Connect your assistant
1. Create a token for MCP
Open MCP in the dashboard and click one of its token buttons, or go to Settings → API tokens → Create token and pick an MCP preset:
| Preset | The assistant can | Tools |
|---|---|---|
| For MCP (read-only) | Look at your sites, backups, updates, settings and activity. It changes nothing. | 19 |
| For MCP (full) | Also create and change sites, take and restore backups, apply updates, manage staging, plugins, PHP, caching, domains and redirects, and make one-time Magic Login links. Destructive actions still need your confirmation. | 54 |
You can also tick permissions yourself: the assistant then sees exactly the tools those permissions allow (see Tools).
- Two-factor authentication is required to create a token. If you turn 2FA off later, your tokens stop working.
- Expiry: 1 to 365 days, 90 by default.
- Only from these addresses (optional): limit the token to your own IP addresses. This works through MCP too: MagicWP checks the address of the computer the assistant runs on.
- Copy the token when it is shown: it appears only once.
A token can never do more than your own role in the workspace. More about tokens: API tokens.
2. Add MagicWP to your assistant
The server address is:
https://mcp.magicwp.io/mcpIt uses Streamable HTTP, and your token goes in the Authorization header.
Replace mwp_your_token_here with your token.
claude mcp add --transport http --scope user magicwp https://mcp.magicwp.io/mcp \
--header "Authorization: Bearer mwp_your_token_here"--scope user makes MagicWP available in every directory, not just the
current project. Check the connection with /mcp inside Claude Code.
Keep the token out of shared files
The token is a password for your workspace. Don't commit a project config file that contains it; prefer the user-level config shown above, or an environment variable where the client supports one.
3. Check it works
Ask your assistant "Which MagicWP workspace am I connected to?". It answers with the workspace, your role and what the token may do. Then try one of the example prompts.
Change or remove access
- Different permissions: create a new token and replace it in your assistant's config, then revoke the old one.
- Remove access: revoke the token under Settings → API tokens. The assistant loses access at once.