MCP (AI assistants)
Tools
Every tool the MagicWP MCP server offers, what it does and the permission it needs
The MCP server has 54 tools. Your assistant sees only the ones your token's permissions allow: a For MCP (full) token sees all 54, a For MCP (read-only) token sees 19. You don't call tools yourself; your assistant picks them from what you ask.
The Needs column is the token permission, as it is named under Settings → API tokens. Any token means every token can use the tool.
Read
These only look. They never change anything on your sites.
| Tool | What it does | Needs |
|---|---|---|
whoami | The workspace you're connected to, your role, what the token may do and when it expires | Any token |
list_sites | Your sites with their status, PHP and WordPress version and storage | Any token |
get_site | One site's details: domains, status, versions, storage, notes | See the site |
site_overview | Everything at a glance: whether the site answers over HTTPS, pending updates, latest backups, running tasks and resource use. Says so while a site is still being built | See the site |
check_site_up | Fetches the site's front page over HTTPS: status code, response time, redirect and certificate | See the site |
site_metrics | CPU, memory, disk and traffic: live, today, or the last 30 days | See the site |
list_activity | What happened on a site, or across the workspace | See the site, or the workspace activity log |
catalog | Regions, base domains, templates, and how many sites you can still create | Any token |
list_tasks | Background tasks running now, or one site's recent tasks | Any token |
get_task | A task's progress and result, and which step a site build is on. Can wait for it to finish | Any token |
list_backups | A site's backups, or full backups across the workspace | Any token |
get_staging | A site's staging copy, and what pushing it live would change | See the site |
list_staging_revert_points | The backups taken automatically before each staging push, so a push can be rolled back | See the site |
list_extensions | Installed plugins or themes with versions and available updates, or a search on WordPress.org | See the site |
list_updates | Pending core, plugin and theme updates on one site or all of them | See the site |
get_site_config | WordPress settings, debug and maintenance mode; PHP version, php.ini, PHP-FPM and extensions; page cache, nginx features and Redis | See the site |
list_wp_users | The site's WordPress users and their roles | Manage WordPress users |
database_stats | Table sizes, and how much a cleanup would remove | See the site |
search_replace_preview | A dry run of a database search and replace: how many rows would change | Database |
list_redirects | The site's redirect rules | See the site |
list_domains | The site's custom domains, their status and the DNS records they need | See the site |
Change
These change something that is easy to change back, or harmless to repeat. Your assistant may still ask before it runs them.
| Tool | What it does | Needs |
|---|---|---|
create_site | Starts building a new WordPress site. The assistant tells you when it's ready | Create sites |
clone_site | Copies a site into a new site | Create sites |
update_site | Renames a site or edits its notes | Edit the label and notes |
site_power | Restarts a site, or runs Fix (repairs Redis, the MagicWP plugin and the database connection) | Restart, fix, maintenance |
create_backup | Takes a full backup now and keeps it until you delete it | Backups |
manage_staging | Creates a staging copy, or gives it more time | Create and extend staging |
manage_extension | Installs, activates, deactivates or updates plugins and themes, or turns their auto-update on or off | Plugins and themes, or updates |
manage_updates | Checks for updates, applies them, and turns auto-updates on or off | Updates |
update_wp_config | WordPress settings (site title, timezone and more), debug mode and maintenance mode | WordPress settings, or restart, fix, maintenance |
magic_login | A one-time link that logs you into wp-admin. It works once and expires after 5 minutes | Magic Login |
send_password_reset_email | Sends WordPress's own Password Reset email to a WordPress user | Manage WordPress users |
manage_wp_user | Creates a WordPress user, edits one, or changes their role | Manage WordPress users |
update_php | PHP version, php.ini, PHP-FPM settings and extensions | PHP, caching and Redis |
update_cache_config | Page-cache expiry, nginx features and the Redis object cache | PHP, caching and Redis |
flush_cache | Clears the WordPress, page, OPcache or Cloudflare cache | Restart, fix, maintenance, or domains |
manage_redirect | Creates, changes or imports redirect rules | Redirects |
manage_domain | Adds a custom domain, re-checks its DNS, or makes it the site's address | Domains |
Destructive
These lose data or are hard to undo. Each one needs confirmation: the site's domain, typed by you (see Safety).
| Tool | What it does | Needs |
|---|---|---|
delete_site | Deletes a site and everything on it | Delete the site |
reset_site | Wipes the site's files and database and reinstalls WordPress | Reset and restore |
restore_backup | Restores a backup over a site, or a full backup of one site onto another | Reset and restore |
clone_into_site | Copies one site over an existing site, replacing everything on it | Reset and restore |
push_staging | Replaces the live site with its staging copy (a revert point is taken first) | Reset and restore |
delete_backup | Deletes a kept or download backup | Backups |
delete_extension | Deletes plugins or themes with their files | Plugins and themes |
delete_wp_user | Deletes a WordPress user and hands their posts to another user | Manage WordPress users |
shuffle_salts | Regenerates the WordPress keys and salts, signing everyone out | WordPress settings |
reset_php | Puts php.ini and PHP-FPM back to the plan defaults | PHP, caching and Redis |
search_replace | Replaces text across the whole database. Runs only after a preview of exactly the same change | Database |
database_maintenance | Optimizes tables, or deletes revisions, drafts, trash, spam and expired transients | Database |
change_db_prefix | Renames every database table to a new prefix | Database |
delete_redirects | Deletes redirect rules | Redirects |
remove_domain | Disconnects or deletes a custom domain | Domains |
detach_cloudflare_dns | Removes the DNS records MagicWP wrote in Cloudflare for the site | Domains |
Not available through MCP
On purpose, the MCP server has no tools for:
- billing and payments, members and invitations, API tokens and site transfers;
- SFTP and database passwords and phpMyAdmin;
- setting a WordPress user's password (use
send_password_reset_email); - backup download links, email provider settings and connecting Cloudflare.
Those stay in the dashboard.