerce 8.2+, PHP 7.4+

## Summary

Egenverk Sluice MCP is a WordPress plugin that runs an MCP (Model Context Protocol) server at `/wp-json/sluice/v1/mcp`. An AI client gets scoped read and write access to WordPress and WooCommerce as a chosen user. Every call is logged, every write can be undone and irreversible calls need human approval. Data does not leave the site.

**Before:** A REST key that can do everything, or the site's data sent through a third-party service.

**With Sluice:** Scopes per area, a log per call and a before/after image of every change.

## What it does, in plain words

- **MCP inside the site.** Endpoint `/wp-json/sluice/v1/mcp`. No relay service, no external account.
- **Scopes per area.** The connection runs as a WordPress user and never gets more than that user.
- **Log and undo.** Every call is logged. Every write saves a before/after image that can be undone.
- **A person approves.** Irreversible calls, such as permanent deletion, wait for a person.
- **WordPress and WooCommerce.** Posts, pages, media, menus, users, plugins — and products, variations, stock, coupons, orders and reports.
- **Emergency stop.** One constant switches everything off or makes it read-only. Keys are stored hashed and shown once.

## One connection, scopes per area

You connect an MCP client with an API key or OAuth. The connection runs as a WordPress user and gets scopes per area.

| Area | Examples |
| --- | --- |
| `content` | Posts, pages and menus |
| `media` | The media library |
| `woo.catalog` | Products, variations, stock and coupons |
| `woo.orders` | Orders and reports |

Every call is logged. Every write saves a before/after image that can be undone, and irreversible calls wait for a person. There is no relay service: traffic goes only between the site and the client.

## Privacy and data

- **Data out:** No. Traffic goes only between the site and the client you connect.
- **Protected:** Protected options and meta can never be written; secret-like values are masked.
- **Sign-in:** API key or OAuth with a consent screen.
- **Per connection:** Approval mode, expiry date, rate limit and IP list.

## Compatibility

- **WordPress:** 6.5 or later (tested to 7.1)
- **PHP:** 7.4 or later, tested to 8.4
- **WooCommerce:** 8.2 or later for the Woo module (HPOS)
- **Requires:** HTTPS (except local development hosts)
- **Version:** 0.109.2 — pre-release, 1.0 after OAuth testing

## Admin screens (example data)

- Log (Settings → Sluice → Log)
- Connections (Settings → Sluice → Connections)

## Questions

### Does my data leave the site?

No. There is no service in the middle; traffic goes only between the site and the MCP client you connect.

### What if the agent gets it wrong?

Every write has a before/after image in the log and can be undone from there. Irreversible calls run only after a person approves them.

### Which clients work?

MCP clients with an API key or OAuth.

### Can I buy Sluice MCP?

Not today. Sluice MCP is a pre-release that we show as an example of agent-ready WordPress. Contact us if you want to run it in your store.

## Resources

- [Contact us](https://egenverk.se/en/contact)

## Related products

- [Egenverk Babbla](https://egenverk.se/en/plugins/babbla): Team chat in wp-admin, with an assistant that answers from WooCommerce using tools that only read. (WordPress 6.2+, WooCommerce 7.0+, PHP 7.4+)
- [Egenverk Lagom](https://egenverk.se/en/plugins/lagom): Cleans the database, slims wp-admin and warns when requests run away. Shows counts before anything is deleted. (WordPress 6.5+, PHP 7.4+)
- [Egenverk Customer Hub](https://egenverk.se/en/plugins/customer-hub): A withdrawal function, returns and tracking in My Account, and AI suggestions from Egenverk Claims that a person approves. (WordPress 6.2+, WooCommerce 7.0+, PHP 7.4+)
