MCP (AI assistants)
Safety and limits
What keeps an AI assistant in check, and the limits that apply through MCP
Your token decides
- The assistant sees only the tools your token's permissions allow, and a token can never do more than your own role in the workspace. If your role changes, the token follows at once.
- Use For MCP (read-only) when the assistant only needs to look. It can't change anything, whatever it is asked.
- Revoke the token under Settings → API tokens and the assistant loses access at once.
- Optionally limit the token to your own IP addresses. MagicWP checks the address of the computer your assistant runs on, not the MCP server's.
Destructive actions need you
Deleting or resetting a site, restoring a backup over it, copying another site over it, pushing staging live, deleting backups, plugins, themes, WordPress users or redirects, database search and replace, cleanup and prefix changes, regenerating salts, resetting PHP and removing domains are all destructive:
- Each one needs the site's domain typed as confirmation. The assistant is told to ask you for it and never to fill it in itself; a wrong or missing domain is refused.
- Each one is marked as destructive, so your client asks for your approval before running it.
- Don't turn on auto-approve for destructive tools in your client, so it always asks you before running them.
- Search and replace runs only after a preview of exactly the same change, made within the last 30 minutes.
- A staging push takes a backup of the live site first, so you can roll it
back for a few days (
list_staging_revert_points).
Magic Login links
magic_login makes a link that logs into wp-admin without a password. Because
the link appears in your chat, it is limited further than in the dashboard:
- it works once;
- it expires after 5 minutes (dashboard links last an hour);
- making one is recorded in Activities; the link itself never is;
- it needs the Magic Login permission, which the read-only preset doesn't have;
- the assistant is told to give you the link, not to open it.
send_password_reset_email uses WordPress's own reset email, so no password
ever passes through the chat. The site must be able to send email (see
Email).
Activity
Everything the assistant changes is recorded in Activities like any other change, marked via MCP, with your IP address.
What the MCP server never does
- It never stores your token: it is passed to the MagicWP API with each request and forgotten.
- It has no tools for billing and payments, members, API tokens, site transfers, SFTP and database passwords or backup download links.
check_site_upandsite_overviewonly fetch the site's own domains over HTTPS.
Limits
| Limit | Value |
|---|---|
| API requests per token | 300 reads and 60 changes per minute (details). One question can use several requests: site_overview makes about six. |
| Requests to the MCP server | 20 per second per IP address, with short bursts allowed |
| Failed sign-ins | After 20 failed attempts (wrong, expired or revoked token) from one address in 10 minutes, that address is refused for the rest of those 10 minutes |
| Waiting for a task | Up to 90 seconds per check. For longer jobs the assistant checks again |
| Magic Login link | Works once, valid 5 minutes |
| Search and replace preview | Valid 30 minutes, for exactly the same values |
| Token lifetime | 1 to 365 days, as chosen when you create it |