One MCP server for every WordPress site you run.
Point your AI tool at Yovale and manage your sites, content and store in plain language — through one MCP server that's scoped, audited and approval-gated by default. In development; the waitlist is open.
in development · works with any MCP client · we'll email when preview opens
Paste one config. Done.
It's a standard remote MCP server over Streamable HTTP, so it drops into any MCP-capable client. Add the endpoint and a scoped token once and your AI tool can see every site on your account.
{
"mcpServers": {
"yovale": {
"url": "https://mcp.yovale.com/sse",
"headers": { "Authorization": "Bearer yv_live_••••" }
}
}
}You ask. It calls the tools.
No syntax to memorise. Describe what you want and the model picks the right tools, runs them in order, and shows its work — every call logged, destructive ones gated behind your approval.
- clone_site(shop.example → staging)12s
- create_backup(staging.shop.example)b-4f2
Not one MCP — a suite of them.
Each surface of the platform gets its own server, with only the tools that surface needs. None of this ships today — here's what the first set covers.
Run all your hosting from one server.
The account-level MCP exposes everything the dashboard can do — sites, backups, domains, SSL, cache, logs, metrics, and a WP-CLI passthrough. Manage one site or fifty in plain language. This is the agency superpower.
- list, create, clone, back up and restore sites
- domains, SSL, cache, container restarts
- tail logs and read metrics without leaving your editor
Your site's content, spoken to.
Built on WordPress 6.9's core Abilities API and the official MCP adapter, shipped as a signed Yovale platform component — no plugin work from you. Posts, media, plugins and settings become tools your AI can call, every one scoped and approval-gated.
- posts, pages, media, plugins, settings as tools
- ships as a signed mu-plugin, zero config
- destructive calls always wait for your approval
- posts / pagescreate · update · publish
- media libraryupload · alt-text
- plugins / themesinstall · activate
- settingsread
Ask your analytics a question.
A read-only server over your traffic, AI-crawler activity, performance and the change timeline. Your AI tool answers “why did traffic drop” with the actual data — and the deploy or plugin that explains it.
- traffic, funnels, AI-bot and referral data
- the change timeline a plugin can't see
- read-only — it can't touch the site
WooCommerce MCP
soonOrders, products, customers, coupons and stock — the backbone for an AI support agent.
Browser MCP
soonA disposable sandboxed browser scoped to your site: visit, screenshot, test a checkout.
wp-intel MCP
soonQuery the competitive dataset — which plugins and stacks your rivals run. Premium.
Multi-site orchestration
soonOperate across your whole portfolio at once — update, scan, report. The agency tier.
The hard part, handled for you.
Most self-hosted MCP setups leave an open, over-privileged port on your origin. Yovale terminates MCP at our control plane and reaches your site over the same authenticated tunnel the dashboard uses.
- Per-site scoped tokens — each only what it needs
- Approval-gated on every destructive call
- Full audit log — who called what, when, with what result
- Rate-limited, revocable, never an open port on your origin
- posts.read
- posts.write
- media.write
- users.deletedenied
- billing.readdenied
Every tool, named.
A reference of what your AI tool can call. Grouped by surface, scoped per token. This is the planned first set — it'll grow.
- list_sites()
- get_site()
- create_site()
- clone_site()
- delete_site()
- backup()
- restore()
- list_backups()
- verify_backup()
- add_domain()
- verify_domain()
- issue_ssl()
- purge_cache()
- restart_container()
- tail_logs()
- get_metrics()
- wp_cli()
- create_post()
- update_post()
- upload_media()
- install_plugin()
- list_orders()
- get_order()
- update_product()
- stock_levels()
Questions before the waitlist.
When does this ship?
Private preview targets 2026, with the Platform MCP first since it's the cheapest to build and the biggest agency win. Waitlist subscribers get access in waves and see the final pricing before paying.
Which AI tools can connect?
Any MCP-capable client. It's a standard remote MCP server over Streamable HTTP, so Claude Desktop, Claude Code, ChatGPT, Cursor and Codex all work — add the endpoint and a token once.
Do I have to install a plugin?
No. The per-site WordPress MCP ships as a signed Yovale platform component built on WordPress 6.9's core Abilities API and the official adapter. Nothing for you to install or configure.
Is it safe to give an AI tool access to my site?
That's the whole point of routing it through us. Tokens are scoped to only the capabilities they need, every call is logged, destructive actions wait for your approval, and MCP terminates at our control plane — never an open port on your origin.
Can it touch every site on my account?
The Platform MCP can, which is the agency superpower — manage fifty sites from one place. You control scope per token, and multi-site actions are still gated and audited.
Is this the same as the AI agents?
Related but separate. Agents are workflows Yovale runs for you. MCP is the bridge that lets your own AI tool drive your sites. Many customers will use both.
Connect your AI tool before preview opens.
We're opening preview in waves, Platform MCP first. Waitlist subscribers help shape the tool catalog and see the pricing before anyone pays.